Forge Offline & Privacy
Know what must be prepared, what may still call out, and how to prove one exact workflow works without internet.
Offline-capable after preparation. Not offline by default.
The inspected Original Forge core can generate from local files without internet after the exact environment and workflow assets are present. It has no universal offline switch, and localhost does not stop Python, Git, installers or extensions from making outbound requests.
Forge disables Gradio analytics in core. That is narrower than “no telemetry anywhere.” Dependencies, optional tools and extensions keep separate boundaries.
A local address is not a network policy.
The browser-to-Forge route and Forge-to-internet route are independent. Check both.
--listen changes inbound reach; a firewall test measures outbound attempts.Network need changes by phase.
A txt2img pass answers one small question. Choose a phase to see what must be local and what can still connect.
A clean checkout is not a complete offline installation.
Your launcher, configuration and files already present.
Missing packages, Torch, pinned repositories and Git archives can be fetched during preparation.
Save the successful first-launch console plus package and model inventory.
A prepared baseline can start offline, but no universal switch exists.
Cached packages, repositories, checkpoint, local default theme and settings.
Explicit update actions, repository repair, remote themes and extension installers can require network.
Restart under an outbound-deny rule; `--skip-install` alone is not proof.
Core inference can run from local files after preparation.
The inspected core loads a local checkpoint and performs inference in-process.
A missing model component, preview decoder or helper can be fetched on first use.
Repeat the same recorded job and inspect process-level connection attempts.
Every optional tool needs its own cache test.
Cached upscalers, annotators, taggers, restoration models and theme files.
Preprocessors, BLIP data, upscalers, restoration models, Spaces and extensions may fetch assets.
Warm and retest each tool; a txt2img pass does not prove it.
Cache the feature, not just the checkpoint.
A row is a possible trigger, not proof that every launch contacts its destination.
Showing all 12 surfaces
Python / Torch packages
setupA dependency is absent or mismatchedPackage index or configured mirror
Prepare online; absence can stop launch
Pinned repositories
setupRequired code asset is absent or repairedConfigured Git repository
Clone/fetch can run before UI startup
Core update check
startup`--update-check` is suppliedGitHub API
Off by default at this commit
Remote Gradio theme
startupNon-default theme is selected and uncachedHugging Face Hub
The default theme avoids this fetch
Preview / VAE helper
workflowAn approximate decoder is missingCode-defined model URL
Cache it before offline testing
Interrogator / DeepBooru
workflowFeature data or model is absentModel or data host
Basic generation proves nothing here
Upscaler / face restoration
workflowSelected model is absentModel host or direct URL
First use can fail offline
ControlNet preprocessor
workflowAnnotator model is absentExtension-defined model host
Reports are tool-specific
Third-party installer
extensionEnabled extension runs its installerChosen by extension code
Outside a core-only claim
Extension index / update
extensionUser loads, installs or updatesIndex or Git host
Intentional; inspect source first
Gradio share / Ngrok
sharingTunnel option is enabledPublic tunnel service
Needs network and changes exposure
Remote API input URL
sharingAPI client supplies an HTTP(S) imageClient-selected URL
Intentional outbound path
Missing from the table does not mean impossible. Third-party extensions execute Python in the Forge environment and may define destinations the core cannot inventory.
Deny, log, repeat.
Checklist state stays in this browser session only. Passing means the recorded workflow passed in the recorded environment.
- STEP 01
Freeze one environment
Record OS, GPU, Python, Torch, Forge commit, launcher, arguments and enabled extensions.
- STEP 02
Define the exact job
Name the checkpoint, VAE, sampler, dimensions, preview mode and every pre/postprocessor.
- STEP 03
Prepare while connected
Complete installation, start Forge and run that workflow once. Wait for intended assets.
- STEP 04
Inventory the result
Record package versions, model/cache paths, file sizes and model checksums.
- STEP 05
Remove uncontrolled variables
Test core with third-party extensions disabled; add required extensions separately.
- STEP 06
Enable the HF cache guard
Set both Hugging Face variables below before process start. They cover Hub calls only.
- STEP 07
Deny outbound traffic
Apply an OS firewall rule to Forge Python while preserving loopback; enable logging.
