Skip to content

Releases: doublepi123/sub2api

Sub2API 0.2.31

Choose a tag to compare

@github-actions github-actions released this 08 Oct 12:12

AI API Gateway Platform - 将 AI 订阅配额分发和管理

本次同步上游 71 个提交,以修复为主,没有新的数据库迁移。只有 VERSION 一处冲突,
fork 的 Kiro 相关改动全部保留。

  • fix(payment): 修复 EasyPay 回调签名可被重放的问题(#7881)。此前付款人可见的
    下单签名可以被当作支付成功通知重放,无需商户密钥。

  • fix(setup): 全新安装不再使用可猜测的管理员账号(Wei-Shaw#7850)。ADMIN_EMAIL 为空时
    生成随机登录邮箱,并校验 ADMIN_PASSWORD 长度(8–72 字节)与邮箱格式。只在
    真正创建管理员时校验,已有部署启动不受影响。

  • fix(deps): 修复前端依赖审计(vue 升到 ^3.5.43,source-map-js 覆盖到 >=1.2.2,
    补充 xlsx 例外)。

  • fix(openai): 上游拒绝加密 reasoning 签名时自动恢复,不再整条请求失败。

  • fix(apicompat): Anthropic thinking 块始终带 signature 字段;Responses 转 Chat
    时保留 refusal;旧版 chat function call 与其结果正确配对;developer 消息保持
    developer 角色;命名 tool_choice 转 Responses 时展平。

  • fix(anthropic): 模拟路径上保持缓存 TTL 顺序合法;保留请求中的 tool 变更 beta 头。

  • fix(grok): Grok Responses 流以空 response.completed 静默拒绝时触发故障转移;
    SSO 设备授权带上 consent token 与 origin。

  • fix(openai-ws): Responses WebSocket 每一轮都按当前分组价格计费,不再沿用连接时
    的快照。

  • fix(openai): WS 透传时计入图片输入用量;剥离 namespace 时按需重建 input。

  • fix(streaming): 保留 chat 流的心跳注释。

  • fix(gateway): 缓冲的 Anthropic 路径忽略负数 content block index。

  • fix(opencode): Zen 模式下 qwen3.8-max 改走 Chat Completions,不支持的模型族
    (gemini-、jev-)直接返回 400;用量快照把 403 视为中性 forbidden;
    Retry-After 提示上限 24 小时。

  • fix(models): 列出复合路由的精确别名;远程 Codex 模型发现遵守账号映射,并支持
    API Key 发现。

  • fix(codex): 模型清单不再下发 null 的 service_tiers。

  • feat(usage) / feat(ops): 使用记录默认显示单请求输出 TPS;运维页显示输出 TPS
    分位数。

  • feat(accounts): 账号搜索与筛选改为紧凑布局。

  • 渠道:追加模型时不再改写已留空的价格条目;渠道监控在有请求样本后才计算健康分,
    智谱探测 URL 改由配置的端点生成。

  • 计费 / 用量:保留用户倍率为 0 的成本明细;缩放价格时保留指数;替换有误导性的
    长上下文倍率标记。

  • 前端:一批「离开页面后旧请求回写」类问题(支付回调轮询、备份轮询、公告、
    通知邮箱验证码、清理任务列表等);Escape 只关闭最上层弹窗;分组 RPM 覆盖值
    编辑时保留数值。

只有 VERSION 冲突,保持 fork 自己的版本线。Kiro 平台、Kiro 模型目录门控的两个
设置项、242 号 Kiro 约束修复迁移、X-Stainless-Package-Version 0.112.1、
account_repo.go 中 len(updates.Credentials) > 0 的条件均已核对完好。

后端 build / vet / -tags=unit / -tags=integration(真实 Postgres)/
golangci-lint(0 issues),前端 typecheck / lint、依赖审计脚本均通过。


📥 Installation

Docker:

# Docker Hub
docker pull doublepi/sub2api:0.2.31

# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.31

One-line install (Linux):

curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bash

Manual download:
Download the appropriate archive for your platform from the assets below.

