Total Pageviews

Sunday, 30 August 2026

CLIProxyAPI

 Wrap Antigravity, ChatGPT Codex, Claude Code, Grok Build as an OpenAI/Gemini/Claude/Codex compatible API service, allowing you to enjoy the free Gemini 3.1 Pro, GPT 5.6 Series, Grok 4.5, Claude model through API.

English | 中文 | 日本語

If you want to use CLIProxyAPI on your desktop, we recommend our EasyCLIProxyAPI desktop client. It provides a graphical configuration UI, automatic updates, system tray integration, and one-click start/stop for the CLIProxyAPI service.

CLIProxyAPI is a proxy server that provides OpenAI/Gemini/Claude/Codex/Grok compatible API interfaces for CLI.

You can access the following providers locally and with multiple CLI accounts through any OpenAI (including Responses), Gemini (including Interactions), or Claude-compatible client or SDK.

Provider Description
Kimi Kimi series models (Kimi K3, Kimi K2.7 Code, etc.). Kimi K3 is Moonshot AI’s most capable model and the world’s first open 3T-class model. With 2.8 trillion parameters, native vision, and a 1-million-token context window, K3 is built for long-horizon coding, knowledge work, and reasoning. CLIProxyAPI supports Kimi through OAuth or compatible API interfaces. Try the Kimi Code subscription, or get an API key from the Kimi Open Platform. Thanks to Kimi for supporting CLIProxyAPI and the open-source community!
OpenAI OpenAI GPT series models (GPT 5.6, GPT 5.5, etc.). GPT-5.6 sets a new quality and efficiency baseline for complex production workflows. GPT-5.6 is especially token-efficient and improves frontend aesthetics, including layout, visual hierarchy, and design judgment.
Anthropic Anthropic Claude series models (Claude Fable, Claude Opus, Claude Sonnet, etc.). Claude Fable 5 is Anthropic's most capable widely released model, built for the most demanding reasoning and long-horizon agentic work.
Antigravity Google Gemini series models (Gemini 3.5 Flash, Gemini 3.1 Pro, etc.). Gemini 3.5 Flash provides sustained frontier-level intelligence optimized for real-world tasks at a higher speed and lower cost. Designed for the agentic era, it excels at sub-agent deployment, multi-step workflows, and long-horizon tasks at scale. This model is particularly effective for rapid agentic loops involving complex coding cycles and iterations.
xAI xAI Grok series models (Grok 4.5, Grok Composer 2.5 Fast, etc.). Grok 4.5 is SpaceXAI's frontier model built for coding, agentic tasks, and knowledge work. It was trained in SpaceXAI's data centers in Memphis with new datasets spanning science, engineering, and math.

Sponsor

https://www.packyapi.com/register?aff=cliproxyapi

Thanks to PackyCode for sponsoring this project!

PackyCode is a reliable and efficient API relay service provider, offering relay services for Claude Code, Codex, Gemini, and more.

PackyCode provides special discounts for our software users: register using this link and enter the "cliproxyapi" promo code during recharge to get 10% off.


