// the find
LibreChat-AI/rag-api
ID-based RAG FastAPI: Integration with Langchain and PostgreSQL/pgvector
A FastAPI wrapper around Langchain's pgvector (or Atlas MongoDB) store that indexes document chunks by file_id, built primarily as LibreChat's RAG backend but usable standalone. Good fit for anyone who wants a thin, swappable-embedding-provider retrieval service instead of building pgvector plumbing from scratch.
Broad provider support out of the box — openai, azure, bedrock, huggingface (local or TEI), google_genai, vertexai, ollama — with a documented dimension/batch-size tradeoff per provider. Async embedding pipeline with bounded queue depth (EMBEDDING_BATCH_SIZE * (MAX_QUEUE_SIZE + PARALLEL_EXECUTION)) and rollback-on-failure, which is the right design for large file ingestion under memory limits. The authorization rewrite in this release is unusually thorough for a project this size: it closes a real IDOR chain (GET /ids enumerating every file, POST /query_multiple doing zero auth, POST /query only checking documents[0]) and centralizes owner-set resolution in one module (app/scope.py) instead of leaving each route to reimplement it.
JWT_SECRET is optional and auth is simply off if you don't set it — meaning the security model this release just hardened is opt-in, and every chunk written while unset is owned by the literal string 'public', which is an easy footgun to hit in a dev-to-prod path. entity_id (agent knowledge bases) is still caller-asserted with no token-level proof of authorization to act for that entity — the README says this explicitly and defers the real fix to a separate, unscheduled change, so multi-tenant deployments exposing this to untrusted callers are still exposed. The upgrade path is fragile by the maintainers' own description: deploying this service before the matching LibreChat client change silently orphans agent files (404 reads as 'already deleted', not an error), and Atlas Mongo users who don't add user_id to their vector index before upgrading get hard query failures instead of a graceful degradation. It's also structurally coupled to LibreChat's file_id/user_id/entity_id metadata conventions, so using it outside that ecosystem means working against the grain of the schema.