sable network
Buy on Index
Documentation · all sections

Models

Sable exposes a curated catalog under stable identifiers so model upgrades don't break your agents. List them at runtime with GET /v1/models. A model id outside the catalog is refused with 400: the gateway never forwards an unknown id to an upstream.

Each entry carries pricing (prompt_usd_per_mtok and completion_usd_per_mtok, in USD per 1M tokens) and an open_weight flag. These are the prices you are charged: the deployment's margin is already included, so the figure you compute from them is the figure in your signed receipt. See Cost & metering.

The tables below are generated from the gateway's own catalog at the default 20% margin. A deployment can set a different margin, so GET /v1/models on the gateway you actually call is the authoritative sheet — it applies that deployment's margin to the same figures.

The catalog is organized in three lanes plus the confidential tier. Where a model runs (and what its host can see) differs by lane; the privacy ladder is the full picture.

The flagship lane: sable, sable-fast, sable-max

Three ids, each kept pointed at a strong frontier engine.

Sable idEngine (current)ContextPrompt $/MtokCompletion $/MtokOpen weights
sableEngine (current)Anthropic Claude Opus 5Context1,000,000Prompt $/Mtok$6.00Completion $/Mtok$30.00Open weights❌
sable-fastEngine (current)Anthropic Claude Sonnet 5Context1,000,000Prompt $/Mtok$2.40Completion $/Mtok$12.00Open weights❌
sable-maxEngine (current)Anthropic Claude Fable 5Context1,000,000Prompt $/Mtok$12.00Completion $/Mtok$60.00Open weights❌

sable is the id to use when you want "the best model Sable serves" without tracking model churn yourself; sable-fast is the cheaper, lower-latency variant, and sable-max is the deepest engine on the catalog. All three carry the same contract: a stable name, a disclosed engine, and the freedom for Sable to repoint the id to a better engine over time without breaking callers: that indirection is the point of having them. The engine is disclosed, not hidden: this page names what each id resolves to, and the signed receipt on every response records the engine that actually served that request.

How the flagship routes

Each flagship id carries an ordered engine chain, not a single engine. If the primary engine's upstream fails (a 5xx or a network error) the request retries on the next engine in the chain. A 4xx never fails over: no engine fixes a malformed request, so a client error comes straight back.

Sable idEngine chain (current)
sableEngine chain (current)Claude Opus 5 → Claude Sonnet 5 → Gemini 2.5 Pro
sable-fastEngine chain (current)Claude Sonnet 5 → Claude Haiku 4.5 → Gemini 2.5 Flash
sable-maxEngine chain (current)Claude Fable 5 → Claude Opus 5 → Gemini 2.5 Pro

Routing is never a black box, because two things hold on every flagship response:

  • The receipt names the engine. Flagship receipts always carry an engine field: the upstream engine that actually served the request. If a failover happened, the receipt says so by naming the engine that ran, not the one you'd have expected.
  • Billing prices the engine that ran. A request served by a fallback engine is metered at that engine's rate, not the primary's.

The privacy dial. A flagship id called with sable_privacy_tier: "confidential" is not refused: it routes to the TEE-attested confidential models (currently sable-confidential-qwen3.6-35b) instead of the closed engine chain: one id, one privacy slider. The receipt keeps the requested id and carries the engine plus the full attestation block. On a deployment with no attested backend configured, the tier stays Phase-1 advisory and the request serves on the standard path.

Frontier slate: anonymized access

Closed vendor models, reached through Sable's own upstream account. The vendor sees Sable's identity, never yours: not your identity, not your API key, not your payment details. The vendor's infrastructure does see the prompt: this is anonymized access, not the confidential tier.

