musistudio/claude-code-router
47.5
Weak · 28 September 2026
176.5k
lines of production code
TypeScript
with JavaScript
4
measurements over time
What this system is
This system is a local AI gateway and desktop application that unifies access to multiple AI providers and local agent tools through a centralized routing infrastructure. It manages complex request routing, model selection, and authentication for services like Claude, OpenAI, and various local CLI agents, while enforcing usage limits and billing tracking. The platform includes a web-based management interface, a built-in browser for credential import, and a plugin system to extend functionality with media generation and web search capabilities.
Features
Automated generation of model catalog and configuration metadata
Added build scripts to automatically generate the model catalog (\packages/core/models.json\) and Claude Code configuration options (\packages/ui/src/generated/claude-code-config-options.json\) from external documentation and API sources. The model catalog script fetches data from LiteLLM, models.dev, and OpenRouter, merging and deduplicating records to provide up-to-date model metadata, while the config script parses official Claude Code documentation to generate localized settings and environment variable references for the UI.
scripts · high confidence
Claude App integration with secure gateway routing and VM storage preparation
The Claude App agent now includes a new gateway service that automatically configures the Claude App to route inference through the CCR gateway, handling API key generation, model discovery, and config backup/restore. It introduces a new model routing system that supports encoded model IDs, one-million-context window variants, and profile-specific target model resolution. Additionally, the app launch process now prepares VM storage by cloning VM seed bundles to ensure the app has the necessary virtual machine environment, and it can optionally open the Claude Design interface via CDP (Chrome DevTools Protocol) when enabled, including secure handling of privacy consent requests.
packages/core/src/agents/claude-app · high confidence
Initial CLI implementation with profile and service management
The CLI package now includes a new \cli.ts\ entry point that provides commands for starting, stopping, and managing the web service (\start\, \stop\, \web\, \ui\) and opening AI profiles (\profile\). This implementation introduces support for the \--daemon\ flag on \start\ and \serve\ commands, handles profile-specific logic for agents like ZCode and Claude App, and integrates with the core package for configuration loading, profile launching, and gateway management.
packages/cli/src · high confidence
Initial project scaffolding and configuration files
This change introduces the foundational configuration files for the project, including .dockerignore, .gitignore, .npmrc, a Dockerfile for containerized builds, a LICENSE file (MIT), and various TypeScript/Playwright configuration files (tsconfig.json, playwright.config.ts). It also adds build and packaging configurations for the desktop application (electron-builder.json) and documentation (components.json, docker-compose.yml). The README files are updated to reflect the new project structure and supported agents/providers.
(repo-wide) · high confidence
Initial release of the CCR provider import button CDN
The \cdn\ directory now hosts the static assets for the embeddable CCR provider import button, including the JavaScript bundle (\ccr-provider-buttons.js\), the icon image, and deployment configuration. This update introduces version 0.2.0 of the button script, which injects styled UI components to allow users to import providers into CCR via a customizable link. The assets are served via Cloudflare Pages at \cdn.ccrdesk.top\ with specific caching headers to optimize performance for the JavaScript and image resources.
cdn · high confidence
Introduce OpenCode profile support with app launch and configuration management
Added support for the OpenCode agent profile, including logic to discover and launch the OpenCode desktop application across Windows, macOS, and Linux, and a configuration writer that generates OpenCode-compatible JSONC settings. The configuration generation enforces model allowlists from the profile, exposes model output limits (context window and max output tokens) in the generated config, and routes requests through the gateway provider with specific client headers.
packages/core/src/agents/opencode · high confidence
Introduce context archive protocol and storage for session continuity
Added a new context archive subsystem that enables preserving and replaying conversation history across agent sessions. The \protocol.ts\ file defines the logic for handling compact handoffs and history replays for Anthropic and OpenAI provider protocols, including specific sanitization for token limits and prompt structures. The \store.ts\ file implements a SQLite-backed persistence layer for archive snapshots, managing session lineage, retention policies, and secure file storage to ensure context can be reliably retrieved and resumed.
packages/core/src/gateway/context-archive · high confidence
Introduce hosted web-search protocol bridge for Anthropic, OpenAI, and Gemini
The gateway now includes a new hosted web-search feature that detects web search tool declarations in requests from Anthropic Messages, OpenAI Chat Completions/Responses, and Gemini Generate Content protocols. When a search is detected, the gateway bridges the request to a configured web search provider, then transforms the provider's results back into the original protocol's format—injecting search evidence into system prompts or instructions and rewriting the response stream (including SSE) to present the search results as native tool outputs or text. This enables models to perform live web searches seamlessly across supported provider APIs without requiring client-side search logic.
