Repository navigation
Releases: doublepi123/sub2api
Release list
Sub2API 0.2.31
AI API Gateway Platform - 将 AI 订阅配额分发和管理
本次同步上游 71 个提交,以修复为主,没有新的数据库迁移。只有 VERSION 一处冲突,
fork 的 Kiro 相关改动全部保留。
-
fix(payment): 修复 EasyPay 回调签名可被重放的问题(#7881)。此前付款人可见的
下单签名可以被当作支付成功通知重放,无需商户密钥。 -
fix(setup): 全新安装不再使用可猜测的管理员账号(Wei-Shaw#7850)。ADMIN_EMAIL 为空时
生成随机登录邮箱,并校验 ADMIN_PASSWORD 长度(8–72 字节)与邮箱格式。只在
真正创建管理员时校验,已有部署启动不受影响。 -
fix(deps): 修复前端依赖审计(vue 升到 ^3.5.43,source-map-js 覆盖到 >=1.2.2,
补充 xlsx 例外)。 -
fix(openai): 上游拒绝加密 reasoning 签名时自动恢复,不再整条请求失败。
-
fix(apicompat): Anthropic thinking 块始终带 signature 字段;Responses 转 Chat
时保留 refusal;旧版 chat function call 与其结果正确配对;developer 消息保持
developer 角色;命名 tool_choice 转 Responses 时展平。 -
fix(anthropic): 模拟路径上保持缓存 TTL 顺序合法;保留请求中的 tool 变更 beta 头。
-
fix(grok): Grok Responses 流以空 response.completed 静默拒绝时触发故障转移;
SSO 设备授权带上 consent token 与 origin。 -
fix(openai-ws): Responses WebSocket 每一轮都按当前分组价格计费,不再沿用连接时
的快照。 -
fix(openai): WS 透传时计入图片输入用量;剥离 namespace 时按需重建 input。
-
fix(streaming): 保留 chat 流的心跳注释。
-
fix(gateway): 缓冲的 Anthropic 路径忽略负数 content block index。
-
fix(opencode): Zen 模式下 qwen3.8-max 改走 Chat Completions,不支持的模型族
(gemini-、jev-)直接返回 400;用量快照把 403 视为中性 forbidden;
Retry-After 提示上限 24 小时。 -
fix(models): 列出复合路由的精确别名;远程 Codex 模型发现遵守账号映射,并支持
API Key 发现。 -
fix(codex): 模型清单不再下发 null 的 service_tiers。
-
feat(usage) / feat(ops): 使用记录默认显示单请求输出 TPS;运维页显示输出 TPS
分位数。 -
feat(accounts): 账号搜索与筛选改为紧凑布局。
-
渠道:追加模型时不再改写已留空的价格条目;渠道监控在有请求样本后才计算健康分,
智谱探测 URL 改由配置的端点生成。 -
计费 / 用量:保留用户倍率为 0 的成本明细;缩放价格时保留指数;替换有误导性的
长上下文倍率标记。 -
前端:一批「离开页面后旧请求回写」类问题(支付回调轮询、备份轮询、公告、
通知邮箱验证码、清理任务列表等);Escape 只关闭最上层弹窗;分组 RPM 覆盖值
编辑时保留数值。
只有 VERSION 冲突,保持 fork 自己的版本线。Kiro 平台、Kiro 模型目录门控的两个
设置项、242 号 Kiro 约束修复迁移、X-Stainless-Package-Version 0.112.1、
account_repo.go 中 len(updates.Credentials) > 0 的条件均已核对完好。
后端 build / vet / -tags=unit / -tags=integration(真实 Postgres)/
golangci-lint(0 issues),前端 typecheck / lint、依赖审计脚本均通过。
📥 Installation
Docker:
# Docker Hub
docker pull doublepi/sub2api:0.2.31
# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.31One-line install (Linux):
curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bashManual download:
Download the appropriate archive for your platform from the assets below.
