How it was done
- Opened twenty accounts programmatically, one residential exit IP each, and instrumented the service from the API keys those accounts issued.
- Measured behaviour rather than documentation: request bodies, receipts, timing, cache headers and the endpoints the web console itself calls.
- Sent controlled inputs, including out-of-band canaries in URL-fetching fields, to see what the service touches on a customer's behalf.
- Where a request failed, we read the API's own validation errors to recover the real field names.
Measurements were taken in October 2026 against the production service. A live platform changes under you; the report is dated for that reason.
Nine findings worth paying for
Blind server-side request forgery
A URL field fetched our canary from two unrelated cloud networks, with a generic Go HTTP client and no sign of an allow-list. Internal endpoints are reachable in principle.
A timing oracle on the same field
Refused, answered and filtered inputs returned in about 2.5, 3.9 and 12.5 seconds. Three reproducible timings tell an observer which path a URL took.
Deterministic failure on image responses
One response shape produced the same 502 with an undecodable body every time, so the fault sits in the platform's handling rather than in model randomness.
Cache hits are free and shared across keys
A cached answer served to a different account's key, and the hit drew down no credit. Good for repeated prompts; worth knowing if you expect isolation between keys.
Failures cost nothing; SLA credit was unreachable
Failed jobs were never billed. Across 600+ observed jobs, every one was recorded as meeting its service promise, so the advertised service credit never triggered.
One supplier holds the market
A single seller held roughly 98% of offers (773 of 786) and 1,882 lifetime jobs, against 379, 267, 54, 49 and 1 for everyone else. Price competition is nominal today.
Referral reward is on fees, not spend
The referral pays 20% of the platform's fee, near 1% of what your referee spends. Materially different from how these programmes are usually read.
Frontier availability follows supply, not naming
On the first pass, dated model snapshots served while alias and 'latest' names failed identically across nineteen request shapes and three surfaces. Re-measured two weeks later the pattern inverted: undated names served and the dated snapshots returned 404. Automatic selection only runs at all once a price bound (`x-liquid-cap-usd`) is supplied.
The useful endpoints are undocumented
Quotes, receipts, balance and throughput routes were found in the shipped bundle, not the manual; provider applications could be filed by API but key creation stayed gated behind human admission.
What the client got
A written report with reproduction steps for every finding, a latency and cost baseline for the models they actually use, and three decisions they could make: which models to pin, where to keep a fallback supplier, and what to ask the platform in writing.