mrkeyoor.com_
Thu 01 Oct 07:53 UTC
Automationevaluationupdated 30 Sept 2026

warp-masque-actions review

Warp Masque Actions is a Chinese-language set of GitHub Actions and a Cloudflare Worker that generate Cloudflare WARP MASQUE credentials and mihomo configurations. The documentation is detailed, but there is no English README, so non-Chinese readers will need translation before handling its credential and client setup.

trackingstars / 7d
Verdict

Our worker run installed 45 packages, used 231 MB, and passed its build and tests in 37 seconds combined, so the code path is small enough to inspect and reproduce. Use Warp Masque Actions if you read Chinese, already accept mihomo Alpha, and understand that 57 endpoints still mean one WARP exit. Skip it when an explicit license, stable-kernel support, or English runbooks are required.

We ran it

Lab card: what happened when we ran warp-masque-actionsScreenshot of warp-masque-actions (github.com/byJoey/warp-masque-actions)
Install✓ · 22s45 packages · 231 MB
Build✓ · 7s
Tests✓ · 30sran, no count parsed
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo25 files~3,806 lines of source · 0.6 MB · 4 CI workflows · tests dir

Answers from our run

Does warp-masque-actions build from source?

Dependencies installed in 22 seconds (45 packages), and the build succeeded in 7 seconds. We cloned commit a18457d into a clean Debian container with 3 CPUs and no project-specific setup.

Do warp-masque-actions's tests pass?

The test command failed in our container, and its output did not report a pass or fail count.

Does warp-masque-actions have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use warp-masque-actions?

Teams that require English operational documentation: the repository has no English README.

What are the alternatives to warp-masque-actions?

usque, wgcf, Oblivion Desktop. Our worker run installed 45 packages, used 231 MB, and passed its build and tests in 37 seconds combined, so the code path is small enough to inspect and reproduce.

Setup4/545 packages and green checks, but client and Worker setup remain
Docs4/5Detailed Chinese guide with no English README
Community3/5995 stars, 5 open issues and PRs, last push September 7
Maturity3/5Tests pass, but no license or tagged release is published

Who it’s for

Chinese-reading users who want a WARP MASQUE configuration without maintaining a server.
Mihomo Alpha users comfortable forking a repository and collecting a GitHub Actions artifact.
Cloudflare Workers users who want a private subscription URL that refreshes short-lived upstream credentials.
Tinkerers who understand that the 57 endpoints provide route choice, not 57 countries.

Who it’s NOT for

Teams that require English operational documentation: the repository has no English README.
Organizations that require an explicit open-source license before adoption: GitHub reports no detected license.
Users staying on stable mihomo or clients such as Surge and Quantumult X: the README says they do not understand the MASQUE configuration.
Anyone expecting country selection from free WARP: the README says all 57 endpoints share the same exit IP, and country selection needs another service.
People who plan to publish a fork without checking artifacts: the README warns that the generated private key is equivalent to an account password and public-repository artifacts can be downloaded by others.

Setup reality

Our run started in the worker/ directory. Npm installed 45 packages in 22 seconds and used 231 MB on disk; the build passed in 7 seconds, and the supplied tests passed in 30 seconds. Npm audit reported 0 known vulnerabilities.

The simple path still needs a GitHub fork, enabled Actions, and a MASQUE-capable client. The Worker path needs a Cloudflare account, Wrangler login, a KV namespace, a deployed Worker, and a password set through its web page. Proton adds three repository secrets.

The generated mihomo file requires the Alpha kernel according to the README. Public artifacts can expose the private key, 28 of the 57 endpoints need IPv6, and the Worker cannot perform the configuration-load check used by the Actions workflow.

The 57 endpoints still share one WARP exit

Warp Masque Actions generates a mihomo configuration with 57 Cloudflare WARP MASQUE endpoints. The number sounds like a location catalog, but the README makes the important distinction: every endpoint belongs to the same WARP account and uses the same exit IP. The variation is at the entry side, so a client can try another address or port when one route is blocked. Free WARP does not let this project choose a country.

That makes the plain workflow useful for a specific job. You fork the repository, enable Actions, run the configuration workflow, and download an artifact containing mihomo YAML, Shadowrocket links, and the original usque configuration. The README says 28 endpoints use IPv6. A client without IPv6 will skip those, leaving the IPv4 entries available. Users expecting 57 distinct exits will be disappointed; users seeking several paths into one WARP account are closer to the intended audience.

