OpenRouter: Why We Vet Every Inference Provider — and the Hidden Risks of Cheap Tokens
Key Info
OpenRouter explains that its thorough security and compliance vetting of every inference provider slows onboarding but is meant to protect users' inference requests. It also warns developers to be cautious when chasing cheap tokens, citing risks like fake tool calls and resold traffic traces.
Highlights
- Security vetting is deliberate: every provider undergoes thorough security and compliance review, which slows onboarding but helps secure inference.
- Cheap tokens can be a red flag: if a provider's pricing is unexplainable, it's safer to avoid it.
- Hidden dangers include malicious providers sending fake tool calls to steal information and selling entire traces to third parties that may be resold again.
- A single leaked API key inside a trace can be enough to compromise your setup.