📚 Documentation

Sub2API 0.2.30

Choose a tag to compare

@github-actions github-actions released this 02 Oct 16:10

AI API Gateway Platform - 将 AI 订阅配额分发和管理

本次同步上游 23 个提交。重点是新增 TypeSafe(Jev System One)平台、充值赠送 /
折扣阶梯,以及邮件验证码、支付查单、antigravity 错误体等几处安全加固。另外修复了
fork 独有的 Kiro 平台在数据库约束里被上游迁移反复覆盖掉的问题。

  • feat: 原生支持 TypeSafe Jev System One(平台名 typesafe,模型 jev-latest,
    仅通过 /v1/systemone 使用)。上游后续又补齐了平台迁移、审计覆盖、端点隔离与
    错误策略,并对齐上游 schema 校验:拒绝重复键和大小写 / Unicode 折叠的变体键,
    防止 {"model":"x","MODEL":"jev-latest"} 这类请求绕过模型白名单与流式限制。

  • fix(billing): TypeSafe API Key 账号支持上游计费探测(此前按默认表单创建会失败)。

  • feat(payment): 充值赠送阶梯,满 X 送 Y%,按到账基数计算并落库(payment_orders
    新增 bonus_amount 列);新增折扣模式,可在赠送 / 折扣之间切换,充值页快捷金额
    显示促销价签。

  • feat(keys): API Key 列表支持按分组名排序。

  • feat(admin): 账号列表的优先级改为可就地加减的步进器,连续点击合并为一次保存,
    失败自动回滚。

  • fix(email): 验证码尝试次数改用 Redis 原子计数,并发猜测无法突破 5 次上限;
    重置密码令牌改为只存 SHA-256 哈希且一次性消费。

  • fix(payment): 未登录的订单查询接口限流为每 IP 每分钟 20 次,防止枚举订单号。

  • fix(antigravity): 返回给客户端的上游错误体做脱敏,不再泄露 GCP 项目号、
    项目 ID 与服务账号邮箱;原始错误体仍保留在运维日志中。

  • fix(billing): 请求进行中 API Key 被删除时,账单仍正常结算。此前 Key 计数更新
    找不到行会让整个计费事务回滚,连余额 / 订阅扣费也一起丢失。

  • fix(deps): 上游同样把 axios 升到 1.20.0,与我们 v0.2.29 的升级一致。

  • fix(i18n): 修正自定义错误码的提示文案。

  • docs: 新增安全策略与私密漏洞报告渠道。

230 / 231 号迁移曾把 kiro 加进 user_platform_quotas 与 composite_model_routes 的
平台 CHECK 约束。但上游的 237(minimax)、238(opencode_go)、241(typesafe)
每次都按自己的平台列表重建这两个约束,而上游列表里没有 kiro,于是 kiro 一次次
被删掉。线上当前两张表都会拒绝 kiro 行,只是还没有人写入过,所以一直没被发现。

新增 242_restore_kiro_platform_checks.sql,把两个约束重建为全部平台的并集
(含 kiro 与 typesafe),与后端 AllowedQuotaPlatforms 一致。同时新增集成测试:
跑完全部迁移后,约束必须接受 AllowedQuotaPlatforms 中的每个平台。以后上游再
重建这两个约束,CI 会直接失败,而不是悄悄丢掉 kiro。去掉 242 时该测试失败。

本次有 19 个文件冲突,全部是上游加入 typesafe 的平台列表与我们的 kiro 撞在同一行。
统一取上游版本并补回 kiro,两者都保留:

  • 后端:配额 schema 校验、分组 / 复合路由 / 渠道的平台列表、调度快照平台集合
    (数组长度从 11 改为 12)、gateway 模型列表(保留 Kiro 与 Antigravity 的默认
    模型分支,同时加入上游的 TypeSafe 分支)、API 合约测试。
  • 前端:类型定义与各处平台顺序列表补回 kiro;配额相关组件继续使用 fork 的集中
    常量 frontend/src/constants/platforms.ts,并在其中加入 typesafe。
  • VERSION 保持 fork 自己的版本线。

Kiro 平台、Kiro 模型目录门控的两个设置项、X-Stainless-Package-Version 0.112.1、
account_repo.go 中 len(updates.Credentials) > 0 的条件均已核对完好。

后端 build / vet / -tags=unit / -tags=integration(真实 Postgres 跑全部迁移)/
golangci-lint(0 issues),前端 typecheck / lint 以及配额、设置页、用户组件相关
的 19 个测试文件(163 个用例)通过。


📥 Installation

Docker:

# Docker Hub
docker pull doublepi/sub2api:0.2.30

# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.30

One-line install (Linux):

curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bash

Manual download:
Download the appropriate archive for your platform from the assets below.

