DEV Community

MR-RAHAD
MR-RAHAD

Posted on

I Built a ChatGPT API Without Login — How the Anonymous Flow Actually Works

I was curious how ChatGPT's logged-out "guest" mode really works under the hood, so I built a small educational project around it: a working API that chats with ChatGPT without any account, login, or API key.

Repository: https://github.com/MR-RAHAD/chatgpt-api

What it does

POST /chat with a prompt returns ChatGPT's reply as JSON. Every request runs a completely fresh anonymous session — the same steps a browser would take, but without a browser.

How it works

Studying the guest flow turned into a tour of modern anti-bot engineering:

  1. Session — the flow is Cloudflare-gated, so the session opens with a Safari TLS fingerprint.
  2. Prepare — the server issues a "Sentinel" challenge: a proof-of-work plus two obfuscated VM bytecode programs.
  3. Proof-of-work — solved in pure Python (an FNV-1a hash puzzle over a base64 config payload).
  4. VM tokens — the bytecode programs (session-observer + turnstile) are XOR-encrypted; I run them in Node/jsdom against the real page environment to produce the required tokens.
  5. Finalize + conversation — the solved challenge is exchanged for a conversation token, the message is sent, and the streamed (SSE) reply is parsed.

Extras

  • Proxy rotation — a round-robin proxy pool with automatic cooldown for dead proxies (the guest flow is rate-limited per IP, so rotation spreads the load).
  • Optional API keys — lock your own deployment down with CHATGPT_API_KEYS.

Honest limitations

  • ~20–40 seconds per reply; requests run one at a time.
  • Guest quota is roughly 10 messages per 5 hours per identity/IP — proxies help, but nothing here is "unlimited".
  • It wraps a web frontend, so bundle changes can break the solver until it's re-derived.

Why build this?

🎓 Education and research. This project exists to demonstrate how modern web platforms defend themselves — TLS fingerprinting, proof-of-work challenges, and VM-based token systems — and how those mechanisms work in practice. It's unofficial, not affiliated with OpenAI, and the README carries a full disclaimer.

If you learned something from it, a ⭐ on the repo helps others find it. Issues and questions are welcome!


A question for you

If you were building on top of a no-login API like this, what would you use it for — a Telegram bot, a CLI tool, or something else? And what's the first thing you'd worry about breaking?

Drop your take in the comments — I read every one.

Top comments (0)