packages/core/src/gateway/features/hosted-web-search · high confidence
Introduce media generation and editing capabilities
This change adds a new media subsystem to the core package, enabling users to generate and edit images and videos through the gateway. It introduces a complete set of MCP tool bindings for image generation, image editing, and video generation (including job status and cancellation), backed by a new \MediaService\ that manages job lifecycles, local artifact storage, and provider routing. The implementation includes specific support for xAI video generation protocols and Grok media models, with logic to migrate legacy model selectors and handle provider capabilities.
packages/core/src/media · high confidence
Introduces local MITM proxy with system proxy integration and certificate management
The proxy module now includes a full local proxy service that intercepts network traffic via a self-managed Certificate Authority (generating and storing CA certificates for MITM decryption) and supports configurable upstream proxy routing (custom or system-detected) on macOS and Windows. This enables the application to capture and inspect network requests while seamlessly respecting system-level proxy configurations.
packages/core/src/proxy · high confidence
Introduces profile-specific configuration and model routing for the Pi agent
The Pi agent now supports distinct profiles, allowing users to configure separate agent directories, session storage, and model allowlists per profile. This change adds a new \profile-config.ts\ module that resolves profile-specific paths, writes isolated \models.json\ configuration files with restricted permissions, and enforces model allowlists via the \profileAllowedModels\ function. It also ensures that model routing and gateway endpoints are correctly resolved for each profile, enabling multi-profile setups where each profile can have its own set of allowed models and provider settings.
packages/core/src/agents/pi · high confidence
New API key authorization and rate-limiting logic in gateway
The gateway now includes a new \api-key-authorizer.ts\ module that handles API key validation, including constant-time comparison for security, support for Claude Code WIF token exchange, and per-key rate limiting with windowed counters. It also manages cached persisted API keys and falls back to legacy configuration formats.
packages/core/src/gateway/auth · high confidence
New API key rate-limiting and request pipeline infrastructure
The gateway now enforces API key usage limits (requests, tokens, images) across configurable time windows (minute, hour, day) using a new window-limiter module that estimates usage from request bodies. This is integrated into the new GatewayRequestPipeline, which handles request routing, header normalization, and upstream proxying with detailed route tracing and observability.
packages/core/src/gateway/request · high confidence
New Chrome extension for importing login cookies and localStorage
The \extension/chrome\ directory now contains a new Chrome extension (v0.1.0) that allows users to import site login cookies and localStorage data into CCR's in-app browser. The extension supports two workflows: a confirmation-page flow triggered by CCR, and a manual flow via the extension popup where users paste a CCR import URL. It reads cookies and localStorage only for explicitly selected domains, deduplicates entries, and submits the data to CCR via a POST request.
extension · high confidence
New Codex agent integration with desktop app bridging and media previews
This change introduces a new Codex agent implementation in the core package, enabling the system to launch and communicate with the ChatGPT desktop application (renamed from 'Codex' in references) and third-party apps like ZCode and WorkBuddy. It includes a new CLI middleware runtime that acts as a bridge for bot workers and remote sync, a model catalog builder that respects profile allowlists and context window settings, and a media preview bridge that uses Chrome DevTools Protocol to display inline images and videos from the desktop app. Users gain the ability to use Codex-compatible desktop apps as agent backends with integrated media handling and standardized model routing.
packages/core/src/agents/codex · high confidence
New Docker deployment configuration for CCR
The Docker deployment now includes a comprehensive setup for running the CCR core server under PM2 and serving the management UI via Nginx. This change introduces a new entrypoint script that handles configuration initialization, synchronizes public endpoints, and generates a dynamic Nginx configuration to route traffic to the management RPC, gateway API, and health checks. A new README provides detailed instructions for deployment via Docker Compose or direct container runs, including environment variable configuration for authentication and network security. The deployment architecture ensures that only the Nginx port is publicly exposed, with internal services running on localhost.
docker · high confidence
New MCP server implementations and configuration modules for Fusion, Media, and Network Capture
This change introduces several new standalone MCP server implementations and their configuration modules within the core package. It adds \browser-web-search-proxy-mcp.ts\ to proxy web search requests, \fusion-vision-mcp.ts\ and \fusion-tool-fallback-mcp.ts\ to handle vision analysis and fallback tool definitions for the Fusion profile, and \fusion-config.ts\ to orchestrate these Fusion servers. Additionally, it includes \grok-media-mcp.ts\ and \media-tools-proxy-mcp.ts\ to expose media generation and editing tools, \grok-media-config.ts\ for their configuration, and \network-capture-mcp.ts\ to provide tools for managing proxy network captures. The \tool-discovery.ts\ and \toolhub-config.ts\ modules are also updated to support these new server types and their integration.
