---
title: "Warnings: not-Jev services, key safety, look-alikes and install names"
type: community
source_tier: community
tags: [community, warnings, key-safety, look-alikes, access]
created: 2026-09-25
updated: 2026-09-25
confidence: medium
sources:
  - raw/x-repos/chigwell__typesafe.pro.md
  - raw/x-repos/chigwell__typesafe.pro__docs-admission.md
  - raw/community/classifier-dev-about.md
  - raw/community/classifier-dev-pricing.md
  - raw/community/classifier-dev-terms.md
  - raw/community/classifier-dev-privacy.md
  - raw/community/classifier-dev-benchmark.md
  - raw/x-repos/fstandhartinger__jevbench__results-v1-4-2.md
  - raw/x-repos/francesco0242__matchcn.md
  - raw/x-repos/andrelandgraf__safer-with-jev.md
  - raw/x-repos/andrelandgraf__safer-with-jev__design.md
  - raw/x-repos/ktaletsk__jevframe.md
  - raw/community/huggingface-co-datasets-sargedev-jev-distill-corpus-v3.md
  - raw/x-repos/HITsz-TMG__JevEmbed.md
  - raw/x-repos/bladedevoff__stuntd.md
  - raw/x-repos/NandhaKishorM__laya.md
  - raw/x-repos/razorback16__openjev.md
  - raw/x-repos/githubnext__localjev.md
  - raw/x-repos/logan-markewich__jeff.md
  - raw/x-repos/0xBakeer__arbiter.md
  - raw/x-repos/chengyongru__fastjev.md
  - raw/x-repos/choxos__jev-reviewer.md
  - raw/x-repos/kylemclaren__jevql.md
  - raw/x-repos/higress-group__HiRoute__decision-extensions-extensions-jev-decider-readme.md
  - raw/x-repos/vinilana__jev-gateway.md
  - raw/x-repos/ikermoel__open-alternative-jev.md
  - raw/x-repos/kshetrajna12__reflex.md
  - raw/x-repos/yoheinakajima__glance.md
  - raw/x-repos/emnlmn__snap.md
  - raw/x-repos/Brainwires__jevwire.md
  - raw/site/typesafe-ai-legal_mca.txt
  - docs/sweep/2026-09-25-mrjev/parta.md
  - docs/sweep/2026-09-25-mrjev/partc.md
jev_version: "jev-1.13.0"
summary: "The wiki's one Warnings block: keyless 'Jev APIs' on someone else's key, Jev answers as training data, key safety, look-alikes, install names; observed, inferred, policy."
---

# Warnings: not-Jev services, key safety, look-alikes and install names

> **TL;DR** Read before offering any community service, package or replica as a way to Jev. Four lists, each split into observed, inferred and policy: (a) keyless "Jev APIs" on someone else's key (not a route, wiki policy), (b) Jev answers as training data, (c) key safety, incl. servers answering to `jev-latest`, (d) install names. Vendor gateways whose own docs list Jev are routes ([[ideas/platforms-and-gateways]]). Moved whole from [[ideas/open-replicas]] on 2026-09-25 so an access question skips the replica tables.

The wiki's one Warnings block (owner decision 2026-09-25); [[ideas/open-replicas]], [[ideas/platforms-and-gateways]], [[ideas/tools-and-integrations]], [[ideas/tools-guardrails]], [[ideas/sdks-and-replicas]] and the builds and repos pages point here. Plain names on purpose: no links (rows elsewhere may link a project for its other uses). Every claim is tagged: *(author)* = the project's own README, docs or card, captured in raw/; *(our check YYYY-MM-DD)* = our source or registry vetting, not captured; `unverified` = neither. Terms ("route", "not a route (wiki policy)", "key safety", "look-alike", "name collision"): [[syntheses/glossary]]. Receipt for every item: [[ideas/warning-receipts]].