AICodeMirror Thanks to AICodeMirror for sponsoring this project! AICodeMirror provides official high-stability relay services for Claude Code / Codex / Gemini, with enterprise-grade concurrency, fast invoicing, and 24/7 dedicated technical support. Claude Code / Codex / Gemini official channels at 38% / 2% / 9% of original price, with extra discounts on top-ups! AICodeMirror offers special benefits for CLIProxyAPI users: register via this link to enjoy 20% off your first top-up, and enterprise customers can get up to 25% off!
APIKEY.FUN Thanks to APIKEY.FUN for sponsoring this project! APIKEY.FUN is a professional enterprise-grade AI relay platform dedicated to providing stable, efficient, and low-cost AI model API access for enterprises and individual developers. The platform supports popular mainstream models such as Claude, OpenAI, and Gemini, with prices as low as 7% of the official price. Register through this project's exclusive link to enjoy a special permanent 5% top-up discount.
RunAPI RunAPI is an efficient and stable API platform—an alternative to OpenRouter. A single API Key gives you access to 150+ leading models, including OpenAI, Claude, Gemini, DeepSeek, Grok, and more, at prices as low as 10% of the original (up to 90% off), with exceptional stability. It's seamlessly compatible with tools like Claude Code, OpenClaw, and others. RunAPI offers an exclusive perk for CPA users: register and contact an administrator to claim ¥7 in free credit.
CyberPay CyberPay was founded in 2021. We are committed to providing stable, efficient, and secure payment settlement solutions for AI industry merchants. Working with us helps your website platform solve Alipay and WeChat payment collection needs. We support business cooperation for selling GPT, Gemini, Claude, and Codex accounts, relay platforms, and other related services, helping merchants address payment collection challenges. Contact us to start your path to growth.
ClaudeAPI Thanks to Claude API for sponsoring this project! Claude API is an official-channel API provider focused on Claude models. Built on Anthropic official keys and AWS Bedrock official channels, it provides a stable integration experience for Claude Code and Agent applications, supports the full Claude model family, and preserves official capabilities such as Tool Use and long context. The service is not reverse-engineered and does not downgrade model capabilities, making it suitable for heavy Claude Code users, Agent engineers, and enterprise technical teams. Register through the Exclusive link and contact customer support to claim free test credits. Invoicing and team onboarding are also supported.
code0 Thanks to Code0 for sponsoring this project! code0.ai is an AI coding workspace for developers and technical teams, bringing together mainstream Agent coding capabilities such as Claude Code and Codex. It supports common development scenarios including code generation, project understanding, debugging, code review, and documentation. It is suitable for independent developers, Agent engineers, open-source maintainers, and enterprise R&D teams, with invoicing and team onboarding supported. Register through the Exclusive link and contact customer support to claim free test credits and experience a more efficient AI coding workflow.
FennoAI FennoAI is a stable and efficient API relay service provider, currently focused on Codex relay services. It is compatible with OpenAI and Anthropic protocols and can flexibly integrate with mainstream coding tools such as Codex, Claude Code, and OpenCode. It can reliably support enterprise-grade demand of hundreds of billions of tokens per day, with B2B settlement and invoicing available for both domestic and overseas entities. FennoAI offers an exclusive benefit for CLIProxyAPI users: purchase a subscription through the exclusive link and receive $50 worth of Coding Plan credits for just $1.99. Referral rewards are also available: earn up to 20% commission when invited friends make a purchase. The more friends you invite, the greater the rewards.
Qiniu Cloud AI Thanks to Qiniu Cloud AI for sponsoring this project! Qiniu Cloud AI is an enterprise-grade large-model MaaS platform under Qiniu Cloud (02567.HK). It provides one-stop access to 150+ mainstream global models, is compatible with protocols from major global model providers, and covers full-modal processing capabilities for text, image, audio, video, and files. It serves more than 1.69 million enterprise and developer users. Exclusive benefits: enterprise users can claim 12 million free tokens, and invite friends to earn up to tens of billions of tokens.
Cubence Thanks to Cubence for sponsoring this project! Cubence is a reliable and efficient API relay service provider, offering relay services for Claude Code, Codex, Gemini, and more. Cubence provides special discounts for our software users: register using this link and enter the "CLIPROXYAPI" promo code during recharge to get 10% off.
FastAIToken Thanks to FastAIToken for sponsoring this project! FastAIToken is an AI API aggregation platform built for developers, focused on speed and stability. It supports leading AI models including OpenAI, Claude, Gemini, and more. With a 1:1 recharge ratio (¥1 = $1 in API credits), developers can access the world's top AI models at lower cost and with greater convenience. Telegram Support Group
The platform offers multiple channels to suit different needs: an ultra-low-cost 0.02× OpenAI promotional tier (limited time), OpenAI channels starting from 0.25×, 0.7× Claude with 95% fixed cache, and 1.2× Claude Max channels. It also provides a public status page displaying real-time availability, latency, and operational status for every channel, ensuring transparent and reliable service. In addition, FastAIToken offers 24/7 human technical support (no bots) for rapid response to developers' needs. For enterprise customers, dedicated SLA-backed channel pools are available with guaranteed stability, contract support, invoicing, and dedicated maintenance.
Infistar.ai Worried about diluted or downgraded models, or opaque pricing? Infistar.ai, a globally leading model aggregation service, verifies every model it offers through real API calls. Its supply comes from official APIs and official account pools, with load balancing across more than 10,000 supply routes to ensure low latency and stability during peak periods. It covers leading models worldwide, including ChatGPT, Claude, Gemini, Grok, GLM, DeepSeek, Kimi, Qwen, and MiniMax, with full-modal capabilities spanning text, video, images, embeddings, reranking, and more. Pricing and usage are transparent, clear, and easy to inspect, with models available from as little as 10% of official prices. CLIProxyAPI users can register and try the service through the exclusive entry. Invitation link: https://www.infistar.cc/register?aff=FQKC6J6R&ref_source=link
Bestproxy Bestproxy provides high-purity residential IPs with dedicated one-IP-per-account support. 🟡Residential Proxy - $0.5/GB;🟡Static Residential Proxy - Starting at $3/IP;🟡Unlimited Residential Proxy - Starting at $67/Day. ✅Get Free Trial.
APIMart Thanks to APIMart for sponsoring this project! APIMart is a low-cost API platform for AI image & video generation — GPT-Image-2 from $0.006/image, 160+ images per dollar. One async API covers both image and video: submit a task, get an ID, fetch results via polling or callback. Batch tens of thousands of images without timeouts, switch models without changing code. Pay-as-you-go with no monthly fee — sign up here to get started.

