OpenAI compatible API · Attested · Public status

Private SillyTavern API Backend: Verifiable Privacy, Crypto Pay

Use TrustedRouter as your SillyTavern API backend: OpenAI-compatible, no prompt or output logs, hardware-attested, with crypto pay-per-request.

Verify gateway
Onebase URL to migrate
100sof models and routes
0prompt or output logs. Always.
Private API for SillyTavern

Point SillyTavern at an API that never logs prompts or outputs and proves what it runs.

SillyTavern speaks OpenAI-compatible chat completions, and so does TrustedRouter. Set the endpoint, paste a key, pick a model. No extension, no proxy script. You get 220+ model routes across 30+ providers: Claude, GPT, Gemini, DeepSeek V4, Kimi K2.7, GLM-5, Qwen 3.5, MiniMax M3, and more, with automatic rollover to another provider when one goes down.

The difference is what happens to your chats afterward. TrustedRouter never logs or stores prompt or output content. The prompt path runs inside a hardware-attested confidential-compute gateway. The gateway source is open, the image digest is published, and the attestation is checkable live from your own terminal. It binds to your TLS session, so it cannot be replayed.

Open the playground Check the attestation

connect + verifybash
# SillyTavern → API Connections
#   Chat Completion Source: Custom (OpenAI-compatible)
#   Endpoint: https://api-azure.trustedrouter.com/v1
#   Model: trustedrouter/auto

# Verify the gateway before you trust it
NONCE=$(openssl rand -hex 16)
curl "https://api-azure.trustedrouter.com/attestation?nonce=$NONCE"
# JWT signed by the CPU vendor's root key
No logs. Always.

Storage you can check

Provider logging toggles ask you to believe a settings page. An attested gateway lets you fetch a JWT signed by the CPU vendor's root key and compare the image digest against the published open-source build. Privacy you can check beats privacy you're promised.

Privacy tiers

ZDR and TEE, labeled per route

Every route carries a tier. Zero-Data-Retention means the provider contractually keeps nothing. TEE means end-to-end confidential compute, where even the provider cannot read the prompt. trustedrouter/cheap always resolves to the cheapest capable route inside a TEE.

Pay your way

Credits, BYOK, or a wallet

Prepaid credits via Stripe, bring your own provider key, or x402 pay-per-request with Continue with MetaMask sign-in that works without a traditional account. That suits users who prefer not to attach an identity to their chats; the anonymous LLM API page covers the details. Per-model rates are on the pricing page: thin markup over provider list prices.

OpenRouterTrustedRouter
SillyTavern setupMature, dedicated setup tutorial; widely used in the communityStandard Custom OpenAI-compatible source; change the base URL and go
Prompt loggingPer-provider logging and ZDR flags you configure and trustNo prompt or output logs or storage, ever, inside an attested TEE gateway
Privacy tiersFive privacy toggles to configure, discussed in community setup guidesEvery route labeled with its tier: Open, Zero-Data-Retention, or TEE
VerificationPrivacy policy and provider disclosuresOpen-source gateway, published image digest, live attestation bound to your TLS session
Verify, don't trust

The same weights behave differently depending on who hosts them.

In our testing, identical GLM weights answered 60 of 60 sensitive questions through TrustedRouter's enclave and 30 of 60 through the vendor-hosted API. That filtering is host-applied, not in the weights. DeepSeek, Kimi, Qwen, GLM, and MiniMax routes here are served by non-Chinese hosting providers on attested infrastructure, so your roleplay prompts never reach the model vendor.

Two plain limits. Every model keeps its own refusal behavior on every route, and acceptable-use terms apply to all traffic. What changes is storage and visibility: a no-log LLM API you can audit, with no prompt or output content ever logged or stored. Moving from OpenRouter takes one base-URL change; keep your SDK, your model ids, and your code.

Live catalog evidence

Current routes, prices, privacy, and measured performance.

Catalog facts come from the routes currently configured in TrustedRouter. Performance uses the same cached metadata snapshot as the public leaderboard. Prompts and outputs are not part of these measurements.