packages/core/src/mcp · high confidence
New UI foundation: BaseUI provider, morph icons, and usage activity logic
This change introduces core UI infrastructure and logic components within the \packages/ui/src/lib\ directory. It adds a \BaseUiProvider\ that wraps the application with BaseUI and Styletron for consistent theming and styling. New morph icon assets (\collapseSidebarToExpandInspectorMorph\, \playPauseMorph\) are exported for use in sidebar and service controls. Additionally, a comprehensive \usage-activity.ts\ module is added to process token usage data, handling date parsing, range-aware calculations (today, 24h, 7d, 30d), and generating activity summaries with intensity levels for visualization. A utility function \cn\ for merging Tailwind classes is also included.
packages/ui/src/lib · high confidence
New agent infrastructure: CDP client, request enrichment, and cached app info
This change introduces three new core modules in the agents package to support improved agent execution and integration. A new CdpClient class provides a robust WebSocket-based interface for Chrome DevTools Protocol communication, featuring connection timeouts, request-response matching, and event handling. A request enrichment system is added via AgentRequestEnricher, allowing modular, ID-tagged modifications to agent requests before processing. Additionally, a cached app-info path reader is introduced to efficiently retrieve installed application paths (ChatGPT, OpenCode, Workbuddy) with a 30-second TTL, reducing redundant discovery calls for informational RPCs.
packages/core/src/agents · high confidence
New build tooling and release verification scripts
The build system now includes a comprehensive suite of new scripts to streamline development, testing, and release packaging. A new benchmark script (\benchmark-request-logs.mjs\) allows performance testing of request logging, while dedicated scripts for Docker (\docker-build.mjs\, \docker-compose.mjs\, \docker-image.mjs\, \docker-local-gateway.mjs\) simplify containerized builds and local gateway integration. Release integrity is enforced through preflight checks for macOS (\macos-release-preflight.mjs\) and Windows (\windows-package-preflight.mjs\), notarization verification (\verify-macos-notarization.cjs\), and post-build validation for packaged apps (\verify-packaged-app.cjs\) and update metadata (\verify-update-metadata.cjs\). Additionally, a metadata merging utility (\merge-macos-update-metadata.mjs\) and a robust test runner (\run-tests.mjs\, \test.mjs\) have been added to support the monorepo's testing and distribution workflows.
build · high confidence
New bundled plugins for Claude Design, Claude Ship, and New API account integration
The desktop application now includes three new bundled plugins: Claude Design and Claude Ship, which open their respective web applications in dedicated Electron windows with traffic routed through the CCR wrapper backend, and a New API Account plugin that reads subscription quota via the built-in browser session. Additionally, the app introduces a built-in browser service with full automation support (MCP tools, event subscriptions, and accessibility snapshots), a Chrome login import service for migrating credentials, and a bot gateway QR window service for handling login flows.
packages/electron · high confidence
New core UI component library added
A new set of accessible, theme-aware UI components has been introduced to the application, including Badge, Button, Card, Checkbox, Dialog, Input, Label, Popover, Select, Switch, Tabs, Textarea, and Tooltip. These components provide a consistent visual language and interaction patterns, with the Dialog component specifically handling focus management, keyboard navigation (including Escape to close), and stacking logic for nested modals.
packages/ui/src/components · high confidence
New core contracts for app, deep links, i18n, and IPC channels
The core package now exposes a comprehensive set of TypeScript contracts that define the application's internal interfaces. This includes the \AppInfo\ and \AppUpdateStatus\ types for desktop app metadata and update states, along with new IPC channel definitions for features like built-in browser control, provider deep-linking, and proxy management. It also introduces structured i18n support for Chinese error messages and robust parsing logic for provider deep links, enabling users to configure providers via URLs and see localized error feedback.
packages/core/src/contracts · high confidence
New gateway feature modules for Anthropic, Codex, and Context Archive handling
The gateway now includes dedicated feature modules to handle specific protocol and client requirements: \anthropic-response-model.ts\ rewrites the model name in Anthropic SSE \message\_start\ events to match the routed model; \codex-multi-agent-bridge.ts\ and \codex-patch-bridge.ts\ transform Codex requests by flattening namespaced tools, updating tool choices, and injecting virtual \apply\_patch\ tools and shell guidance; \context-archive-continuation.ts\ manages context archive tool continuations and compact handoff tasks for both Anthropic and OpenAI protocols; \cursor-compat.ts\ injects system prompts and tools for simplified Cursor OpenAI-compatible chat requests; and \model-discovery.ts\ handles model discovery and routing for Claude CLI, Claude App, and OpenAI-compatible clients, including bootstrap payload generation and profile-based model allowlisting.
