{
  "id": 12956173,
  "title": "I Built a ChatGPT API Without Login — How the Anonymous Flow Actually Works",
  "url": "https://urgent.news/2026/10/08/i-built-a-chatgpt-api-without-login-how-the-anonymous-flow-actually",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-08T21:08:11.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/mrrahad/i-built-a-chatgpt-api-without-login-how-the-anonymous-flow-actually-works-1dcn"
  },
  "original_language": "en",
  "account": "I was curious how ChatGPT's logged-out guest mode functions under the hood, so I created a small educational project around it. The project is a working API that chats with ChatGPT without requiring any account, login, or API key. You can find the repository at https://github.com/MR-RAHAD/chatgpt-api.\n\nThe API allows users to POST a prompt and receives ChatGPT's reply as JSON. Every request initiates a completely fresh anonymous session, replicating the steps a browser would take but without an actual browser. The project serves as an exploration of modern anti-bot engineering techniques.\n\nThe session process begins with a Cloudflare-gated challenge, where the session opens with a Safari TLS fingerprint. The server then issues a Sentinel challenge, which involves a proof-of-work plus two obfuscated VM bytecode programs. To solve the proof-of-work, I used pure Python to crack an FNV-1a hash puzzle over a base64 config payload. The bytecode programs (session-observer and turnstile) are XOR-encrypted and executed in Node.js against the real page environment to generate the required tokens.\n\nAfter solving the challenge, the obtained conversation token is exchanged for a conversation, the message is sent, and the streamed (SSE) reply is parsed. The project includes a proxy rotation mechanism with a round-robin pool and automatic cooldown for dead proxies, which helps spread the load as the guest flow is rate-limited per IP. Additionally, users can optionally lock their own deployment down with CHATGPT_API_KEYS.\n\nHowever, there are some limitations to keep in mind. The project takes approximately 20-40 seconds per reply, as requests are processed one at a time. The guest quota is roughly 10 messages per 5 hours per identity/IP, but proxies help extend this limit. Keep in mind that the project is unofficial and not affiliated with OpenAI, and the README contains a full disclaimer. If you found the project helpful, consider giving it a ⭐ on the repository. Issues and questions are welcome!",
  "summary": "I was curious how ChatGPT's logged-out \"guest\" mode really works under the hood, so I built a small educational project around it: a working API that chats with ChatGPT without any account, login, or API key . Repository: https://github.com/MR-RAHAD/chatgpt-api What it does POST /chat with a prompt returns ChatGPT's reply as JSON. Every request runs a completely fresh anonymous session — the same…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}