Unofficial AI Wrappers: Your API Is Someone Else's Login, and the Account Is the Collateral

Unofficial AI wrappers turn a consumer login into an API, and a personal account becomes the collateral. Inventory each lane's credential and retire the risk.

Unofficial AI wrappers: an API badge chained to one person's account card that holds mail, files and repos, tagged collateralUnofficial AI wrappers: an API badge chained to one person's account card that holds mail, files and repos, tagged collateral
The API is free. The collateral is the account behind it.

We don’t integrate, recommend or endorse any tool named here. This is a warning, not a setup guide.

One lane in your fleet answers on an OpenAI-shaped endpoint that nobody bought. No key sits on the budget sheet and no invoice arrives. Behind it sits a person’s GitHub login, a Google cookie jar or a browser profile signed into a personal Microsoft account, plus a small program that turns that login into an API.

That’s what unofficial AI wrappers are: consumer chat products, reverse-engineered into something code can call. The trade looks cheap. You skip the API bill, and the credential becomes somebody’s consumer session.

When the host notices the traffic, it doesn’t revoke a key. It acts on an account, and that account also holds someone’s mail, files and repos.

So the move for Tuesday is an inventory. Label every lane by credential class, find the consumer-session lanes, write down the account each one puts up as collateral, apply four rules and drill the kill. Chatbots suggest; agents act. An agent lane is exactly the automated, scripted caller that copilot-api’s own warning describes.

Three unofficial AI wrappers, and what their own READMEs admit

We read three public repos through the GitHub API on Sep 28, 2026. They’re examples of a class, named so you can recognize the shape in your own fleet.

ericc-ch/copilot-api (created Jan 11, 2025; last push Nov 10, 2025) signs in with the user’s GitHub account and re-exposes that Copilot subscription as an OpenAI- or Anthropic-style API on the local machine. The README says it works with “individual, business, and enterprise GitHub Copilot plans”, which is how an org-paid seat ends up behind one developer’s proxy. Its warning is narrow, and worth reading exactly. Excessive automated or scripted use “may trigger GitHub’s abuse-detection systems,” and further anomalous activity “could result in temporary suspension of your Copilot access.”

copilot-api README on GitHub showing two warning boxes: the project is a reverse-engineered proxy not supported by GitHub, and a GitHub Security Notice that scripted use may trigger abuse detection and temporary suspension of Copilot access Screenshot: GitHub, “GitHub - ericc-ch/copilot-api: Turn GitHub Copilot into OpenAI/Anthropic API compatible server. …” (last push Nov 10, 2025), captured Sep 28, 2026.

The whole-account language comes from a user, not from GitHub’s published terms. In issue #84 (Aug 13, 2025), a user posted a GitHub Security email saying “we have suspended your access to Copilot”. Access came back after some back-and-forth.

The final message, as that user posted it, warned of possible “permanent suspension of your GitHub account.” The repo’s owner replied that he’d had the same warning in March. It’s one user report, and it’s the only documented enforcement against a user of any of these three tools.

HanaokaYuzu/Gemini-API (created Feb 11, 2024; last push Aug 27, 2026) calls itself a “Reverse-engineered Python API for Google Gemini web app”. It reuses the user’s Google session cookies from Gemini’s consumer chat, refreshes them “in background”, and bills itself as “Optimized for always-on services”. Its extension support reaches YouTube and Gmail. The README carries no terms or ban warning at all, and that absence is the finding.

Google fills the gap. Its Gemini Apps Privacy Hub says “The Google Terms of Service and the Generative AI Prohibited Use Policy apply to Gemini Apps”. Those terms, effective Jul 30, 2026, list “using automated means to access content from any of our services in violation of the machine-readable instructions on our web pages” as abuse, and say “Google may suspend or terminate your access to the services or delete your Google Account if any of these things happen”.

sums001/Windows-Copilot-API (created Jun 19, 2026; last push Jun 27, 2026) isn’t Windows Copilot, whatever the name says. It’s a browser bot that drives the consumer chat at copilot.microsoft.com and clears its human-verification step. You sign in “with your Microsoft or Google account”, and the tool “bridges a single signed-in Copilot account” for every caller.