📚 Documentation
Sub2API 0.2.30
AI API Gateway Platform - 将 AI 订阅配额分发和管理
本次同步上游 23 个提交。重点是新增 TypeSafe(Jev System One)平台、充值赠送 /
折扣阶梯,以及邮件验证码、支付查单、antigravity 错误体等几处安全加固。另外修复了
fork 独有的 Kiro 平台在数据库约束里被上游迁移反复覆盖掉的问题。
-
feat: 原生支持 TypeSafe Jev System One(平台名 typesafe,模型 jev-latest,
仅通过 /v1/systemone 使用)。上游后续又补齐了平台迁移、审计覆盖、端点隔离与
错误策略,并对齐上游 schema 校验:拒绝重复键和大小写 / Unicode 折叠的变体键,
防止 {"model":"x","MODEL":"jev-latest"} 这类请求绕过模型白名单与流式限制。 -
fix(billing): TypeSafe API Key 账号支持上游计费探测(此前按默认表单创建会失败)。
-
feat(payment): 充值赠送阶梯,满 X 送 Y%,按到账基数计算并落库(payment_orders
新增 bonus_amount 列);新增折扣模式,可在赠送 / 折扣之间切换,充值页快捷金额
显示促销价签。 -
feat(keys): API Key 列表支持按分组名排序。
-
feat(admin): 账号列表的优先级改为可就地加减的步进器,连续点击合并为一次保存,
失败自动回滚。 -
fix(email): 验证码尝试次数改用 Redis 原子计数,并发猜测无法突破 5 次上限;
重置密码令牌改为只存 SHA-256 哈希且一次性消费。 -
fix(payment): 未登录的订单查询接口限流为每 IP 每分钟 20 次,防止枚举订单号。
-
fix(antigravity): 返回给客户端的上游错误体做脱敏,不再泄露 GCP 项目号、
项目 ID 与服务账号邮箱;原始错误体仍保留在运维日志中。 -
fix(billing): 请求进行中 API Key 被删除时,账单仍正常结算。此前 Key 计数更新
找不到行会让整个计费事务回滚,连余额 / 订阅扣费也一起丢失。 -
fix(deps): 上游同样把 axios 升到 1.20.0,与我们 v0.2.29 的升级一致。
-
fix(i18n): 修正自定义错误码的提示文案。
-
docs: 新增安全策略与私密漏洞报告渠道。
230 / 231 号迁移曾把 kiro 加进 user_platform_quotas 与 composite_model_routes 的
平台 CHECK 约束。但上游的 237(minimax)、238(opencode_go)、241(typesafe)
每次都按自己的平台列表重建这两个约束,而上游列表里没有 kiro,于是 kiro 一次次
被删掉。线上当前两张表都会拒绝 kiro 行,只是还没有人写入过,所以一直没被发现。
新增 242_restore_kiro_platform_checks.sql,把两个约束重建为全部平台的并集
(含 kiro 与 typesafe),与后端 AllowedQuotaPlatforms 一致。同时新增集成测试:
跑完全部迁移后,约束必须接受 AllowedQuotaPlatforms 中的每个平台。以后上游再
重建这两个约束,CI 会直接失败,而不是悄悄丢掉 kiro。去掉 242 时该测试失败。
本次有 19 个文件冲突,全部是上游加入 typesafe 的平台列表与我们的 kiro 撞在同一行。
统一取上游版本并补回 kiro,两者都保留:
- 后端:配额 schema 校验、分组 / 复合路由 / 渠道的平台列表、调度快照平台集合
(数组长度从 11 改为 12)、gateway 模型列表(保留 Kiro 与 Antigravity 的默认
模型分支,同时加入上游的 TypeSafe 分支)、API 合约测试。 - 前端:类型定义与各处平台顺序列表补回 kiro;配额相关组件继续使用 fork 的集中
常量 frontend/src/constants/platforms.ts,并在其中加入 typesafe。 - VERSION 保持 fork 自己的版本线。
Kiro 平台、Kiro 模型目录门控的两个设置项、X-Stainless-Package-Version 0.112.1、
account_repo.go 中 len(updates.Credentials) > 0 的条件均已核对完好。
后端 build / vet / -tags=unit / -tags=integration(真实 Postgres 跑全部迁移)/
golangci-lint(0 issues),前端 typecheck / lint 以及配额、设置页、用户组件相关
的 19 个测试文件(163 个用例)通过。
📥 Installation
Docker:
# Docker Hub
docker pull doublepi/sub2api:0.2.30
# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.30One-line install (Linux):
curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bashManual download:
Download the appropriate archive for your platform from the assets below.
