The 57 endpoints still share one WARP exit
Warp Masque Actions generates a mihomo configuration with 57 Cloudflare WARP MASQUE endpoints. The number sounds like a location catalog, but the README makes the important distinction: every endpoint belongs to the same WARP account and uses the same exit IP. The variation is at the entry side, so a client can try another address or port when one route is blocked. Free WARP does not let this project choose a country.
That makes the plain workflow useful for a specific job. You fork the repository, enable Actions, run the configuration workflow, and download an artifact containing mihomo YAML, Shadowrocket links, and the original usque configuration. The README says 28 endpoints use IPv6. A client without IPv6 will skip those, leaving the IPv4 entries available. Users expecting 57 distinct exits will be disappointed; users seeking several paths into one WARP account are closer to the intended audience.
What happened when we ran it
Our sandbox installed commit a18457d in 22 seconds, adding 45 packages and using 231 MB on disk. The build succeeded in 7 seconds. The supplied tests then completed successfully in 30 seconds, and npm audit reported 0 known vulnerabilities. The container had 3 CPUs, 8 GB of RAM, Node 22, no secrets, and no elevated privileges.
The checkout contained 25 files, about 3,806 lines of source, and occupied 0.6 MB before installation. It includes 4 GitHub Actions workflow files, a test directory, and no Dockerfile. Those results cover the JavaScript Worker in worker/; they do not prove that a generated tunnel connects from your network, that an upstream account survives provider controls, or that a chosen client accepts the output.
Four workflows spread setup across GitHub and Cloudflare
The repository has 4 workflows for plain WARP, Opera over MASQUE, Proton, and Windscribe. The plain WARP job has read-only repository permission, downloads usque, registers a device, creates the files, loads the YAML with mihomo as a parser check, and uploads the result as an artifact. The Opera workflow can also commit generated YAML back to the fork, so it requests write permission when that option is used.
Credentials deserve more attention than the green workflow badge. The README compares the generated private key to an account password and says a public fork's artifact is downloadable. Artifacts default to 7 days, but shortening retention does not make a public artifact private while it exists. Proton requires PROTON_USER, PROTON_PASS, and a Worker push URL in GitHub Secrets. If that account boundary feels too loose, use a private fork and rotate the generated WARP identity after any exposure.
Mihomo Alpha is a hard client requirement
The README says MASQUE requires mihomo's Alpha branch, and a stable kernel rejects the proxy type. Updating a desktop client does not automatically switch its embedded kernel. The guide gives separate paths for Clash Verge Rev, ClashMi, Shadowrocket, and a direct mihomo binary, while it rules out Surge, Quantumult X, and Karing for this configuration. That is a compatibility boundary, not a cosmetic preference.
The chained Opera configuration narrows the field further because it uses dialer-proxy. Shadowrocket can consume the plain MASQUE links but cannot use that chained layout, according to the project. Opera adds regional exits in Asia, Europe, and the Americas, while Proton and Windscribe add other country or region choices. Each extra hop also adds another provider, credential lifetime, and failure point to diagnose.
The Worker refreshes credentials but skips one Actions check
The Cloudflare Worker checks Opera credentials on subscription access and treats 4 hours as their lifetime. It stores the WARP registration and generated configuration in KV, exposes a password-protected management page, and signs subscription URLs so clients do not need a login cookie. The README says failed logins from one IP lock for 15 minutes after 8 attempts, and changing the password invalidates old subscription links.
This path removes the need to run a workflow each time Opera credentials expire. It also changes what gets verified. The Actions workflow downloads mihomo and asks it to parse the generated file. The Worker cannot perform that load check, which the README calls out directly. You gain an always-available URL and automatic refresh, but a bad generated configuration can travel farther before a client reports it.
Five open items include provider-side credential failures
GitHub listed 5 open issues and pull requests on September 30, 2026, and the last push was September 7. Two issue reports concern Proton or Windscribe credentials failing in GitHub Actions. Issue 10 includes an HTTP 422 response requiring a CAPTCHA, while issue 5 says the runner IP could not pass provider verification. Those reports match the README's warning that provider controls can reject automated registration.
There is no tagged release, and GitHub reports no detected license. Neither point proves the code is unmaintained: the September push and current issue activity show recent work. They do limit adoption. Without a license, a company cannot assume permission to redistribute or modify the code. Without releases, users track a moving branch or pin a commit themselves. Warp Masque Actions is a practical personal setup for its narrow audience, not a low-policy network component for an organization.