📚 Documentation

Sub2API 0.2.29

Choose a tag to compare

@github-actions github-actions released this 01 Oct 14:54

AI API Gateway Platform - 将 AI 订阅配额分发和管理

本次同步带来 GPT-6.1 Sol 的代码级支持(上游 Wei-Shaw#7730),在此之前只能靠账号
model_mapping 放行。另含 Claude 额度重置兑换、API Key 创建限制、并发透支
防护等改动,以及 axios 升级到 1.20.0 以修复 Security Scan。

  • feat(models): 支持 GPT-6.1 Sol(gpt-6.1-sol)。含模型注册、别名归一化、
    推理等级(low 到 max,不支持 none / minimal)及内置定价,
    官方价 $2 / $10 每 MTok,缓存读取 $0.10,超 272K 上下文按长上下文阶梯计费。

  • fix(openai): 支持 GPT-6 Astra Ultrafast 的能力声明与计费倍率。

  • feat(codex): 识别当前 Codex 订阅档位;客户端配置支持远程模型目录。

  • feat(claude): 兑换 Claude 原生额度重置,授权由服务端选定。

  • feat(accounts): 账号页在重置次数旁新增带确认的重置按钮;
    确认框内的窗口标签更易读。

  • feat(api-key): 新增 API Key 创建数量与频率限制,
    创建频率默认值为每小时 60 次。

  • fix(billing): 为在途请求预留余额,防止并发透支;预留保持到账单落库;
    预估价与实际计费口径一致;其余端点也接入预留。

  • fix(billing): 无定价的别名按计费回退模型估价,已过期的预留不再续期;
    仅在无定价时才从调度快照读取账号级映射。

  • fix(gateway): Claude Code 限制分组的 OpenAI 兼容入口改走降级分组,
    不再直接返回 403。

  • fix(grok): 按正常交互式 CLI 抓包修正 Grok 身份头;修正 Grok CLI 版本门槛,
    并对齐官方无界面请求头。

  • fix(deps): axios 从 1.18.x 升到 1.20.0,修复 7 条 high 级公告
    (fromDataURI 与 shouldBypassProxy 的 ReDoS、toFormData 原型污染、
    HTTP/2 适配器绕过 DNS 与代理控制等)。这些公告此前使
    Security Scan 的前端审计步骤失败。锁文件仅变动 axios 与其依赖 hasown
    (2.0.2 到 2.0.4)。
    上游同期做了同样的升级,合并时自动收敛,无冲突。

本次与上游合并无内容冲突。VERSION 保持 fork 自己的版本线。
Kiro 平台、Kiro 模型目录门控的两个设置项、X-Stainless-Package-Version
0.112.1、account_repo.go 中 len(updates.Credentials) > 0 的条件,
均已核对完好。

后端 build / vet / -tags=unit / -tags=integration / golangci-lint
(0 issues),前端 typecheck / lint / 生产构建通过,
依赖审计脚本本地复现通过。


📥 Installation

Docker:

# Docker Hub
docker pull doublepi/sub2api:0.2.29

# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.29

One-line install (Linux):

curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bash

Manual download:
Download the appropriate archive for your platform from the assets below.

