mrkeyoor.com_
Mon 05 Oct 06:26 UTC
Self-Hostedevaluationupdated 05 Oct 2026

vm2api review

vm2api is a Chinese-first project, and its long README also includes English documentation. It turns Claude and ChatGPT subscription sessions into Anthropic- and OpenAI-compatible API endpoints by running official client processes inside isolated containers or virtual machines.

Verdict

Our vm2api test command ran for 310 seconds and exited 1 despite 9 reported passing tests, while npm audit found 1 moderate vulnerability. Treat it as a noncommercial infrastructure experiment for operators who understand Docker's host privileges and can judge provider-account risk themselves. Businesses should stop at the license, and teams with official API credentials will usually get a simpler system from LiteLLM or a conventional API relay.

We ran it

Lab card: what happened when we ran vm2apiScreenshot of vm2api (github.com/dofastted/vm2api)
Install✓ · 42s26 packages · 137 MB
Buildn/ano build script
Tests✗ · 310s9 passed · 0 failed of 9 (node:test)
Known vulns10 critical · 0 high · 1 moderate · 0 low (npm audit)
Repo1034 files~179,178 lines of source · 155.8 MB · 3 CI workflows · Dockerfile · tests dir

Answers from our run

Does vm2api build from source?

Dependencies installed in 42 seconds (26 packages), and the project has no separate build step. We cloned commit a3b267c into a clean Debian container with 3 CPUs and no project-specific setup.

Do vm2api's tests pass?

Yes: 9 of 9 passed when we ran the project's own test command (node:test). Some failures need services or credentials a bare container does not have.

Does vm2api have known vulnerabilities in its dependencies?

npm audit flagged 1 known advisory in the dependency tree at the time of our run.

Who should not use vm2api?

Any business without written permission from the author: the custom license prohibits commercial use, including internal revenue-producing use.

What are the alternatives to vm2api?

LiteLLM, One API, New API. Our vm2api test command ran for 310 seconds and exited 1 despite 9 reported passing tests, while npm audit found 1 moderate vulnerability.

Setup2/526 packages install quickly; real slots need privileged host setup
Docs4/5Long bilingual README plus detailed deployment and firewall guides
Community3/5782 stars, 4 open issues and PRs, pushed 2026-10-05
Maturity2/5Frequent releases, experimental ARM64, and a nonzero test exit

Who it’s for

Experienced self-hosters researching subscription-backed AI gateways for personal, noncommercial use.
Operators comfortable with Docker networking, dedicated per-slot egress, host firewalls, and provider credentials.
Developers who need Anthropic Messages, OpenAI Chat Completions, and Responses-style endpoints from one private gateway.
Chinese-speaking operators who can use the primary documentation, while English readers can follow the translated README sections.

Who it’s NOT for

Any business without written permission from the author: the custom license prohibits commercial use, including internal revenue-producing use.
Teams that need a gateway endorsed by Anthropic or OpenAI: the README says vm2api is independent, while its design emulates hardware and client behavior to reduce account restrictions.
Restricted hosting where mounting Docker's socket or using host networking is forbidden: the deployment guide requires both for the control plane.
Debian 12 or risk-averse ARM64 operators: the deployment guide says slot kernels often fail on Debian 12, while ARM64 control-plane support is experimental and still runs amd64 slots through QEMU.
Release gates that accept only a zero-exit test command: our run exited 1 even though the reported node:test set had 9 passes and no failed assertions.

Setup reality

Our sandbox installed commit a3b267c in 42 seconds: 26 packages occupied 137 MB. There was no build script, so no build ran. The test command ran for 310 seconds and exited 1, although node:test reported 9 passed and 0 failed out of 9. npm audit found 1 moderate vulnerability.

A real deployment needs at least an API key, admin password, database secret, provider credentials, and one network egress for every active slot. The guide targets Ubuntu 24.04 with Docker Compose, mounts the Docker socket, uses host networking, and documents firewall rules for the per-slot bridges.

The install script can pull prepared images, but operations are not one-click. Default admin credentials must be replaced, slot state needs persistent storage, and HTTPS needs a reverse proxy. ARM64 support is experimental and runs amd64 slot processes through QEMU.

1,034 files sit behind the one-line installer

vm2api presents one public API in front of official Claude Code and Codex client processes. It accepts Anthropic Messages, OpenAI Chat Completions, and Responses-shaped requests, then routes work through isolated slots. The README describes hardware fingerprints, separate machine identities, per-slot credentials, quota windows, and dedicated network exits. This is much closer to running a small hosting control plane than configuring an HTTP adapter. Our checkout contained 1,034 files, about 179,178 lines of source, and 155.8 MB before installation, which explains why the deployment guide spends so much time on containers, networks, workers, and recovery.