The README asks users to stay “within Microsoft’s terms”. Those terms, effective Aug 18, 2026, are short on this point.

Microsoft Copilot Terms of Use, Who can use Copilot section, including the line telling users not to use bots or scrapers to access Copilot and that Copilot is for personal use only Screenshot: Microsoft, “Copilot - Terms of Use” (effective Aug 18, 2026), captured Sep 28, 2026.

Microsoft’s Copilot terms say: “Don’t use tools or computer programs (like bots or scrapers) to access Copilot. You can only use Copilot for your own personal use.” The same terms let Microsoft “limit, suspend, or permanently revoke your access to or use of Copilot (and potentially all other Services)”. “Services” is defined in the Microsoft Services Agreement, whose covered services include Outlook.com and OneDrive. A Google login doesn’t keep you out of that: “If you log in to Copilot using a non-Microsoft account, we may automatically create a Microsoft account for you, or let you link that non-Microsoft account to your existing Microsoft Account.”

Google’s February bans need scoping. They enforced the Antigravity terms against third-party tools and proxies. Google’s own announcement, discussion #20632 on the Gemini CLI repo (Feb 27, 2026), called harvesting or piggybacking on Gemini CLI’s OAuth “a direct violation of Gemini CLI’s applicable terms and policies.” It also named the spillover: “bans for Antigravity usage also blocked access to Gemini CLI and Gemini Code Assist.”

None of that was about Gemini’s consumer chat, so it says nothing direct about Gemini-API. It does show the mechanism this piece is about. Enforcement lands wherever the vendor’s abuse prevention sits, and that layer doesn’t know which of your products you meant to risk.

Side by side, the three projects’ own docs and the host terms read like this.

Project (created · last push) Credential it rides on What its own docs say about risk What the host’s terms say
copilot-api (Jan 11, 2025 · Nov 10, 2025) The user’s GitHub login and Copilot seat; the token is stored on the host Abuse detection, then “temporary suspension of your Copilot access” AUP §4 bans “excessive automated bulk activity”; §6 bans exploiting “access to the Service”
Gemini-API (Feb 11, 2024 · Aug 27, 2026) Google session cookies from Gemini’s consumer chat, refreshed in the background No terms or ban warning Google ToS (Jul 30, 2026): automated access against machine-readable instructions is abuse; the account can be deleted
Windows-Copilot-API (Jun 19 · Jun 27, 2026) A browser profile signed into a Microsoft or Google account “use it responsibly and within Microsoft’s terms” Copilot Terms of Use (Aug 18, 2026): no bots or scrapers; revocation can reach “potentially all other Services”

GitHub’s published terms have no Copilot-specific clause on proxies or wrappers. The on-point rules sit in the Acceptable Use Policies: §4 bans “excessive automated bulk activity”, and §6 bans reselling or exploiting “access to the Service”.

Money moved too. Copilot’s usage-based billing went live for all users on Jun 1, 2026, and the changelog says that for individual plans GitHub “may limit your total additional AI Credits based on your usage patterns, billing history, and verification status for your user account.” The metering side of that change is its own story. Here it matters for one reason: the unit GitHub watches is the user account.

Why an agent lane turns a gray-area habit into an account incident

A person poking a wrapper from a terminal sends a few dozen requests a day, at human hours, from one machine. An agent lane retries, fans out and runs at 3 a.m. Sometimes it runs from CI, which copilot-api explicitly supports with authentication “suitable for CI/CD environments”. That’s the “rapid or bulk requests” pattern its own warning names.

The failure shape changes too. A revoked API key is a 401 and a ticket: you reissue it and the lane comes back. A consumer-session lane fails as an enforcement action against a person.

