Frontier coding and cybersecurity
GLM 5.3 Abliterated
The most powerful open model for cyber tasks to date, with refusals removed.
- DeepSWE66.9* agentic coding*
- CyberGym84.5* cybersecurity*
- ExploitGym105/130* exploits solved*
PROMO$5 FREE CREDITS
Abliterated models served via OpenAI-compatible endpoints, zero prompt retention.
Credit card & cryptocurrency accepted
for cybersecurity teams and professionals
Cost-effective cyber intelligence
Very powerful model competing with frontier at much lower cost.
OpenCode and Pi both speak this API.
{
"$schema": "https://opencode.ai/config.json",
"model": "refuseless/glm-5.3-abliterated",
"provider": {
"refuseless": {
"npm": "@ai-sdk/openai-compatible",
"name": "Refuseless",
"options": {
"baseURL": "https://api.refuseless.com/v1",
"apiKey": "{env:REFUSELESS_API_KEY}"
},
"models": {
"glm-5.3-abliterated": {
"name": "GLM 5.3 Abliterated",
"tools": true,
"reasoning": true,
"limit": {
"context": 1048576,
"output": 16384
}
},
"glm-5.3-flash-abliterated": {
"name": "GLM 5.3 Flash Abliterated",
"tools": true,
"reasoning": true,
"limit": {
"context": 1048576,
"output": 16384
}
}
}
}
}
}
export REFUSELESS_API_KEY="rk-…" on Mac, $env:REFUSELESS_API_KEY="rk-…" on Windows. The sample above reads it via {env:REFUSELESS_API_KEY}.~/.config/opencode/opencode.json, Windows: C:\Users\<you>\.config\opencode\opencode.json. Create it if missing. If it already has a "provider" object, add "refuseless" inside it — don't overwrite the rest.opencode --model refuseless/glm-5.3-abliterated, or /models inside the TUI and pick refuseless / glm-5.3-abliterated. Model glm-5.3-abliterated (context 1,048,576) — all 2 lineup models ship in the block, swap the id after refuseless/ to switch — send Say ok. to verify.
Same request shape as OpenAI chat completions. Point the base URL at Refuseless, set a lineup id, send the key.
curl https://api.refuseless.com/v1/chat/completions \
-H "Authorization: Bearer $REFUSELESS_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"model": "glm-5.3-refuseless",
"messages": [{"role": "user", "content": "Write a tight system prompt."}]
}'
Host and path are the intended contract. Auth is the API key.