Model or dataset
yeahhe365/Gemini-Nexus avatar
yeahhe365/Gemini-Nexus

Gemini Nexus: a Chrome side panel that drives Gemini Web, the Gemini API and OpenAI-compatible endpoints

Gemini Nexus 是一款面向浏览器场景的 AI 助手扩展,集成 Gemini Web、Gemini API 与 OpenAI 兼容接口,支持网页上下文、图像处理、工具调用和 MCP 浏览器控制。

1,111 stars153 forksJavaScriptMIT

At a glance

What is it?
Gemini Nexus is an MV3 Chrome extension that puts a provider-switching AI assistant in the side panel, adds an injected floating toolbar, and can control the browser through Chrome DevTools Protocol tools. Its Gemini Web mode works by reverse-engineering internal RPC endpoints, which the README itself flags as a likely terms-of-service violation.
Who is it for?
Adopt Gemini Nexus if you want one side panel that can talk to Gemini Web without a key, switch to a keyed API provider when you need grounding or tool use, and drive tabs through CDP tools. Do not adopt it if you cannot accept the README's own warning that the Gemini Web provider likely violates Google's terms of service, or if you need a project with a published security review rather than a SECURITY.md and a drift-check script.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 24 days ago.
What is it written in?
Mainly JavaScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What Gemini Nexus solves, and for whom

Browser AI extensions usually pick one lane. They either wrap a paid API behind a key, or they scrape a chat web UI and hope the markup holds. Gemini Nexus deliberately does both, plus a third path through OpenAI-compatible endpoints, and puts the switch in a single side panel.

The target user is someone who already lives in Chrome and wants the assistant next to the page rather than in a separate tab. The README describes the extension as giving the browser a native AI layer, and the pieces it lists are concrete: a side panel, an injected floating toolbar, image and screenshot input, Chrome DevTools Protocol based browser-control tools, and optional external MCP tools.

The provider list is the real differentiator. One settings surface covers Gemini Web, the Gemini API, OpenAI Compatible API, OpenAI Official API, DeepSeek API, OpenRouter API, Qwen / DashScope API, Anthropic API and Zhipu API, each with its own Base URL, API Key and Model IDs. That is a lot of surface area for one extension, and the README does not pretend the providers behave identically.

If you only ever use one provider, the switching machinery is overhead you will pay for in settings complexity. The extension makes most sense for people who keep a free Gemini Web session for casual questions and a keyed provider for work that needs grounding, tool calls or a specific model.

Provider drivers, token extraction and the data path

The repository keeps one driver per provider family under services/providers. The README names the files: web.js for the Gemini Web client, official.js for the Gemini API, openai_compatible.js shared by OpenAI Compatible, OpenAI Official, DeepSeek, OpenRouter, Qwen / DashScope and Zhipu, and anthropic.js for the native Messages API adapter. Behaviour is adapted dynamically in code rather than through one generic request shape.

The Gemini Web path is the one worth reading carefully. According to the README, the extension accesses gemini.google.com by reverse-engineering internal RPC endpoints and extracting authentication tokens (atValue, blValue, f.sid) from the page HTML. Those tokens are stored locally and used to mimic browser requests so the extension can work without an official API key. Requests go to Google's servers, specifically gemini.google.com and push.clients6.google.com, carrying the user's session credentials.

The README states plainly that this approach likely violates Google's Terms of Service and may be considered unauthorized access. It also documents that for Gemini-generated images the extension removes embedded watermarks (metadata markers) so the image can be downloaded directly, which strips attribution from AI-generated content. These are not buried in a footnote; they sit in a section titled Reverse Engineering and Data Flow Disclosure.

For every other provider the flow is the ordinary one: user text, images and uploaded files go to the configured provider's endpoint, and API keys are stored locally in Chrome extension storage. The README says keys are not transmitted to any third party beyond the chosen provider. Because the Gemini Web path depends on undocumented internals, it is also the path most likely to break without warning. The repository ships scripts/gemini-web-drift-check.mjs and a check:gemini-web npm script, which is an admission that this surface moves.

Installing Gemini Nexus from source and running a first query

The README does not give a step-by-step install section, so the reliable path is the one the repository itself implies: build with Vite and load the unpacked extension. The package.json declares the scripts. Install dependencies first.

bash
npm install
npm run build

The build script is vite build, so the output lands in a build directory rather than in the repository root. Open chrome://extensions, enable Developer mode, choose Load unpacked, and point it at that build output. The manifest.json at the repository root is Manifest V3, which is what current Chrome expects.

For a packaged artifact instead of a raw build, the repository provides a packaging script that runs the build first.

bash
npm run package:extension

Once the extension is loaded, open the side panel and pick a provider. The lowest-friction option is Gemini Web, which needs no API key, only a signed-in Google account in the same browser. The README also notes a temporary-chat toggle so Web-provider requests are not added to Gemini Recent chats; turn that on before you ask anything you would rather not keep.

If you plan to develop against the source, the full check chain is a single command.

bash
npm run check

That runs format:check, build, tsc --noEmit, knip for unused code and vitest. It is a heavier gate than most extensions of this size bother with, and it tells you the maintainers expect contributors to run it before a pull request.

Where Gemini Nexus is the wrong tool

The Gemini Web provider is the part most people will try first, and it is the part with the clearest risk. The README does not soften this: it says the approach likely violates Google's Terms of Service, may be considered unauthorized access, and that users assume responsibility for consequences. If your organisation has any policy about automating access to consumer accounts, this feature is not for you, regardless of how well it works.

