Coding-Agent Routers (2026): claude-code-router vs OmniRoute vs 9router vs CLIProxyAPI vs sub2api β€” Savings vs. Ban Risk

Last updated 2026-07-27 Β· Part of Awesome AI Gateway β€” the only AI-gateway list with a reproducible cost benchmark and a security-honest scorecard. ⭐ Star it.

πŸ“Š Key numbers Β· The savings don't come from the router β€” the same coding-agent session costs $0.021 to $1.75 depending on the model behind it, a ~83Γ— spread (computed, unit-tested script). The risk doesn't come from the router brand either β€” it comes from the mechanism: BYO API keys are provider-sanctioned; routing your own subscription OAuth through third-party tools has been explicitly disallowed by Anthropic since 2026-02-20 (policy change); and pooled-account quota resale is the thing Anthropic says it is actively banning for (clarified 2026-02-19).

Every heavy Claude Code / Codex / Cursor user eventually shops for a router β€” claude-code-router, OmniRoute, 9router, CLIProxyAPI, sub2api, opencodex, freellmapi β€” and asks the same two questions: how much do I actually save, and will this get my account banned? The honest answer depends almost entirely on which of three mechanisms the tool uses, not on its GitHub stars. Here is each tool classified by what its own README says it does, with the actual ToS clauses and dated ban reports β€” no vibes.

The three mechanism tiers

TierMechanismProvider stanceRealistic worst case
1 Β· BYO API keyRoutes to providers over your own pay-per-token API keysSanctioned β€” API keys exist precisely for programmatic accessRate limits; a bigger bill
2 Β· Own-account OAuth proxyingReuses your own consumer subscription (Claude Pro/Max, ChatGPT Plus, Copilot) outside the official clientGray β†’ disallowed. Anthropic restricted subscription OAuth to its own surfaces on 2026-02-20; automated non-API access needs explicit permission under its consumer ToSYour subscription β€” and the account behind it β€” gets banned
3 Β· Pooled-account arbitragePools many subscription accounts and redistributes the quota to other users, often for moneyViolation β€” both Anthropic and OpenAI consumer ToS prohibit sharing credentials and reselling accessWhole account pools banned; buyers are holding resold, unverifiable capacity

Where each tool sits β€” from its own docs

ToolTierWhat its own docs say (verbatim)
Claude Code Router ⭐ 36.2k1 β€” BYO keyQuick start: "Open Providers β†’ Add Provider … enter the API key, select the protocol and models". One gray edge: the features table lists "local login import where supported" β€” skip importing CLI logins and you stay cleanly in Tier 1
freellmapi ⭐ 17.2k1 β€” BYO key, free tiers"add your provider keys on the Keys page"; ships its own per-provider ToS review (May 2026) with the rule of thumb "one account per provider, no reselling, no sharing your endpoint with other humans"; repo self-labels "personal experimentation only"
opencodex ⭐ 5.4k1 or 2 β€” mode-dependentTier 1 path: "Paste your API key (or log in via OAuth…)". Tier 2 path: "It can also manage a ChatGPT account pool for Codex auth. Add multiple ChatGPT / Codex accounts" with quota-based auto-routing
9router ⭐ 23.8k2 β€” own-OAuth cascadeRequest flow: "Tier 1: SUBSCRIPTION β€” Claude Code, Codex, GitHub Copilot" falling back to cheap/free; "Multi-account β€” Round-robin between accounts per provider"; the repo carries a PR titled "Antigravity anti-ban alignment"
OmniRoute ⭐ 32.3k2 β€” own-OAuth + free-tier stacking"auto-falls back across 4 provider tiers β€” Tier 1 Subscription (Claude Code, Codex, Copilot) … Tier 4 Free"; its own free-tier budget card admits "15 providers ToS-flagged so you decide"; the feature list includes "TLS fingerprint stealth"
CLIProxyAPI ⭐ 45.2k2, drifting toward 3"Claude Code support via OAuth login"; "Claude Code multi-account load balancing"; the README's sponsor slots sell "ready-to-use accounts" at "10% of the official GPT subscription price"
sub2api ⭐ 34.7k3 β€” pooled-account distributionSelf-described "AI API Gateway Platform for Subscription Quota Distribution" where "Users can access upstream AI services through platform-generated API Keys"; its own disclaimer: "The authors assume no liability for account bans…"

Three reads between the lines. First, what separates Tier 2 from Tier 3 is whose accounts are in the pool: 9router and OmniRoute route your own logins on your own machine; sub2api exists to redistribute pooled quota to other people, with "carpool" billing built in. Second, tooling tells you what the authors expect β€” OmniRoute ships TLS-fingerprint stealth and 9router ships anti-ban code, which only matter if providers are detecting you. Third, sub2api's sponsor list includes residential-IP and browser-fingerprint vendors marketed as reducing "the probability of association-based risk control" β€” infrastructure whose sole purpose is evading ban systems. None of this is hidden; it's all in the READMEs.

What the ToS actually say

Ban evidence, tool by tool

The pattern is exactly the tier table: every documented ban sits in Tier 2/3 OAuth or pooled traffic; we found zero ban reports against BYO-API-key routing.

Claimed savings vs. measured reality

ToolClaimed savingsStatus
OmniRouteCompression "saves 15–95% tokens (~89% avg)"; "~1.53B free tokens/mo" across stacked free tiersVendor-claimed (README hero + free-tier card); not independently verified
9router"Save 20-40% tokens with RTK + auto-fallback"Vendor-claimed (README tagline)
freellmapi"roughly 4 billion tokens per month" of stacked free-tier capacityVendor-claimed (README); capacity, not a savings %
Claude Code RouterNo headline savings figure β€” pitch is routing + observabilityNot documented
CLIProxyAPINo savings figure β€” the value prop is reusing subscription quotaNot documented
sub2apiNo savings figure β€” the value prop is cost-sharing pooled quotaNot documented
opencodexNo savings figureNot documented

Now the measured contrast, from this repo's own unit-tested benchmark: the same coding-agent session (50K in / 20K out / +30K thinking) costs $0.021 on DeepSeek V4-Flash and $1.75 on GPT-5.5 β€” ~83Γ— (Part 3.3). On capability per dollar, DeepSeek V4 Pro ties Gemini 3.1 Pro on SWE-bench Verified (80.6%) at ~11Γ— less, and the 95% ceiling costs ~46Γ— the cheapest model that still clears 80%. In other words: model choice through a plain Tier-1 BYO-key router captures the bulk of the savings these tools advertise β€” with zero ToS exposure. And if you route Claude Code cross-format to an OpenAI-style upstream, use a gateway that measurably survives the translation: LiteLLM and Bifrost both pass 3/3 (tools + streaming + usage) in our independent fidelity test; pin your version.

What we'd do

Full cost tables, the SWE-bench-vs-cost chart and the gateway scorecard are in the evaluation set β†’. Browse every gateway by need in Awesome AI Gateway β†’.


Found this useful? ⭐ Star the list β€” it's how the next engineer choosing a gateway finds it. CC0, no signup, no tracking, no vendor money.