Overview

  • OpenAI/Gemini/Claude/Grok compatible API endpoints for CLI models
  • OpenAI Codex support (GPT models) via OAuth login
  • Claude Code support via OAuth login
  • Grok Build support via OAuth login
  • Streaming, non-streaming, and WebSocket responses where supported
  • Function calling/tools support
  • Multimodal input support (text and images)
  • Multiple accounts with round-robin load balancing (Gemini, OpenAI, Claude, Grok)
  • Simple CLI authentication flows (Gemini, OpenAI, Claude, Grok)
  • Generative Language API Key support
  • AI Studio Build multi-account load balancing
  • Claude Code multi-account load balancing
  • OpenAI Codex multi-account load balancing
  • Grok Build multi-account load balancing
  • OpenAI-compatible upstream providers via config (e.g., OpenRouter)
  • Reusable Go SDK for embedding the proxy (see docs/sdk-usage.md)

Getting Started

CLIProxyAPI Guides: https://help.router-for.me/

Management API

see MANAGEMENT_API.md

Usage Statistics

Since v6.10.0, CLIProxyAPI and CPAMC no longer ship built-in usage statistics. If you need usage statistics, use:

Standalone persistence and visualization service for CLIProxyAPI, with periodic data sync, SQLite storage, aggregate APIs, and a built-in dashboard for usage and statistics.

Full CLIProxyAPI management center with request-level monitoring and cost estimates. CPA-Manager tracks collected requests by account, model, channel, latency, status, and token usage; estimates cost with editable model prices and one-click LiteLLM price sync; persists events in SQLite; and provides Codex account-pool operations with batch inspection, quota detection, unhealthy account discovery, cleanup suggestions, and one-click execution for day-to-day multi-account maintenance.

SDK Docs

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

  1. Fork the repository
  2. Create your feature branch (git checkout -b feature/amazing-feature)
  3. Commit your changes (git commit -m 'Add some amazing feature')
  4. Push to the branch (git push origin feature/amazing-feature)
  5. Open a Pull Request

Who is with us?

Those projects are based on CLIProxyAPI:

Native macOS menu bar app to use your Claude Code & ChatGPT subscriptions with AI coding tools - no API keys needed

A cross-platform desktop and web app to translate and validate SRT subtitles using your existing LLM subscriptions (Gemini, ChatGPT, Claude, etc.) via CLIProxyAPI - no API keys needed.

CLI wrapper for instant switching between multiple Claude accounts and alternative models (Gemini, Codex, Antigravity) via CLIProxyAPI OAuth - no API keys needed

Native macOS menu bar app that unifies Claude, Gemini, OpenAI, and Antigravity subscriptions with real-time quota tracking and smart auto-failover for AI coding tools like Claude Code, OpenCode, and Droid - no API keys needed.

Windows-native CLIProxyAPI fork with TUI, system tray, and multi-provider OAuth for AI coding tools - no API keys needed.

VSCode extension for quick switching between Claude Code models, featuring integrated CLIProxyAPI as its backend with automatic background lifecycle management.

Windows desktop app built with Tauri + React for monitoring AI coding assistant quotas via CLIProxyAPI. Track usage across Gemini, Claude, OpenAI Codex, and Antigravity accounts with real-time dashboard, system tray integration, and one-click proxy control - no API keys needed.

A lightweight web admin panel for CLIProxyAPI with health checks, resource monitoring, real-time logs, auto-update, request statistics and pricing display. Supports one-click installation and systemd service.

A Windows tray application implemented using PowerShell scripts, without relying on any third-party libraries. The main features include: automatic creation of shortcuts, silent running, password management, channel switching (Main / Plus), and automatic downloading and updating.

霖君 is a cross-platform desktop application for managing AI programming assistants, supporting macOS, Windows, and Linux systems. Unified management of Claude Code, Gemini, OpenAI Codex, and other AI coding tools, with local proxy for multi-account quota tracking and one-click configuration.

A modern web-based management dashboard for CLIProxyAPI built with Next.js, React, and PostgreSQL. Features real-time log streaming, structured configuration editing, API key management, OAuth provider integration for Claude/Gemini/Codex, usage analytics, container management, and config sync with OpenCode via companion plugin - no manual YAML editing needed.

Browser extension for one-stop management of New API-compatible relay site accounts, featuring balance and usage dashboards, auto check-in, one-click key export to common apps, in-page API availability testing, and channel/model sync and redirection. It integrates with CLIProxyAPI through the Management API for one-click provider import and config sync.