It arrives as a warning email, a suspended seat or, in the worst case the terms allow, the loss of the account itself. Nobody on the fleet team can reissue that. The person who owns it may not even know an agent was using it.

Step 1: Label every lane with one of four credential classes

List every lane: each CLI, each harness, each scheduled job. Give each one exactly one credential class, and split mixed lanes until they aren’t mixed. The class is whatever credential actually leaves the host, not what the config file calls it. A Copilot provider entry pointed at a local proxy is a consumer session.

Credential class What it looks like in a lane Risk when it fails Allowed use Owner Retirement date
API key A key in the lane’s secret store, billed to an org account Key revoked or rate-limited; reissue it and the lane returns Unattended work and org data, within your data policy The team that owns the budget Rotation schedule, no end date
OAuth app A registered app holding scoped grants for a user or an org Grants revoked or scopes cut; the app stops, the account stays Integrations that need delegated access The app’s registered owner When the integration retires
Service principal A non-human identity in your IdP with its own role Principal disabled; nobody’s mailbox goes with it Unattended fleet and CI work The platform team Rotation schedule, no end date
Consumer session A person’s login reused by a script: a cookie, a stored personal token or a signed-in browser profile Warning, suspension or closure of a person’s account Attended experiments only; no org or customer data The named human whose account it is Required and short; 30 days is our illustrative default

copilot-api’s stored token belongs in the last row even though it came from a real GitHub sign-in. It’s one person’s seat, used through a proxy GitHub doesn’t support. A human’s SSO on a sanctioned tool is a different problem with its own fix: give the agent its own service principal rather than filing it here.

Step 2: Find the consumer-session lanes by their tells

Nobody files a wrapper in the architecture doc. You find them by what they leave behind:

  1. A model base URL pointed at this machine, or a teammate’s, instead of a vendor’s API host, with a chat product behind it.
  2. Cookie or session material in lane config: a cookie string, a token file, a saved browser storage state.
  3. A headless or automated browser running under a lane’s service account and signed into a personal identity.
  4. A finance tell: a lane that produces model output with no matching line on any API invoice.

The sweep below is illustrative and read-only. It surfaces candidates for the register, and a named human confirms every hit.

# Illustrative, read-only sweep for consumer-session candidates.
# Output is a list to review, never an automatic verdict.
ROOTS="$HOME/.config $HOME/agents /etc/agent-lanes"

# 1. Model base URLs that resolve to this machine instead of a vendor API
grep -rEni 'base_?url.*(localhost|127\.0\.0\.1)' $ROOTS

# 2. Cookie or browser-session material in lane config
grep -rEli 'cookie|session_?token|storage_?state|user-data-dir' $ROOTS

# 3. Automated browsers running under lane service accounts
ps -eo user,pid,args | grep -Ei 'headless|playwright|chromium' | grep -v grep

The sweep has limits. It sees config on the hosts you scan. It won’t see a proxy on a contractor’s laptop, or a wrapper renamed to something bland.

Treat it as a smoke detector and put a wall behind it: fleet hosts get an egress allowlist that reaches only the API hosts you pay for. Consumer chat domains aren’t on that list, so a cookie or browser-bot wrapper on a fleet host fails closed, and the failure tells you where to look. A proxy riding a Copilot seat your org already pays for reaches an allowed host, so for that case tell 1 is the check that counts. If the allowlist itself is misconfigured, the finance tell still catches most lanes at month end.

Tool cookie stores and browser profiles carry a custody problem of their own; the cookie-custody register covers them.

Step 3: Name the collateral account behind each consumer session

For every consumer-session row, write down the identity the host will act on, whose it is and what else it holds. That column is the point of the inventory. The terms tell you how far each host can reach:

  • GitHub. The account behind a Copilot seat is the account that holds the repos and the org memberships. Published terms reach it through the Acceptable Use Policies; the whole-account warning on record is the user-posted email above.
  • Microsoft. The Copilot terms put “potentially all other Services” in scope, and the Services Agreement lists Outlook.com and OneDrive among them. A Google sign-in may create or link a Microsoft account, so signing in with Google doesn’t move the collateral out of reach. These terms don’t cover work or school (Entra) sign-ins at all, which is one more reason to keep org identities out of consumer chat.
  • Google. The terms allow deleting the Google Account, and with it the Gmail and Drive that live there.

