pi-provider-qoder
Pi extension for Qoder AI — with OAuth authentication, COSY signatures and WAF bypass
Package details
Install pi-provider-qoder from npm and Pi will load the resources declared by the package manifest.
$ pi install npm:pi-provider-qoder- Package
pi-provider-qoder- Version
0.2.9- Published
- Jul 22, 2026
- Downloads
- 486/mo · 179/wk
- Author
- simonsmh
- License
- MIT
- Types
- extension
- Size
- 67.7 KB
- Dependencies
- 0 dependencies · 0 peers
Pi manifest JSON
{
"extensions": [
"./dist/index.js"
]
}Security note
Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.
README
pi-provider-qoder
A pi provider extension that connects pi to the Qoder API, exposing Qoder Global and Qoder China models through provider surfaces.
Features
- Two provider entries:
qoder— Global / international Qoder.qoder-cn— Qoder China, forced to CN endpoints and independent ofQODER_REGION.
- Interactive Login: Global Qoder supports browser device-code flow or Personal Access Token (PAT) login.
- Qoder CN PAT Login: China edition uses a separate PAT login entry (
/login qoder-cn) and CN token exchange endpoints. - WAF Bypass: Built-in WAF obfuscation and body encoding (
Encode=1). - COSY Signing: Full COSY signature header generation (RSA/AES-CBC/MD5).
- Dynamic Model Catalog: Dynamically fetches model limits, effort configurations, and options from the
/algo/api/v2/model/listendpoint. - Reasoning/Thinking Support: Real-time extraction of thinking process from API reasoning or HTML-like
<think>tags.
Quick start
Install the provider:
pi install npm:pi-provider-qoder
Or install it globally with npm:
npm install -g pi-provider-qoder
Then log in from pi.
Global / international edition:
/login qoder
China edition:
/login qoder-cn
Personal Access Token (PAT)
A Qoder PAT (pt-...) cannot authenticate API calls directly — the provider
exchanges it for a short-lived job token (mirroring the official qodercli /
qoderclicn flow) and resolves your account identity automatically.
Global Qoder:
- Run
/login qoderand choose Use API Key (PAT), then paste the token. - Or set
QODER_PERSONAL_ACCESS_TOKEN(orQODER_PAT) before starting pi. QODER_API_KEYis also accepted; when set, pi automatically exchanges it and logs the provider in during startup.
Qoder China:
- Run
/login qoder-cn, then paste the CN PAT. - Or set
QODERCN_PERSONAL_ACCESS_TOKEN(orQODERCN_PAT) before starting pi. QODERCN_API_KEYis also accepted and triggers the same automatic startup login.
The exchanged job token is short-lived; the provider transparently re-exchanges the stored PAT when it expires.
Region environment variables
The provider also understands these optional variables:
export QODER_REGION=cn # or QODER_BACKEND=cn / QODER_MODE=cn
Setting a CN PAT without a global PAT also auto-selects CN mode for the qoder
entry, but the recommended explicit China entry is still /login qoder-cn and
--provider qoder-cn.
Endpoints
Global:
- PAT exchange:
https://openapi.qoder.sh/api/v1/jobToken/exchange - User info:
https://openapi.qoder.sh/api/v1/userinfo - Usage:
https://openapi.qoder.sh/api/v2/quota/usage - Model / chat gateway:
https://api3.qoder.sh/algo/api/v2/...
China:
- PAT exchange:
https://openapi.qoder.com.cn/api/v1/jobToken/exchange - User info:
https://openapi.qoder.com.cn/api/v1/userinfo - Usage:
https://openapi.qoder.com.cn/api/v2/quota/usage - Model / chat gateway:
https://gateway.qoder.com.cn/algo/api/v2/...
Models
Global qoder
Exposes the backing model keys returned by Qoder, including:
- Tier Models:
auto,ultimate,performance,efficient,lite - Frontier Models:
qmodel(Qwen3.7 Plus)qmodel_latest(Qwen3.7 Max)dmodel(DeepSeek V4 Pro)dfmodel(DeepSeek V4 Flash)gm51model(GLM)kmodel(Kimi)mmodel(MiniMax)
China qoder-cn
The China provider exposes friendly model IDs and maps them back to Qoder CN's internal keys at request time:
| Friendly ID | Qoder CN key | Context | Images | Reasoning |
|---|---|---|---|---|
auto |
auto |
180K | ✅ | ✅ |
qwen3.7-max |
qmodel_latest |
1M | ✅ | ✅ |
qwen3.7-plus |
qmodel |
1M | ❌ | ✅ |
qwen3.6-flash |
q36fmodel |
1M | ❌ | ✅ |
deepseek-v4-pro |
dmodel |
1M | ❌ | ✅ |
deepseek-v4-flash |
dfmodel |
1M | ❌ | ❌ |
glm-5.2 |
gm51model |
200K | ✅ | ✅ |
kimi-k2.6 |
kmodel |
256K | ✅ | ✅ |
minimax-m2.7 |
mmodel |
200K | ❌ | ❌ |
Compatibility aliases are also accepted for request mapping, such as
qwen3.6-plus → qmodel, glm-5.1 → gm51model, and minimax-m3 → mmodel.
Usage
Once logged in, select any Qoder model in pi:
/model qwen3.7-plus
Or start directly:
pi --provider qoder-cn --model qwen3.7-plus
Global example:
pi --provider qoder --model auto
Architecture
src/
├── index.ts # Extension registration
├── cosy.ts # COSY signature, machine ID, region/endpoints, CN model aliases
├── login.ts # OAuth device flow + PAT login sequence
├── pat.ts # PAT → job-token exchange + identity resolution
├── models.ts # Model definitions and dynamic config cache
├── oauth.ts # PAT / OAuth callback orchestrator
├── stream.ts # Main streaming response handler
├── transform.ts # Message conversions (OpenAI schema mapping)
├── thinking-parser.ts # Fallback <think> tag parser
└── qoder-encoding.ts # WAF bypass body encoder
License
MIT