Shadow AI is an AI assistant tool designed specifically for restricted environments. It provides a stealthy operation mode without windows or traces, and enables cross-device AI Q&A interaction and control via the local area network ( LAN). Essentially, it is an automated collaboration layer of "screen/audio capture + AI inference + low-friction delivery", helping users to immersively use AI assistants across applications on controlled devices or in restricted environments.

Cross-platform desktop app (macOS, Windows, Linux) wrapping CLIProxyAPI with a native GUI. Connects Claude, ChatGPT, Gemini, GitHub Copilot, and custom OpenAI-compatible endpoints with usage analytics, request monitoring, and auto-configuration for popular coding tools - no API keys needed.

Ready-to-use cross-platform quota inspector for CLIProxyAPI, supporting per-account codex 5h/7d quota windows, plan-based sorting, status coloring, and multi-account summary analytics.

Native macOS SwiftUI app for monitoring ChatGPT/Codex account quotas in CLIProxyAPI pools. Displays account availability, Plus-base capacity, 5-hour and weekly quota bars, plan weights, and restore forecasts through the Management API.

Multi-agent orchestration for AI coding assistants. Runs CLIProxyAPI as a local sidecar so its agents can drive GPT models through a ChatGPT subscription, pointing Claude Code at an Anthropic-compatible endpoint with no OpenAI API key required.

Windows desktop UI that manages CLIProxyAPI and Perplexity WebUI Scraper from a single interface, inspired by Quotio and VibeProxy. Connect OAuth providers (Claude, Gemini, Codex, Kimi, Antigravity), custom API keys, and Perplexity session accounts, then point any coding agent at the local endpoint.

Cross-platform (Tauri) port of Quotio for Windows, macOS and Linux. Manages a pool of AI accounts (Codex, Claude Code, GitHub Copilot, Gemini, Antigravity, Kiro, Cursor, Trae, GLM) through CLIProxyAPI, with per-account 5-hour/weekly quota bars, Codex rate-limit reset credits with one-click reset, smart scheduling, usage statistics, and multi-instance Codex — no API keys needed.

VS Code extension that brings your Claude, ChatGPT/Codex, Antigravity, Grok, and Kimi subscriptions into GitHub Copilot Chat as native language models — and can power your Git commit messages, chat titles, and summaries too. Runs CLIProxyAPI in a fully managed background lifecycle (download, verify, supervise) shared across all windows, so it's zero-setup. No API keys needed, just OAuth.

A PowerShell-based Windows system tray launcher for CLIProxyAPI. It supports running in the background without a console window, opening the management page, keeping the backend running after the management window closes, and reopening the page from the tray. It also supports checking for CLIProxyAPI updates on startup, SHA-256 verification with rollback, one-click CLIProxyAPI restart and update, PID-validated process management, and safe service shutdown.

An HTTP-only Model Context Protocol server that uses a CLIProxyAPI deployment to provide Grok-powered real-time web search, X/Twitter search, and model discovery to MCP clients. It adds MCP transport, client API-key management, quotas, usage tracking, and a web administration panel.

Native macOS SwiftUI dashboard for AI subscriptions and coding proxies. It manages official CLIProxyAPI releases end to end (download, verify, supervise, update, and roll back), unifies OAuth accounts and live models, and connects one gateway to Codex, Claude Code/Science, OpenCode, or OpenAI/Anthropic/Gemini clients, with optional LAN access.

Run multiple native-feeling Claude Code commands, each powered by a different model (Codex, GLM, Kimi, Gemini, Grok, MiniMax, DeepSeek, Cursor, Copilot, Claude). Every dialect launches the real Claude Code interface with its own isolated config, history, ports, and an embedded CLIProxyAPI instance linked through the Go SDK — no separate proxy install. macOS only. Learn more at claude-dialects.cc.

Browser agent that can connect to CLIProxyAPI's local OpenAI-compatible endpoint as a model provider. See WebBrain's independent setup, security, and account-risk guide for using CLIProxyAPI through EasyCLIProxyAPI.

Note

If you developed a project based on CLIProxyAPI, please open a PR to add it to this list.

More choices

Those projects are ports of CLIProxyAPI or inspired by it:

A Next.js implementation inspired by CLIProxyAPI, easy to install and use, built from scratch with format translation (OpenAI/Claude/Gemini/Ollama), combo system with auto-fallback, multi-account management with exponential backoff, a Next.js web dashboard, and support for CLI tools (Cursor, Claude Code, Cline, RooCode) - no API keys needed.

Never stop coding. Smart routing to FREE & low-cost AI models with automatic fallback.

OmniRoute is an AI gateway for multi-provider LLMs: an OpenAI-compatible endpoint with smart routing, load balancing, retries, and fallbacks. Add policies, rate limits, caching, and observability for reliable, cost-aware inference.

