What’s Changed: SillyTavern character cards are PNG or JSON files that hold a character’s full definition, and most come from Chub, JannyAI or Botbooru, or from writing your own. SillyTavern’s Import from URL recognises only six card sites, and it fetches Janitor AI links from JannyAI’s archive rather than Janitor itself. For any other site, download the file and import it.
Finding SillyTavern character cards is easy, and getting a pasted link to import is where people get stuck. SillyTavern’s own import code recognises links from only six card sites.
It sends Janitor AI links to a third-party archive called JannyAI and refuses every other domain unless you add it to a whitelist.
That one detail explains most “not found” errors, and it is the first thing I check when an import fails.
A card itself is a small file, usually a PNG portrait with the character’s definition hidden inside it. Below is where to get cards, how to import them, how to judge one before it eats your context, and the two safety rules that matter.

Where Can You Find SillyTavern Character Cards?
SillyTavern character cards mostly come from Chub, JannyAI, Datacat, Botbooru, AICharacterCards and CharaVault, and each of those sites handles imports differently.

Chub is the site I start with, because it holds a huge catalog and SillyTavern imports its links directly, lorebooks included. Its search is the weak spot, as one card-hunting thread spells out, so lean on tag filters.
If card hunting sounds like more upkeep than you want, a hosted app like Nectar AI gives you card-style roleplay without importing anything or running a model yourself.
It charges through paid plans and credit packs, so you trade money for setup time.
| Site | What it is | Import by link? | Watch out for |
|---|---|---|---|
| Chub (also characterhub.org) | A huge open library of cards and lorebooks | Yes, cards and lorebooks | Weak search, so filter by tags |
| JannyAI | An archive of Janitor AI bots | Only through the matching janitorai.com link | A jannyai.com link fails |
| Datacat (datacat.run) | A browser for Janitor AI bots | No, download the file | Janitor bots only |
| Botbooru | A card gallery and archive | No, download the file | Quality varies card to card |
| AICharacterCards | A smaller card site | Yes | Smaller catalog |
| CharaVault | A large archive behind an age check | No, download the file | Its title claims 195K+ cards, its browse link says 52,000+ |
If you are bringing bots over from Janitor AI, the SillyTavern explainer has a section on what carries over. If a card’s download button is gone on Chub, Chub’s missing download button covers the workaround.
Why Won’t a SillyTavern Character Card Link Import?
A pasted card link fails because SillyTavern’s Import from URL only handles six card sites, fetches Janitor AI links through JannyAI’s archive, and refuses every other domain that is not on its whitelist.