📚 Documentation
Sub2API 0.2.29
AI API Gateway Platform - 将 AI 订阅配额分发和管理
本次同步带来 GPT-6.1 Sol 的代码级支持(上游 Wei-Shaw#7730),在此之前只能靠账号
model_mapping 放行。另含 Claude 额度重置兑换、API Key 创建限制、并发透支
防护等改动,以及 axios 升级到 1.20.0 以修复 Security Scan。
-
feat(models): 支持 GPT-6.1 Sol(gpt-6.1-sol)。含模型注册、别名归一化、
推理等级(low 到 max,不支持 none / minimal)及内置定价,
官方价 $2 / $10 每 MTok,缓存读取 $0.10,超 272K 上下文按长上下文阶梯计费。 -
fix(openai): 支持 GPT-6 Astra Ultrafast 的能力声明与计费倍率。
-
feat(codex): 识别当前 Codex 订阅档位;客户端配置支持远程模型目录。
-
feat(claude): 兑换 Claude 原生额度重置,授权由服务端选定。
-
feat(accounts): 账号页在重置次数旁新增带确认的重置按钮;
确认框内的窗口标签更易读。 -
feat(api-key): 新增 API Key 创建数量与频率限制,
创建频率默认值为每小时 60 次。 -
fix(billing): 为在途请求预留余额,防止并发透支;预留保持到账单落库;
预估价与实际计费口径一致;其余端点也接入预留。 -
fix(billing): 无定价的别名按计费回退模型估价,已过期的预留不再续期;
仅在无定价时才从调度快照读取账号级映射。 -
fix(gateway): Claude Code 限制分组的 OpenAI 兼容入口改走降级分组,
不再直接返回 403。 -
fix(grok): 按正常交互式 CLI 抓包修正 Grok 身份头;修正 Grok CLI 版本门槛,
并对齐官方无界面请求头。 -
fix(deps): axios 从 1.18.x 升到 1.20.0,修复 7 条 high 级公告
(fromDataURI 与 shouldBypassProxy 的 ReDoS、toFormData 原型污染、
HTTP/2 适配器绕过 DNS 与代理控制等)。这些公告此前使
Security Scan 的前端审计步骤失败。锁文件仅变动 axios 与其依赖 hasown
(2.0.2 到 2.0.4)。
上游同期做了同样的升级,合并时自动收敛,无冲突。
本次与上游合并无内容冲突。VERSION 保持 fork 自己的版本线。
Kiro 平台、Kiro 模型目录门控的两个设置项、X-Stainless-Package-Version
0.112.1、account_repo.go 中 len(updates.Credentials) > 0 的条件,
均已核对完好。
后端 build / vet / -tags=unit / -tags=integration / golangci-lint
(0 issues),前端 typecheck / lint / 生产构建通过,
依赖审计脚本本地复现通过。
📥 Installation
Docker:
# Docker Hub
docker pull doublepi/sub2api:0.2.29
# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.29One-line install (Linux):
curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bashManual download:
Download the appropriate archive for your platform from the assets below.
