← Files Empire LLM for CodexARCHIVED FILE
docs/benchmarks/API_ENDPOINT_BENCHMARK_RESULTS.md
4.5 KB · Oct 2, 2026 · 00:29 UTC
# API endpoint benchmark results Verified endpoint snapshot: `2026-07-26`. Manifest SHA-256: `3c4e15a2dd5bed083fe658b681281ec96e5b991c8edfb4507daa5d13a136888b`. ## Summary | Metric | Result | |---|---:| | Providers | 6 | | Cataloged URL records | 27 | | Callable endpoint records | 21 | | Offline fuzz cases | 311 | | Offline fuzz passed | 311 | | Offline fuzz failed | 0 | | Live catalog probes executed | no | | Billable inference executed | no | ## Recorded API-call speed evidence These observations are retained because API-call speed is an important routing metric. They are different workloads and are not a direct-provider ranking. | Observation | Route/model | Samples | Latency | Cost | Comparable provider benchmark? | |---|---|---:|---:|---:|:---:| | Bounded live review | openrouter / `nvidia/nemotron-3-super-120b-a12b:free` | 1 | 1,703.0 ms | $0.000000 | no | | Free-route scout demo | openrouter / `google/gemma-4-26b-a4b-it:free` | 1 | 30,611.0 ms | $0.000000 | no | | Blinded Empire evaluation mean | codex_plus_empire / `mixed_bounded_tasks` | 5 | 43,029.4 ms | $0.010295 | no | A publishable provider comparison must use the same synthetic prompt hash, model class, requested output limit, region, streaming mode, warm-up policy, timeout, and measured sample count. Report DNS, connect, TLS, time to first byte, time to first token, output tokens per second, end-to-end latency, p50, p90, p95, median absolute deviation, completion rate, retry rate, rate-limit rate, and cost per successful request. ## Security validation snapshot | Control | Result | |---|---:| | Offline regression tests | 184 / 184 passed | | Endpoint URL and model-family fuzzing | 311 / 311 passed | | Security audit checks | 7 / 7 passed | | Bandit high-severity findings | 0 | | Bandit medium-severity findings | 0 | | Bandit reviewed low-severity alerts | 17 | | Credentials detected | 0 | The low-severity Bandit alerts were reviewed as subprocess argument-array/path warnings and one naming false positive. 39 detect-secrets entropy alerts were verified as SHA-256 asset digests. Passing results support the documented controls but do not prove that the software has zero vulnerabilities. ## Provider endpoint inventory | Provider | Role | Method | Class | Callable | Verified | |---|---|:---:|---|:---:|---:| | anthropic | `count_tokens` | POST | inference | yes | 2026-07-26 | | anthropic | `message_batch` | POST | inference | yes | 2026-07-26 | | anthropic | `messages` | POST | inference | yes | 2026-07-26 | | anthropic | `models` | GET | catalog | yes | 2026-07-26 | | deepseek | `anthropic_compatible_base_url` | POST | inference | no | 2026-07-26 | | deepseek | `base_url` | POST | inference | no | 2026-07-26 | | deepseek | `beta_base_url` | POST | inference | no | 2026-07-26 | | deepseek | `chat_completions` | POST | inference | yes | 2026-07-26 | | deepseek | `models` | GET | catalog | yes | 2026-07-26 | | google_gemini | `base_url` | POST | inference | no | 2026-07-26 | | google_gemini | `count_tokens` | POST | inference | yes | 2026-07-26 | | google_gemini | `generate_content` | POST | inference | yes | 2026-07-26 | | google_gemini | `interactions` | POST | inference | yes | 2026-07-26 | | google_gemini | `models` | GET | catalog | yes | 2026-07-26 | | google_gemini | `stream_generate_content` | POST | inference | yes | 2026-07-26 | | higgsfield | `base_url` | POST | inference | no | 2026-07-26 | | higgsfield | `generation` | POST | inference | yes | 2026-07-26 | | higgsfield | `request_cancel` | POST | job_control | yes | 2026-07-26 | | higgsfield | `request_status` | GET | job_control | yes | 2026-07-26 | | openrouter | `chat_completions` | POST | inference | yes | 2026-07-26 | | openrouter | `models` | GET | catalog | yes | 2026-07-26 | | xai | `base_url` | POST | inference | no | 2026-07-26 | | xai | `chat_completions` | POST | inference | yes | 2026-07-26 | | xai | `language_models` | GET | catalog | yes | 2026-07-26 | | xai | `model` | GET | catalog | yes | 2026-07-26 | | xai | `models` | GET | catalog | yes | 2026-07-26 | | xai | `responses` | POST | inference | yes | 2026-07-26 | ## Interpretation The offline result validates manifest structure, URL rejection behavior, and direct-provider model-ID boundaries. The recorded route observations above provide latency evidence, but a controlled provider-by-provider inference speed suite has not yet run. Live catalog latency remains opt-in, and billable inference latency requires a separate explicit cost ceiling. > Point-in-time endpoint and latency evidence; no provider-wide performance guarantee.
SHA-256: a2dd3c29c066df4cc8d0a9c9f67e55b54130969e6ccd7db5fe53db1069d53641