- STEP 08
Repeat and preserve evidence
Restart, run the same job, inspect console and firewall log, document exceptions.
Use cache. Fail when incomplete.
VERIFIEDThe pinned huggingface-hub 0.26.2 reads these variables before import. They govern Hub access and Hub telemetry—not GitHub, PyPI, direct URLs, tunnels or extensions.
--offline flag.The inspected parser has no universal control by that name. A fork’s option is not Original Forge evidence.
set HF_HUB_OFFLINE=1
set HF_HUB_DISABLE_TELEMETRY=1
call webui-user.batexport HF_HUB_OFFLINE=1
export HF_HUB_DISABLE_TELEMETRY=1
./webui.shLocal generation still creates shareable traces.
Review the server, dependencies, extensions and output files separately.
Gradio analytics is disabled.
Forge sets the environment option false and builds main Gradio Blocks with analytics disabled.
No blanket telemetry guarantee.
Dependencies and extensions can behave separately. A core setting cannot certify arbitrary code.
Prompts can travel inside images.
Infotext is enabled by default. PNG also defaults to stealth Alpha. Inspect final files before sharing.
Tunnels are intentional exposure.
--share, Ngrok and broad binding change who can reach the UI.
Only a clean-environment, process-level deny-and-log test can support that claim for one exact installation and workflow.
Locate the first missing boundary.
Keep the full traceback. The last progress percentage is not a diagnosis.
Forge stops before the local URL appears
Find the first URL, Git, pip, import or missing-file line. Prepare only that dependency in a controlled staging environment.
Basic txt2img works, but a preprocessor fails
The checkpoint is cached; the optional tool is not proven. Record its extension revision, preprocessor and expected model path, then retest only that workflow.
Generation reaches 100% and times out
Inspect preview, postprocessing, save callbacks, metadata and extension hooks. Issue #2042 is a dated similar report, not a universal cause.
Offline mode reports a missing Hub file
This is expected under HF_HUB_OFFLINE=1 when cache is incomplete. Prepare the named asset separately and retain evidence.
Forge works until extensions are enabled
The clean core passed. Add extensions one at a time at pinned revisions and monitor installer plus runtime traffic.
Offline and privacy answers.
First run, caches, firewalls, prompts, APIs, extensions and air-gapped transfer—without turning one test into a universal promise.
Can Stable Diffusion WebUI Forge run completely offline?
A prepared Original Forge installation can run a tested local workflow without internet. “Completely” must be scoped: missing dependencies, helper models, extensions, remote themes, tunnels and API URLs can still request network. There is no universal offline flag in the inspected core.
Does Forge need internet every time it starts?
Not for a prepared core baseline. It may need network when preparation finds missing assets, an update action runs, a theme is uncached, or an enabled extension installer performs its own checks.
What does Forge download on the first run?
Depending on installation state, preparation can obtain packages, Torch and required repositories. Exact payloads vary by platform and version, so retain the first-run console rather than trusting a fixed size list.
Why does generation stop at 100% when I am offline?
Issue #2042 contains a dated report; the reporter later updated and confirmed flight-mode operation. Use the current traceback: a percentage cannot identify saving, preview, extension or model-fetch work.
Is localhost the same as offline?
No. Localhost describes how the browser reaches the server on the same computer. The Python process can still connect outbound.
Does 127.0.0.1 send my prompts to the internet?
That loopback request stays on the computer, but it does not prove Forge, a dependency or extension makes no separate request. Verify at process or firewall level.
What is the difference between 127.0.0.1 and 0.0.0.0?
127.0.0.1 is loopback. 0.0.0.0 is a bind instruction for all interfaces, not a browse address. Broader binding can expose the UI to the LAN.
Does Forge send telemetry?
The inspected core disables Gradio analytics. Forge does not set the Hugging Face telemetry opt-out. A universal claim is unknown because dependencies and extensions have separate behavior.
How do I disable Hugging Face network access?
Set HF_HUB_OFFLINE=1 before import. Cache is used and missing files error. This does not block GitHub, PyPI, direct URLs, tunnels or extension traffic.
How do I disable Hugging Face telemetry?