This is a tool built with Tauri 2 + Vue 3 for managing multiple OpenAI Codex desktop accounts. Switch between saved ChatGPT/Codex certification profiles, check 5-hour and weekly quota usage in real time, verify token health, view active account details, and import or save auth.json files without manual copying.

from  https://github.com/router-for-me/CLIProxyAPI

Cloud-Mail

 

A Cloudflare-based email service | 基于 Cloudflare 的邮箱服务 | Cloudflare Email 邮箱 Mail

skymail.ink

基于 Cloudflare 的简约响应式邮箱服务,支持邮件发送、附件收发 🎉

简体中文 | English

releases issues stargazers forks

trendshift

项目简介

只需要一个域名,就可以创建多个不同的邮箱,类似各大邮箱平台,本项目支持署到 Cloudflare Workers ,降低服务器成本,搭建自己的邮箱服务

项目展示

功能介绍

  • 💰 低成本使用: 可部署到 Cloudflare Workers 降低服务器成本

  • 💻 响应式设计:响应式布局自动适配PC和大部分手机端浏览器

  • 📧 邮件发送:集成Resend发送邮件,支持群发,内嵌图片和附件发送,发送状态查看

  • 🛡️ 管理员功能:可以对用户,邮件进行管理,RABC权限控制对功能及使用资源限制

  • 📦 附件收发:支持收发附件,使用R2对象存储保存和下载文件

  • 🔔 邮件推送:接收邮件后可以转发到TG机器人或其他服务商邮箱

  • 📡 开放API:支持使用API批量生成用户,多条件查询邮件

  • 🔢 验证码识别:使用Workers AI,自动识别邮件验证码

  • 📈 数据可视化:使用ECharts对系统数据详情,用户邮件增长可视化显示

  • 🎨 个性化设置:可以自定义网站标题,登录背景,透明度

  • 🤖 人机验证:集成Turnstile人机验证,防止人机批量注册

  • 📜 更多功能:正在开发中...

技术栈

目录结构

cloud-mail
├── mail-worker				    # worker后端项目
│   ├── src                  
│   │   ├── api	 			    # api接口层			
│   │   ├── const  			    # 项目常量
│   │   ├── dao                 # 数据访问层
│   │   ├── email			    # 邮件处理接收
│   │   ├── entity			    # 数据库实体
│   │   ├── error			    # 自定义异常
│   │   ├── hono			    # web框架配置、拦截器、全局异常等
│   │   ├── i18n			    # 语言国际化
│   │   ├── init			    # 数据库缓存初始化
│   │   ├── model			    # 响应体数据封装
│   │   ├── security			# 身份权限认证
│   │   ├── service			    # 业务服务层
│   │   ├── template			# 消息模板
│   │   ├── utils			    # 工具类
│   │   └── index.js			# 入口文件
│   ├── pageckge.json			# 项目依赖
│   └── wrangler.toml			# 项目配置
│
├── mail-vue				    # vue前端项目
│   ├── src
│   │   ├── axios 			    # axios配置
│   │   ├── components			# 自定义组件
│   │   ├── echarts			    # echarts组件导入
│   │   ├── i18n			    # 语言国际化
│   │   ├── init			    # 入站初始化
│   │   ├── layout			    # 主体布局组件
│   │   ├── perm			    # 权限认证
│   │   ├── request			    # api接口
│   │   ├── router			    # 路由配置
│   │   ├── store			    # 全局状态管理
│   │   ├── utils			    # 工具类
│   │   ├── views			    # 页面组件
│   │   ├── app.vue			    # 入口组件
│   │   ├── main.js			    # 入口js
│   │   └── style.css			# 全局css
│   ├── package.json			# 项目依赖
└── └── env.release				# 项目配置 
from  https://github.com/maillab/cloud-mail

gonc is a Golang-based netcat tool designed to facilitate peer-to-peer communication


Netcat with automated NAT traversal, secure P2P, and advanced features for shell access, file transfer, and network proxying.

 

README in 中文English

gonc is a Golang-based netcat tool designed to facilitate peer-to-peer communication. Its main features include:

  • 🔁 Automated NAT Traversal: Zero configuration. Both sides only need to agree on a passphrase. By using the -p2p parameter, peers can automatically discover each other’s network addresses and establish a point-to-point connection through NAT traversal, leveraging public STUN and MQTT services for address exchange.

  • 🔒 End-to-End Encrypted with Mutual Authentication: Supports TLS for TCP and DTLS for UDP encrypted transmission, with passphrase-based mutual identity authentication.

  • 🧩 Flexible Service Configuration: With the -e parameter, you can flexibly set the application to serve each connection. For example, -e /bin/sh can provide a remote cmd shell. You can also use built-in virtual commands for convenient SOCKS5 service, HTTP file service, and traffic forwarding.


Latest version download

docs


Related Projects

  • gonc-gui — a desktop (Windows) and Android app built on gonc: convenient cross-device, cross-network P2P direct connection and secure file transfer. Just share a passphrase (or scan a QR code); no command line required.