packages/core/src/gateway/features · high confidence
New gateway infrastructure and routing capabilities
The gateway package now includes a comprehensive router plugin (\claude-code-router-plugin.ts\) that handles request routing, model selection, and body rewrites based on compiled configuration. A new context archive service (\context-archive.ts\) enables session history archiving and replay. The system introduces a model catalog (\model-catalog.ts\) for discovering model capabilities and limits, and adds an existing gateway probe (\existing-gateway-probe.ts\) to detect and interact with external CCR gateways. Remote control capabilities are exposed via a new service (\remote-control-service.ts\) for session management and event streaming, while runtime configuration changes are now tracked and can trigger gateway restarts (\runtime-change.ts\, \runtime-config-control.ts\).
packages/core/src/gateway · high confidence
New local provider integrations for Claude Code, Codex, Grok, Kimi, OpenCode, and ZCode
Users can now import authentication and configuration from several local AI agents directly into the gateway. The system scans for and imports login state from Claude Code (reading OAuth tokens from the macOS Keychain), OpenCode Zen (including public free-tier access with specific client headers), OpenCode Go, Kimi CLI, xAI Grok CLI, and ZCode. Each provider exposes its available models, usage quotas, and billing limits, allowing the gateway to act as a unified interface for these locally authenticated services.
packages/core/src/agents/local-providers · high confidence
New model catalog loading and usage cost estimation capabilities
The core models package now includes a new \catalog-file.ts\ module that loads model definitions from a JSON file, searching a prioritized list of paths including environment variables (\CCR\_MODEL\_CATALOG\_PATH\, \CCR\_MODELS\_JSON\_PATH\) and standard project locations. Additionally, a new \pricing-service.ts\ module has been added to estimate usage costs in USD. This service fetches and caches a price catalog from external sources (LiteLLM, models.dev, OpenRouter) with a 24-hour TTL, supports custom provider pricing configurations, and correctly handles routed model names (e.g., \\<providerId\>::\<protocol\>/\<model\>\) to ensure accurate cost estimation.
packages/core/src/models · high confidence
New plugin infrastructure with backend services and marketplace integration
The plugin system has been significantly expanded with new core capabilities. A new backend service allows plugins to register and manage their own HTTP servers and persistent SQLite storage, including automatic database recovery from corruption. The marketplace loader now supports fetching, caching, and validating plugin entries with integrity checks. Additionally, a built-in provider router has been added to automatically route OpenRouter requests to the most cost-effective endpoints based on configurable discount settings.
packages/core/src/plugins · high confidence
New provider account, credential, and model management infrastructure
The core provider layer now includes dedicated services for managing provider accounts, credentials, and model catalogs. A new account service handles fetching and caching account snapshots, supporting various connector types including web content JSON and local estimates. A credential pool tracks usage limits and applies cooldowns for rate-limited credentials. Model management is enhanced with automatic background refresh for providers that opt in, and a centralized model catalog service resolves available models and metadata. Additional utilities include a manifest fetcher for validating remote provider configurations, an icon detection service for provider branding, and specialized connectors for services like New API and OpenRouter.
packages/core/src/providers · high confidence
New provider presets and account configuration system
The application now supports a significantly expanded set of AI providers through new preset configurations, including Anthropic, Alibaba Bailian, code0.ai, DeepSeek, Fenno, Google Gemini, Infistar AI, Kimi Coding, MiniMax (Global and China), Mistral, Moonshot (Global and China), NVIDIA NIM, OpenAI, OpenCode Go, OpenRouter, Qiniu Cloud AI, RunAPI, SiliconFlow, TeamoRouter, Unity2.Ai, Xiaomi MiMo (with regional token plans), and Z.ai (Global and China). This update introduces a structured provider preset system that defines base URLs, supported protocols (such as OpenAI Chat Completions, Anthropic Messages, and Gemini Generate Content), and default models for each provider. Additionally, it adds detailed account configuration connectors for usage tracking and balance monitoring for providers like DeepSeek, Kimi, Mistral, Moonshot, OpenRouter, SiliconFlow, OpenCode Go, and Zhipu AI, enabling users to view their quota and credit usage directly within the application.
packages/core/src/providers/presets · high confidence
New usage tracking and billing synchronization infrastructure
This change introduces a new usage tracking and billing synchronization system within the core package. It adds a \GatewayBillingSynchronizer\ to handle incoming billing events via a dedicated HTTP endpoint, ensuring idempotent ingestion and proper authentication. A new \UsageStore\ class manages persistent storage of usage events in SQLite, capturing detailed metrics such as token counts (input, output, cache read/write), costs, and latency. The system includes a \normalizeUsageInputTokens\ module to correctly handle token accounting across different provider protocols (e.g., Anthropic vs. OpenAI) and source conventions (billing headers vs. response bodies). Additionally, a \resolveUsageModelAttribution\ function maps logical model selectors to physical provider models, supporting virtual model profiles and route selectors. These components work together to provide accurate usage attribution and cost estimation for routed model requests.
