mrkeyoor.com_
Wed 07 Oct 07:31 UTC
AI Toolsevaluationupdated 07 Oct 2026

underclass review

Underclass combines several ChatGPT/Codex and GitHub Copilot subscriptions behind one local OpenAI-compatible address. It keeps sessions on the same account, removes exhausted accounts from rotation, and brings them back when their quotas reset.

Verdict

Our underclass run passed all 178 tests after a 177-second build, so the code earned more confidence than its unreleased 0.1.0 label suggests. Use it when you accept the security and account-policy responsibility of placing several subscription tokens behind one local service. Wait if OpenCode v2 compatibility, tagged releases, or recovery after streaming begins are requirements.

We ran it

Lab card: what happened when we ran underclassScreenshot of underclass (ghuntley.com)
Install✓ · 16s271 packages
Build✓ · 177s
Tests✓ · 85s178 passed · 0 failed of 178 (cargo test)
Repo66 files~8,315 lines of source · 0.5 MB · 1 CI workflows · tests dir

Answers from our run

Does underclass build from source?

Dependencies installed in 16 seconds (271 packages), and the build succeeded in 177 seconds. We cloned commit 3e35c3b into a clean Debian container with 3 CPUs and no project-specific setup.

Do underclass's tests pass?

Yes: 178 of 178 passed when we ran the project's own test command (cargo test). Some failures need services or credentials a bare container does not have.

Who should not use underclass?

Teams that want a stateless gateway: Underclass stores account credentials, sticky bindings, model catalogs, and keys in a local SQLite database.

What are the alternatives to underclass?

LiteLLM, Portkey Gateway, Open WebUI. Our underclass run passed all 178 tests after a 177-second build, so the code earned more confidence than its unreleased 0.

Setup3/5Clean build and tests, but every account needs an OAuth login
Docs4/5Detailed routing, secrets, NixOS, API, and failure behavior
Community2/5177 stars, 2 open issues, and mostly automated pull requests
Maturity2/5178 tests passed, though 0.1.0 has no tags or releases

Who it’s for

Developers who already pay for several Codex or Copilot subscriptions and need one endpoint for them.
OpenCode users willing to manage OAuth device logins and a local proxy.
Small teams that need sticky sessions, quota cooldowns, and per-attempt token records.
NixOS operators who want a packaged service with a local monitor socket.

Who it’s NOT for

Teams that want a stateless gateway: Underclass stores account credentials, sticky bindings, model catalogs, and keys in a local SQLite database.
Operators unwilling to centralize several personal subscription tokens on one machine.
Anyone expecting mid-stream recovery: after the first response byte, an upstream error passes through without retrying another account.
OpenCode v2 users who need confirmed compatibility before adoption: open issue 3 records a generated-config failure, and the maintainer's reply said v2 had not yet been tried.
Buyers requiring signed releases or stable version tags: GitHub returned no latest release, the tag list was empty, and the manifest still says 0.1.0.

Setup reality

Our fresh Rust sandbox installed commit 3e35c3b in 16 seconds and pulled 271 packages. The build succeeded in 177 seconds. Cargo test finished in 85 seconds with all 178 tests passing and 0 failures.

Running the proxy requires a client bearer key, an admin UI token, and an OAuth device login for every ChatGPT/Codex or GitHub Copilot subscription in the pool. State and credentials live in SQLite. The service talks to the provider endpoints, so this is not an offline tool.

The default bind is localhost on port 8080. Rust and Cargo work for a source run, while Nix and a NixOS module are the packaged paths. The repository has no Dockerfile. OpenCode integration edits global config by default, though dry-run, project-only, backup, and removal options are documented.

One endpoint rotates across several subscriptions

Underclass accepts OpenAI-style Responses and Chat Completions requests, then sends each one through a pool of ChatGPT/Codex or GitHub Copilot accounts. A quota error cools an account until its reset window, and the account returns to rotation automatically. When every eligible account is cooling, the proxy returns HTTP 429 with the earliest reset time. It does not leave the caller waiting on an empty pool.

Sticky bindings keep a session on one subscription for 24 hours, which preserves upstream prompt-cache behavior across turns. The selection policy prefers accounts with fewer requests in flight and filters them by the model catalog. State survives a restart in SQLite. For a developer with several existing subscriptions, that is a specific solution to a real nuisance: client tools see one address while Underclass tracks which account can still accept work.

This design also concentrates access. The same database holds account credentials, sticky bindings, model entries, and minted keys. Underclass says it does not log authorization headers, refresh tokens, or prompt bodies, while account labels and usage do appear in its diagnostics and UI. The burden sits with the operator to protect pool.db, the admin token, backups, and the host itself.

