A stealth model called Ox Alpha appeared on OpenRouter this evening, August 20, 2026, at 20:04:55 UTC. The catalog record describes a reasoning model with a 1,048,576-token context window, text, image and video input, zero-priced prompts and completions, and a provider field that names nobody. OpenRouter’s own announcement called it “a frontier model built for efficient coding, sustained agentic work, and real-world production use.” That description is the vendor’s; neither Artificial Analysis, LMArena nor BenchSift listed the model on the day it appeared.
Stealth listings are not new. Ox Alpha is the fourteenth stealth slot OpenRouter has run since April 2025, and the pattern is familiar: a free, high-context endpoint collects real traffic for a week or two, and more often than not the operator steps forward afterwards. What makes this one worth a same-day read is the fine print. The Stealth Program’s default terms grant a perpetual, sublicensable licence over what you send, for the stated purpose of training the stealth model. Ox Alpha carries a note that it is not used for training, and OpenRouter’s own wording for that note was “this time.”
This post is the record as it stood on the evening of the listing: the API fields, the first seventy minutes reconstructed from timestamps, the capacity number that is circulating without an OpenRouter source behind it, the terms side by side, what can and cannot be said about who built it, and the routing decision a builder faces tonight. Anything learned after today belongs in a later piece, not this one.
- 01The record is the only hard evidence.stealth/ox-alpha listed at 20:04:55 UTC on August 20 with a 1,048,576-token context, 131,072-token max completion, $0 pricing, text, image and video input, mandatory reasoning, no published request cap, no moderation layer and no open weights.
- 02The no-training note is an exception, not the default.The Stealth Program terms grant a perpetual, sublicensable licence over User Content for training. Ox Alpha’s page says prompts are retained but not used for training. OpenRouter’s own post said “this time,” which marks a carve-out, not a policy change.
- 03Retention still happens and the promise is unverifiable.“Retained by the provider and not used for training” is a policy statement from an anonymous operator. Nothing outside OpenRouter and that provider can check it, and the terms state no retention window.
- 04The 100-trillion-token figure is a reseller’s marketing copy.It appears in a downstream coding-agent product’s post, not in any OpenRouter surface. OpenRouter publishes no cap at all. The arithmetic, roughly 1.16 billion tokens per second sustained, is why it should be treated as a claim rather than a spec.
- 05Prototype freely; route client data only after reading the terms.A free 1M-context endpoint with tool calling is a useful experiment. It is also anonymous, unbenchmarked, uncapped on paper and historically short-lived. Of the thirteen stealth slots before it, seven were confirmed by an official statement and two were never resolved at all, so a name is likely rather than promised.
01 — The RecordWhat the catalog entry actually says.
Everything verifiable about Ox Alpha lives in one JSON object returned by the OpenRouter models API and the matching model page. The id and canonical_slug are both stealth/ox-alpha; the display name is Ox Alpha. The created field reads 1787256295, which converts to 20:04:55 UTC today, Thursday, August 20, 2026. That is a listing timestamp, not a launch date, and the difference matters more than usual for a model nobody has launched. We covered the general discipline in our catalog-literacy guide; here it is the whole story.
The hard numbers: a context_length of 1,048,576 tokens, which is exactly 220, and a max_completion_tokens of 131,072, exactly 217, so the window is eight times the longest single reply. Both pricing.prompt and pricing.completion are the string "0". This is a genuinely free endpoint, not a discounted tier.
Tokens of context
Exactly 2 to the 20th. Enough for a mid-sized repository, a long transcript set, or a multi-document brief in a single call, if the model holds up across it, which nobody has measured yet.
Longest single reply
Exactly 2 to the 17th, one eighth of the window. Reasoning is mandatory and defaults to max effort, so a meaningful share of that budget can go to thinking before the answer.
Prompt and completion
Both fields read zero. No per-request limit is published either: per_request_limits is null, which means OpenRouter states no cap, not that the cap is unlimited.
The rest of the record is mostly about what is missing. hugging_face_id is null: there are no open weights and no repository to read. knowledge_cutoff is null: not published. architecture.tokenizer is the literal string "Other", which is OpenRouter’s way of declining to say which tokenizer family the model belongs to. top_provider.is_moderated is false, meaning no moderation layer sits between your request and the model. Parameter count, architecture family and licence are simply absent.