📚 Documentation
Sub2API 0.2.28
AI API Gateway Platform - 将 AI 订阅配额分发和管理
本次同步的重点是 Claude Sonnet 5.5 支持(上游 Wei-Shaw#7683 已合并),以及 Claude
重置额度状态、风控白名单等新功能,外加一批网关与计费修复。
-
Claude Sonnet 5.5(claude-sonnet-5-5):模型注册、effort 档位、Bedrock 映射、
内置定价与家族匹配一并进入。官方价 $2 / $10 每 MTok,缓存读取 $0.2。
Sonnet 5.5 不再接受 thinking: {"type":"disabled"} 与 tool_choice any/tool,
上游已对这两类请求做兼容处理。 -
账号页:按需显示 Claude 重置额度状态,并与 Codex 重置次数按钮对齐;
后端暴露脱敏后的原生重置额度状态。 -
风控:新增风控用户白名单(cyber_policy_user_allowlist),名单内用户只记录日志、
不触发会话屏蔽。 -
前端:Claude Code 专用分组隐藏不支持的客户端。
-
仪表盘:近期用量可在 Token 与花费之间切换。
-
fix(anthropic): 保留请求中的 structured-outputs beta;工具名改写合并为单次遍历。
-
fix(openai): 保留 Responses multi-agent beta;上下文回滚时断开 websocket 链;
额度暂停保持到已知的未来重置时间。 -
fix(gateway): 客户端断开统一记为 499,不再被记成 502 或 200 上游错误。
-
fix(antigravity): 首个内容出现前保持兼容流存活;Signature-only 事件不计入
有效数据判定。 -
fix(billing): 账号统计定价遵守长上下文闸门;Free Fast 无定价时保留零成本用量日志。
-
fix(apicompat): 转换后的 role 条目标记为 message。
-
fix(ccswitch) / fix(keys): 保留 Codex provider 根端点;Windows 下 Codex 模型
目录路径使用 ~/。 -
fix: OpenAI 分组不再下发 Codex 模型目录。
-
fix(deploy): redis command 改用 exec 列表形式;fix(setup): 去除过时的限流默认值。
-
domain_constants.go:设置项常量块取并集,保留我们独有的 Kiro 模型目录门控
两个 key,同时加入上游新增的 cyber_policy_user_allowlist。 -
VERSION 保持 fork 自己的版本线。
OpenAI 已发布 gpt-6.1-sol。上游对应的适配 PR Wei-Shaw#7730 尚未合并,本版本不含代码级
支持;账号侧通过 model_mapping 白名单放行,定价在 new-api 侧单独配置。
后端 build / vet / -tags=unit / -tags=integration / golangci-lint(0 issues),
前端 typecheck / lint 均通过。
📥 Installation
Docker:
# Docker Hub
docker pull doublepi/sub2api:0.2.28
# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.28One-line install (Linux):
curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bashManual download:
Download the appropriate archive for your platform from the assets below.
📚 Documentation
Sub2API 0.2.27
AI API Gateway Platform - 将 AI 订阅配额分发和管理
本次同步的重点是:我们此前提给上游的两个修复已被合并回来,Opus 5.5 / GPT-6
的模型与定价改由上游实现,另有一大批网关与计费侧修复。
-
Wei-Shaw#7489 fix(tools): 清洗工具 Schema 里非法的 null required
修复 xAI / Moonshot / 小米 MiMo 在客户端发送 "required": null 时返回 400。
本地对应实现已由上游版本取代。 -
Wei-Shaw#7432 fix(antigravity): 裸 Gemini 模型名在所有转发入口解析到思考变体
修复 /v1/messages 与 /v1/chat/completions 上的 404 / 502。 -
Claude Opus 5.5(claude-opus-5-5):$4 / $20 每 MTok,缓存读取 $0.2。
-
GPT-6 Sol($2 / $10)与 GPT-6 Luna($0.1 / $0.5)。
-
Claude Code 客户端版本号改为自动同步(feat(claude)),替代原先硬编码基线;
Opus 5.5 要求客户端 >= 2.1.280,该机制可自动满足。 -
我方保留 X-Stainless-Package-Version = 0.112.1(实抓 Claude Code 2.1.280
流量所得),与自动同步的 CLI 版本匹配,避免被判第三方。 -
OpenCode Go 官方用量窗口查询与自动刷新,支持同 Key 组共享、活动防抖、
超窗强刷,用量单元格可主动查询,周/月徽章改为 7d / 1m。 -
用量窗口资格扩展到其它厂商挂载。
-
简易模式可选启用 API Key 消费窗口限制。
-
备份支持月度归档与独立保留策略。
-
日志滚动保留策略可配置。
-
返利提取支持登记线下提现。
-
fix(responses): 终端事件即结束流式,不再等待上游 EOF;协议错误只发一次;
剥离超长 input item ID。 -
fix(streaming): OpenAI 转换前丢弃 Anthropic ping 心跳;心跳不再混入语义输出。
-
fix(scheduler): 调度投影保留账号 RPM 配置;调度倍率补账号倍率回退。
-
fix(antigravity): 系统提示词中和 Claude Agent SDK 身份(规避 429);