The check runs on your own SillyTavern server, which reads the link’s domain before it downloads anything. I treat a failed import as a domain problem first, and the table below covers every case in the current release, version 1.19.0.
| What you paste | What SillyTavern does | Why it can fail |
|---|---|---|
| A chub.ai or characterhub.org link | Downloads the card or lorebook from Chub | The card is gone or private |
| A janitorai.com character link | Asks JannyAI’s archive for that character ID | JannyAI never archived it, or JannyAI is down |
| A jannyai.com page link | Refuses it as an unlisted site | Download the PNG and import it as a file |
| A pygmalion.chat, aicharactercards.com (AICC) or RisuRealm link | Downloads the card from that site | The card is gone or private |
| A perchance.org character link | Downloads the Perchance character | The link is not a character page |
| Any other site’s link | Refuses it and logs “site is not whitelisted” | Download the file, or whitelist the domain |
A comment in the code warns that JannyAI’s download endpoint sits behind Cloudflare’s Bot Fight Mode, so a copy hosted on Azure, AWS, Google Cloud or Colab “might get blocked by IP”.
The same comment adds that it “should work normally on self-host PC/Android”, so a home install is fine. When JannyAI itself is down, one thread points people to Datacat as a second source.
How Do You Whitelist a Card Site in SillyTavern?
You whitelist a card site by adding its domain to the whitelistImportDomains list in SillyTavern’s config.yaml, then restarting SillyTavern.
The default list holds four hosts, and a new domain goes on its own line underneath them:
whitelistImportDomains:
- localhost
- cdn.discordapp.com
- files.catbox.moe
- raw.githubusercontent.com
- your-trusted-card-site.comThe list is a security feature. The fix for CVE-2026-26286, a server-side request forgery flaw patched in version 1.16.0, added a domain check you configure through this same list.
I leave the list alone and import files instead, since a downloaded PNG works on every setup.
How Do You Import a Character Card Into SillyTavern?
You import a character card with Import Character from File, which accepts PNG, JSON, YAML, CHARX and BYAF files, or with External Import for a link from one of the six supported sites.
This is the order I follow for every new card:
- Download the card from the site as a PNG, since the portrait is the card, or as a JSON file.
- Open Character Management in SillyTavern and click Import Character from File.
- Choose the file, and the character appears in your list with its portrait as the avatar.
- Open the card and check its token count before you chat, using the checks further down.
- Answer the regex prompt if the card carries embedded scripts, which the safety section explains.
What is CHARX: The zip bundle defined by the V3 card format, holding the card’s JSON plus assets such as extra art and backgrounds.
In 2024 a SillyTavern developer said it imported only the JSON from a CHARX file. The current import code also saves the bundle’s sprites and backgrounds into the character’s folder, and BYAF files from Backyard AI import with their chats.
What Is Inside a SillyTavern Character Card?
A SillyTavern character card is a block of JSON, usually hidden inside the PNG, holding the name, description, personality, scenario, first message and example dialogues, plus extras like alternate greetings and an embedded lorebook.
In a PNG card the JSON sits in a hidden text chunk named “chara” for V2 cards or “ccv3” for V3 cards, per the V3 specification. That is why the image looks normal while carrying a whole character.
The V2 specification added creator notes, a system prompt, post-history instructions, alternate greetings, an embedded lorebook, tags and a version number.
Its authors nested every field inside a data object to stop older editors “from successfully loading a V2 card, but silently destroying its V2-only fields.”
V3 cards add assets, a nickname, notes in several languages, group-only greetings and creation dates. SillyTavern reads V3 cards but stores them in the V2 format, and its card writer keeps only the V2 “chara” block when it saves.
The field I judge a card by first is the opening message, because a card that speaks for you in its first line tends to keep doing it.
An embedded lorebook works like a standalone one, which the lorebooks guide covers in depth.
How Do You Tell a Good SillyTavern Character Card From a Bad One?
A good SillyTavern character card keeps its permanent fields short, shows the character’s voice in example dialogues, and leaves your system prompt alone. A bad one crams traits into the description until the token counter turns red.
SillyTavern’s Character Design guide names the permanent fields, the ones “sent to the AI with every generation request”: name, description, personality and scenario.
It turns the token counter red when a card’s definitions take “over half of the model-defined context length”.
Example dialogues work the other way. They are “only kept until chat history fills up the context”, so a card that relies on them for its voice fades as the chat grows unless you force them to stay.
The docs also say a description can be any length and “won’t break anything”, while a card guide on r/ChatbotRefugees says 500 to 1,000 tokens for description and personality combined is plenty.
I side with the short card, because every extra token in those four boxes is gone from memory for the whole chat.
Check the system prompt field too. The V2 specification requires frontends to replace your global system prompt with the card’s by default, unless the card’s field is empty.
What is W++: A bracketed shorthand for listing a character’s traits, such as [Mara: stubborn, sarcastic, loyal], used in place of full sentences.
Card writers split on W++ trait lists versus plain prose, and I come down on prose. One reply says prose “stops the stacking” of questions and actions:
Before: [Mara: stubborn, sarcastic, loyal, hates rain, ex-sailor, scared of storms]
After: “Mara is stubborn and quick with a sarcastic line, but she never leaves a friend behind. She hates rain because a storm sank the ship she grew up on.”
| Check | Where to look | Red flag |
|---|---|---|
| Permanent token count | The token counter under the card | The counter turns red |
| Example dialogues | The examples of dialogue box | Empty, or written as the user |
| First message | The first message box | It acts or speaks for you |
| System prompt | Advanced definitions | It replaces yours with rules you did not want |
| Embedded scripts | The popup on first chat | Scripts you did not expect |
Is It Safe to Import SillyTavern Character Cards From Strangers?
Importing a stranger’s character card is reasonably safe on a current SillyTavern release, because embedded scripts need your approval, and the bigger risk is card-browser extensions, one of which stole API keys in 2026.
When a card carries embedded regex scripts, SillyTavern asks first: “This character has embedded regex script(s). Would you like to allow using them?” Regex scripts rewrite text in the chat, so decline them on any card you do not trust.
On May 3, 2026, SillyTavern’s maintainers warned that a third-party extension called Bot Browser used a patched flaw in versions before 1.17.0 “to exfiltrate API keys of users who had it installed.”
They told anyone who had used it to “rotate your API keys immediately” and called every version before 1.17.0 insecure. Weeks earlier, a reply in a JannyAI import thread had recommended that same extension for browsing card sites.
Card-adjacent bugs have been patched too. CVE-2026-34522 let a crafted chat import write files outside the chats folder before 1.17.0, and SillyTavern’s security record lists the rest.
I don’t install card-browser extensions at all now, and I import cards as files.
Should You Write Your Own SillyTavern Character Card?
Writing your own card is worth it once you know what you want, because a short card built for your model usually beats a long one built for someone else’s.
My own cards stay small: a few sentences of description, a scenario with a goal, and two or three example dialogues. Build yours in this order:
- Write the description in two to four plain sentences.
- Put the personality in prose, not a trait list.
- Give the character a goal beyond talking to you, a tip one card thread recommends.
- Write a first message that sets the scene without acting for you.
- Add two or three example dialogues in the character’s voice.
- Move long backstory into a lorebook entry instead of the description.
Pair the card with the model you run, since the same card reads differently on each one. The free OpenRouter setup covers the no-cost options.
If you would pay to skip building and importing altogether, Candy AI is built around one-to-one chat with a character you create in the app. Its free tier ends after 5 messages, so plan on a subscription if you switch.
Quick Takeaways
- SillyTavern imports card links from six sites only: Chub, Janitor AI through JannyAI, Pygmalion, AICharacterCards, RisuRealm and Perchance.
- For any other site, download the PNG and use Import Character from File rather than whitelisting domains.
- Judge a card by its permanent tokens, and treat a red counter as a card eating more than half your context.
- Decline embedded regex scripts on cards you do not trust, and skip card-browser extensions after the 2026 Bot Browser key theft.
- A short card written for your own model usually beats a long downloaded one.
