Settings → Integrations: Local API key and Browser Plugin (port, token)
Install the Chrome extension
Repo / release notes: starcat-chrome-plugin. If it is on the Chrome Web Store, prefer the site or README install link.
Chrome extension ──HTTP──► 127.0.0.1:port /plugin/v1/* Bearer token (same as Integrations) │ ▼ Starcat on this Mac
Quitting the app breaks the inject. Launch Starcat, then reload GitHub.Verify on any starred GitHub repo page. The enhance block should appear (features). If not: extension permission, port / token, app running.
A leaked token is a local API credential (lower risk while bound to 127.0.0.1; still do not screenshot Settings into a chat). Safari: Safari extension.