Model or dataset
neurogen-dev/NeuroAPI avatar
neurogen-dev/NeuroAPI

NeuroAPI's installer ships the agents branch while every release tag still says NeuroGPT

NeuroAPI: российский AI API для Codex CLI и Claude Code — безопасные one-click установщики для Windows и macOS.

1,314 stars140 forksTypeScriptMIT

At a glance

What is it?
A Russian project that points Codex CLI and Claude Code at a ruble billed API aggregator, with a profile that disables five tool families and a key that never lands in a config file. The download link serves a branch head, and the newest release tag predates the rename by close to three years.
Who is it for?
This is a thin installer over a commercial third party API, and the two deserve separate judgements. As an installer it is careful: the key goes to DPAPI or the login Keychain and never to a config file or a command line, an existing config.toml is backed up before any edit, a conflict stops the run rather than overwriting, and the client version floor is checked by reading codex --help instead of being assumed.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 2, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The download is a branch archive, and the newest tag still says NeuroGPT

What reaches a user is a GitHub branch archive, the archive/refs/heads/agents.zip link, and the repository's default branch is agents rather than main. The page says outright that changes to an open pull request appear in that archive only after they are merged into agents, so the artifact a machine installs is a moving branch head with no release checksum attached to it. The tag history is stranger. The three releases listed are v2.1.1, v2.1.0 and v2.0.0, and every one of them is titled NeuroGPT rather than NeuroAPI, dated 2023-12-08 and 2023-11-28. That is close to three years before the last push on 2026-10-01, so nothing published under releases has ever carried the current product name.

The generated Codex profile switches off five tool families

The profile the installer writes is not a passthrough. It points at https://codex.neuroapi.host/v1 with supports_websockets = true and turns off hosted web search, multi-agent, goals, apps and browser use. The reason given is narrow and specific: the newest Codex client sends those tools even on simple tasks, while NeuroAPI does not guarantee provider side execution for them. Local commands, and reading and editing files, are left working, so the profile trades tool breadth for reliability rather than switching the client off. The same paragraph offers a narrower diagnostic for connection problems, setting supports_websockets = false inside the generated profile while keeping the URL and the credential helper untouched.

The version floor is checked by reading codex --help

The install refuses to continue unless the Codex on the machine is new enough, and the check is done by reading help output rather than by parsing a version string. codex --help has to describe --profile as loading a <name>.config.toml file, which is the separate per profile file layout. A machine on an older client that keeps [profiles.name] sections inside one shared config is told to update first, before the installer runs at all. The version requirement exists because the profile lands in its own file at ~/.codex/neuroapi-host.config.toml on both Windows and macOS instead of the shared config.toml. Claude Code takes a different route again, with its own installer owned JSON file handed to the client through --settings.

DPAPI on Windows, the login Keychain on macOS, and no key in any config

The setup table carries one row per platform and maps the same job onto two different stores. On Windows the key is read with Read-Host -AsSecureString and encrypted through DPAPI against the current user and machine, with no separately stored master key. On macOS a protected prompt driven by /usr/bin/security writes into the login Keychain using an interactive -w. Both platforms retrieve the token through a helper rather than a file: a command backed auth helper on Windows, apiKeyHelper with a Keychain helper on macOS, and each helper prints only the token to stdout when the launcher or the client asks for it. The stated limit is worth repeating: this protects against publishing the key by accident, not against malware already running as the same user.

Claude Desktop is set by hand while Codex Desktop is edited in place

Claude Desktop sits outside what the installer will touch, and that reads as a deliberate boundary rather than an omission. The installer does not change the application's closed settings, so a Claude Desktop user turns on Developer Mode and enters NeuroAPI in the built in Configure Third-Party Inference form, following a separate instruction. Codex Desktop goes the other way and only after the installer asks its own yes or no question: it backs up the existing config.toml, changes it atomically, attaches a DPAPI or Keychain helper, and writes the catalog of available models, after which the app is restarted and a new local task is created. If the backup step finds a conflict, the installation stops rather than overwriting what is there.