What happened when we ran it

Our sandbox installed commit 3e35c3b in 16 seconds and pulled 271 Rust packages. The build succeeded in 177 seconds, and cargo test completed in 85 seconds. All 178 tests passed with 0 failures. The container had 3 CPUs, 12 GB of RAM, no secrets, and no elevated privileges. This was a clean result for the repository mechanics we could exercise.

The checkout was only 0.5 MB, with 66 files and about 8,315 lines of source. It has a tests directory and 1 CI workflow. There is no Dockerfile. The small tree makes the proxy easier to inspect than a multi-service gateway, although its 271-package dependency graph and 177-second build still deserve normal supply-chain review and pinned artifacts.

We did not connect a paid account, spend quota, or send a live request to either provider. The passing 178-test suite covers the local test harness at that commit. It does not prove that an OAuth flow, quota response, model catalog, or provider policy will remain unchanged. Those surfaces belong to services outside this repository and need a live acceptance test with accounts you are authorized to use.

Two bearer secrets protect different surfaces

The quick start asks for a proxy key for /v1/* clients and a separate UI token for administration. Each subscription then goes through its provider's device flow. By default the server binds to 127.0.0.1:8080, and the NixOS module keeps the firewall closed. Those are sensible defaults for a service holding several OAuth tokens. Binding it beyond localhost changes the risk sharply.

The CLI can write an Underclass provider and credential entry into OpenCode's global configuration. It makes backups, supports a dry run, and can remove its changes. Nix users get a package, app, development shell, and NixOS module. Everyone else can run it through Cargo. With no Dockerfile in the 66-file repository, teams standardized on containers must create and maintain that packaging themselves.

Streaming errors never move to a second account

Failover ends once the first response byte has been sent. If the chosen upstream breaks later, Underclass passes the error to the caller because silently replaying part of a generated answer could duplicate or corrupt output. That is the right trade for correctness, but it means account pooling cannot make a long streaming request immune to provider failures.

Automatic use of banked Codex resets is enabled by default. When all eligible Codex accounts are unavailable, Underclass may spend one reset on the account facing the longest wait. Operators who treat those credits as manually controlled inventory should set UNDERCLASS_AUTO_CODEX_RESETS=false. Token totals also exclude attempts whose upstream counts are missing, so the dashboard describes those totals as lower bounds rather than complete billing data.

OpenCode v2 compatibility still needs a local check

Open issue 3 reports that the generated OpenCode configuration sent Chat Completions fields to the Codex Responses path. The maintainer replied on September 23, 2026 that the integration had been created for OpenCode v1 and that v2 had not yet been tried. The issue remains open. A README quick start can be accurate for one client generation and still fail for the next, so run underclass connect --dry-run and make a real request before changing team configs.

The web UI and terminal monitor are useful once the proxy is live. They show account state, a 60-minute attempt chart, current-month token accounting, sticky sessions, and Codex quota windows. The local monitor socket avoids placing an admin token in a terminal command, but its snapshot includes account labels and usage. Local users allowed to read that socket receive operational metadata.

Version 0.1.0 has no tagged release

The repository was pushed on October 7, 2026, the day of our review, and GitHub showed 177 stars. Its 9 open issues and pull requests split into 2 issues and 7 pull requests, with most pull requests opened by dependency automation. Current activity is clear. A broad contributor community is not.

GitHub returned no latest release, the repository had 0 tags, and Cargo.toml still declared version 0.1.0. That early state matters more here because the tool stores OAuth credentials and sits between coding clients and paid services. The 178 passing tests are a strong start, especially beside the explicit routing ADRs, yet teams should pin a commit and rehearse database backup and credential rejection before depending on it.

Underclass is easiest to recommend to one technical operator who understands every account in the pool. Our 85-second test run found no failing test at commit 3e35c3b. The unresolved OpenCode v2 report and missing release history still make a staged deployment the sensible choice: localhost first, one disposable client configuration, then additional subscriptions only after routing, cooldowns, and reset behavior match your expectations.

Alternatives

ProjectWhat it isPick it when
LiteLLM gh↗An OpenAI-compatible gateway for many model providers, API keys, budgets, and routing rules.pick this instead when you are routing provider API credentials rather than pooling personal subscriptions.
Portkey GatewayA gateway focused on provider routing, guardrails, and request controls.pick this instead when policy checks and broad provider coverage matter more than Codex or Copilot quota pooling.
Open WebUI gh↗A self-hosted chat interface for local and hosted model endpoints.pick this instead when people need a full chat workspace rather than a subscription-pooling proxy.

What people are saying

  1. [velocity-scout] ghuntley/underclass

Sources

  1. Underclass repository
  2. Underclass README
  3. OpenCode generated configuration issue
  4. Automatic Codex banked resets decision
  5. Underclass Cargo manifest

More ai tools reviews

embodied-jev · minecraft-agent · laya-coreml · CometixCode · openJev-verdict-2.0 · editaplot2026 · the whole board →