automazeio/vibeproxy
52.9
Adequate · 30 September 2026
5.1k
lines of production code
Swift
primary language
2
measurements over time
What this system is
VibeProxy is a macOS application that acts as a local proxy server for various AI model providers, including Claude, Gemini, and custom OpenAI-compatible services. It manages multiple authenticated accounts, handles credential storage, and routes requests through a configurable backend CLI with support for features like Vercel AI Gateway integration. The system includes auto-update capabilities, security hardening via loopback binding, and automated release packaging.
Features
Initial configuration file for CLIProxyAPI
The \src/Sources/Resources/config.yaml\ file has been added to define the default settings for the CLIProxyAPI server. This configuration sets the server to listen on port 8318 bound to localhost (127.0.0.1) for security, enables usage statistics, and configures a 10-minute request timeout suitable for extended thinking operations. It also includes settings for Amp CLI integration, retry logic, and OAuth-based authentication without requiring explicit API keys.
src/Sources/Resources · high confidence
Introduce multi-account support, custom provider configuration, and Vercel AI Gateway integration
The application now supports managing multiple authenticated accounts per service (Claude, Codex, Gemini, etc.) with the ability to enable or disable individual accounts, while automatically handling expired credentials. Users can also configure custom OpenAI-compatible providers via the settings UI, with credentials stored securely and validated against reserved provider names. Additionally, a toggle for Vercel AI Gateway integration allows routing Claude requests through an external gateway for enhanced access control, and the menu bar now includes a standard Edit menu with keyboard shortcuts (Cmd+C/V/X/A).
src/Sources · high confidence
New scripts for release packaging and backend flag parity checking
Added \scripts/create-release.sh\ to automate building the VibeProxy app bundle and generating a distributable ZIP with SHA-256 checksums, and \scripts/check-backend-flag-parity.sh\ to verify that login flags required by the app (such as GitHub Copilot, Gemini, and Qwen logins) are supported by the backend CLI, gating unavailable features at runtime.
scripts · high confidence
Removals
Removal of macOS menu bar application components
The macOS menu bar application entry point (AppDelegate) and its associated core logic have been removed. This includes the deletion of the ServerManager (which handled starting/stopping the CLI proxy binary and managing logs), the AuthManager (which tracked authentication status for Claude and Codex services), and the SettingsView (the UI for server controls, launch-at-login, and service connections). Users will no longer have access to the menu bar interface for managing the proxy server or its authentication states.
Sources · high confidence
Behavioural changes
Rebrand to VibeProxy and enable Sparkle auto-updates
The application has been rebranded from ProxyBar to VibeProxy, reflected in the bundle identifier (com.vibeproxy.app), display name, and copyright holder (Automaze, Ltd.). The version has been updated to 1.5.0. Additionally, Sparkle auto-update support has been integrated, configuring the app to check for updates daily via a specific GitHub-hosted appcast, with automatic updates disabled but automatic checks enabled.
src · high confidence
VibeProxy rebrand, multi-provider support, and security hardening
The application has been rebranded from ProxyBar to VibeProxy, with the Makefile, README, and installation guides updated to reflect the new name and expanded capabilities. Users can now authenticate with additional providers including Gemini, Kimi, Qwen, Antigravity, and Z.AI GLM, and control model availability via a new Provider Priority toggle. Security and stability have improved: the proxy now binds to loopback (127.0.0.1) by default with an optional LAN setting, the main executable is signed with entitlements to fix the missing menu bar icon, and login buttons are gated by backend CLI capabilities to prevent raw errors. The Swift test suite now runs in CI, and the CHANGELOG documents these fixes alongside the rebrand.
