ORIGINAL FORGE · NETWORK BOUNDARY

Forge Offline & Privacy

Know what must be prepared, what may still call out, and how to prove one exact workflow works without internet.

Core commitdfdcbabNetwork surfaces12Runtime testNot executedChecked31 Aug 2026
DIRECT ANSWER

Offline-capable after preparation. Not offline by default.

VERIFIED

The inspected Original Forge core can generate from local files without internet after the exact environment and workflow assets are present. It has no universal offline switch, and localhost does not stop Python, Git, installers or extensions from making outbound requests.

Forge disables Gradio analytics in core. That is narrower than “no telemetry anywhere.” Dependencies, optional tools and extensions keep separate boundaries.

CORE INFERENCEOFFLINE-CAPABLE
GRADIO ANALYTICSDISABLED IN CORE
NO OUTBOUNDTEST REQUIRED
01 · TWO QUESTIONS

A local address is not a network policy.

The browser-to-Forge route and Forge-to-internet route are independent. Check both.

YOUR COMPUTER
BBrowser127.0.0.1
LOOPBACK
FForge Pythonlocal server
SEPARATE OUTBOUND PATH
NETWORK
Git / packagesModel hubsExtensions / tunnels
Default local bind limits inbound reach. It does not block outbound traffic. --listen changes inbound reach; a firewall test measures outbound attempts.
02 · LIFECYCLE

Network need changes by phase.

A txt2img pass answers one small question. Choose a phase to see what must be local and what can still connect.

NETWORK EXPECTED

A clean checkout is not a complete offline installation.

CAN STAY LOCAL

Your launcher, configuration and files already present.

MAY CONNECT

Missing packages, Torch, pinned repositories and Git archives can be fetched during preparation.

ACCEPTANCE PROOF

Save the successful first-launch console plus package and model inventory.

03 · DOWNLOAD SURFACES

Cache the feature, not just the checkpoint.

A row is a possible trigger, not proof that every launch contacts its destination.

Showing all 12 surfaces

SurfaceTrigger / destinationOffline result
VERIFIED

Python / Torch packages

setup

A dependency is absent or mismatchedPackage index or configured mirror

Prepare online; absence can stop launch

VERIFIED

Pinned repositories

setup

Required code asset is absent or repairedConfigured Git repository

Clone/fetch can run before UI startup

VERIFIED

Core update check

startup

`--update-check` is suppliedGitHub API

Off by default at this commit

VERIFIED

Remote Gradio theme

startup

Non-default theme is selected and uncachedHugging Face Hub

The default theme avoids this fetch

VERIFIED

Preview / VAE helper

workflow

An approximate decoder is missingCode-defined model URL

Cache it before offline testing

VERIFIED

Interrogator / DeepBooru

workflow

Feature data or model is absentModel or data host

Basic generation proves nothing here

VERIFIED

Upscaler / face restoration

workflow

Selected model is absentModel host or direct URL

First use can fail offline

COMMUNITY-REPORTED

ControlNet preprocessor

workflow

Annotator model is absentExtension-defined model host

Reports are tool-specific

VERIFIED

Third-party installer

extension

Enabled extension runs its installerChosen by extension code

Outside a core-only claim

VERIFIED

Extension index / update

extension

User loads, installs or updatesIndex or Git host

Intentional; inspect source first

VERIFIED

Gradio share / Ngrok

sharing

Tunnel option is enabledPublic tunnel service

Needs network and changes exposure

VERIFIED

Remote API input URL

sharing

API client supplies an HTTP(S) imageClient-selected URL

Intentional outbound path

Missing from the table does not mean impossible. Third-party extensions execute Python in the Forge environment and may define destinations the core cannot inventory.

04 · ACCEPTANCE TEST

Deny, log, repeat.

Checklist state stays in this browser session only. Passing means the recorded workflow passed in the recorded environment.

Airplane modeproves work can finish≠Deny + logalso exposes attempts
  1. STEP 01

    Freeze one environment

    Record OS, GPU, Python, Torch, Forge commit, launcher, arguments and enabled extensions.