A catalog check does not prove that generation works

The installer's own verification is narrower than a passing run suggests. It checks that the key can reach both model catalogs, and it does so without paying for any generation, sending the key only to NeuroAPI for that check. The two clients point at different subdomains, https://claude.neuroapi.host for Claude Code and https://codex.neuroapi.host/v1 for Codex, and the launcher fetches a current catalog from the matching subdomain every time codex-neuroapi or claude-neuroapi starts, so the catalog can differ between install and first use. The page is direct about the limit: a catalog check by itself does not confirm generation, so one short real request has to be sent afterwards and checked in the usage history in the dashboard.

An already set CODEX_HOME is honoured and never changed

The macOS path leaves the smallest footprint of the two, because it does not use sudo and does not edit a shell profile, and the two wrappers it installs land in ~/.local/bin:

bash
bash setup-macos.command
bash
~/.local/bin/codex-neuroapi
~/.local/bin/claude-neuroapi

If ~/.local/bin is already on PATH the bare names work, and otherwise the full paths do. The Windows batch file needs no administrator rights either, and on both platforms the key is refused as a command line argument and pasted into a hidden prompt instead. Two details about removal are worth knowing. An already set CODEX_HOME is used for the profile and left alone, so the same value has to be present at install, at run and at removal, and the tree carries uninstall-windows.bat and uninstall-macos.command next to a reconnect-after-update page for people who already tried the setup and met errors.

TypeScript in the metadata, installers and docs in the tree

The repository presents itself as a set of one click installers, and the language tag records TypeScript as the primary language, yet no source directory appears at the top level. What is there is setup-windows.bat, setup-macos.command, their two uninstall counterparts, a VERSION file, AGENTS.md, SECURITY.md, docs/ and tests/. The README is written in Russian and links to an English version present in the same tree as README.en.md. The service it points at is billed in rubles by a Russian company with infrastructure hosted in Russia, offering one endpoint across OpenAI, Anthropic Claude, Google Gemini and DeepSeek models plus image and video generation. No pricing sits in the repository at all, because the page points to a live catalog and tells readers to confirm current models and prices there.

Editorial conclusion

This is a thin installer over a commercial third party API, and the two deserve separate judgements. As an installer it is careful: the key goes to DPAPI or the login Keychain and never to a config file or a command line, an existing config.toml is backed up before any edit, a conflict stops the run rather than overwriting, and the client version floor is checked by reading codex --help instead of being assumed. As a routing decision it moves your prompts, your code context and your key to an aggregator run by a Russian company with infrastructure in Russia and billed in rubles, and the agreement you accept with that provider is what governs your data, not anything in this repository. Read that provider's terms and its live price catalog before installing. Teams that rely on the Codex hosted web search, multi-agent, goals, apps or browser use tools should know up front that the generated profile turns all five off. Anyone installing from the branch archive should expect the code to move under them, since that link serves a branch head rather than a tagged release.

Frequently asked questions

What does the NeuroAPI installer change on my machine?

It writes a separate ~/.codex/neuroapi-host.config.toml for Codex on both platforms and an installer owned JSON file handed to Claude Code through --settings. An existing config.toml is backed up and changed atomically only after you agree, and a conflict stops the install instead of overwriting.

Does the NeuroAPI installer need sudo or administrator rights?

No. The Windows batch file needs no administrator rights, and the macOS command script does not use sudo and does not edit a shell profile. On macOS the two wrappers go into ~/.local/bin, so if that directory is not already on PATH you call the full paths.

Where does the NeuroAPI installer store my API key?

On Windows the key is read with Read-Host -AsSecureString and encrypted with DPAPI against the current user and machine. On macOS it is written into the login Keychain by /usr/bin/security with an interactive -w. It is never saved to .env, TOML, JSON or the repository, and it is not accepted as a command line argument.

Which version of Codex CLI does NeuroAPI require?

A current one that loads per name profile files, so codex --help must describe --profile as loading a <name>.config.toml file. Older clients that keep [profiles.name] sections inside one shared config are told to update before the installer runs, because the profile is written to its own file.

How do I remove the NeuroAPI setup?

The repository tree ships uninstall-windows.bat and uninstall-macos.command. Removal also has to use the same CODEX_HOME value that was in place at install time, since an already set CODEX_HOME is honoured for the profile and never modified. A reconnect-after-update page covers people who already tried the setup and hit errors.

Official sources

  1. License: MIT
  2. neurogen-dev/NeuroAPI on GitHub
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/neurogen-dev-neuroapi.svg)](https://hysenlabs.com/projects/neurogen-dev-neuroapi)