Set HF_HUB_DISABLE_TELEMETRY=1 before launch. It controls the pinned Hub library, not arbitrary extensions and not the firewall.
Is `--skip-install` an offline mode?
No. It skips package and extension installer work, but other preparation branches remain and an incomplete environment can fail later.
Should I use `--skip-prepare-environment` offline?
Only on a proven complete environment. It bypasses preparation; it does not enforce privacy or deny outbound traffic.
Can ControlNet work offline in Forge?
Yes when its exact extension code, preprocessor and model are present. Community reports show first-use annotator downloads, so test every required preprocessor.
Can upscalers and face restoration work offline?
Yes when the selected model files are cached. Each different model needs its own preparation receipt.
Do Forge extensions work offline?
Some do; others use online services or contact package/Git hosts. Disable extra extensions for the baseline and audit exact revisions one at a time.
Does `--share` work offline?
No. It requests a public Gradio tunnel and changes the exposure boundary. Keep share and Ngrok off for the offline baseline.
Can the Forge API fetch an image from the internet?
At this commit, the API can accept HTTP(S) image URLs when request fetching is enabled. Use local uploads or restrict the capability in an isolated deployment.
Are prompts stored inside Forge output images?
By default, generation infotext is written to image metadata. PNG also defaults to stealth Alpha mode. This is local metadata, not telemetry, but it may travel with a shared file.
How do I remove prompt metadata from generated images?
Disable infotext writing before generating release files, then inspect the exported artifact independently. Removing visible PNG text alone may not address the enabled stealth payload.
Can browser DevTools prove Forge made no network requests?
No. DevTools sees browser traffic; Forge runs Python and may launch installers or Git subprocesses. Use process-level logging or a deny-and-log firewall rule.
Is airplane mode a sufficient privacy test?
It proves a workflow can finish disconnected, but not whether failed calls were attempted. A logging firewall supplies stronger evidence.
How do I move Forge to an air-gapped computer?
Prepare on a closely matching staging machine, transfer reviewed code/packages/models under your controls, verify checksums, and retest. Portability across OS, Python, drivers and GPUs is not guaranteed.
Source-audited, not network-certified.
The clean checkout at dfdcbab was inspected on 31 Aug 2026. Forge was not launched, no model downloaded and no packet capture performed.
Primary / direct evidence
Package, Torch, repository, update and extension-installer branches.
↗ORIGINAL FORGEServer defaultsLoopback and listen behavior.
↗ORIGINAL FORGERuntime initializationGradio analytics environment setting.
↗ORIGINAL FORGECore UIMain Blocks use analytics_enabled=false.
↗ORIGINAL FORGEWebUI launchShare, bind, TLS and auth parameters.
↗ORIGINAL FORGECommand parserNo universal offline flag; separate exposure controls.
↗ORIGINAL FORGETheme loaderNon-default theme cache/download.
↗ORIGINAL FORGEAPI implementationOptional HTTP(S) input fetching.
↗ORIGINAL FORGEExtension managerIndex, install and update actions.
↗ORIGINAL FORGEMetadata optionsInfotext and stealth Alpha defaults.
↗ORIGINAL FORGEImage savingPNG text and JPEG/WebP metadata paths.
↗ORIGINAL FORGEPinned versionsGradio 4.40.0 and Hub 0.26.2 boundary.
↗Fresh intent and boundary checks
Local research reviewed: 8 relevant records
Original repository and README
Identity, launch routes and original-repository boundary.
Original Forge commit history
Dated state used for all current claims.
Original Forge issues
Offline, telemetry and optional-download intent.
Original Forge discussions
Cache location and preprocessor-download intent.
Offline generation report #2042
Dated flight-mode test and later successful retest.
Getting Forge to work offline
Air-gap transfer intent; not used as core fact.
DeepWiki architecture map
Secondary vocabulary; claims rechecked in source.
DeepWiki setup guide
Secondary first-run intent; not product authority.
Core analytics, binding, preparation branches, network features, metadata defaults and absent offline flag.
Offline success and tool-download symptoms describe real jobs, not every build.
Your extensions, packet flow, every dependency, air-gap portability and legal compliance.