(repo-wide) · high confidence
Test coverage
Added test coverage for backend capability detection, config merging, and credential stores
New tests in src/Tests verify that the app correctly detects backend CLI flags (distinguishing between Plus-era and stock CLIProxyAPI builds), maps authentication commands to their required backend flags, and merges user configuration with bundled defaults while preserving runtime-editable keys. Additional tests cover the config input fingerprinting logic (ensuring only config and managed credential files trigger rebuilds), the custom provider credential store (save, load, disable/reenable, concurrent access, and malformed file handling), the ZAI API key store, the model alias mapper (rewriting ghcp-op/son/haiku aliases), the ThinkingProxy loopback binding, and the provider wiring that connects service types to their specific authentication flows.
src/Tests · high confidence
Dependencies
Add Sparkle and Yams dependencies
The project now includes the Sparkle (v2.5.0+) and Yams (v5.1.3+) libraries as dependencies, enabling auto-update support and YAML configuration parsing. The package structure has also been reorganized with the manifest moved to src/ and a new test target added.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 54 → 53 (-1.2)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 83 → 81 (-2.3)
- Architecture 100 → 100 (+0.0)
- Maturity 46 → 47 (+1.3)
- Readiness 56 → 57 (+1.4)
- Security 48 → 46 (-1.7)
Resolved (1)
- Documentation: no installation or build instructions (README.md)
New (29)
- AccountRowView.body (cognitive 25) (src/Sources/SettingsView.swift)
- AccountRowView.body (cyclomatic 17) (src/Sources/SettingsView.swift)
- Coverage not measured — Swift suite
- CustomProviderCredentialRowView.body (cognitive 21) (src/Sources/SettingsView.swift)
- CustomProviderRow.body (cognitive 35) (src/Sources/SettingsView.swift)
- CustomProviderRow.body (cyclomatic 18) (src/Sources/SettingsView.swift)
- Duplicated block (10–12 lines × 2) (src/Sources/SettingsView.swift)
- Duplicated block (11–12 lines × 2) (src/Sources/ServerManager.swift)
- Duplicated block (12 lines × 2) (src/Sources/SettingsView.swift)
- Duplicated block (16 lines × 2) (src/Sources/SettingsView.swift)
- Duplicated block (18 lines × 2) (src/Sources/ServerManager.swift)
- Duplicated block (18–19 lines × 2) (src/Sources/SettingsView.swift)
- Duplicated block (25 lines × 2) (src/Sources/SettingsView.swift)
- Duplicated block (4–6 lines × 8) (src/Sources/SettingsView.swift)
- Duplicated block (6 lines × 4) (src/Sources/SettingsView.swift)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: src/Sources/ServerManager.swift (src/Sources/ServerManager.swift)
- …and 9 more
Changes since last survey
- 67 commits — 64 feature/other, 3 fixes
By area
- (root) — 42 commits
- src/Sources — 23 commits
- .github/workflows — 1 commit
- src/Tests — 1 commit
Notable commits
- fix: fix: bind ThinkingProxy to loopback by default; sign main executable with entitlements (#565)
- fix: fix: gate login flows on backend CLI capabilities (Copilot/Gemini/Qwen) + CI parity guard (#566)
- fix: fix: point the in-app backend credit link at CLIProxyAPI (#573)
- change: Bump CLIProxyAPI to 7.3.10 (#557)
- change: Bump CLIProxyAPI to 7.3.11 (#558)
- change: Bump CLIProxyAPI to 7.3.12 (#559)
- change: Bump CLIProxyAPI to 7.3.14 (#560)
- change: Bump CLIProxyAPI to 7.3.15 (#561)
- change: Bump CLIProxyAPI to 7.3.16 (#562)
- change: Bump CLIProxyAPI to 7.3.17 (#563)
- change: Bump CLIProxyAPI to 7.3.18 (#567)
- change: Bump CLIProxyAPI to 7.3.19 (#568)
- change: Bump CLIProxyAPI to 7.3.3 (#550)
- change: Bump CLIProxyAPI to 7.3.4 (#551)
- change: Bump CLIProxyAPI to 7.3.5 (#552)
- change: Bump CLIProxyAPI to 7.3.6 (#553)
- change: Bump CLIProxyAPI to 7.3.7 (#554)
- change: Bump CLIProxyAPI to 7.3.8 (#555)
- change: Bump CLIProxyAPI to 7.3.9 (#556)
- change: Bump CLIProxyAPI to 8.0.1 (#569)
- …and 47 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
automazeio/vibeproxy was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit f88df7da38593cf7014ccbb88f0f1820c318d439 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.