What is present is a full tool-calling surface. The supported parameters are tools, tool_choice, response_format, reasoning, reasoning_effort, include_reasoning, max_tokens, temperature, top_p and top_k, with defaults of temperature: 1 and top_p: 0.95. For an agent harness that is the complete set, which is consistent with OpenRouter’s description of the model as built for “sustained agentic work.”
expiration_date of 2098-12-31. That is OpenRouter’s platform-wide placeholder for no expiry set, and it is not a statement about how long the preview will run. Likewise, per_request_limits: null means no cap is published, not that usage is unlimited. Neither field tells you anything about when this endpoint goes away or how hard you can hit it.02 — TimelineThe first seventy minutes, by the timestamp.
The order in which things happened tonight is itself informative, because the loudest claim about the model went out before the platform hosting it had said a word. Every row below that carries a timestamp takes it from the record or post itself, not from a reporting time.
| Event | UTC, Aug 20 | Minutes after listing | Source of the timestamp |
|---|---|---|---|
| Listing goes live in the OpenRouter catalog | 20:04:55 | 0 | API record, created field |
| OpenCode posts its “100T tokens per day” capacity claim | 20:59:49 | +55 | @opencode on X |
| OpenRouter announces the model | 21:02:16 | +57 | @OpenRouter on X |
| OpenRouter’s “This time” data note, posted as a reply | same thread | reply | @OpenRouter on X, reply in thread |
| First public tokenizer comparison, labelled unconfirmed by its author | 21:12:41 | +68 | @aitrackerbot on X |
Three things fall out of the sequence. A reseller’s promotional post landed 55 minutes after the listing and two minutes before OpenRouter’s own announcement, which is why the capacity figure spread as if it were platform data. OpenRouter’s data note was a reply, not the headline. And community fingerprinting began within 68 minutes, before anyone could have run a benchmark of any size. For what shipped in the first week of August, our August release tracker is the dated ledger; this post stays on the one entry with no name on it.
03 — The Circulating NumberThe figure that is not a spec.
The claim you will see repeated is that the endpoint has capacity for 100 trillion tokens per day. It deserves one precise sentence: that figure is a downstream reseller’s marketing claim, not an OpenRouter figure. It appears in a post by OpenCode, a separate open-source coding-agent product that resells access to the free tier, at 20:59:49 UTC. It does not appear in the API record, on the model page, in OpenRouter’s announcement thread, or anywhere else OpenRouter publishes. The only thing OpenRouter says about limits is per_request_limits: null, which is no statement at all.
The arithmetic is the reason to keep it in the claim column. One hundred trillion tokens divided by the 86,400 seconds in a day is roughly 1.157 billion tokens per second, sustained, for a single free preview endpoint. That is not a number an anonymous provider has ever published for anything, and the post offering it is not from the provider. Whether the figure describes real provisioned compute, a burst ceiling, or enthusiasm is unknowable from outside, and “unknowable” is the correct status for a spec sheet.
04 — Data TermsThe default licence, and what “this time” carves out.
This is the spine of the post, and it is the detail most same-day coverage will flatten into “no training, so it is safe.” Two documents govern what happens to a prompt sent to a stealth model. The first is the Stealth Program terms, which apply to every stealth listing. They grant OpenRouter a “non-exclusive, irrevocable, perpetual, transferable, worldwide, fully paid-up, royalty-free license to (i) copy, store, use, host, and distribute your User Content,” and allow OpenRouter to sublicense that content to the stealth provider “for the sole purpose of enabling the Stealth Provider(s) to train, evaluate, and improve those Stealth Model(s).” Training is the stated purpose. That is the default.
The second is the Ox Alpha model page, which adds one sentence on top of the default. OpenRouter’s announcement thread then restated it in a two-line note, that the model is free and that “This time, the provider does not train on your prompts or completions.” “This time” is not a policy change. It is an exception OpenRouter is pointing at while the underlying terms stay exactly as they were.