Usage Examples

Basic Usage

  • Use it like nc:

    gonc www.baidu.com 80
    gonc -tls www.baidu.com 443

    can only establish point-to-point connections based on IP and port.

  • Now, you can also establish point-to-point connections based on a shared passphrase, with automated NAT traversal.

    The following diagram shows the process of gonc establishing a P2P connection between a home broadband network (hard NAT) and a peer on a mobile network (symmetric NAT). Since both sides have IPv6, the -4 option is used on both ends to force IPv4 in order to demonstrate NAT traversal.

    hole-punching

P2P Tunnel and HTTP File Server

  • Both sides agree on the same passphrase. On the sender side, start an HTTP file server to expose the files or directories to be shared. The -httpserver option accepts multiple paths, each of which can be either a single file or a directory:

    gonc -p2p <passphrase> -httpserver c:/RootDir1 c:/RootDir2
  • On the receiving side, there are two options:

  1. Automatically download the entire directory

    After running the following command, all files will be downloaded recursively to the local machine. If the process is interrupted, re-running the command will automatically resume from where it left off:

    gonc -p2p <passphrase> -download c:/SavePath
  2. Browse and selectively download via browser

    This option does not start downloading automatically. Instead, you need to manually open a browser and visit http://127.0.0.1:9999 to view the peer’s file list and download files as needed:

    gonc -p2p <passphrase> -httplocal-port 9999

    If you need to download a specific subdirectory, the browser becomes inconvenient, but you can do it like this:

    gonc -http-download c:/SavePath http://127.0.0.1:9999/subdir

Secure Encrypted P2P Communication

  • Establish secure encrypted P2P communication between two different networks by agreeing on a passphrase (use gonc -psk . to generate a high-entropy passphrase to replace passphrase). This passphrase is used for mutual discovery and certificate derivation, ensuring communication security with TLS 1.3.

    gonc -p2p passphrase

    On the other side, use the same parameters (the program will automatically attempt TCP or UDP communication (TCP preferred), negotiate roles (TLS client/server), and complete the TLS protocol):

    gonc -p2p passphrase

    Note that if the other end delays the running time, it will exit if it cannot find the other end to interact with information within about half a minute. Therefore, it also supports a waiting mechanism based on MQTT message subscription, using -mqtt-wait and -mqtt-hello to synchronize the timing of the two parties to start P2P. For example, the following uses -mqtt-wait to wait continuously,

    gonc -p2p passphrase -mqtt-wait

    On the other side,

    gonc -p2p passphrase -mqtt-hello
  • Check your NAT type

    gonc -nat-checker

    This will check your IPv6 and IPv4 TCP and UDP NAT addresses and analyze port changes after NAT. If no TCP6 or UDP6 addresses are listed, it means you don't have IPv6. Each protocol address ends with "(easy)", indicating the highest success rate for hole punching; "(hard)" indicates a higher success rate; and "(symm)" is the most difficult. Symm requires the other end to be either "easy" or "hard" for P2P to work.

Reverse Shell (Pseudo-Terminal Support for UNIX-like Systems)

  • Listener (does not use -keep-open, accepts only one connection; no authentication with -psk):
    gonc -tls -exec ":sh /bin/bash" -l 1234
  • Connect to obtain a shell (supports TAB, Ctrl+C, etc.):
    gonc -tls -pty x.x.x.x 1234
  • Use P2P for reverse shell (passphrase is used for authentication, ensuring secure communication with TLS 1.3):
    gonc -exec ":sh /bin/bash" -p2p passphrase
    On the other side:
    gonc -pty -p2p passphrase

Transmission Speed Test

  • Send data and measure transmission speed (built-in /dev/zero and /dev/urandom):
    gonc.exe -send /dev/zero -P x.x.x.x 1234
    Example output:
    IN: 76.8 MiB (80543744 bytes), 3.3 MiB/s | OUT: 0.0 B (0 bytes), 0.0 B/s | 00:00:23
    
    On the receiving side:
    gonc -P -l 1234 > NUL

P2P Tunnel and SOCKS5 / HTTP Proxy

  • Wait for the tunnel to be established:

    gonc -p2p passphrase -linkagent
  • On the other side, start a local SOCKS5 / HTTP proxy service on port 3080 to access the remote network:

    # The link option controls how the local and remote proxy endpoints are created.
    # Use none to indicate that no listening port is opened on that side:
    gonc -p2p passphrase -link "3080;none"

    Next, for example, if you want to connect to 10.0.0.1:3389 in the remote network, you can simply enter the following address in your local Remote Desktop client:

    10.0.0.1-3389.gonc.cc:3080
    

    This domain will be resolved into an IP in the form of 127.b.c.d. As a result, the Remote Desktop client will connect to the local SOCKS5 proxy on port 3080, and then gonc will reverse-parse the 127.b.c.d address to extract the information 10.0.0.1-3389 from the domain name.

