I was curious how ChatGPT's logged-out "guest" mode really works under the hood, so I built a small educational project around it: a working API that chats with ChatGPT without any account, login, or API key.
Repository: https://github.com/MR-RAHAD/chatgpt-api
What it does
POST /chat with a prompt returns ChatGPT's reply as JSON. Every request runs a completely fresh anonymous session — the same steps a browser would take, but without a browser.
How it works
Studying the guest flow turned into a tour of modern anti-bot engineering:
- Session — the flow is Cloudflare-gated, so the session opens with a Safari TLS fingerprint.
- Prepare — the server issues a "Sentinel" challenge: a proof-of-work plus two obfuscated VM bytecode programs.
- Proof-of-work — solved in pure Python (an FNV-1a hash puzzle over a base64 config payload).
- VM tokens — the bytecode programs (session-observer + turnstile) are XOR-encrypted; I run them in Node/jsdom against the real page environment to produce the required tokens.
- Finalize + conversation — the solved challenge is exchanged for a conversation token, the message is sent, and the streamed (SSE) reply is parsed.
Extras
- Proxy rotation — a round-robin proxy pool with automatic cooldown for dead proxies (the guest flow is rate-limited per IP, so rotation spreads the load).
-
Optional API keys — lock your own deployment down with
CHATGPT_API_KEYS.
Honest limitations
- ~20–40 seconds per reply; requests run one at a time.
- Guest quota is roughly 10 messages per 5 hours per identity/IP — proxies help, but nothing here is "unlimited".
- It wraps a web frontend, so bundle changes can break the solver until it's re-derived.
Why build this?
🎓 Education and research. This project exists to demonstrate how modern web platforms defend themselves — TLS fingerprinting, proof-of-work challenges, and VM-based token systems — and how those mechanisms work in practice. It's unofficial, not affiliated with OpenAI, and the README carries a full disclaimer.
If you learned something from it, a ⭐ on the repo helps others find it. Issues and questions are welcome!
A question for you
If you were building on top of a no-login API like this, what would you use it for — a Telegram bot, a CLI tool, or something else? And what's the first thing you'd worry about breaking?
Drop your take in the comments — I read every one.
Top comments (0)