with one click
sub2api
sub2api contains 27 collected skills from youxuanxue, with repository-level occupation coverage and site-owned skill detail pages.
Skills in this repository
Capture real Claude Code TLS/HTTP fingerprints and diff/fix TokenKey constants. Use after cc version changes, ingress UA cohort drift, OAuth mimicry/beta/stainless drift, CC geo-stego body drift (system/messages/system-reminder), or refreshing tk_canonical_cc_oauth alignment.
Run the combined TokenKey fingerprint refresh for Claude Code, Kiro, Antigravity, Codex, Gemini CLI, and Grok CLI. Enter after client-release-watch reports drift, or when capture-all finds actionable fingerprint drift; use platform-specific skills for single-client refreshes.
Read-only TokenKey prod/edge troubleshooting workflow. Use for live logs, ops_error_logs, SSM/Docker checks, gateway UA/TLS/body evidence, CI/deploy traces, and evidence-based root-cause summaries.
TokenKey Kiro OAuth re-authorization and refresh troubleshooting workflow. Use when a Kiro edge account shows OAuth 401, Invalid bearer token, grant revoked upstream, repeated manual re-oauth, Kiro refresh failures, or when copying freshly logged-in local Kiro credentials onto an edge and verifying Kiro Claude traffic.
TokenKey model operations hub — single ops entry for catalog/menu refresh, newapi mapping drift, mirror diff, account model_mapping runtime hotfix, and onboard prep. Routes read-only plan, catalog write, runtime setting sync, or onboard write.
Drive TokenKey Stage0 release, prod deploy, edge rollout, smoke, rollback, and release-risk checks. Use for release tagging, deploy-stage0, Lightsail edge rollout, structured smoke results, or post-release OAuth checks.
TokenKey served+priced model onboarding workflow for curated newapi mapping accounts. Use when adding/pricing Qwen or DeepSeek long-tail models, serving a model via accounts 39/60, or debugging priced-but-empty-pool 429/503 drift.
Write sub-flow for TokenKey catalog/menu allowlist refresh (branch B). Enter via tokenkey-modelops-planner first; load this skill only when executing refresh-servable-allowlist probe/run/apply and Gemini/Volcengine edge cases.
Probe a specific TokenKey prod or edge account against one model by reusing reserved __tk_probe_* debug resources. Use when debugging whether account_id N on prod/edge can actually serve a model, when isolating routing from account capability, or when checking a suspect prod/edge account before changing scheduling.
Align the TokenKey OpenAI-platform Codex client fingerprint to the locally-installed Codex CLI. Use when `codex` upgrades and the forged UA / `version` header / probe version / admin-UI placeholders need a version bump, or to diff TK pins against the installed CLI. Reads the installed binary (no mitmproxy); never auto-changes the non-version pins (originator=codex_cli_rs, OpenAI-Beta), and keeps the OS/terminal UA segment verbatim.
Read-only TokenKey production user billing/usage/error watch. Use for 盯盘, billing watch, user 1/16 monitoring, 30-minute reporting loops, anomaly notification, or distinguishing client noise from real metering/system issues.
TokenKey Anthropic OAuth read/check/remediation workflow. Use for manage-anthropic-config snapshot/check/sync-runtime, tk_canonical_cc_oauth TLS template drift, Claude Code UA/http mimicry sync, or OAuth stability guard checks across prod/edges.
Audit TokenKey endpoint compatibility across direct platform keys, universal keys, and newapi channels. Use for prod endpoint matrix probes, universal-key full matrix checks, direct-vs-universal routing parity, count_tokens fallback status, or reports about chat/responses/messages/images/video support. Separates route-gate openness from true upstream servability and forbids unsupported claims without code/probe evidence.
TokenKey Anthropic OAuth account creation from local Claude Desktop/web cookies with edge-only Anthropic egress. Use when a user asks to turn local `~/Library/Application Support/Claude/Cookies` into TokenKey Anthropic OAuth credentials, create or verify an edge account such as `edge-or-2-c`, compare web-cookie auth with TokenKey OAuth credentials, or explicitly says local direct Claude/Anthropic access is forbidden because the IP must be the edge IP.
Rebalance TokenKey Anthropic OAuth account priority by remaining 5h/7d usage windows across deployable edges. Use for snapshot/plan/apply/verify of accounts.priority only; does not change tier, rpm limits, groups, or credentials.
Read-only TokenKey prod/edge traffic profiling. Use to reconstruct per-minute RPM, sticky/load-balance split, sessions, concurrency, cap pressure, admin account-card gauges, or no-available-accounts throttling evidence.
Add a TokenKey Stage0 Edge gateway on AWS Lightsail. Use for new edge registration, Lightsail provisioning, DNS pointing, smoke checks, upgrades, or rollbacks on the current edge platform.
Capture and diff real Antigravity IDE HTTP fingerprints against TokenKey constants. Use when cloudcode-pa UA/body/header mimicry may have drifted or Antigravity impersonation constants need refresh; capture/diff only, never fabricate JA3.
Align TokenKey Gemini CLI gateway fingerprint pins to upstream @google/gemini-cli releases. Use when client-release-watch reports gemini-cli drift or GeminiCLI/* User-Agent rejection.
Align TokenKey grok-cli OAuth relay fingerprint pins to upstream @xai-official/grok releases. Use when client-release-watch reports grok-cli drift or xAI OAuth relay UA rejection.
Capture and diff real Kiro IDE TLS JA3 and aws-sdk-js User-Agent against TokenKey constants. Use for Kiro TLS onboarding, suspected IDE JA3 drift, or pre-Phase-2 TLS gate verification; capture/diff only.
Run the local Docker Stage0 stack for TokenKey. Use for Caddy/app/Postgres/Redis local deploy, compose setup, smoke verification, teardown, or matching deploy/aws behavior on a workstation.
TokenKey upstream merge workflow for importing Wei-Shaw/sub2api upstream/main. Use when merging or reviewing upstream drift, preparing an upstream merge PR, or maintaining recurring upstream update discipline.
Deprecated TokenKey EC2/CFN edge expansion path. Use only to redirect old edge-add requests to tokenkey-stage0-edge-lightsail-expansion.
Deprecated TokenKey EC2 edge IP rotation path. Use only to redirect polluted edge egress IP rotation requests to tokenkey-stage0-edge-lightsail-ip-rotation.
Rotate a TokenKey Stage0 Lightsail Edge egress Static IP after provider risk-blocking or pollution. Use for uk/us/fra/sg edge IP swaps, DNS/Caddy follow-up, and clean-egress verification.
Deprecated TokenKey EC2 edge platform migration path. Use only to explain that edges are Lightsail-only and redirect new edge work to tokenkey-stage0-edge-lightsail-expansion.