Z.AI Model API
3 model routes currently listed at zero price.
https://api.z.ai/api/paas/v4Models mentioned
glm-4.7-flashglm-4.6v-flashglm-4.5-flashEquivalent paid value
How this was valued: The published allowance or a defensible paid comparison is not precise enough to calculate.
The zero-price routes (glm-4.7-flash, glm-4.6v-flash, glm-4.5-flash) have documented per-request ceilings (200K context / 128K max output for GLM-4.7-Flash) and an exact-model paid reference exists (Z.AI's own accelerated GLM-4.7-FlashX at $0.07 input / $0.40 output per 1M, and OpenRouter's z-ai/glm-4.7-flash at $0.06/$0.40), but no finite period envelope survives either the documented or the modeled tier. Neither docs.z.ai nor the operator's Chinese platform documentation publishes any numeric request-rate, token-rate, or concurrency ceiling for these routes. Both state that per-model rates are visible only in the signed-in rate-limit console, so per-request ceilings alone leave requests per period unbounded. Modeling the missing request-rate quantity would have no first-party published example to cite (third-party reports of a 1-request concurrency cap are leads, not evidence, and a concurrency cap without a first-party generation-speed figure still yields no token envelope), which the modeled tier does not permit.
Limits and terms
- Published Numeric Limits
- No
- Source Of Truth
- Signed-in rate-limit dashboard.
What happens to your prompts?
The API DPA describes real-time processing without storage and requires explicit agreement before content-based development or improvement.
- Plan Scope
- Z.AI developer API; the consumer-service terms differ materially.
- Prompt Retention
- The API DPA says prompt and generated content is processed in real time and not stored on Z.AI servers.
- Response Retention
- The API DPA gives generated API content the same no-storage treatment as input.
- Ordinary Logging
- Performance and usage metrics such as model version, inference, timing, diagnostics, and technical data may be collected and used to improve the service.
- Model Training
- API End User Content is not used to develop or improve services unless the API customer explicitly agrees.
- Product Improvement
- Technical usage metrics may be used for improvement; content use requires explicit agreement for API customers.
- Human Or Operator Access
- Content is processed to deliver the service and may be handled by approved subprocessors; no zero-operator-access promise is published.
- Subprocessors And Routing
- The DPA permits subcontractors and generally locates processing in Singapore; third-party model terms apply when selected.
- Deletion Controls
- Content is not stored under the API DPA; other customer data is deleted after termination unless law requires retention.
- Caveat
- Do not apply the consumer Z.AI policy, which permits broad content improvement use, to the developer API; the API Additional Terms and DPA control API content.
Governing documents
- Terms Of Service
- https://docs.z.ai/legal-agreement/terms-of-use
- Privacy Policy
- https://docs.z.ai/legal-agreement/privacy-policy
Eligibility
- Account Required
- Yes
- Payment Method Required
- not documented
Primary sources
Before you build with Z.AI Model API
Read the classification narrowly
This record has current first-party evidence for some zero-cost hosted inference. The label describes the bounded offer supported by evidence on 2026-09-19; it does not guarantee permanence, production suitability, uptime, latency, model quality, or access from every region.
Resolve the live model route
This snapshot records 3 model IDs. Match the exact ID against the provider's live catalog before using it in code; zero-price routes and aliases can rotate while an older documentation page remains online. The recorded base endpoint is https://api.z.ai/api/paas/v4, but the provider's current API reference remains authoritative for paths, authentication, and request shape.
Confirm account and billing boundaries
An account is required, so public catalog evidence cannot by itself prove the limits, balance, or billing behavior attached to your workspace. The reviewed evidence explicitly says no payment card is required. Re-check the signup flow because eligibility and billing controls can change after the snapshot. The equivalent paid value shown here prices a documented allowance where possible; it is not cash, guaranteed savings, or protection from overage.
Re-read the prompt policy for your plan
This record classifies the reviewed handling as “Private”: The API DPA describes real-time processing without storage and requires explicit agreement before content-based development or improvement. Provider policies can distinguish free, paid, enterprise, opted-in, and feature-specific traffic, so verify the governing terms for the exact account and route that will receive your data.
Follow the evidence, then re-check it
The record links 11 first-party sources covering the offer, catalog, limits, pricing, terms, privacy, or adoption evidence available to the audit. Prefer the newest governing document or live catalog when sources disagree, and submit a correction when a provider changes a material term.
Match the quota to the workload shape
Translate the published allowance into the traffic pattern you actually expect instead of comparing headline totals alone. A daily token pool can look generous while a low requests-per-minute or concurrency ceiling blocks interactive bursts; a high request limit can still fail a long-context job when input, output, or per-request tokens are capped. Separate prompt tokens from generated tokens, include retries and tool calls, and test the largest realistic payload. If the provider documents more than one limit window, the tightest window at your peak load is the practical ceiling. Research, experimental, and community access can also carry eligibility or fair-use constraints that cannot be modeled as a simple number.
Plan fallback without changing the rules
A fallback should preserve more than API syntax. Confirm that the substitute route supports the required modality, context length, streaming behavior, structured output, tools, and safety controls, then compare its prompt-retention and training terms. An OpenAI-compatible request shape does not make providers operationally or contractually equivalent. Decide which errors may trigger a retry, cap retry storms, and prevent an exhausted free route from silently switching to a billable model. If deterministic output matters, record the model revision and sampling settings; rotating aliases and free-model pools can change behavior even when the endpoint remains available.
Monitor the offer as a dependency
Capture the model ID, response model field, rate-limit headers, usage fields, latency, HTTP status, and any provider request identifier for each test. Watch for authorization failures, quota exhaustion, catalog removal, policy revisions, and dashboard balance changes as separate failure modes. Re-check the provider’s live catalog and governing pages on a schedule proportionate to the workload’s importance, and keep the dated sources that supported your decision. Free capacity is especially suitable for prototypes, evaluations, fallbacks, and bounded workloads when the application can tolerate change; a production dependency still needs observability, an exit path, and an owner responsible for re-verification.
Test one complete request before scaling
Start with the smallest permitted request using the exact credential, model ID, endpoint, and account type you intend to deploy. Record the HTTP status, response headers, usage fields, latency, and any dashboard balance change. Then exercise the failure path: an invalid model, an exhausted quota, or a rate-limit response should fail clearly without silently switching to a paid route. If the provider supports streaming or tool calls, validate those features separately because a free model can expose a narrower capability set than its paid counterpart. Keep a budget ceiling outside the application whenever billing is possible, and avoid sending sensitive data until the observed route matches the reviewed data agreement.