Sable idEngine / ownerContextPrompt $/MtokCompletion $/MtokOpen weights
sable-claude-opus-5Engine / ownerAnthropic Claude Opus 5Context1,000,000Prompt $/Mtok$6.00Completion $/Mtok$30.00Open weights❌
sable-claude-sonnet-5Engine / ownerAnthropic Claude Sonnet 5Context1,000,000Prompt $/Mtok$2.40Completion $/Mtok$12.00Open weights❌
sable-claude-fable-5.1Engine / ownerAnthropic Claude Fable 5.1Context1,000,000Prompt $/Mtok$12.00Completion $/Mtok$60.00Open weights❌
sable-claude-sonnet-4.5Engine / ownerAnthropicContext1,000,000Prompt $/Mtok$3.60Completion $/Mtok$18.00Open weights❌
sable-claude-haiku-4.5Engine / ownerAnthropicContext200,000Prompt $/Mtok$1.20Completion $/Mtok$6.00Open weights❌
sable-gpt-6-astraEngine / ownerOpenAIContext1,050,000Prompt $/Mtok$12.00Completion $/Mtok$60.00Open weights❌
sable-gemini-3.8-flashEngine / ownerGoogleContext1,048,576Prompt $/Mtok$0.90Completion $/Mtok$4.50Open weights❌
sable-gemini-2.5-proEngine / ownerGoogleContext1,048,576Prompt $/Mtok$1.50Completion $/Mtok$12.00Open weights❌
sable-gemini-2.5-flashEngine / ownerGoogleContext1,048,576Prompt $/Mtok$0.36Completion $/Mtok$3.00Open weights❌
sable-grok-4.6Engine / ownerxAIContext500,000Prompt $/Mtok$2.40Completion $/Mtok$7.20Open weights❌
sable-gpt-4o-miniEngine / ownerOpenAIContext128,000Prompt $/Mtok$0.18Completion $/Mtok$0.72Open weights❌

Anonymized is not confidential. Anonymized access hides who is asking from the vendor; confidential (TEE) hides what is asked from the host. On this lane the vendor cannot tie a request to you, but its servers still process the plaintext prompt. Only the sable-confidential-* models below carry the hardware guarantee that the host provably cannot read the request, and they are the only models allowed to carry the word "confidential". The privacy ladder spells out the difference rung by rung.

Open-weight workhorses

Public-weight models served on the standard path. The serving host sees the prompt (see the privacy contract), but because the weights are public, these are the models that can follow the confidential pair into an attested enclave over time.

Sable idEngine / ownerContextPrompt $/MtokCompletion $/MtokOpen weights
sable-kimi-k3Engine / ownerMoonshotContext1,048,576Prompt $/Mtok$3.177766Completion $/Mtok$15.939269Open weights✅
sable-qwen3.8-a95bEngine / ownerAlibabaContext1,048,576Prompt $/Mtok$2.40Completion $/Mtok$7.20Open weights✅
sable-glm-5.3Engine / ownerZ.aiContext1,310,720Prompt $/Mtok$1.68Completion $/Mtok$5.28Open weights✅
sable-deepseek-v4.1-flashEngine / ownerDeepSeekContext1,048,576Prompt $/Mtok$0.18Completion $/Mtok$0.72Open weights✅
sable-deepseek-r1Engine / ownerDeepSeekContext64,000Prompt $/Mtok$0.84Completion $/Mtok$3.00Open weights✅
sable-deepseek-v3Engine / ownerDeepSeekContext65,536Prompt $/Mtok$0.30888Completion $/Mtok$1.23444Open weights✅
sable-qwen3-coderEngine / ownerAlibabaContext262,144Prompt $/Mtok$0.36Completion $/Mtok$1.20Open weights✅
sable-mistral-largeEngine / ownerMistralContext128,000Prompt $/Mtok$2.40Completion $/Mtok$7.20Open weights✅
sable-llama-3.3-70bEngine / ownerMetaContext131,072Prompt $/Mtok$0.12Completion $/Mtok$0.384Open weights✅
sable-qwen-2.5-72bEngine / ownerAlibabaContext32,768Prompt $/Mtok$0.432Completion $/Mtok$0.48Open weights✅
sable-llama-3.1-8bEngine / ownerMetaContext131,072Prompt $/Mtok$0.06Completion $/Mtok$0.096Open weights✅

Confidential: TEE-attested

The two models served inside an attested Intel TDX enclave, with the attestation stamped into the signed receipt (verification: "tee-attested"; response_bound is the stricter per-response claim and reads false today — see the confidential tier). These are the only models the confidential tier accepts: requesting any other model on that tier fails closed with 400, never a silent downgrade.

Sable idEngine / ownerContextPrompt $/MtokCompletion $/MtokOpen weights
sable-confidential-qwen3.6-35bEngine / ownerQwen (attested TDX)Context131,072Prompt $/Mtok$0.36Completion $/Mtok$0.72Open weights✅
sable-confidential-gemma4-26bEngine / ownerGemma (attested TDX)Context65,536Prompt $/Mtok$0.18Completion $/Mtok$0.36Open weights✅

Private lane: double-blind routing

The private lane is rung 2 of the privacy ladder: these models are pinned to a second intermediary (Venice), so the request travels caller → Sable → Venice → vendor. The vendor is two hops from your identity; Venice sees only Sable's identity, never yours; Sable never persists content. No single party outside Sable holds who and what together, and Sable itself keeps only metadata.