## (i) What we observed

**(a) Keyless or public Jev on someone else's key**

- **typesafe.pro is not TypeSafe** (TypeSafe's API is `api.typesafe.ai`): its site calls itself an independent gateway (our check 2026-09-25). No token means anonymous access at 30 requests/minute per IP; free and paid tokens get 120 and 1,000 requests/minute (author). It forwards to TypeSafe's API over several operator master keys (`TYPESAFE_MASTER_API_TOKEN_N`, 1,200 requests/minute and 250,000 tokens/second each) and its README keeps activity and error events, including real client IPs, for seven days, while its admission doc keeps error events three days plus cleanup lag, with client/IP identity hashed (author; the two files differ). The docs do not say whether those keys sit under one account or Order.
- **classifier.dev**: classification with no key or account (3,000 fast requests/minute and 20,000/day per IP), plus paid workspaces and Pro (author). It says its fast tier is Jev, packed a thousand items to a request, and its smart tier re-asks a reasoning model on answers under 0.7 confidence; texts go to TypeSafe directly or through Vercel AI Gateway, smart-tier items to OpenRouter; public requests are not stored with their text (author). Its /about page names the operator as Michael Ryaboy, an independent developer; it issues its own partner keys under separate written terms (author); whether it holds a TypeSafe agreement is unknown. JevBench v1.4.2 lists it unranked because it runs on Jev (author of JevBench). matchcn depends on it ([[ideas/builds-apps]]).
- **safer-with-jev** (a personal developer-relations demo, per its design doc): its API has no caller auth and runs Jev on the owner's server key; `/ask-jev` answers any yes/no over any text; limits 10 requests/minute per IP and 1,000 Jev attempts/day deployment-wide (author). It forwards a body only after a pass, to the caller's own URL with the caller's own credentials, so callers' upstream API keys pass through its server; it refuses a hosted default model because that "would be an open paid proxy" (author). Whether the owner's TypeSafe terms cover public use is unknown.
- **jevframe's "sponsored gateway"**: the example notebook, not the library, uses it when no key is set; edited questions and larger samples share 2,000 new row requests per UTC day across visitors, and it caches and shares inputs and answers, so public data only (author). A Railway host with a shared demo key (our check 2026-09-25); who operates it and whether it answers requests from outside the notebook: `unverified`. Your own key never goes there (author).

**(b) Jev answers published or used as training data**

- **SargeDev jev-distill-corpus-v3**: its card says its largest stream, 498,010 of 740,957 rows, has labels distilled from Jev 1.13 via OpenRouter (author).
- **JevEmbed-Data** (HIT-TMG): includes 37,663 train + 877 test rows from that corpus, the Jev-labelled stream as inferred from domain names (our check 2026-09-25); JevEmbed's own training runs use Open-Jev data only (author), so the item is the published dataset.
- **laya-jev-GraphRAG**: its ablation mode writes paired Laya/Jev answers to JSONL, which its README pitches as training data for Laya (our check 2026-09-25).
- **stuntd**, only in its mode in front of the paid Jev API: it relays, learns a local head from the provider's answers, and takes the decision over once the head agrees often enough (author). Its local mode (base Laya, no key) is not this item; row under "Laya and its servers" on [[ideas/open-replicas]].

**(c) Key safety**

- **SiliconLabAI/OpenJev** can expose the API keys it holds (TypeSafe, decider or OpenAI) to web pages you visit while it runs (our check 2026-09-25; not listed).
- **razorback16/openjev**'s README puts a Codiv key in `TYPESAFE_API_KEY` beside `TYPESAFE_BASE_URL=https://api.codiv.ai` (author).
- **Replicas that answer to Jev's model names**: localjev, razorback16/openjev, jeff and arbiter accept `jev-latest`, localjev and openjev also `jev-preview` (author); an SDK whose base URL points at one gets local answers with no error, and only the response `model` tells (look-alikes). fastjev rejects `jev-latest` (our check 2026-09-25).
- **jev-reviewer's hosted copies** send study text and questions through the author's `server.js`, which adds a shared TypeSafe key under a per-address rate cap and a daily input-token budget; a visitor who pastes a key uses their own quota (author). Not in (a): the questions are the user's own screening and extraction questions, and whether the relay answers anything else is `unverified`.
- **Tools that send or expose your own key**: askjev's hosted mode, jev-explained's hosted site, jevql `serve --insecure`, jev-gateway's `/router/decide`, HiRoute's jev-decider. Facts and tags: Key safety on [[ideas/tools-and-integrations]].

