Skip to main content
Go to documentation:
⌘U
Weaviate Database

Develop AI applications using Weaviate's APIs and tools

Deploy

Deploy, configure, and maintain Weaviate Database

Query Agent

Run agentic search over your Weaviate Cloud collections

Weaviate Cloud

Manage and scale Weaviate in the cloud

Engram

Persistent memory for LLM agents and applications

Additional resources

Integrations
Weaviate Academy

Need help?

Weaviate LogoAsk AI Assistant⌘K
Support
Community Forum
Contributor guide

Web client

@weaviate/web is a browser build of the v3 client. Use it in browsers and edge runtimes such as Cloudflare Workers and Vercel, where a plain gRPC connection is not possible.

It has the same API as weaviate-client, but sends queries over gRPC-Web. Connect options take one HTTP(S) endpoint. There is no gRPC host or port to set, because Weaviate serves gRPC-Web on the REST port.

Alpha

@weaviate/web 3.15.0-alpha.6 is an alpha. The latest tag still points at 3.15.0-alpha.2, an older alpha that fails to load, so always install the version explicitly.

Install​

Install the alpha explicitly:

npm install @weaviate/web@3.15.0-alpha.6

The latest tag still points at an older alpha that fails to load, so name the version.

The package is ESM-only.

Connect to Weaviate​

Use a connectTo* helper. The low-level weaviate.client(params) entry point does not add the /v1/grpc-web prefix. grpcHost, grpcPort and grpcSecure are not connect options. If you pass them, they are ignored.

Added in v1.38.3

Weaviate serves gRPC-Web by default from v1.38.3.

So the web client needs Weaviate v1.38.3 or later. On v1.38.2 it fails to connect, and the error names the missing path:

/grpc.health.v1.Health/Check UNIMPLEMENTED: Received HTTP 404 response:
{"code":404,"message":"path /v1/grpc-web/grpc.health.v1.Health/Check was not found"}

For the server side, see gRPC-Web.

Browser notes​

Provider API keys work in the browser. Other custom headers do not. Model provider keys passed through headers, such as X-OpenAI-Api-Key, are on Weaviate's default CORS allow-list, so they work cross-origin out of the box. Any other header fails the browser's CORS preflight unless the operator lists it in CORS_ALLOW_HEADERS on the server. Setting that variable replaces the default list, so include the defaults you still need. Node runs no preflight, so test header behavior in a real browser.

Browser credentials are visible to the user

Anyone who loads your page can read whatever the bundle holds, including Weaviate and model provider API keys. Use a read-only API key with the least RBAC permissions the app needs. Never ship an admin key to a browser.

Questions and feedback​