"Prompts and completions for this model are retained by the provider and are not used for training; all other use is governed by the Stealth Model Terms."— OpenRouter, stealth/ox-alpha model page
Read that sentence in halves. The first half says two things, and the reassuring one tends to crowd out the other: the data is retained by the provider, and it is not used for training. The second half hands everything else back to the default terms, which state no retention window and whose only privacy backstop is a hashed user identifier plus a contractual promise from the provider not to try to reverse it. Side by side, the default and the carve-out look like this.
| Question | Stealth Program default (terms page) | Ox Alpha (model page + Aug 20 posts) |
|---|---|---|
| What happens to the content you send | ||
| Used for training? | Yes, in scope. The sublicence exists “for the sole purpose of enabling the Stealth Provider(s) to train, evaluate, and improve those Stealth Model(s).” | No, per OpenRouter: “not used for training.” A policy statement, framed as “this time.” |
| Retained? | Yes. The licence covers the right to “copy, store, use, host, and distribute” User Content. | Yes. “Retained by the provider,” in OpenRouter’s own words. |
| Licence scope | Non-exclusive, irrevocable, perpetual, transferable, worldwide, fully paid-up, royalty-free. | Unchanged. “All other use is governed by the Stealth Model Terms.” |
| How long, who, and can you check | ||
| Duration of the commitment | Perpetual licence. No retention window is stated for collected User Content. | No duration stated for the no-training note. No retention window either. |
| Who is bound | OpenRouter, and the Stealth Provider(s) it sublicenses to. | An anonymous third-party provider, via OpenRouter’s statement on its behalf. |
| Privacy backstop | A hashed identifier replaces the user; providers are contractually barred from re-identifying users from the identifier or the content. | Same backstop, inherited from the default terms. |
| Verifiable from outside? | Not applicable; the default makes no promise to verify. | No. Nothing outside OpenRouter and the provider can check whether the content is actually excluded from training. |
The practical reading is narrower than the headline. If your concern is “will my client’s codebase end up in someone’s training set,” Ox Alpha’s note addresses that concern, on the word of an operator who will not say who they are. If your concern is “will my client’s codebase sit on a server I cannot name, for a period nobody has stated, under a perpetual licence,” the note does not address it, and the terms say yes. Most client agreements care about the second question at least as much as the first. How the coding agents themselves handle the same question is in our coding-agent data-terms census; a stealth endpoint sits underneath all of them.
05 — Modality CheckThree inputs in, one out, and three reasoning rungs.
The architecture block lists input_modalities of text, image and video, and output_modalities of text only. Coverage tends to call video input “rare” and move on. We counted instead. Filtering the same models API for every listing whose input_modalities array includes video gives 69 models out of 422 in the catalog at the time of listing, roughly 16%. Ox Alpha is one of the 69. Rare is fair; one in six is the checked number.
Video input across the OpenRouter catalog · 69 of 422 listings
Source: count of OpenRouter catalog listings whose input_modalities include video, 422 models at the time of listingThe reasoning block is the other place the record is specific. reasoning.mandatory is true: there is no non-thinking mode on this model, so every call pays a reasoning cost in latency even though it pays nothing in dollars. The supported efforts are max, high and low; there is no medium rung, which will trip any harness that assumes a low/medium/high ladder. The default is max, the heaviest setting available.
reasoning_effort: max
The heaviest rung is the default. On a free endpoint the serving cost is the provider’s, but the latency and the share of the 131,072-token reply budget spent on thinking are yours. Set the effort explicitly.
reasoning_effort: high
There is no medium. A harness that maps its own “medium” to the model’s ladder will either error or silently land somewhere else; check what your router does with an unsupported value.
reasoning_effort: low
Low is the floor. reasoning.mandatory is true, so an effort of none or a disabled reasoning flag is not a valid request on this model. Budget for thinking tokens on every call.
One more field interacts with both of these. is_moderated: false means OpenRouter places no moderation layer in front of the model. For a coding harness that is usually welcome. For anything a member of the public can type into, it means the only filtering is whatever the anonymous provider built into the model, which is unknown, and whatever you put in front of it yourself.
06 — IdentityNobody has claimed it.
OpenRouter’s statement is the whole of the official position: “Ox Alpha is a stealth model. It is developed and operated by a third-party provider who has chosen to remain anonymous during this preview.” The API record, the model page and both of OpenRouter’s posts tonight name no provider. No lab has stepped forward. The tokenizer field reads "Other", which is a deliberate non-answer, not an oversight.
What exists on the community side is a same-day tokenizer comparison that its author labelled unconfirmed: one account ran a set of prompts through the endpoint and compared native token counts against named models, posting the result 68 minutes after the listing with the words “Identity is unconfirmed” in the post itself. That is an early, single, unaudited test pointing at a possibility. It is not evidence of who built the model, and it does not become evidence by being repeated. Token-count matching is a heuristic that can be fooled by shared tokenizer lineages, wrappers and fine-tunes; it narrows a guess, it does not settle one.