Sable idEngine / ownerContextPrompt $/MtokCompletion $/MtokOpen weights
sable-privateEngine / ownerAnthropic Claude Opus 5Context1,000,000Prompt $/Mtok$7.20Completion $/Mtok$36.00Open weights❌
sable-private-fastEngine / ownerAnthropic Claude Sonnet 5Context1,000,000Prompt $/Mtok$3.60Completion $/Mtok$18.00Open weights❌
sable-venice-uncensoredEngine / ownerVenice Uncensored 1.2Context128,000Prompt $/Mtok$0.24Completion $/Mtok$1.08Open weights✅

Two properties are enforced, not promised:

  • The route is the product, so it never falls back. A pinned model hard-fails when its route is down rather than silently serving through a path with a different privacy posture.
  • No hidden vendor prompt. The intermediary's default system prompt is disabled at Sable's egress shim, so you are not billed for tokens you never sent and no unseen instructions shape the reply. (Pass your own venice_parameters object to override.)

Whether the lane is active on a deployment is visible in GET /v1/models: a model pinned to a route the deployment has not configured is omitted from the listing entirely: an advertised model that cannot serve would be a lie.

This lane hides who from every party past Sable and narrows what to parties two hops from your identity. It is not the confidential tier: the vendor's infrastructure still processes the plaintext to run the model.

Embeddings

Sable idEngine / ownerMax inputPrompt $/MtokCompletion $/MtokOpen weights
sable-embed-3-smallEngine / ownerOpenAIMax input8,192 tokensPrompt $/Mtok$0.024Completion $/Mtok—Open weights❌
sable-embed-3-largeEngine / ownerOpenAIMax input8,192 tokensPrompt $/Mtok$0.156Completion $/Mtok—Open weights❌
sable-embed-nomicEngine / ownerNomicMax input8,192 tokensPrompt $/Mtok$0.012Completion $/Mtok—Open weights✅

Embeddings bill on input tokens only.

Open-weight vs. vendor-hosted

/v1/models marks every model open_weight: true or false. It matters for the privacy roadmap:

  • open_weight: true means the weights are public (Llama, DeepSeek, Mistral, Qwen, Gemma, Nomic), so the model can run inside a Sable-verified enclave. Two do today: sable-confidential-qwen3.6-35b and sable-confidential-gemma4-26b. The rest are served on the standard path for now.
  • open_weight: false means the model only runs on its vendor's servers (the flagship lane's current engines, the frontier slate, and the text-embedding-3 models). The vendor's infrastructure sees the input, and it will never be confidential beyond encrypt-in-transit plus anonymized access. We'd rather tell you that than ship a closed model under a privacy banner, so these stay standard tier only. (The flagship ids are names, not weights: the privacy dial above moves them to attested open-weight engines, it never puts a closed engine in an enclave.)

Provider pinning

A catalog model can be pinned to a single named upstream provider, and a pinned model never fails over to another provider: if its provider is down, the request fails rather than being served somewhere else. The private lane is pinned this way: a double-blind route (see the privacy ladder) only means something if the request provably cannot leak to a different upstream. A deployment that lacks a pinned model's provider omits that model from GET /v1/models rather than advertising a route it cannot serve.

Retired ids stay resolvable

A published Sable id is a contract, so we don't delete one when its upstream goes away. sable-confidential-24b originally mapped to a model the backend has since retired; it is now a compatibility alias for sable-confidential-qwen3.6-35b. Existing callers keep working, and it is deliberately omitted from GET /v1/models so nobody builds against it fresh. Name a model from the tables above in new integrations.

Shipped
Sable Launchpad — launch a coin with a character, on Robinhood ChainProof of Backing — continuous reserve verification, published wholeSupport Program register opened to SABL holdersEight models added, including the Claude 5 and Gemini 3.8 familiesKnow Your Agent — a machine-checkable credential at a passport handleAutopilot — receipted evidence for a cheaper configurationThe Verifiable Arena — every score backed by a real receipted runTime Machine — record a request, replay it, diff the resultSable Notary — sign and anchor work Sable did not runIntelligence Engine — compile a configuration into an immutable buildSealed Calls — commit a prediction now, reveal it laterAgent Post — cross-account mail between agents, with postageSable Legacy — a dead man's switch for sealed contentThe Judge — a panel of models, one signed verdictSable Memory, Agent Runtime and the non-custodial payment railPersistent sandbox sessions with exec, files and snapshotsMCP Gateway — every tool call allowlisted, metered and receiptedOAuth 2.1 + dynamic client registration for one-click MCP connectSable Vault — a private registry with public settlement