Data flows the other way too. What a lane sends can become that person’s consumer chat history. Windows-Copilot-API notes that “a tiny throwaway chat lands in your history”, and Google’s Privacy Hub says reviewed chats are “retained for up to three years.” That’s org data sitting in a personal account under consumer retention, where your deletion policy can’t reach it.

Diagram of the credential chain behind unofficial AI wrappers: a script calls a wrapper, the wrapper rides a consumer session, and the session belongs to a personal account holding mail, files and repos, while a sanctioned lane runs through an API key or service principal to an org accountDiagram of the credential chain behind unofficial AI wrappers: a script calls a wrapper, the wrapper rides a consumer session, and the session belongs to a personal account holding mail, files and repos, while a sanctioned lane runs through an API key or service principal to an org account Same script, two chains. On the top one, enforcement lands on a person.

Write the collateral in plain words, one sentence per lane. An illustrative entry: personal GitHub account of the on-call engineer, owner of two private repos, member of the company org. If you can’t write that sentence for a lane, you don’t know whose account you’re betting.

Step 4: Apply four rules to every consumer session you keep

Some lanes you’ll retire the same day. The ones that survive get four rules, and nobody files exceptions in chat:

  1. No unattended runs. A human sits at the keyboard for every call. No cron, no CI, no overnight queue. The CI/CD sign-in copilot-api advertises is the exact case this rule refuses.
  2. No org or customer data. Consumer terms, consumer retention, a personal history. If a prompt would need a data review on a sanctioned API, it can’t go here at all.
  3. A named human owner. The owner is the account holder, and they accept the risk in writing. A team alias isn’t an owner.
  4. A retirement date onto a sanctioned API key. Every row gets a date and a named replacement: the API key, OAuth app or service principal that takes over. If the wrapper exists because the budget ran out, the fix is a budget increase request, not a cookie.

The register entry carries all four. The shape below is illustrative, and the field names are ours.

# lane-credentials.yaml: one entry per lane (illustrative shape)
- lane: docs-summarizer
  credential_class: consumer_session   # api_key | oauth_app | service_principal | consumer_session
  host_product: Microsoft Copilot consumer chat
  collateral_account: personal Microsoft account of j.doe (Outlook.com, OneDrive)
  owner: j.doe                         # the account holder, by name
  attended_only: true
  org_data_allowed: false
  retirement_date: 2026-10-28
  replacement: service principal svc-docs-summarizer on the org API account
  kill: unschedule lane, revoke stored session, confirm the lane fails closed

These rules are policy, and policy fails quietly. Someone adds the lane to a nightly schedule because it worked in testing. Put two walls behind the rules.

Fleet hosts carry no personal browser profiles or session files at all, and the scheduler refuses any lane whose entry says attended_only: true. When that scheduler check breaks, the egress allowlist from step 2 still stands, and it doesn’t care what the YAML says.

Step 5: Drill the kill before the host runs it for you

Pick a quiet afternoon and ask the question literally: what breaks tonight if the host rotates auth or suspends the account?

The hosts keep their own calendar. In 2026 the rules and enforcement around this class moved at least four times, none of them on your schedule. Google’s Antigravity bans came in February, Copilot’s usage billing on Jun 1, Google’s terms on Jul 30 and Microsoft’s Copilot terms on Aug 18. copilot-api’s last push, on Nov 10, 2025, predates all four.