📚 Documentation

Sub2API 0.2.28

Choose a tag to compare

@github-actions github-actions released this 30 Sep 02:42

AI API Gateway Platform - 将 AI 订阅配额分发和管理

本次同步的重点是 Claude Sonnet 5.5 支持(上游 Wei-Shaw#7683 已合并),以及 Claude
重置额度状态、风控白名单等新功能,外加一批网关与计费修复。

  • Claude Sonnet 5.5(claude-sonnet-5-5):模型注册、effort 档位、Bedrock 映射、
    内置定价与家族匹配一并进入。官方价 $2 / $10 每 MTok,缓存读取 $0.2。
    Sonnet 5.5 不再接受 thinking: {"type":"disabled"} 与 tool_choice any/tool,
    上游已对这两类请求做兼容处理。

  • 账号页:按需显示 Claude 重置额度状态,并与 Codex 重置次数按钮对齐;
    后端暴露脱敏后的原生重置额度状态。

  • 风控:新增风控用户白名单(cyber_policy_user_allowlist),名单内用户只记录日志、
    不触发会话屏蔽。

  • 前端:Claude Code 专用分组隐藏不支持的客户端。

  • 仪表盘:近期用量可在 Token 与花费之间切换。

  • fix(anthropic): 保留请求中的 structured-outputs beta;工具名改写合并为单次遍历。

  • fix(openai): 保留 Responses multi-agent beta;上下文回滚时断开 websocket 链;
    额度暂停保持到已知的未来重置时间。

  • fix(gateway): 客户端断开统一记为 499,不再被记成 502 或 200 上游错误。

  • fix(antigravity): 首个内容出现前保持兼容流存活;Signature-only 事件不计入
    有效数据判定。

  • fix(billing): 账号统计定价遵守长上下文闸门;Free Fast 无定价时保留零成本用量日志。

  • fix(apicompat): 转换后的 role 条目标记为 message。

  • fix(ccswitch) / fix(keys): 保留 Codex provider 根端点;Windows 下 Codex 模型
    目录路径使用 ~/。

  • fix: OpenAI 分组不再下发 Codex 模型目录。

  • fix(deploy): redis command 改用 exec 列表形式;fix(setup): 去除过时的限流默认值。

  • domain_constants.go:设置项常量块取并集,保留我们独有的 Kiro 模型目录门控
    两个 key,同时加入上游新增的 cyber_policy_user_allowlist。

  • VERSION 保持 fork 自己的版本线。

OpenAI 已发布 gpt-6.1-sol。上游对应的适配 PR Wei-Shaw#7730 尚未合并,本版本不含代码级
支持;账号侧通过 model_mapping 白名单放行,定价在 new-api 侧单独配置。

后端 build / vet / -tags=unit / -tags=integration / golangci-lint(0 issues),
前端 typecheck / lint 均通过。


📥 Installation

Docker:

# Docker Hub
docker pull doublepi/sub2api:0.2.28

# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.28

One-line install (Linux):

curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bash

Manual download:
Download the appropriate archive for your platform from the assets below.

📚 Documentation

Sub2API 0.2.27

Choose a tag to compare

@github-actions github-actions released this 24 Sep 01:57

AI API Gateway Platform - 将 AI 订阅配额分发和管理

本次同步的重点是:我们此前提给上游的两个修复已被合并回来,Opus 5.5 / GPT-6
的模型与定价改由上游实现,另有一大批网关与计费侧修复。

  • Wei-Shaw#7489 fix(tools): 清洗工具 Schema 里非法的 null required
    修复 xAI / Moonshot / 小米 MiMo 在客户端发送 "required": null 时返回 400。
    本地对应实现已由上游版本取代。

  • Wei-Shaw#7432 fix(antigravity): 裸 Gemini 模型名在所有转发入口解析到思考变体
    修复 /v1/messages 与 /v1/chat/completions 上的 404 / 502。

  • Claude Opus 5.5(claude-opus-5-5):$4 / $20 每 MTok,缓存读取 $0.2。

  • GPT-6 Sol($2 / $10)与 GPT-6 Luna($0.1 / $0.5)。

  • Claude Code 客户端版本号改为自动同步(feat(claude)),替代原先硬编码基线;
    Opus 5.5 要求客户端 >= 2.1.280,该机制可自动满足。

  • 我方保留 X-Stainless-Package-Version = 0.112.1(实抓 Claude Code 2.1.280
    流量所得),与自动同步的 CLI 版本匹配,避免被判第三方。

  • OpenCode Go 官方用量窗口查询与自动刷新,支持同 Key 组共享、活动防抖、
    超窗强刷,用量单元格可主动查询,周/月徽章改为 7d / 1m。

