About this project

Liapi is a self-hosted HTTP service that exposes an OpenAI-compatible API externally and aggregates multiple upstream model services internally (OpenAI, Claude, OpenRouter, SiliconFlow, Ollama, etc.). The project is implemented purely on Go 1.22+ standard library with no third-party dependencies, producing a binary in one go build step. Core features: - Unified authentication: client tokens are fully separated from upstream API Keys, supporting three sources: Bearer / x-api-key / ?token=, using SHA-256 digest + constant-time comparison to prevent timing attacks, with tokens masked before logging. - Model routing: ordered by ascending priority, weighted random within the same priority group; supports explicit fallback chains (fallbacks), exact model aliases, and regex alias rules (including parameter overrides). - Failover: switching decisions are made before the first WriteHeader, automatically switching upstreams on 429/5xx, fast-failing without retry on 4xx (non-429); supports internal retries within a single upstream. - Streaming forwarding: detects text/event-stream, copies line by line and flushes; streaming has no hard timeout and is driven by client disconnect; when the client disconnects, reading from the upstream stops and the connection is released. - Rate limiting: sliding window rate limiting, supporting per-token requests per minute and daily UTC quotas, with per-device overrides. - Logging and statistics: JSONL log files + in-memory ring buffer, recording path, model, upstream, status, latency, token usage, and cost estimates; supports aggregation by upstream/model/token/time period, providing P50/P90/P99 latency and error code distribution. - Health checks: a background goroutine periodically probes upstreams concurrently, marking them unhealthy after N consecutive failures, automatically avoiding them during routing (toggleable), and falling back to all when everything is down. - Web console: a static SPA built with Nuxt 4, embedded into the binary via go:embed, supporting upstream/token/device management, config hot reload, log queries, statistics export, and debug testing. The management API provides full CRUD: upstream management, device token management (only SHA-256 hashes stored, plaintext issued only once), config import/export (supporting OneAPI channels format import), statistics aggregation and CSV/JSON export, and Prometheus metrics. Console login uses username + password (PBKDF2-HMAC-SHA256 salted hash), issuing short-lived session tokens strictly separated from business call tokens. Config files are forced to 0600 permissions and validated at startup. The business API is compatible with the OpenAI format, covering /v1/chat/completions, /v1/completions, /v1/embeddings, /v1/models, /v1/messages (Claude native format); clients only need to change base_url to use it.