The project is Chinese-first, with substantial English sections in the same README. English readers can understand the architecture and quick start, but the Chinese deployment guide carries more of the operational detail. GitHub showed 782 stars and 4 open issues and pull requests on 2026-10-05. The audience is narrow: an operator who understands the upstream subscription accounts, accepts the project's custom license, and wants to manage multiple isolated client sessions through one interface. Anyone expecting a small JavaScript proxy will be surprised by the host access and slot lifecycle behind port 8787.

3 secrets and one egress are the minimum real setup

The deployment guide requires VM2API_API_KEY, VM2API_ADMIN_PASSWORD, and VM2API_DB_SECRET, plus provider credentials inside working slots. Every active slot also needs a bound network egress. The control plane mounts docker.sock, uses host networking, and creates bridge paths for slot traffic. If UFW or firewalld blocks those paths, the guide says slot requests can return 502 incomplete_response even while the panel's proxy probe looks normal. That is a useful warning because it names an operational failure that a green dashboard can miss.

Ubuntu 24.04 is the recommended host. The guide says Debian 12 often cannot start the slot kernel, and ARM64 support is marked experimental. On ARM64, the control plane is native but the slot remains amd64 and runs through QEMU. The default console login can be admin with password 123456 when no value is configured, so replacing it before exposing port 8787 is mandatory housekeeping. HTTPS is also left to a reverse proxy, with a separate WebSocket route required for the browser terminal. None of this is impossible, but it belongs in an infrastructure change review.

What happened when we ran it

Our sandbox installed commit a3b267c in 42 seconds. npm added 26 packages and used 137 MB on disk, while the checked-out repository occupied 155.8 MB. There was no build script or target, so we skipped that step rather than inventing one. npm audit reported 1 known vulnerability at moderate severity, with no critical or high findings. The repository had 3 CI workflow files, a Dockerfile, a Compose file, and a tests directory. Those are useful maintenance signals, although they do not replace a clean command exit.

The test command ran for 310 seconds and exited with code 1. Its node:test summary reported 9 passed and 0 failed out of 9, and the supplied log tail only showed successful cases, including non-ELF kernel rejection and xxh64 reference checks. The tail did not show why the overall command returned 1, so we will not assign a cause. The practical finding is specific: assertions in the reported set passed, yet an automated release gate based on the process exit would still fail. Reproduce that command before trusting an upgrade.

The noncommercial license blocks unapproved business use

The repository is source-available under a custom noncommercial license, not a standard permissive open-source license. It allows personal learning, research, evaluation, and noncommercial self-hosting. Selling access, using it to deliver a business, charging for a derivative, or operating it inside a company for production revenue requires separate written authorization. That condition rules out many plausible gateway deployments before technical evaluation starts. The README also says the project has no direct affiliation with Anthropic or OpenAI, so prospective users must review the providers' current subscription and acceptable-use terms themselves.

v1.3.107 is active, but activity does not remove account risk

Version v1.3.107 was published on 2026-10-05, the same date GitHub recorded the latest push. Its notes describe logging changes, an ARM64 control plane, multi-architecture images, and fixes for QEMU-managed slot processes. Two open items were pull requests for guest lifecycle work and proxy credential handling; the remaining issues concerned duplicate Claude account rows and minimum machine sizing. That is current development, not a dormant dump. It also cannot prove that hardware emulation, independent egress, or official-client forwarding will satisfy a provider's rules or prevent restrictions.

vm2api makes the most sense as a personal research system whose operator wants to study this exact subscription-to-API design. A standard provider gateway has fewer moving pieces because it begins with supported API credentials rather than maintaining simulated client machines. LiteLLM, One API, and New API all fit that more ordinary job. vm2api earns attention for the depth of its slot isolation, but the custom license, Docker host privileges, one-egress-per-slot model, and unexplained test exit make it a deliberate lab choice rather than a default gateway.

Alternatives

ProjectWhat it isPick it when
LiteLLM gh↗A multi-provider proxy built around supported model APIs and a common request format.pick this instead when official provider API keys and broad vendor routing matter more than reusing subscription sessions.
One APIA self-hosted key-management and relay layer for several model APIs.pick this instead when you need ordinary API-key distribution and usage control with less host-level machinery.
New API gh↗A newer multi-model API management and distribution system derived from One API.pick this instead when channel management, billing controls, and standard upstream APIs are the main job.

What people are saying

  1. [velocity-scout] dofastted/vm2api

Sources

  1. vm2api bilingual README
  2. vm2api deployment guide
  3. vm2api license
  4. vm2api v1.3.107 release
  5. vm2api issues and pull requests

More self-hosted reviews

hysteria · skillbox · FounderOS-DEMO · UFI-TOOLS · awesome-cloudflare-selfhosted · life · the whole board →