The absence of a benchmark is worth stating plainly because the title of this post, and OpenRouter’s own copy, use the word frontier. That word is the platform’s description of the model, repeated here as such. Our vendor-benchmark reproducibility audit found that even named vendors with published tables rarely give a buyer enough to reproduce a row; an anonymous vendor with no table gives nothing to reproduce at all. “Frontier-class” is a claim to be tested on your own tasks, not a tier the model has earned.
07 — PrecedentThirteen stealth slots, and the two that never resolved.
Ox Alpha is the fourteenth stealth slot OpenRouter has run since April 2025. The table below is compact context, not a dataset: it exists to answer one question, which is whether “we will find out who built it” is a safe assumption. Seven of the thirteen slots before it were confirmed by an official first-party statement. Four came from OpenRouter itself, in the Quasar and Optimus reveal post of April 14, 2025 and the GPT-5 launch post of August 7, 2025 that named Horizon Alpha and Horizon Beta. Three came from the lab that built them rather than from OpenRouter: Xiaomi’s MiMo team claimed Hunter Alpha and Healer Alpha on March 18, 2026, and Meituan claimed Owl Alpha on June 30, 2026 as LongCat-2.0-Preview. Four of the remaining rows are reported identities from secondary coverage or the model record, and are labelled accordingly; two were never resolved at all.
| Stealth slot | Listed | Turned out to be | Evidence tier |
|---|---|---|---|
| Confirmed by an official first-party statement | |||
| Quasar Alpha | Apr 2025 | GPT-4.1, an OpenAI pre-release test | Verified · OpenRouter blog reveal, Apr 14, 2025 |
| Optimus Alpha | Apr 2025 | GPT-4.1, a nearer-final snapshot | Verified · same blog post, Apr 14, 2025 |
| Horizon Alpha | Jul 2025 | An early GPT-5 checkpoint | Verified · OpenRouter blog and X, Aug 7, 2025 |
| Horizon Beta | Aug 2025 | A later GPT-5 checkpoint, which superseded Horizon Alpha | Verified · same announcement, Aug 7, 2025 |
| Hunter Alpha | Mar 2026 | Xiaomi MiMo-V2-Pro, “an early internal test build” | Verified · Xiaomi’s own MiMo team, Mar 18, 2026 |
| Healer Alpha | Mar 2026 | Xiaomi MiMo-V2-Omni, the multimodal sibling | Verified · same Xiaomi statement, Mar 18, 2026 |
| Owl Alpha | Apr 2026 | Meituan LongCat-2.0-Preview | Verified · Meituan’s own blog and X, Jun 30, 2026 |
| Identity reported, never confirmed by anyone | |||
| Sonoma Dusk Alpha | Sep 2025 | Presumed early Grok 4 Fast | Reported · model record; xAI never confirmed |
| Sonoma Sky Alpha | Sep 2025 | Presumed early Grok 4 Fast, larger variant | Reported · model record; xAI never confirmed |
| Polaris Alpha | Nov 2025 | Believed early GPT-5.1 snapshot | Reported · secondary only; OpenAI never confirmed |
| Sherlock Think Alpha | Nov 2025 | Believed early Grok 4.1 Fast, reasoning | Reported · secondary only; xAI never confirmed |
| Never resolved | |||
| Cypher Alpha | Jul 2025 | Unknown; listed under a provider name OpenRouter itself called fictional | Unresolved · no vendor statement |
| Aurora Alpha | Feb 2026 | Unknown; the one circulating theory is circumstantial by its own proponents’ account | Unresolved · no vendor statement |
| Open | |||
| Ox Alpha | Aug 2026 | Unrevealed on the day it listed | Open |
How stealth slots resolved · 14 slots since April 2025
Source: the precedent table above; the seven verified rows rest on OpenRouter’s own reveal posts of April 14, 2025 and August 7, 2025, Xiaomi’s MiMo team on March 18, 2026 and Meituan on June 30, 2026, the four reported rows on secondary coverage or the model record aloneTwo patterns hold across the table. The first is that a reveal, when it comes, comes from an official channel and never from community fingerprinting. OpenRouter’s own blog named Quasar Alpha, Optimus Alpha and both Horizon slots; the labs themselves named the other three, Xiaomi’s MiMo team for Hunter and Healer Alpha and Meituan for Owl Alpha, on its own blog and X account and corroborated in the trade press. Fingerprinting has preceded a reveal and has sometimes pointed at the right lab, but it has never once been the thing that settled one. The second pattern is that the free alpha endpoint is retired afterwards; the Quasar and Optimus slugs went to HTTP 404 with no redirect.
