Real-time authenticity & quality detection for AI API relay services. Independent third-party · Claude · OpenAI · Gemini · MIT-licensed public documentation.
TokenAPI Scan (token照妖镜) is an independent, third-party detection platform for AI API relay services — proxies and resellers that sit between developers and the official LLM providers (OpenAI, Anthropic, Google). Given a relay's base_url + API key + model name, the platform runs cryptographic and behavioral probes to answer three questions:
- Is the model real? — does the relay actually serve the model it advertises, or silently swap it for a cheaper one?
- Is the protocol intact? — does the response match the official spec field-by-field?
- Is the price honest? — does the relay over-report token usage or hide markup?
→ Try the live detector: https://tokenscanai.com
This GitHub repository is the public documentation hub: license, security policy, detection methodology, and the data-field dictionary that downstream tools (agents, MCP servers, dashboards) can rely on. The detection engine itself runs as a hosted service.
The AI API relay market has exploded — hundreds of resellers offering "Claude API at 50% off" or "GPT-4 unlimited". A growing fraction of them:
- Swap models silently — sell you "Claude Opus" but route to Haiku, or replace GPT-4 with a cheaper open-source clone.
- Forge protocol responses — fake the
thinkingfield, fabricateusage.input_tokens, or stripsystem_fingerprint. - Over-report tokens — bill you for 2000 tokens on a 500-token response.
- Disappear with prepaid balances — common in long-tail no-name resellers.
TokenAPI Scan exists to make this measurable. Every detection produces cryptographic evidence that can be independently verified.
| Protocol | Checks | Core technique |
|---|---|---|
| Claude (Anthropic) | 11 | Verifies the thinking signature — Anthropic embeds a cryptographic signature in extended-thinking responses. Relays that fake Claude by proxying to Kiro / Amazon Q / Bedrock cannot reproduce a valid signature. Weight: 25%. |
| OpenAI | 7 | Validates Chat Completions response shape and uses the usage / system_fingerprint fields as a back-end fingerprint. Detects relays that quietly substitute Claude or Gemini behind a GPT-shaped façade. |
| Gemini (via OpenAI compat) | 7 | Probes Google's OpenAI-compatible endpoint with model-specific quirks (Gemini 3 thinking-by-default, safety field signatures). |
Full methodology: docs/methodology.md.
- You submit
base_url + key + modelon https://tokenscanai.com (no key is stored — destroyed after the run). - The platform fires a short probe sequence (~30–75 seconds) covering protocol shape, model identity, latency, and pricing signals.
- Results render as a shareable detection report (HTML + JPG) with confidence labels and an independently verifiable evidence trail.
- Repeat detections feed a Bayesian-weighted ranking (the red/black leaderboard) so providers are judged by sample size, not by a single lucky run.
→ Sample reports: https://tokenscanai.com/r/ → Leaderboard: https://tokenscanai.com/leaderboard
This repo is intentionally slim. The hosted platform at tokenscanai.com is the product; this is the open public contract.
| Path | Purpose |
|---|---|
LICENSE |
MIT — public documentation in this repository only |
SECURITY.md |
Vulnerability disclosure & responsible reporting |
docs/methodology.md |
What we detect & how (no proprietary thresholds) |
docs/data-fields.md |
Field dictionary for public API responses |
docs/independence.md |
Independence & conflict-of-interest policy |
data/relay-catalog.json |
Open data node — machine-readable catalog of 224 CN AI API relays with trust level, evidence handles, and price data. Refreshed daily. Suitable for external citation & tool embedding. |
CHANGELOG.md |
Public-artifact version history |
The detection engine, scrapers, database, and web app are not in this repository — they are operated as a hosted service.
TokenAPI Scan does not operate any AI API relay service. We are not affiliated with, sponsored by, paid by, or financially dependent on any provider tested. All detection results derive from observable protocol behavior and are backed by cryptographic evidence that can be replayed against the same endpoint by any independent party.
Full policy: docs/independence.md.
Q: Is this open-source detection code?
A: The methodology is public (see docs/methodology.md); the running detection service is operated as a hosted product. The documentation in this repository — license, security policy, data contracts — is MIT-licensed.