packages/core/src/usage · high confidence
New web-based management server for local configuration and control
A new local HTTP management server is now available, providing a web interface for managing the application's configuration, providers, and plugins. This server exposes an RPC endpoint that allows authenticated web clients (such as the bundled desktop app or browser-based docs) to perform administrative tasks including provider probing, plugin marketplace interactions, profile management, and usage statistics reset. It listens on a local loopback address by default and requires an authentication token for API access, while also supporting CORS for specific trusted origins to enable seamless integration with web-based setup wizards.
packages/core/src/web · high confidence
New web-client bridge for CCR API communication
The UI now includes a new \web-client-bridge.ts\ module that exposes a \window.ccr\ API for communicating with the CCR backend. This bridge handles RPC calls to the \/api/ccr/rpc\ endpoint, manages web authentication tokens via URL parameters and session storage, and implements methods for provider management, proxy control, bot gateway interactions, and usage statistics. This enables the web interface to interact with core CCR services like gateway status, provider connectivity, and configuration updates.
packages/ui/src · high confidence
Redesigned home dashboard and settings interface with new browser page
The application's user interface has been significantly restructured. The main home view now features a customizable dashboard with draggable widgets for usage statistics, agent analysis, and provider account balances, replacing the previous layout. A new dedicated browser page has been added, providing a built-in tabbed browser with navigation controls and Chrome login import capabilities. The settings and configuration experience has been overhauled with new dedicated views for managing API keys (including search, expiration, and limits), extensions (with installation and configuration), profiles, providers, and routing rules, all unified under a new dialog stack system.
packages/ui/src/pages · high confidence
Support for Kilo Code profiles with enforced model allowlists
The system now supports Kilo Code profiles, introducing a new configuration module that resolves, reads, and writes Kilo-specific JSONC config files. This change enforces profile model allowlists by validating selected models against a defined set of permitted options before writing gateway overrides, ensuring that only approved models are used within the Kilo integration.
packages/core/src/agents/kilo · high confidence
Behavioural changes
Bot Gateway environment configuration and platform normalization
The bot-gateway module now centralizes environment variable generation and platform normalization. A new env.ts file constructs the runtime environment for bot gateways, introducing a specific behavioral change where streaming replies are disabled for the Weixin iLink platform (while remaining enabled for others based on configuration). The module also normalizes platform identifiers (e.g., mapping 'lark' to 'feishu', 'dingding' to 'dingtalk', and various WeChat variants to 'weixin-ilink') and handles SDK module resolution, preferring a bundled SDK if available. Additionally, new services handle QR login flows for Weixin iLink and scan for Bluetooth/Wi-Fi handoff targets, supporting cross-platform device handoff capabilities.
packages/core/src/agents/bot-gateway · high confidence
Gateway runtime configuration and request handling are restructured
The gateway core-runtime module has been refactored to improve request routing, provider coordination, and startup reliability. A new config compiler centralizes gateway configuration, while a dedicated bootstrap process manages the gateway startup via IPC, including a configurable config-acceptance timeout (default 30s, adjustable via CCR\_GATEWAY\_CONFIG\_TIMEOUT\_MS) to prevent premature failures on slower hosts. Request handling now includes an upstream header sanitizer that strips internal CCR routing and proxy headers before they reach providers, and applies specific protocol conversions: OpenAI Responses tool strictness is only stamped for Anthropic source adapters, and session affinity (prompt\_cache\_key) is preserved for OpenAI Responses upstreams while being skipped for Codex. Additionally, a meta token floor ensures a minimum token count for specific Meta models routed through OpenRouter, and local agent authentication hooks provide live OAuth token resolution for Claude Code, Grok, and Kimi providers.
packages/core/src/gateway/core-runtime · high confidence
Improved Windows application discovery and socket compatibility
The platform layer now includes robust Windows-specific utilities to enhance application launching and system integration. A new Windows app discovery module (\windows-app-discovery.ts\) significantly expands how the application locates installed desktop programs by scanning standard installation directories, resolving .lnk shortcuts via PowerShell, checking Windows App Execution Aliases, and querying MSIX package locations. Additionally, a socket compatibility layer (\socket-compat.ts\) has been added to gracefully handle \setTypeOfService\ errors on Windows, preventing crashes when the underlying OS does not support specific socket options. A helper module (\windows-system.ts\) ensures reliable execution of system commands like PowerShell by resolving their absolute paths within the Windows system directory.
