mrkeyoor.com_
Wed 07 Oct 14:57 UTC
Self-Hostedevaluationupdated 07 Oct 2026

workbuddy2api-panel review

WorkBuddy2API Panel's README and operating guidance are in Simplified Chinese, with no English guide in the repository. It is an unofficial self-hosted gateway that turns your own Tencent CodeBuddy or WorkBuddy accounts into an OpenAI-compatible chat-completions endpoint, with a browser panel for account pooling, OAuth login, usage, tasks, and configuration.

Verdict

Our WorkBuddy2API Panel run built in 38 seconds and passed all 30 tests in 23 seconds, the cleanest lab result in this batch. Use it only as a private adapter for accounts you control, with a nonempty API key, HTTPS, and strict protection for the plaintext OAuth files. Choose a gateway built on official provider APIs if you need a stable public service or broad protocol support.

We ran it

Lab card: what happened when we ran workbuddy2api-panelScreenshot of workbuddy2api-panel (github.com/linguo2625469/workbuddy2api-panel)
Install✓ · 4s13 packages
Build✓ · 38s
Tests✓ · 23s30 passed · 0 failed of 30 (go test)
Repo160 files~46,073 lines of source · 2 MB · 2 CI workflows · Dockerfile

Answers from our run

Does workbuddy2api-panel build from source?

Dependencies installed in 4 seconds (13 packages), and the build succeeded in 38 seconds. We cloned commit 9478287 into a clean Debian container with 3 CPUs and no project-specific setup.

Do workbuddy2api-panel's tests pass?

Yes: 30 of 30 passed when we ran the project's own test command (go test). Some failures need services or credentials a bare container does not have.

Who should not use workbuddy2api-panel?

Public API sellers or shared account pools: the README limits use to the operator's own accounts and rejects resale and bulk-account use.

What are the alternatives to workbuddy2api-panel?

LiteLLM, Portkey AI Gateway, One API. Our WorkBuddy2API Panel run built in 38 seconds and passed all 30 tests in 23 seconds, the cleanest lab result in this batch.

Setup4/54-second install, clean build, and all 30 tests passed
Docs4/5Detailed Chinese operations guide, but no English documentation
Community4/52,077 stars and 42 active issues and PRs after an October push
Maturity3/5Strong tests and packaging, but an unofficial upstream with a short history

Who it’s for

Chinese-speaking developers connecting their own CodeBuddy accounts to OpenAI-compatible clients.
Self-hosters who need account rotation, cooldowns, circuit breaking, and sticky conversations.
Operators prepared to protect OAuth tokens, put the service behind HTTPS, and watch upstream changes.
Go teams that want a single binary or Docker deployment with an embedded admin panel.

Who it’s NOT for

Public API sellers or shared account pools: the README limits use to the operator's own accounts and rejects resale and bulk-account use.
English-only operations teams: the project documentation and much of its user-facing context are Chinese.
Deployments that cannot store plaintext OAuth access and refresh tokens in auths/.
Clients requiring native Responses or Anthropic Messages APIs: the documented model endpoint is /v1/chat/completions, and issue 89 asks about missing native Responses support.
Anyone planning to expose the default configuration directly: an empty api_key disables authentication, port 7863 binds publicly in Compose, and the service has no built-in TLS.
Mobile-first administrators: open issue 73 says the panel overflows small screens and some controls become hard to use.

Setup reality

Our sandbox installed commit 9478287 in 4 seconds with 13 packages. The Go build passed in 38 seconds, then all 30 tests passed in 23 seconds. The checkout had 160 files, about 46,073 lines of source, and occupied 2 MB.

Useful operation needs one or more personal CodeBuddy accounts and OAuth authorization. The gateway also needs a nonempty API key before network exposure. Redis is optional for mirroring sticky-session state; local files hold configuration, account state, and plaintext OAuth tokens.

The repository offers a single binary, Docker Compose, and a GHCR image. It listens on port 7863 without TLS, so public use needs an HTTPS reverse proxy and rate limits. Our scan found two CI workflows, a Dockerfile, and a Compose file.

A Chinese panel wraps CodeBuddy behind one chat endpoint

WorkBuddy2API Panel exposes /v1/chat/completions and /v1/models in an OpenAI-compatible shape while sending work to Tencent CodeBuddy accounts. The README and operational guidance are written in Simplified Chinese, and the root contains no English guide. A browser panel handles OAuth login, account status, usage, model information, configuration, logs, and reward tasks. This is a focused adapter for one upstream account system, not a general model gateway.

Its account pool is the reason to consider it. Selection can weigh expiring credits and cost, limit in-flight work, cool accounts after upstream errors, trip a circuit breaker, and keep a conversation on one account. Redis can mirror sticky-session state, while local state supports restart recovery. The panel also shows request timing and source metadata without recording prompts, response bodies, or credentials in its JSONL archive.