The watermark removal feature is the second boundary. It strips metadata markers from Gemini-generated images to enable direct download, which the README ties to copyright implications and Google's policies on generated content usage. If you need provenance on generated images, this extension actively removes it.

There is also a structural fragility. Any provider that reaches into page HTML for authentication tokens is coupled to markup you do not control. The presence of a dedicated drift-check script suggests the maintainers know this. A drift check tells you the shape changed; it does not keep the provider working.

Finally, consider the scope. Nine provider integrations, a side panel, an injected toolbar, CDP browser control and MCP tools in one extension is a large trust surface for something that runs on every page you visit. The README does not document a rollback path for a bad provider response, and it does not describe how to revoke a stored token beyond the general statement that keys live in Chrome extension storage. If you need a narrow, auditable tool, this is not it.

How it compares with a plain API wrapper extension

The obvious alternative is a thin extension that calls one API with your key and does nothing else. The difference is not cosmetic. A single-provider wrapper has no token extraction, no reverse-engineered RPC layer and no watermark handling, so its terms-of-service exposure is limited to the one provider you configured.

Gemini Nexus trades that simplicity for reach. It gives you Gemini Web without a key, then lets you switch to official.js for Gemini API work with Thinking and Google Search grounding, or to openai_compatible.js for Chat Completions and Responses API endpoints with optional web search. The README notes that DeepSeek gets reasoning_content display, OpenRouter fetches /models and accepts provider routing JSON, and Qwen / DashScope gets enable_thinking plus VL image input. Those are per-provider adaptations, not a lowest-common-denominator request builder.

The cost of that reach is configuration. Each provider wants its own Base URL, API Key and Model IDs, and the README does not claim they are interchangeable. A wrapper with one provider has one failure mode. This extension has one per provider, plus the shared side panel and browser-control layer.

If you want the browser-control side, the comparison changes again. The CDP tools and optional MCP tools are the reason to pick this over a chat-only extension, and they are also the reason to read the permissions in manifest.json before you install.

Maintenance, upgrades and what the MIT licence does and does not cover

The repository is not archived, and the last push was on 2026-09-06. Releases have been frequent: v5.3.0 on 2026-09-03, v5.2.4 on 2026-08-24 and v5.2.0 on 2026-08-22, while package.json already declares version 5.4.0. That gap between the manifest version and the latest tagged release is normal for a project that tags after the fact, but it does mean you should read CHANGELOG.md rather than trust the version string alone.

Upgrade cost concentrates in the Gemini Web provider. Every time Google changes the page, the token extraction can break, and the repository's answer is the drift check.

bash
npm run check:gemini-web

Run that after a Gemini Web failure to see whether the script still recognises the current page shape. If it fails, the fix is upstream, not in your settings. The API providers do not carry that risk, because they speak documented protocols.

The licence is MIT, which is permissive and places few obligations on you. It does not grant you anything with respect to Google's terms, and it does not cover the watermark removal feature, which the README frames as research and experimental use with liability disclaimed for misuse. MIT governs the code you receive; it says nothing about whether the way you use the Gemini Web provider is permitted by the service you are talking to. That question is separate and the README does not answer it for you.

Editorial conclusion

Adopt Gemini Nexus if you want one side panel that can talk to Gemini Web without a key, switch to a keyed API provider when you need grounding or tool use, and drive tabs through CDP tools. Do not adopt it if you cannot accept the README's own warning that the Gemini Web provider likely violates Google's terms of service, or if you need a project with a published security review rather than a SECURITY.md and a drift-check script. Before installing, read the Reverse Engineering and Data Flow Disclosure section, decide which provider you will actually configure, and run npm run check:gemini-web after any Gemini Web breakage to see whether the drift check still passes. The extension ships under MIT, so the licence question is settled; the provider terms question is not.

Frequently asked questions

What is Gemini Nexus?

It is a Chrome extension that combines Gemini Web, the Google Gemini API, OpenAI-compatible APIs and several third-party providers in one side panel, with an injected floating toolbar, image and screenshot input, CDP-based browser-control tools and optional MCP tools.

Does Gemini Nexus need a Gemini API key?

Not for the Gemini Web provider, which reuses a signed-in Google account by extracting authentication tokens from the Gemini page. The other providers each need their own API key and Base URL.

How do I install Gemini Nexus?

The README does not give install steps, so build it with npm run build and load the Vite output as an unpacked extension in chrome://extensions, or run npm run package:extension to produce a packaged artifact.

Which providers does Gemini Nexus support?

The README lists Gemini Web, Gemini API, OpenAI Compatible API, OpenAI Official API, DeepSeek API, OpenRouter API, Qwen / DashScope API, Anthropic API and Zhipu API, each with provider-specific Base URL, API Key and Model IDs.

Is the Gemini Web provider in Gemini Nexus against Google's terms?

The README states that reverse-engineering internal RPC endpoints and extracting tokens likely violates Google's Terms of Service and may be considered unauthorized access, and that users assume responsibility for consequences.

Official sources

  1. Issues
  2. License: MIT
  3. README
  4. Releases
  5. yeahhe365/Gemini-Nexus on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/yeahhe365-gemini-nexus.svg)](https://hysenlabs.com/projects/yeahhe365-gemini-nexus)