Timeline chart of unofficial AI wrappers against vendor rules: Gemini-API active from Feb 2024 to Aug 2026, copilot-api from Jan to Nov 2025, Windows-Copilot-API for eight days in Jun 2026, with Google, GitHub and Microsoft rule dates marked in 2026Timeline chart of unofficial AI wrappers against vendor rules: Gemini-API active from Feb 2024 to Aug 2026, copilot-api from Jan to Nov 2025, Windows-Copilot-API for eight days in Jun 2026, with Google, GitHub and Microsoft rule dates marked in 2026 Created and last-push dates from the GitHub API; rule dates from the vendors’ own pages. All read Sep 28, 2026.

Run the drill once per consumer-session lane:

  1. Pull the session for one night. Revoke or remove the stored session, then let the scheduler run as normal.
  2. Record the failure mode. Did the lane fail closed, with an error someone sees, or open, with a silent fallback to something worse?
  3. Walk the account side on paper. If the host suspended this identity at 02:00, who loses mail, files or repos, and who tells them?
  4. Time the fallback. Measure the minutes from alarm to the sanctioned credential carrying the lane.
  5. File every surprise against the retirement date. Pull the date forward if the fallback took longer than a night.

A pass is boring. The lane errors loudly, the replacement takes over, and nobody’s personal inbox is involved. Anything else is telling you the real retirement date.

How lanes built on unofficial AI wrappers fail, and the signal for each

Failure Signal First move
The host changes its consumer chat and the wrapper breaks Parse errors or empty replies on one lane while sanctioned lanes stay green Fail over to the replacement credential; don’t patch the wrapper at 2 a.m.
Abuse detection flags the account A security email lands in a person’s inbox, not on your pager (user-reported for copilot-api) Stop the lane within the hour and log the notice in the register
The session expires Gemini-API issue #275 reports sessions that stop after a while and need a fresh cookie login Accept that the human who logs in again is the credential
A ban spreads to sibling products Google: Antigravity bans also blocked Gemini CLI and Gemini Code Assist Map every product that shares the flagged account before anyone appeals
A second violation Google’s Gemini CLI post: a second flagged ToS violation means a permanent ban Retire the lane; there is no third attempt
The maintainer moves on A user-opened copilot-api issue (#233, Apr 9, 2026) says the repo is “no longer actively maintained” Treat it as the retirement date arriving early
Org data lands in a personal history Throwaway chats in the account’s history; reviewed Gemini chats kept up to three years Handle it as a data incident under your own policy

Most signals in that table show up somewhere other than your monitoring: a person’s inbox, a GitHub issue, a vendor’s announcement thread. That’s the operating cost of a credential you don’t own. You learn about its failures second-hand, usually after the lane has already stopped.

Credential class belongs on the fleet map, next to owner and kill switch

An operating layer for a fleet answers a short list of questions per lane: who owns it, what it costs, what it can touch and how you stop it. Credential class belongs on that list beside the kill switch, because it decides what the kill switch has to protect. A multi-agent command center that shows lanes without their credential class is showing you half the risk.

The inventory pairs with the last-hop register, which asks where a vendor forwards your prompt. That register tracks where the words go. This one tracks whose account carries them, and on a consumer-session lane the answer is a person who never signed up to be infrastructure.

FAQ

Is using an unofficial Copilot API against GitHub’s terms?

GitHub publishes no Copilot-specific clause on proxies. Its Acceptable Use Policies ban excessive automated bulk activity and exploiting access to the service, and copilot-api’s own README warns of temporary suspension of Copilot access. Microsoft’s consumer Copilot, a separate product, forbids bots and scrapers outright. Assume the account carries the risk.

Can a wrapper ban spread to my other Google or Microsoft services?

The terms allow it. Microsoft’s Copilot terms put “potentially all other Services” in scope, and Google’s terms allow deleting the Google Account. In February 2026, Google said Antigravity bans also blocked Gemini CLI and Gemini Code Assist. No source shows Google or Microsoft enforcing against these wrappers specifically.

Sources

YOU'RE THROUGH THIS ONE.

Keep connecting the dots.

Back to the library