392public models
49providers
1270configured routes
250ZDR routes
8provider E2EE routes
887recent availability samples
Model Providers Context Input Output Privacy Measured route
Anthropic: Claude Opus 4.8anthropic/claude-opus-4.8
3 routes
1,000,000 $5.25/1M $26.25/1M varies 5 cited scores 1598 ms TTFT anthropic · 100.00% available · n=5
OpenAI: GPT-5.5openai/gpt-5.5
4 routes
1,050,000 $5.25/1M $31.5/1M ZDR 3 cited scores Warming up
Google: Gemini 3.5 Flashgoogle/gemini-3.5-flash
+1
7 routes
1,048,576 $1.575/1M $9.45/1M ZDR measured google-ai-studio · 0.00% available · n=14
MoonshotAI: Kimi K2.7 Codemoonshotai/kimi-k2.7-code
+8
19 routes
262,144 $0.735/1M to $0.9975/1M $3.675/1M to $4.2/1M ZDR 5 cited scores measured inceptron · 0.00% available · n=14
Z.ai: GLM 5.2z-ai/glm-5.2
+22
45 routes
1,048,576 $0.714/1M to $1.575/1M $1.575/1M to $5.5125/1M E2EE 4 cited scores measured engy · 0.00% available · n=73
MiniMax: MiniMax M3minimax/minimax-m3
+8
21 routes
1,048,576 $0.2835/1M to $0.63/1M $1.155/1M to $2.52/1M ZDR 4 cited scores 2056 ms TTFT wafer · 100.00% available · n=21
AnthropicPolicy varies 12 models 1807 ms p50 · n=24
GMI CloudPolicy varies 53 models 2549 ms p50 · n=12
OpenAIZDR on prepaid 33 models 1337 ms p50 · n=26
Atlas CloudPolicy varies 73 models measured · n=22
Google AI StudioPolicy varies 11 models measured · n=24
Google Vertex AIZDR on prepaid 9 models measured · n=24
Lightning AIPolicy varies 17 models 1471 ms p50 · n=20
KimiPolicy varies 11 models 1386 ms p50 · n=19

Browse every modelReview provider policiesOpen the full leaderboardSnapshot 2026-08-05T02:34:40Z

Questions

How do I connect SillyTavern to TrustedRouter?

Use SillyTavern's Chat Completion API with a Custom OpenAI-compatible source: set the endpoint to https://api.trustedrouter.com/v1, add your key, and pick any of 220+ model routes, or trustedrouter/auto to let the router choose per request. If a provider goes down, requests roll over to another automatically. Coming from OpenRouter, the only required change is the base URL; your model ids and code carry over.

Does TrustedRouter log my roleplay chats?

TrustedRouter never logs or stores prompt or output content. The prompt path runs inside a hardware-attested confidential-compute gateway whose source is open and whose image digest is published. You can request a live attestation, a JWT signed by the CPU vendor's root key and bound to your TLS session, and verify it yourself instead of relying on a policy page. Details are on the security page.

Can I pay without creating a traditional account?

Yes. Besides prepaid Stripe credits and bringing your own provider key, TrustedRouter supports x402 pay-per-request and Continue with MetaMask wallet sign-in, which works without a traditional account. That suits users who prefer not to attach an identity to their chats, though it is a payment option, not an anonymity guarantee. Per-model pricing is listed on the pricing page.

Will models refuse less through TrustedRouter?

Model behavior belongs to the model: upstream refusal behavior applies on every route, and acceptable-use terms apply to all traffic. One published finding of ours: the same GLM weights answered 60 of 60 sensitive questions through TrustedRouter's enclave versus 30 of 60 via the vendor-hosted API, because that filtering is host-applied rather than in the weights. TrustedRouter changes who can read and store your prompts, not what a model chooses to say.

Workspace access

Sign in

Choose a sign in method to access your TrustedRouter workspace.

By signing in you agree to the terms of service and privacy policy.