packages/core/src/platform · high confidence
Improved error visibility and request performance in the HTTP gateway
The gateway now surfaces specific upstream failure reasons (such as 429 throttling or 403 access denied) directly in the main error message, ensuring clients that only display a single error field can see the actual cause instead of a generic 'All target providers failed' message. Additionally, request body parsing is now cached to avoid redundant JSON deserialization for the same buffer, improving performance for repeated reads.
packages/core/src/gateway/http · high confidence
Introduce internal utility modules for gateway core logic
The gateway's internal package now includes dedicated modules for shared types, value parsing, collection utilities, and timing control. New files define core provider and search protocol types (shared.ts), safe readers for untyped payloads (value.ts), helper functions for clamping and deduplication (collections.ts), and an abort-aware delay mechanism (clock.ts). These additions support the gateway's request routing, provider coordination, and retry/backoff behavior by centralizing common logic and type definitions.
packages/core/src/gateway/internal · high confidence
Migrate configuration storage from JSON files to SQLite
The application now stores app configuration, API keys, and runtime state in a local SQLite database (\config.sqlite\) instead of legacy JSON files. This change introduces a new \ConfigRepository\ that handles the migration from old storage formats, enforces secure file permissions (0o700 for directories, 0o600 for files), and provides a unified interface for reading and writing settings. Users will benefit from improved data integrity and performance, while the system automatically archives legacy JSON config files during the transition.
packages/core/src/config · high confidence
New auth mode and environment configuration for Claude Code agent
The Claude Code agent now supports configurable authentication modes, defaulting to 'api-key-helper' but allowing explicit selection of 'wif' (Workload Identity Federation) or 'auto' via the CCR\_CLAUDE\_CODE\_AUTH\_MODE environment variable. Additionally, a new environment configuration module standardizes model selection by mapping various Anthropic model environment variables (such as ANTHROPIC\_MODEL, CCR\_CLAUDE\_CODE\_MODEL, and specific model aliases like Opus, Sonnet, Haiku) to a unified configuration structure, ensuring consistent model resolution across different deployment contexts.
packages/core/src/agents/claude-code · high confidence
New gateway service implementation with unified request handling
The gateway application layer now uses a new \GatewayService\ class that consolidates request routing, provider coordination, and gateway lifecycle management. This service introduces a structured request pipeline (\GatewayRequestPipeline\) and HTTP request handler (\GatewayHttpRequestHandler\) to manage incoming traffic, while integrating with the \ClaudeCodeRouterPlugin\ for route script execution and validation. It also adds support for live token rate tracking, billing synchronization, and raw trace synchronization, ensuring that gateway status, configuration reloads, and child process management are handled within a single, focused module.
packages/core/src/gateway/application · high confidence
Overhauled request logging and observability infrastructure
The observability subsystem has been significantly restructured to improve reliability, performance, and data fidelity. Raw trace spooling now uses a dedicated synchronizer with robust retry, dead-letter, and replay mechanisms to prevent data loss, particularly on Windows. Request body capture is now bounded by strict size limits, and large inline Base64 images are automatically compacted to reduce memory usage. A new admission store manages request acceptance with SQLite-backed state and heartbeat leases, while route traces are now recorded with bounded sizes and sensitive header redaction. Additionally, the system now tracks live token rates and stream experience metrics, providing real-time insights into request performance.
packages/core/src/observability · high confidence
Profile-specific API keys and model allowlists
Profiles now automatically generate and manage unique API keys for each enabled profile, ensuring that requests are authenticated and attributed to the correct profile context. Additionally, a model allowlist system enforces per-profile restrictions, filtering available gateway models so that each profile only sees and uses the models explicitly permitted in its configuration.
packages/core/src/profiles · high confidence
Refactored gateway upstream execution and retry logic
The gateway's upstream request handling has been restructured to improve routing precision and reliability. A new executor module centralizes provider capability routing, ensuring that target providers and model selectors are correctly qualified and rewritten based on the client protocol before requests are sent. Additionally, a dedicated retry policy module now manages backoff strategies, introducing configurable exponential backoff limits and proper handling of Retry-After headers, while also supporting the ability to abort retry backoffs on disconnect to prevent unnecessary delays.
packages/core/src/gateway/upstream · high confidence
Router architecture refactored with new configuration compilation and execution flow
The routing system has been restructured to introduce a dedicated configuration compilation phase (config-compiler) that validates rules and profiles against a model registry before execution. This change adds a new execution plan builder to handle fallback modes (retry, model-chain) and a failure classifier to determine when to trigger fallbacks based on HTTP status codes. Additionally, the router now supports a policy engine for extensible decision-making, protocol adapters for normalizing request bodies across different provider endpoints (e.g., Gemini, OpenAI), and a secure, sandboxed script runtime using Node.js worker threads with circuit breakers and strict resource limits for custom routing logic.