What happened when we ran it

Our sandbox installed commit 9478287 in 4 seconds. Go fetched 13 packages, and the checkout occupied 2 MB with 160 files and about 46,073 lines of source. The build completed successfully in 38 seconds. We used a fresh unprivileged Debian container with 3 CPUs, 8 GB of RAM, Go 1.24, and no secrets.

The test step passed in 23 seconds. go test reported 30 passed and zero failed out of 30. The repository had two CI workflow files, a Dockerfile, and a Compose file, although our scan found no separate tests directory because Go tests live beside package code. Those results cover repository mechanics. We did not authorize a CodeBuddy account or send traffic to Tencent.

This is a reassuring baseline for the code we could exercise. A 4-second dependency fetch, successful 38-second build, and complete 30-test result make the local development path credible. They do not verify account longevity, upstream policy compatibility, reward-task behavior, model output, or resilience under real rate limits. Those require an authorized account and live service conditions that were absent from the sandbox.

Plaintext OAuth files make private deployment mandatory

The project stores each account's access token and refresh token in plaintext under auths/, along with account metadata. It documents restrictive file permissions, but permissions do not help if the host, backup, image, or mounted volume is exposed. Treat that directory as a credential store: exclude it from Git, encrypt backups, limit host access, and rotate the associated accounts after any suspected copy.

Network defaults need equal attention. Docker Compose maps port 7863 on all interfaces, and the service supplies plain HTTP rather than TLS. An empty api_key means the API and panel allow requests without authentication. The README tells public operators to set the key and put Nginx or Caddy in front. Follow that advice before the first OAuth login, not after the endpoint appears in a scan.

The browser keeps the panel API key in localStorage when authentication is enabled. That is workable on a dedicated admin origin, but it raises the cost of any script injection or shared-browser mistake. Security headers, constant-time key comparison, path checks, and front-end escaping are useful defenses already described by the project. They do not reduce the impact of a stolen refresh token.

OpenAI compatibility stops short of newer native protocols

The documented client surface centers on chat completions, models, status, and health. Streaming requests are rebuilt as server-sent events, while nonstreaming replies are aggregated locally. The gateway normalizes roles and tool choices, fills reasoning content, chooses supported effort levels, and sanitizes selected fingerprints. Those transformations help existing chat-completions clients, but they also create behavior that differs from a direct official API.

Open issue 89 asks whether native Responses support is absent, and issue 9 requests native Anthropic Messages support. A client that merely uses the OpenAI SDK is not automatically compatible if it depends on those newer routes. Open issue 81 also documents a conversation where repeated tool-call IDs led to upstream rejection and repeated 503 responses. The report calls its diagnosis a high-confidence inference rather than a closed reproduction, which is the right caveat to preserve.

Seventeen automated reward tasks increase policy risk

The panel says it can complete 17 of 18 growth tasks through APIs, including fabricated client event chains and a small number of real model conversations. That engineering is detailed, but it is also the part most exposed to upstream policy and schema changes. The repository calls itself unofficial and says it is for self-owned accounts, local or private testing, check-ins, and personal tool access.

The README explicitly rejects bulk registration, quota resale, paid API pooling, and repackaged commercial distributions. It says the target service terms prohibit bulk accounts and commercial resale. The deleted upstream repository is mentioned, but the author does not claim to know why it disappeared. A buyer should take that uncertainty seriously. Even personal automation can stop when Tencent changes endpoints, fingerprints, task rules, or account enforcement.

Version 1.12.0 is active after only three weeks

GitHub showed 2,077 stars and 42 open issues and pull requests on October 7, 2026, split into 39 issues and 3 pull requests in the API response. The repository was created on September 12 and pushed on October 6. Release v1.12.0 shipped on October 5 with CI-built binaries for five platforms plus checksums. The activity is current, though the public history is still measured in weeks.

That combination explains our score. The Go project builds, all 30 tests passed, container assets exist, releases are packaged, and the Chinese README is unusually detailed about failure modes and secrets. The upstream dependency remains unofficial, plaintext tokens carry real consequences, and protocol gaps appear in open issues. For one careful self-hoster using personal accounts, it is capable. For a public API business, the project's own rules and risk profile say no.

Alternatives

ProjectWhat it isPick it when
LiteLLM gh↗A multi-provider gateway and SDK built around official model APIs and broad client compatibility.pick this instead when you have provider API credentials and need routing across many vendors.
Portkey AI GatewayAn AI gateway focused on routing, fallbacks, observability, and policy controls.pick this instead when production gateway controls matter more than wrapping a CodeBuddy account.
One APIA Chinese and English gateway for managing keys across many model providers.pick this instead when multi-provider key management and distribution are the actual job.

What people are saying

  1. [velocity-scout] linguo2625469/workbuddy2api-panel

Sources

  1. WorkBuddy2API Panel repository and README
  2. WorkBuddy2API Panel v1.12.0 release
  3. Issue 81: duplicate tool-call IDs and 503 responses
  4. Issue 89: native Responses support question
  5. Issue 73: mobile panel usability

More self-hosted reviews

sparkDash · jeff · OpenGFW · splash · quivr · bindery · the whole board →