Great news, and very good work, thanks for sharing.
One thing that I am concerned about (or have questions about), is how would you make sure you are not exposing the service to outside, so that when the laptop is on a coffee shop network others can query the credentials?
I mean, it often happens that a developer needs to expose a webserver they are running to outside to showcase something or demo or .... It is not very hard to make a mistake and expose everything right?