packages/core/src/routing · high confidence
Zcode agent now enforces accurate context windows and profile allowlists
The Zcode agent configuration and model resolution logic has been updated to ensure that context windows are correctly calculated based on the underlying model catalog and provider settings, rather than relying on static defaults. This change introduces a new model catalog builder that resolves physical models and applies maximum input token limits from the gateway, ensuring that Fusion and other routed models respect their actual context constraints. Additionally, the profile configuration writer now integrates with the model allowlist system, ensuring that only permitted models are written to the local Zcode config files (including v2 cache and provider settings), which prevents invalid model selections and improves compatibility with the Claude Code Router.
packages/core/src/agents/zcode · high confidence
Test coverage
Added integration tests for CLI help and argument validation; Added integration tests for Codex CLI middleware runtime; Added integration tests for Fusion Vision, Grok Media, and ToolHub MCP runtimes; Added integration tests for observability request logging and pricing; Added integration tests for plugin service resilience and backend error handling; Added integration tests for profile service configuration and cleanup logic; Added integration tests for provider configuration and UI components; Added integration tests for usage attribution and store statistics; Added request body and request log benchmarks; Added test support for waiting on TCP listeners; Added tests for gateway architecture constraints and upstream proxy configuration; Added tests for media executor download error handling; Added unit tests for ToolHub browser automation and media tools MCP configuration; Added unit tests for UI configuration, routing, and usage logic; Added unit tests for config repository, credential handling, and plugin migration; Added unit tests for model catalog resolution and pricing service logic; Added unit tests for observability subsystems; Added unit tests for profile management and launch infrastructure; Added unit tests for provider credential caching, session header injection, and usage endpoint resolution; Added unit tests for routing internals; Added unit tests for runtime path resolution and storage migration utilities; Added unit tests for usage token normalization logic; Added unit tests for web management server and gateway integration; Expanded unit test coverage for agent launch, gateway, and configuration logic; Gateway unit test coverage expanded for Anthropic model rewriting, API key authorization, and Codex bridges; Initial component and integration test coverage for the UI package; Integration tests added for gateway model allowlists, Anthropic tool IDs, client disconnects, and OpenCode Go provider; New architecture, E2E, and system test suites for CLI web, Electron, and Docker.
Dependencies
Project restructured as a monorepo with new documentation and CDN sites
The project has been reorganized into a monorepo structure, introducing new package manifests for the CLI, core gateway, Electron desktop shell, and web UI, alongside dedicated manifests for a new documentation site (Astro-based) and a CDN deployment site. The root package.json now defines workspaces and specifies a Node.js engine requirement of \>=22, while the dependency tree has been updated to include @the-next-ai/ai-gateway ^1.0.21, openai ^6.27.0, better-sqlite3 ^12.11.1, and electron ^42.3.3, with lockfiles generated for both npm and pnpm to manage these dependencies.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 35 → 47 (+12.6)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 41 → 42 (+0.6)
- Architecture 71 (new)
- Maturity 59 → 65 (+5.3)
- Readiness 23 → 44 (+21.1)
- Security 50 → 57 (+6.7)
- Accessibility 63 (new)
- Performance 60 (new)
Resolved (135)
- (anonymous) (cognitive 27) (packages/electron/bundled-plugins/claude-design/index.cjs)
- (anonymous) (cyclomatic 26) (packages/electron/bundled-plugins/claude-design/index.cjs)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dimension evaluation failed
- FileTooLong: agents/codex-cli-middleware-runtime.test.mjs (packages/core/test/integration/agents/codex-cli-middleware-runtime.test.mjs)
- FileTooLong: agents/context-archive.test.mjs (packages/core/test/unit/agents/context-archive.test.mjs)
- FileTooLong: gateway/gateway-virtual-models.test.mjs (packages/core/test/integration/gateway/gateway-virtual-models.test.mjs)
- FileTooLong: gateway/router-builtins.test.mjs (packages/core/test/unit/gateway/router-builtins.test.mjs)