  • link Configuration Format

    # Based on the established tunnel, both local and remote sides listen on port 1080.
    # The proxy supports both HTTP and SOCKS5 protocols, with transparent proxy capability enabled.
    gonc -p2p <passphrase> -link "1080;1080"
    
    # Below is the configuration method for the URL format. The parameter value of -link must be enclosed in quotes; otherwise, parsing problems may occur.
    # The left side x://0.0.0.0:1080?tproxy=1 is equivalent to simply writing 1080.
    # The right side enables port 1080 on the remote host, without transparent proxy support.
    gonc -p2p <passphrase> -link "x://0.0.0.0:1080?tproxy=1;x://127.0.0.1:1080"
    
    # The left side f://127.0.0.1:1080?to=1.2.3.4:80
    # means listening locally on port 1080 and forwarding traffic to 1.2.3.4:80 on the remote side.
    # The right side 'none' indicates that no port is opened remotely.
    gonc -p2p <passphrase> -link "f://127.0.0.1:1080?to=1.2.3.4:80;none"
    
    # The right side f://0.0.0.0:80?to=127.0.0.1:80
    # means listening on port 80 on the remote side and forwarding traffic back to 127.0.0.1:80 locally.
    gonc -p2p <passphrase> -link "none;f://0.0.0.0:80?to=127.0.0.1:80"
    
    # The left side x+tls means the proxy protocol with TLS encryption and allows for certificate configuration. The right side specifies the outbound IP address via `outbound_bind` (suitable for multi-IP environments).
    gonc -p2p <口令> -link "x+tls://user:pass@0.0.0.0:1080?cert=ca.pem&key=key.pem;none?outbound_bind=10.0.0.5"

Flexible Service Configuration

  • Use -exec to flexibly configure the application to provide services for each connection. For example, instead of specifying /bin/bash for shell commands, it can also be used for port forwarding. However, the following example starts a new gonc process for each connection:
    gonc -keep-open -exec "gonc -tls www.baidu.com 443" -l 8000
  • To avoid spawning multiple child processes, use the built-in nc module:
    gonc -keep-open -exec ":nc -tls www.baidu.com 443" -l 8000

Socks5 Proxy Service

  • Configure client mode:

    gonc -x s.s.s.s:port x.x.x.x 1234
  • Built-in Socks5 server: Use -e :s5s to provide standard Socks5 service. Support -auth to set a username and password for Socks5. Use -keep-open to continuously accept client connections to the Socks5 server. Thanks to Golang's goroutines, it achieves good multi-client concurrency performance:

    gonc -e ":s5s -auth user:passwd" -keep-open -l 1080
  • Secure Socks5 over TLS: Since standard Socks5 is unencrypted, use -e :s5s with -tls and -psk to customize secure Socks5 over TLS communication. Use -P to monitor connection transmission information, and -acl to implement access control for incoming connections and proxy destinations. For the acl.txt file format, see acl-example.txt.

    gonc.exe -tls -psk passphrase -e :s5s -keep-open -acl acl.txt -P -l 1080

    On the other side, use :s5c (built-in s5c command) to convert Socks5 over TLS to standard Socks5, providing local client access on 127.0.0.1:3080:

    gonc.exe -e ":s5c -tls -psk passphrase x.x.x.x 1080" -keep-open -l -local 127.0.0.1:3080

Establishing a Tunnel for Other Applications

  • Assist WireGuard in NAT Traversal to Form a VPN

    On the passive (listening) side, PC-S, run the following command (using the WireGuard peer’s public key as the passphrase, and assuming WireGuard is listening on port 51820):

    gonc -p2p <PublicKey-of-PS-S> -mqtt-wait -u -k -e ":nc -u 127.0.0.1 51820"

    On the active (initiating) side, PC-C, set the WireGuard peer (PS-S)'s Endpoint to 127.0.0.1:51821, with its own WireGuard interface listening on 51820. Then run the following command. The -k flag allows gonc to automatically reconnect if the network drops:

    gonc -p2p <PublicKey-of-PS-S> -mqtt-hello -u -k -e ":nc -u -local 127.0.0.1:51821 127.0.0.1 51820"

P2P NAT Traversal Capabilities

How does gonc establish a P2P connection?