  2. STEP 02

    Define the exact job

    Name the checkpoint, VAE, sampler, dimensions, preview mode and every pre/postprocessor.

  3. STEP 03

    Prepare while connected

    Complete installation, start Forge and run that workflow once. Wait for intended assets.

  4. STEP 04

    Inventory the result

    Record package versions, model/cache paths, file sizes and model checksums.

  5. STEP 05

    Remove uncontrolled variables

    Test core with third-party extensions disabled; add required extensions separately.

  6. STEP 06

    Enable the HF cache guard

    Set both Hugging Face variables below before process start. They cover Hub calls only.

  7. STEP 07

    Deny outbound traffic

    Apply an OS firewall rule to Forge Python while preserving loopback; enable logging.

  8. STEP 08

    Repeat and preserve evidence

    Restart, run the same job, inspect console and firewall log, document exceptions.

0 / 8 marked
05 · HUGGING FACE GUARD

Use cache. Fail when incomplete.

VERIFIED

The pinned huggingface-hub 0.26.2 reads these variables before import. They govern Hub access and Hub telemetry—not GitHub, PyPI, direct URLs, tunnels or extensions.

Do not invent a --offline flag.

The inspected parser has no universal control by that name. A fork’s option is not Original Forge evidence.

set HF_HUB_OFFLINE=1
set HF_HUB_DISABLE_TELEMETRY=1
call webui-user.bat
06 · PRIVACY BOUNDARIES

Local generation still creates shareable traces.

Review the server, dependencies, extensions and output files separately.

VERIFIEDCORE ANALYTICS

Gradio analytics is disabled.

Forge sets the environment option false and builds main Gradio Blocks with analytics disabled.

UNKNOWNWHOLE ENVIRONMENT

No blanket telemetry guarantee.

Dependencies and extensions can behave separately. A core setting cannot certify arbitrary code.

VERIFIEDPUBLIC ACCESS

Tunnels are intentional exposure.

--share, Ngrok and broad binding change who can reach the UI.

Review bind flags →
“My prompts never leave my PC” is not established by this audit.

Only a clean-environment, process-level deny-and-log test can support that claim for one exact installation and workflow.

07 · WHEN OFFLINE FAILS

Locate the first missing boundary.

Keep the full traceback. The last progress percentage is not a diagnosis.

Forge stops before the local URL appears

Find the first URL, Git, pip, import or missing-file line. Prepare only that dependency in a controlled staging environment.

Basic txt2img works, but a preprocessor fails

The checkpoint is cached; the optional tool is not proven. Record its extension revision, preprocessor and expected model path, then retest only that workflow.

Generation reaches 100% and times out

Inspect preview, postprocessing, save callbacks, metadata and extension hooks. Issue #2042 is a dated similar report, not a universal cause.

Offline mode reports a missing Hub file

This is expected under HF_HUB_OFFLINE=1 when cache is incomplete. Prepare the named asset separately and retain evidence.

Forge works until extensions are enabled

The clean core passed. Add extensions one at a time at pinned revisions and monitor installer plus runtime traffic.

08 · USER QUESTIONS

Offline and privacy answers.

First run, caches, firewalls, prompts, APIs, extensions and air-gapped transfer—without turning one test into a universal promise.

Can Stable Diffusion WebUI Forge run completely offline?

A prepared Original Forge installation can run a tested local workflow without internet. “Completely” must be scoped: missing dependencies, helper models, extensions, remote themes, tunnels and API URLs can still request network. There is no universal offline flag in the inspected core.

Does Forge need internet every time it starts?

Not for a prepared core baseline. It may need network when preparation finds missing assets, an update action runs, a theme is uncached, or an enabled extension installer performs its own checks.

What does Forge download on the first run?

Depending on installation state, preparation can obtain packages, Torch and required repositories. Exact payloads vary by platform and version, so retain the first-run console rather than trusting a fixed size list.

Why does generation stop at 100% when I am offline?