  • 用量窗口资格扩展到其它厂商挂载。

  • 简易模式可选启用 API Key 消费窗口限制。

  • 备份支持月度归档与独立保留策略。

  • 日志滚动保留策略可配置。

  • 返利提取支持登记线下提现。

  • fix(responses): 终端事件即结束流式,不再等待上游 EOF;协议错误只发一次;
    剥离超长 input item ID。

  • fix(streaming): OpenAI 转换前丢弃 Anthropic ping 心跳;心跳不再混入语义输出。

  • fix(scheduler): 调度投影保留账号 RPM 配置;调度倍率补账号倍率回退。

  • fix(antigravity): 系统提示词中和 Claude Agent SDK 身份(规避 429);
    Schema 清理支持 prefixItems 并为数组补有效 items 兜底。

  • fix(grok): 账号冷却期间仍允许配额查询。

  • fix(openai): 透传模式下尊重图片选项;OAuth 图片别名保留在测试选择器;
    账号测试模型按 model mapping 过滤;保留携带 Responses Lite 标记的 GPT-5.5 请求。

  • fix(upstream): 关闭 body 前先取消响应尝试。

  • fix(gateway): 为 Gemini 分组列出混合 antigravity 模型。

  • claude/constants.go:采用上游把 DefaultHeaders 改为函数的重构(配合版本自动
    同步),仅保留我方的 SDK 版本值。

  • account_repo.go / admin_account.go / account_handler.go:取并集,保住 fork
    独有的 Kiro 平台(凭据变更触发 catalog 清理、token refresher、extra 键)。

  • 定价 JSON:采用上游格式与数据(与官方价一致)。

后端 build / vet / -tags=unit / -tags=integration / golangci-lint(0 issues)
前端 typecheck / lint 全部通过。


📥 Installation

Docker:

# Docker Hub
docker pull doublepi/sub2api:0.2.27

# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.27

One-line install (Linux):

curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bash

Manual download:
Download the appropriate archive for your platform from the assets below.

📚 Documentation

Sub2API 0.2.26

Choose a tag to compare

@github-actions github-actions released this 23 Sep 02:33

AI API Gateway Platform - 将 AI 订阅配额分发和管理


📥 Installation

Docker:

# Docker Hub
docker pull doublepi/sub2api:0.2.26

# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.26

One-line install (Linux):

curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bash

Manual download:
Download the appropriate archive for your platform from the assets below.

📚 Documentation

Sub2API 0.2.25

Choose a tag to compare

@github-actions github-actions released this 22 Sep 13:41

AI API Gateway Platform - 将 AI 订阅配额分发和管理


📥 Installation

Docker:

# Docker Hub
docker pull doublepi/sub2api:0.2.25

# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.25

One-line install (Linux):

curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bash

Manual download:
Download the appropriate archive for your platform from the assets below.

📚 Documentation

Sub2API 0.2.24

Choose a tag to compare

@github-actions github-actions released this 22 Sep 09:19

AI API Gateway Platform - 将 AI 订阅配额分发和管理


📥 Installation

Docker:

# Docker Hub
docker pull doublepi/sub2api:0.2.24

# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.24

One-line install (Linux):

curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bash

Manual download:
Download the appropriate archive for your platform from the assets below.

📚 Documentation

Sub2API 0.2.23

Choose a tag to compare

@github-actions github-actions released this 22 Sep 08:53

AI API Gateway Platform - 将 AI 订阅配额分发和管理


📥 Installation

Docker:

# Docker Hub
docker pull doublepi/sub2api:0.2.23

# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.23

One-line install (Linux):

curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bash

Manual download:
Download the appropriate archive for your platform from the assets below.

📚 Documentation

Sub2API 0.2.22

Choose a tag to compare

@github-actions github-actions released this 22 Sep 08:26

AI API Gateway Platform - 将 AI 订阅配额分发和管理


📥 Installation

Docker:

# Docker Hub
docker pull doublepi/sub2api:0.2.22

# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.22

One-line install (Linux):

curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bash

Manual download:
Download the appropriate archive for your platform from the assets below.

📚 Documentation