Schema 清理支持 prefixItems 并为数组补有效 items 兜底。 -
fix(grok): 账号冷却期间仍允许配额查询。
-
fix(openai): 透传模式下尊重图片选项;OAuth 图片别名保留在测试选择器;
账号测试模型按 model mapping 过滤;保留携带 Responses Lite 标记的 GPT-5.5 请求。 -
fix(upstream): 关闭 body 前先取消响应尝试。
-
fix(gateway): 为 Gemini 分组列出混合 antigravity 模型。
-
claude/constants.go:采用上游把 DefaultHeaders 改为函数的重构(配合版本自动
同步),仅保留我方的 SDK 版本值。 -
account_repo.go / admin_account.go / account_handler.go:取并集,保住 fork
独有的 Kiro 平台(凭据变更触发 catalog 清理、token refresher、extra 键)。 -
定价 JSON:采用上游格式与数据(与官方价一致)。
后端 build / vet / -tags=unit / -tags=integration / golangci-lint(0 issues)
前端 typecheck / lint 全部通过。
📥 Installation
Docker:
# Docker Hub
docker pull doublepi/sub2api:0.2.27
# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.27One-line install (Linux):
curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bashManual download:
Download the appropriate archive for your platform from the assets below.
📚 Documentation
Sub2API 0.2.26
AI API Gateway Platform - 将 AI 订阅配额分发和管理
📥 Installation
Docker:
# Docker Hub
docker pull doublepi/sub2api:0.2.26
# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.26One-line install (Linux):
curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bashManual download:
Download the appropriate archive for your platform from the assets below.
📚 Documentation
Sub2API 0.2.25
AI API Gateway Platform - 将 AI 订阅配额分发和管理
📥 Installation
Docker:
# Docker Hub
docker pull doublepi/sub2api:0.2.25
# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.25One-line install (Linux):
curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bashManual download:
Download the appropriate archive for your platform from the assets below.
📚 Documentation
Sub2API 0.2.24
AI API Gateway Platform - 将 AI 订阅配额分发和管理
📥 Installation
Docker:
# Docker Hub
docker pull doublepi/sub2api:0.2.24
# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.24One-line install (Linux):
curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bashManual download:
Download the appropriate archive for your platform from the assets below.
📚 Documentation
Sub2API 0.2.23
AI API Gateway Platform - 将 AI 订阅配额分发和管理
📥 Installation
Docker:
# Docker Hub
docker pull doublepi/sub2api:0.2.23
# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.23One-line install (Linux):
curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bashManual download:
Download the appropriate archive for your platform from the assets below.
📚 Documentation
Sub2API 0.2.22
AI API Gateway Platform - 将 AI 订阅配额分发和管理
📥 Installation
Docker:
# Docker Hub
docker pull doublepi/sub2api:0.2.22
# GitHub Container Registry
docker pull ghcr.io/doublepi123/sub2api:0.2.22One-line install (Linux):
curl -sSL https://raw.githubusercontent.com/doublepi123/sub2api/main/deploy/install.sh | sudo bashManual download:
Download the appropriate archive for your platform from the assets below.