What happened when we ran it

Our sandbox installed commit a18457d in 22 seconds, adding 45 packages and using 231 MB on disk. The build succeeded in 7 seconds. The supplied tests then completed successfully in 30 seconds, and npm audit reported 0 known vulnerabilities. The container had 3 CPUs, 8 GB of RAM, Node 22, no secrets, and no elevated privileges.

The checkout contained 25 files, about 3,806 lines of source, and occupied 0.6 MB before installation. It includes 4 GitHub Actions workflow files, a test directory, and no Dockerfile. Those results cover the JavaScript Worker in worker/; they do not prove that a generated tunnel connects from your network, that an upstream account survives provider controls, or that a chosen client accepts the output.

Four workflows spread setup across GitHub and Cloudflare

The repository has 4 workflows for plain WARP, Opera over MASQUE, Proton, and Windscribe. The plain WARP job has read-only repository permission, downloads usque, registers a device, creates the files, loads the YAML with mihomo as a parser check, and uploads the result as an artifact. The Opera workflow can also commit generated YAML back to the fork, so it requests write permission when that option is used.

Credentials deserve more attention than the green workflow badge. The README compares the generated private key to an account password and says a public fork's artifact is downloadable. Artifacts default to 7 days, but shortening retention does not make a public artifact private while it exists. Proton requires PROTON_USER, PROTON_PASS, and a Worker push URL in GitHub Secrets. If that account boundary feels too loose, use a private fork and rotate the generated WARP identity after any exposure.

Mihomo Alpha is a hard client requirement

The README says MASQUE requires mihomo's Alpha branch, and a stable kernel rejects the proxy type. Updating a desktop client does not automatically switch its embedded kernel. The guide gives separate paths for Clash Verge Rev, ClashMi, Shadowrocket, and a direct mihomo binary, while it rules out Surge, Quantumult X, and Karing for this configuration. That is a compatibility boundary, not a cosmetic preference.

The chained Opera configuration narrows the field further because it uses dialer-proxy. Shadowrocket can consume the plain MASQUE links but cannot use that chained layout, according to the project. Opera adds regional exits in Asia, Europe, and the Americas, while Proton and Windscribe add other country or region choices. Each extra hop also adds another provider, credential lifetime, and failure point to diagnose.

The Worker refreshes credentials but skips one Actions check

The Cloudflare Worker checks Opera credentials on subscription access and treats 4 hours as their lifetime. It stores the WARP registration and generated configuration in KV, exposes a password-protected management page, and signs subscription URLs so clients do not need a login cookie. The README says failed logins from one IP lock for 15 minutes after 8 attempts, and changing the password invalidates old subscription links.

This path removes the need to run a workflow each time Opera credentials expire. It also changes what gets verified. The Actions workflow downloads mihomo and asks it to parse the generated file. The Worker cannot perform that load check, which the README calls out directly. You gain an always-available URL and automatic refresh, but a bad generated configuration can travel farther before a client reports it.

Five open items include provider-side credential failures

GitHub listed 5 open issues and pull requests on September 30, 2026, and the last push was September 7. Two issue reports concern Proton or Windscribe credentials failing in GitHub Actions. Issue 10 includes an HTTP 422 response requiring a CAPTCHA, while issue 5 says the runner IP could not pass provider verification. Those reports match the README's warning that provider controls can reject automated registration.

There is no tagged release, and GitHub reports no detected license. Neither point proves the code is unmaintained: the September push and current issue activity show recent work. They do limit adoption. Without a license, a company cannot assume permission to redistribute or modify the code. Without releases, users track a moving branch or pin a commit themselves. Warp Masque Actions is a practical personal setup for its narrow audience, not a low-policy network component for an organization.

Alternatives

ProjectWhat it isPick it when
usqueA command-line reimplementation of Cloudflare WARP's MASQUE protocol.pick this instead when you want the underlying registration and tunnel tool without this repository's generated mihomo layout.
wgcf gh↗An unofficial cross-platform CLI for creating Cloudflare WARP WireGuard profiles.pick this instead when a WireGuard profile fits your client and you do not need MASQUE or the Worker subscription page.
Oblivion DesktopA desktop WARP client for Windows, macOS, and Linux.pick this instead when you want a graphical client rather than generated credentials and YAML files.

What people are saying

  1. [velocity-scout] byJoey/warp-masque-actions

Sources

  1. Warp Masque Actions README
  2. Warp Masque Actions repository
  3. Plain WARP workflow at commit a18457d
  4. Proton CAPTCHA failure report
  5. Provider credential failure report

More automation reviews

mactap-app · cloudflare-turnstile-bypass · turnstile-bypass · autoshorts · ARES · appium · the whole board →