  • Concurrently uses multiple public STUN servers to detect local TCP/UDP NAT mappings and intelligently determine NAT type
  • Exchanges address information securely via public MQTT servers, using a hash derived from the SessionKey as the shared topic
  • Attempts direct connection in the following priority order: IPv6 TCP > IPv4 TCP > IPv4 UDP, aiming for true peer-to-peer communication
  • No relay servers are used, and no fallback mechanisms are provided — either the connection fails, or it's a real P2P success

How to Deploy a Relay Server for Cases Where P2P Is Not Feasible

  • A SOCKS5 server with UDP ASSOCIATE support running on a public IP is sufficient as a relay. You can also run gonc's built-in SOCKS5 proxy on your own VPS to act as a relay server.

    The following command starts a SOCKS5 proxy that only supports UDP forwarding. The -psk and -tls options enable encryption and PSK-based authentication. Note: Don’t just open port 1080 in your firewall—UDP forwarding uses random ports for each session.

    gonc -e ":s5s -u -c=0" -psk <password> -tls -k -l 1080

  • When P2P fails, you only need one side of gonc to retry the P2P process using the -x option to route through the SOCKS5 relay:

    gonc -p2p <passphrase> -x "-psk <password> -tls <socks5server-ip>:1080"

    Alternatively, you can use a standard SOCKS5 proxy server that supports UDP forwarding:

    gonc -p2p <passphrase> -x "<socks5server-ip>:1080" -auth "user:password"

For example, if both peers are behind symmetric NATs and P2P fails, having just one side use a SOCKS5 UDP relay effectively changes its NAT behavior to “easy,” making it much easier to establish a connection. The data remains end-to-end encrypted.

Used public servers(STUN & MQTT):

"tcp://turn.cloudflare.com:80",
"udp://turn.cloudflare.com:53",
"udp://stun.l.google.com:19302",
"stun.gonc.cc:3478",
"global.turn.twilio.com:3478",
"stun.nextcloud.com:443",

"tcp://broker.hivemq.com:1883",
"tcp://broker.emqx.io:1883",
"tcp://test.mosquitto.org:1883",
"tcp://mqtt.gonc.cc:1883"

How effective is gonc at NAT traversal?

Except in symmetric NAT scenarios on both ends, gonc achieves a very high success rate

gonc classifies NAT types into three categories:

  1. Easy: A single internal port maps to the same external port across multiple STUN servers

  2. Hard: A single internal port maps to a consistent but different external port across STUN servers — harder than type 1

  3. Symmetric: A single internal port maps to different external ports depending on the destination — the most difficult type

To handle these NAT types, gonc employs several traversal strategies:

  • Uses multiple STUN servers to detect NAT behavior and identify multi-exit IP scenarios

  • Prefers IPv6 connections when both sides support it (e.g., TCP6-to-TCP6 direct dial)

  • Both peers listen on TCP while simultaneously dialing each other to increase TCP hole punching success

  • The peer with the easier NAT delays its initial UDP packet to avoid triggering port changes on the harder side

  • The peer with the harder NAT sends UDP packets with a low TTL to reduce interference from the remote firewall

  • As a last resort, uses a "birthday paradox" strategy: the harder side uses 600 random source ports, and the other side tries 600 random destination ports, increasing the chance of a successful UDP port collision.

    from  https://github.com/threatexpert/gonc

OpenList

 

A new AList Fork to Anti Trust Crisis

 

OpenList is a resilient, long-term governance, community-driven fork of AList — built to defend open source against trust-based attacks.

latest version License Build status latest version

discussions Downloads


Disclaimer

OpenList is an open-source project independently maintained by the OpenList Team, following the AGPL-3.0 license and committed to maintaining complete code openness and modification transparency.

We have noticed the emergence of some third-party projects in the community with names similar to this project, such as OpenListApp/OpenListApp, as well as some paid proprietary software using the same or similar naming. To avoid user confusion, we hereby declare:

  • OpenList has no official association with any third-party derivative projects.

  • All software, code, and services of this project are maintained by the OpenList Team and are freely available on GitHub.

  • Project documentation and API services primarily rely on charitable resources provided by Cloudflare. There are currently no paid plans or commercial deployments, and the use of existing features does not involve any costs.

We respect the community's rights to free use and derivative development, but we also strongly urge downstream projects:

  • Should not use the "OpenList" name for impersonation promotion or commercial gain;

  • Must not distribute OpenList-based code in a closed-source manner or violate AGPL license terms.

To better maintain healthy ecosystem development, we recommend:

  • Clearly indicate the project source and choose appropriate open-source licenses in accordance with the open-source spirit;

  • If involving commercial use, please avoid using "OpenList" or any confusing naming as the project name;

  • If you need to use materials located under OpenListTeam/Logo, you may modify and use them under compliance with the agreement.

Thank you for your support and understanding of the OpenList project.

Features

Document

Demo

Discussion

Please refer to Discussions for raising general questions, Issues is for bug reports and feature requests only.

from  https://github.com/OpenListTeam/OpenList

-------------------------------------------------------

相关帖子:

 https://briteming.blogspot.com/2022/02/alist.html