**(d) Install names that don't exist or belong to someone else** (name collisions; our registry check 2026-09-25): PyPI `open-alternative-jev` and `deepopen` do not exist; PyPI `llm2jev` is tic-top's, not Yinsongxu's; PyPI `openjev` is balys's; npm `fastjev` is an unrelated package (use PyPI `fastjev`); PyPI `reflex`, `glance`, `snap` are unrelated; npm `jevwire` is 404; npm `pi-jev-guard` and `pi-jev-router` belong to other publishers ([[ideas/tools-and-integrations]]).

## (ii) What we infer (inference, not observation)

- **(a)** A keyless or shared-key front door can stop, change what answers, or lose its access without notice; your state passes through its operator, whose terms and retention apply rather than TypeSafe's DPA; and you cannot confirm that the answers come from Jev (inferred). For pooled keys: the MCA ties Usage Limits to the Order ([[reference/legal-and-data]]) and the docs do not say whether rate limits are per key or per account, so pooling keys under one Order should raise no limit, and a pool could exceed what one Order allows only if its keys sit under several Orders, which nothing we hold shows either way (inferred).
- **(b)** A model trained on those rows learns to imitate Jev's answers; anyone who trains on a published Jev-labelled set inherits the question, and labels bought through a gateway come under that gateway's terms and whatever TypeSafe's agreement with it passes down (inferred).
- **(c)** A builder who points `TYPESAFE_BASE_URL` at Codiv while `TYPESAFE_API_KEY` still holds a TypeSafe key sends that key to Codiv; a key held by a third-party server can be spent through it; a replica answering `jev-latest` swaps calibration silently, so Jev-tuned thresholds break (all inferred).
- **(d)** An unclaimed or foreign install name can be taken or changed by someone else, and installing it runs their code (inferred).

## (iii) The wiki's exclusion policy

"Not a route" is this wiki's conservative policy, not an observed fact and not a finding against anyone. We do not offer an (a) service as a way to reach Jev, even while direct signup is closed ([[entities/typesafe-console]]); we do not recommend the (b) datasets or modes, or the (c) setups as described; we point installs at the right names in (d). A relay belongs in (a) when it answers any state and questions on its operator's key; an app that asks only its own fixed questions does not. A vendor gateway is a route when its own captured docs describe the endpoint, price and data policy (the vendor rows on [[ideas/platforms-and-gateways]], OpenCode Zen included), unlike anonymous key pools. The reason is TypeSafe's Master Customer Agreement, which binds TypeSafe's customers, not their users: §2.3(a) bars offering or making the Services available as a standalone service; §2.3(b) bars using the Services or any Output for model distillation, to train a model to imitate their output, or to develop (or facilitate the development of) a similar or competing product; §2.3(j) bars exceeding Usage Limits, which are set per Order; §2.4 requires Access Credentials to be kept confidential and not shared. Whether pooled or shared keys engage §2.3(j) or §2.4 is inferred (see (ii)). Any operator may hold terms with TypeSafe that we cannot see, so any item can go stale. Flagged, not adjudicated; our reading, not legal advice ([[reference/legal-and-data]]).

## Related

- [[ideas/warning-receipts]] — the check behind each item: date, upstream, observed, inferred, unresolved
- [[entities/typesafe-console]] — direct access to TypeSafe
- [[ideas/open-replicas]], [[ideas/open-replicas-servers]] — the replicas and servers themselves (not Jev), their numbers and which is which
- [[reference/legal-and-data]] — the MCA restrictions behind the policy paragraph; [[reference/environment-variables]] — `TYPESAFE_BASE_URL` and `TYPESAFE_API_KEY`

## Sources

Files in frontmatter `sources:`, captured 2026-09-23 to 25; "our check" items come from the 2026-09-25 vetting record (docs/sweep/2026-09-25-mrjev), not raw captures.