The residual is smaller than the silence around a listing suggests, and it is not zero. Seven of the thirteen slots before this one were confirmed by whoever built or hosted them, four carry a reported identity no vendor has ever stood behind, and two, Cypher Alpha and Aurora Alpha, have never been resolved at all. A name for Ox Alpha is therefore likely rather than promised. Whatever you build on stealth/ox-alpha tonight, build it expecting the slug to stop answering, and do not put a delivery date on the reveal. The July picture of what OpenRouter normally lists in a month is in our July catalog roundup; stealth slots are the exception to that cadence, not part of it.
08 — Routing DecisionWhere it belongs in a builder’s router tonight.
Put the record, the terms and the precedent together and the routing decision is not close. A free, 1M-context, tool-calling reasoning model with image and video input is a genuinely useful thing to have on the bench for a week. It is also anonymous, unbenchmarked, unmoderated, uncapped on paper only, retained by an operator you cannot name, and historically a 404 in waiting. Those two facts point at different workloads, and the line between them is whose data is in the prompt.
Throwaway experiments and your own code
Long-context refactors on a public or internal repo, agent-loop tuning, tool-schema testing, video-to-text experiments. Nothing in the prompt belongs to a client. The $0 price and the full tool surface make this the obvious use.
Anything touching a client’s code, content or customers
Only after reading the Stealth Program terms and the model page with the client’s own data agreement next to them. Retention by an unnamed operator for an unstated period is what you are agreeing to; the no-training note does not change that.
Anything a customer can reach
No published cap, no moderation layer, no benchmark, no provider to escalate to, and a slug that precedent says will stop answering. A free preview is not a dependency.
A slot in your eval harness
Worth it, for a week. Pin the concrete slug, run your own task set at each of max, high and low, log the thinking-token share, and treat any score as a snapshot of an endpoint that may be swapped out underneath you without notice.
The evaluation row deserves one more sentence, because a stealth slot is a sharper version of a risk we wrote about yesterday. A floating alias such as ~z-ai/glm-latest can silently repoint to a different model; a stealth slug can silently become a different snapshot of an unnamed model, and then disappear. Pinning stealth/ox-alpha pins nothing you can name. Any number you record this week describes the endpoint on the day you measured it, and no other day.
For teams deciding whether a new endpoint is allowed anywhere near client traffic, the questions are the same ones we put in our pre-signature procurement list: who operates it, where the data sits, for how long, under what licence, and what happens when it goes away. Ox Alpha answers one of those tonight, partially. That is the honest routing input. If you want a second set of eyes on a model-routing policy that has to survive listings like this one, our AI transformation engagements start with exactly that review, and our development team builds the eval harnesses that keep a free preview from becoming a production dependency by accident.
09 — ConclusionA free window, a perpetual licence, and a word that matters.
Treat the record as fact, the terms as binding, and everything else as a claim.
What is known about Ox Alpha tonight fits in one JSON object and two sentences of policy. The object says 1,048,576 tokens of context, 131,072 of reply, text, image and video in, mandatory reasoning with no medium rung, $0, no cap published, no moderation layer, no weights, no cutoff, no name. The policy says the anonymous provider retains what you send and, this time, does not train on it. The default it is carved out of is a perpetual licence whose stated purpose is training.
Everything louder than that is somebody else’s claim. The capacity figure belongs to a reseller. The identity belongs to a fingerprinting post that calls itself unconfirmed. The word “frontier” belongs to OpenRouter’s copy until an audited benchmark exists, and on the day it appeared none did. Seven of the thirteen stealth slots before this one were eventually claimed by an official statement, from OpenRouter or from the lab itself, but two were never resolved at all, so the reveal that would turn a stealth endpoint into a procurement decision is likely, not promised.
The routing decision follows. Prototype on it freely this week; it costs nothing and the tool surface is complete. Put client data through it only after reading the Stealth Program terms beside the client’s own agreement, because retention by an operator you cannot name is the part the no-training note leaves intact. Keep it out of anything a customer can reach. And run your own evals, with the concrete slug pinned, expecting the endpoint to change under you and then to stop answering. That is not cynicism about the model, which may be very good. It is reading the record as written.