Issue #2042 contains a dated report; the reporter later updated and confirmed flight-mode operation. Use the current traceback: a percentage cannot identify saving, preview, extension or model-fetch work.

Is localhost the same as offline?

No. Localhost describes how the browser reaches the server on the same computer. The Python process can still connect outbound.

Does 127.0.0.1 send my prompts to the internet?

That loopback request stays on the computer, but it does not prove Forge, a dependency or extension makes no separate request. Verify at process or firewall level.

What is the difference between 127.0.0.1 and 0.0.0.0?

127.0.0.1 is loopback. 0.0.0.0 is a bind instruction for all interfaces, not a browse address. Broader binding can expose the UI to the LAN.

Does Forge send telemetry?

The inspected core disables Gradio analytics. Forge does not set the Hugging Face telemetry opt-out. A universal claim is unknown because dependencies and extensions have separate behavior.

How do I disable Hugging Face network access?

Set HF_HUB_OFFLINE=1 before import. Cache is used and missing files error. This does not block GitHub, PyPI, direct URLs, tunnels or extension traffic.

How do I disable Hugging Face telemetry?

Set HF_HUB_DISABLE_TELEMETRY=1 before launch. It controls the pinned Hub library, not arbitrary extensions and not the firewall.

Is `--skip-install` an offline mode?

No. It skips package and extension installer work, but other preparation branches remain and an incomplete environment can fail later.

Should I use `--skip-prepare-environment` offline?

Only on a proven complete environment. It bypasses preparation; it does not enforce privacy or deny outbound traffic.

Can ControlNet work offline in Forge?

Yes when its exact extension code, preprocessor and model are present. Community reports show first-use annotator downloads, so test every required preprocessor.

Can upscalers and face restoration work offline?

Yes when the selected model files are cached. Each different model needs its own preparation receipt.

Do Forge extensions work offline?

Some do; others use online services or contact package/Git hosts. Disable extra extensions for the baseline and audit exact revisions one at a time.

Does `--share` work offline?

No. It requests a public Gradio tunnel and changes the exposure boundary. Keep share and Ngrok off for the offline baseline.

Can the Forge API fetch an image from the internet?

At this commit, the API can accept HTTP(S) image URLs when request fetching is enabled. Use local uploads or restrict the capability in an isolated deployment.

Are prompts stored inside Forge output images?

By default, generation infotext is written to image metadata. PNG also defaults to stealth Alpha mode. This is local metadata, not telemetry, but it may travel with a shared file.

How do I remove prompt metadata from generated images?

Disable infotext writing before generating release files, then inspect the exported artifact independently. Removing visible PNG text alone may not address the enabled stealth payload.

Can browser DevTools prove Forge made no network requests?

No. DevTools sees browser traffic; Forge runs Python and may launch installers or Git subprocesses. Use process-level logging or a deny-and-log firewall rule.

Is airplane mode a sufficient privacy test?

It proves a workflow can finish disconnected, but not whether failed calls were attempted. A logging firewall supplies stronger evidence.

How do I move Forge to an air-gapped computer?

Prepare on a closely matching staging machine, transfer reviewed code/packages/models under your controls, verify checksums, and retest. Portability across OS, Python, drivers and GPUs is not guaranteed.

09 · SOURCES & LIMITS

Source-audited, not network-certified.

The clean checkout at dfdcbab was inspected on 31 Aug 2026. Forge was not launched, no model downloaded and no packet capture performed.

Primary / direct evidence

Fresh intent and boundary checks

Local research reviewed: 8 relevant records
VERIFIEDVerified in code

Core analytics, binding, preparation branches, network features, metadata defaults and absent offline flag.

COMMUNITY-REPORTEDDated observations

Offline success and tool-download symptoms describe real jobs, not every build.

UNKNOWNNot certified

Your extensions, packet flow, every dependency, air-gap portability and legal compliance.

Author Forge Field Guide editorial teamTechnical review Original Forge at dfdcbabRuntime Source audit; Forge not executedUpdated 31 Aug 2026