1,034 files sit behind the one-line installer
vm2api presents one public API in front of official Claude Code and Codex client processes. It accepts Anthropic Messages, OpenAI Chat Completions, and Responses-shaped requests, then routes work through isolated slots. The README describes hardware fingerprints, separate machine identities, per-slot credentials, quota windows, and dedicated network exits. This is much closer to running a small hosting control plane than configuring an HTTP adapter. Our checkout contained 1,034 files, about 179,178 lines of source, and 155.8 MB before installation, which explains why the deployment guide spends so much time on containers, networks, workers, and recovery.
The project is Chinese-first, with substantial English sections in the same README. English readers can understand the architecture and quick start, but the Chinese deployment guide carries more of the operational detail. GitHub showed 782 stars and 4 open issues and pull requests on 2026-10-05. The audience is narrow: an operator who understands the upstream subscription accounts, accepts the project's custom license, and wants to manage multiple isolated client sessions through one interface. Anyone expecting a small JavaScript proxy will be surprised by the host access and slot lifecycle behind port 8787.
3 secrets and one egress are the minimum real setup
The deployment guide requires VM2API_API_KEY, VM2API_ADMIN_PASSWORD, and VM2API_DB_SECRET, plus provider credentials inside working slots. Every active slot also needs a bound network egress. The control plane mounts docker.sock, uses host networking, and creates bridge paths for slot traffic. If UFW or firewalld blocks those paths, the guide says slot requests can return 502 incomplete_response even while the panel's proxy probe looks normal. That is a useful warning because it names an operational failure that a green dashboard can miss.
Ubuntu 24.04 is the recommended host. The guide says Debian 12 often cannot start the slot kernel, and ARM64 support is marked experimental. On ARM64, the control plane is native but the slot remains amd64 and runs through QEMU. The default console login can be admin with password 123456 when no value is configured, so replacing it before exposing port 8787 is mandatory housekeeping. HTTPS is also left to a reverse proxy, with a separate WebSocket route required for the browser terminal. None of this is impossible, but it belongs in an infrastructure change review.
What happened when we ran it
Our sandbox installed commit a3b267c in 42 seconds. npm added 26 packages and used 137 MB on disk, while the checked-out repository occupied 155.8 MB. There was no build script or target, so we skipped that step rather than inventing one. npm audit reported 1 known vulnerability at moderate severity, with no critical or high findings. The repository had 3 CI workflow files, a Dockerfile, a Compose file, and a tests directory. Those are useful maintenance signals, although they do not replace a clean command exit.
The test command ran for 310 seconds and exited with code 1. Its node:test summary reported 9 passed and 0 failed out of 9, and the supplied log tail only showed successful cases, including non-ELF kernel rejection and xxh64 reference checks. The tail did not show why the overall command returned 1, so we will not assign a cause. The practical finding is specific: assertions in the reported set passed, yet an automated release gate based on the process exit would still fail. Reproduce that command before trusting an upgrade.
The noncommercial license blocks unapproved business use
The repository is source-available under a custom noncommercial license, not a standard permissive open-source license. It allows personal learning, research, evaluation, and noncommercial self-hosting. Selling access, using it to deliver a business, charging for a derivative, or operating it inside a company for production revenue requires separate written authorization. That condition rules out many plausible gateway deployments before technical evaluation starts. The README also says the project has no direct affiliation with Anthropic or OpenAI, so prospective users must review the providers' current subscription and acceptable-use terms themselves.
v1.3.107 is active, but activity does not remove account risk
Version v1.3.107 was published on 2026-10-05, the same date GitHub recorded the latest push. Its notes describe logging changes, an ARM64 control plane, multi-architecture images, and fixes for QEMU-managed slot processes. Two open items were pull requests for guest lifecycle work and proxy credential handling; the remaining issues concerned duplicate Claude account rows and minimum machine sizing. That is current development, not a dormant dump. It also cannot prove that hardware emulation, independent egress, or official-client forwarding will satisfy a provider's rules or prevent restrictions.
vm2api makes the most sense as a personal research system whose operator wants to study this exact subscription-to-API design. A standard provider gateway has fewer moving pieces because it begins with supported API credentials rather than maintaining simulated client machines. LiteLLM, One API, and New API all fit that more ordinary job. vm2api earns attention for the depth of its slot isolation, but the custom license, Docker host privileges, one-egress-per-slot model, and unexplained test exit make it a deliberate lab choice rather than a default gateway.