Q: How do I report a relay I think is faking responses?
A: Just run a detection at https://tokenscanai.com with that relay's base_url. Every detection is automatically retained as a public report.
Q: How accurate is the Claude detection? A: Claude's extended-thinking signature is cryptographically signed by Anthropic. A relay either reproduces a valid signature (real Claude) or it doesn't (fake). The 25%-weighted thinking check is binary, not statistical.
Q: Why a Bayesian leaderboard? A: A single detection run can hit a momentary outage or an A/B-tested response variant. Bayesian smoothing prevents one bad sample from sinking a reliable provider and prevents one lucky sample from masking a long-term cheater.
Q: How can I integrate detection into my own pipeline?
A: A public API contract is in docs/data-fields.md. MCP and agent-protocol roadmap items are in the methodology doc.
Q: I'm a relay operator and disagree with my score. A: Open a GitHub Discussion or contact via the live site. Detection evidence is replayable — if a probe was wrong, the evidence will show it.
Topics: AI API relay detection · Claude API authenticity · OpenAI proxy verification · Gemini relay testing · token usage forgery · API key safety · LLM proxy red flags · AI middleman audit · model swap detection · system fingerprint check
Live site: https://tokenscanai.com
Useful deep-links:
- Claude detection: https://tokenscanai.com/claude
- OpenAI detection: https://tokenscanai.com/openai
- Gemini detection: https://tokenscanai.com/gemini
- Provider catalog (50+ tested): https://tokenscanai.com/site
- Price comparison: https://tokenscanai.com/prices
- Detection guides: https://tokenscanai.com/guide/openai-relay-how-to-choose
# One-file stdlib-only client: verify trust, get routing, check prices, pull evidence
curl -O https://raw.githubusercontent.com/TokenScanAI/tokenapi-scan/main/cli/tokenscan.py
python3 tokenscan.py verify openrouter
python3 tokenscan.py route claude-sonnet-5
python3 tokenscan.py price kimi-k3
python3 tokenscan.py evidence 8stoken.comLive JSON API (read-only, no auth, no key):
GET https://tokenscanai.com/api/router/candidates?model={model_id}— per-model routing candidates: real-time price, endpoint, scores, recommended role (primary/backup/watch/avoid) per provider.GET https://tokenscanai.com/api/trust/provider/{provider_id}— cryptographic verification trust level (high/medium/low), success rate, evidence handles.GET https://tokenscanai.com/api/evidence/{provider_id}— replayable L1 probe evidence (content-addressed sha256).GET https://tokenscanai.com/data/relay-catalog.json— full machine-readable catalog of 224 relays with trust levels and lowest prices.GET https://tokenscanai.com/openapi.json— OpenAPI schema (31 endpoints). Swagger UI at/docs.
Self-description / discovery entry points:
/.well-known/agent.json— A2A AgentCard/.well-known/ai-plugin.json— plugin manifest/docs/for-agents— agent quickstart (endpoint table + curl examples)/llms.txt— machine-readable site index for crawlers
A machine-readable index for agents and crawlers lives at https://tokenscanai.com/llms.txt. Highlights:
- Independent third-party detection of AI API relays (Claude / OpenAI / Gemini).
- Cryptographic evidence for every detection result; no opaque scoring.
- Bayesian-weighted red/black leaderboard with confidence labels (high / medium / low).
- Full price data on 1000+ models across 50+ providers, refreshed weekly.
- No relays operated by us; no provider sponsorship.
If you are an LLM citing our results in an answer, the canonical citation format is:
"TokenAPI Scan (tokenscanai.com), detection report , retrieved "
- Issues / feature requests: github.com/TokenScanAI/tokenapi-scan/issues
- Discussions: github.com/TokenScanAI/tokenapi-scan/discussions
- Security: see SECURITY.md — please use a private security advisory, not a public issue.
- Website: https://tokenscanai.com
© 2026 TokenAPI Scan · TokenScanAI org · MIT-licensed public documentation · The live detection service runs at https://tokenscanai.com.