- FileTooLong: mcp/toolhub-mcp-runtime.test.mjs (packages/core/test/integration/mcp/toolhub-mcp-runtime.test.mjs)
- FileTooLong: observability/request-log-runtime.test.mjs (packages/core/test/integration/observability/request-log-runtime.test.mjs)
- FileTooLong: observability/request-log-store.test.mjs (packages/core/test/integration/observability/request-log-store.test.mjs)
- FileTooLong: profiles/profile-service.test.mjs (packages/core/test/integration/profiles/profile-service.test.mjs)
- FileTooLong: providers/provider-account-service.test.mjs (packages/core/test/unit/providers/provider-account-service.test.mjs)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 115 more
New (978)
- (anonymous) (cognitive 41) (cdn/public/ccr-provider-buttons.js)
- (anonymous) (cyclomatic 40) (cdn/public/ccr-provider-buttons.js)
- App.App (cognitive 552) (packages/ui/src/pages/home/App.tsx)
- App.App (cyclomatic 524) (packages/ui/src/pages/home/App.tsx)
- Banned license: pm2
- Boundary-crossing change coupling: preload.ts ↔ electron.d.ts (packages/electron/src/main/preload.ts)
- BrowserAutomationMcpService.runTool (cognitive 42) (packages/electron/src/main/browser-automation-mcp.ts)
- BrowserAutomationMcpService.runTool (cyclomatic 65) (packages/electron/src/main/browser-automation-mcp.ts)
- CcrRemoteControlService.appendEvent (cognitive 18) (packages/core/src/gateway/remote-control-service.ts)
- CcrRemoteControlService.appendEvent (cyclomatic 16) (packages/core/src/gateway/remote-control-service.ts)
- Change coupling: App.tsx ↔ electron.d.ts (packages/ui/src/pages/home/App.tsx)
- Change coupling: app-launch.ts ↔ cli-middleware-runtime.ts (packages/core/src/agents/codex/app-launch.ts)
- Change coupling: dashboard.tsx ↔ shared.tsx (packages/ui/src/pages/home/components/dashboard.tsx)
- Change coupling: deep-link.ts ↔ providers.ts (packages/core/src/contracts/deep-link.ts)
- Change coupling: deep-link.ts ↔ providers.tsx (packages/core/src/contracts/deep-link.ts)
- Change coupling: launch-core.ts ↔ profiles.ts (packages/core/src/profiles/launch-core.ts)
- Change coupling: launch-core.ts ↔ service.ts (packages/core/src/profiles/launch-core.ts)
- Change coupling: management-server.ts ↔ ipc.ts (packages/core/src/web/management-server.ts)
- Change coupling: probe.ts ↔ providers.ts (packages/core/src/providers/probe.ts)
- Change coupling: probe.ts ↔ providers.tsx (packages/core/src/providers/probe.ts)
- …and 958 more
Changes since last survey
- 155 commits — 79 feature/other, 76 fixes
By area
- packages/core — 72 commits
- (repo) — 45 commits
- packages/ui — 17 commits
- (root) — 12 commits
- docs/src — 3 commits
- tests/e2e — 2 commits
- .github/workflows — 1 commit
- build/docker-build.mjs — 1 commit
- packages/cli — 1 commit
- packages/electron — 1 commit
Notable commits
- fix: Add Claude Code regression test for local agent auth provider hook
- fix: Fix profile-specific model routing and gateway shutdown
- fix: Fix release lockfile dependency sync
- fix: Merge pull request #1640 from pacocartones/fix/raw-trace-directory-fsync-eperm-windows
- fix: Merge pull request #1657 from pacocartones/fix/request-log-store-test-teardown
- fix: Merge pull request #1665 from jesieleo/fix/account-balance-compact-overflow
- fix: Merge pull request #1672 from pacocartones/fix/sse-utf8-chunk-boundary
- fix: Merge pull request #1681 from songkuan-zheng/fix/usage-cache-convention-by-source
- fix: Merge pull request #1691 from dylanpulver/fix/responses-session-affinity
- fix: Merge pull request #1695 from songkuan-zheng/fix/fusion-vision-validate-image-inputs
- fix: Merge pull request #1696 from Burlesque1/fix/large-json-body-and-extraheaders
- fix: Merge pull request #1699 from krajcik/fix/gateway-preload-undici-major-mismatch
- fix: Merge pull request #1700 from diogomcd/fix/provider-account-meters-flattening
- fix: Merge pull request #1705 from kskadart/fix/claude-code-auth-hook-regression
- fix: Merge pull request #1711 from diogomcd/fix/invalidate-claude-gateway-model-cache
- fix: Merge pull request #1713 from pacocartones/fix/media-download-release-response-body
- fix: Merge pull request #1715 from diogomcd/fix/responses-unsupported-metadata
- fix: Merge pull request #1723 from gtapps/fix/1722-responses-tool-strictness
- fix: Merge pull request #1736 from BetterAndBetterII/fix/preserve-cowork-egress-hosts
- fix: Merge pull request #1742 from Pgooone/fix/overview-account-bento-row-clip
- …and 135 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
musistudio/claude-code-router was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit f2e01bfe0c01e0c7ea7a37077747473f69869048 — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-24a00d372a4b.