DEVELOPER RESOURCES / API REFERENCE
Build with CyberKimi.
Connect your security workflows through an OpenAI-compatible API.
Configure the base URL, add your API key, and select
lordx64/cyberkimi.
lordx64/cyberkimiExamples configured for CyberKimi.
Quickstart
1. Top up your wallet at billing.adverserial.ai
(prepaid, any amount). 2. Create an API key in the billing dashboard. 3. Call
https://api.adverserial.ai. That's the whole onboarding — no waitlist,
no membership.
API keys
Keys live in the billing dashboard (billing.adverserial.ai
Account API keys). Create as many as you like, name them per tool
(burp, ci-runner, laptop),
and revoke them independently. Usage debits your wallet in real time — when it hits $0,
keys stop until you top up (or enable auto-refill).
api.adverserial.ai. The chat
platform's own API rejects end-user keys by design — every key call goes through the shim's
wallet preflight. Never embed keys in client-side code, public repos, or shared images.
Rotate on suspicion.Endpoints
| WHAT | WHERE |
|---|---|
| Base URL | https://api.adverserial.ai/v1 |
| Chat completions | POST /v1/chat/completions |
| Model list | GET /v1/models |
| Model id | lordx64/cyberkimi |
| Auth | Authorization: Bearer <your key> |
Python
# pip install openai from openai import OpenAI client = OpenAI( api_key="sk-YOUR-KEY", base_url="https://api.adverserial.ai/v1", ) resp = client.chat.completions.create( model="lordx64/cyberkimi", messages=[ {"role": "system", "content": "You are a red-team operator assistant."}, {"role": "user", "content": "Write a Sigma rule for this behavior: ..."}, ], max_tokens=2048, ) print(resp.choices[0].message.content)
cURL
curl https://api.adverserial.ai/v1/chat/completions \ -H "Authorization: Bearer sk-YOUR-KEY" \ -H "Content-Type: application/json" \ -d '{"model":"lordx64/cyberkimi","messages":[{"role":"user","content":"triage this log line: ..."}],"max_tokens":1024}'
Streaming
stream = client.chat.completions.create(
model="lordx64/cyberkimi",
messages=[{"role": "user", "content": "Explain this alert: ..."}],
max_tokens=2048,
stream=True,
)
for chunk in stream:
if not chunk.choices:
continue
delta = chunk.choices[0].delta
reasoning = getattr(delta, "reasoning_content", None) or getattr(delta, "reasoning", None)
print(reasoning or delta.content or "", end="", flush=True)Reasoning
CyberKimi can emit reasoning before the final answer. Depending on the API dialect, reasoning arrives in reasoning_content or reasoning, while the answer arrives in content. With streaming, inspect the corresponding fields on each delta. If finish_reason="length" arrives with empty content, increase the output budget.
Prompt caching
Repeated prefixes may be reused when present in the serving engine’s cache. Cache availability depends on the model and current server state. Reported cache reads appear in usage.prompt_tokens_details.cached_tokens (Anthropic dialect: cache_read_input_tokens) and bill at the model’s cached-input rate.
Pricing
| ITEM | CYBERKIMI | CYBERGLM |
|---|---|---|
| Input (cache miss) | $4 / 1M tokens | $2 / 1M tokens |
| Input (cache read) | $0.40 / 1M tokens | $0.20 / 1M tokens |
| Output | $20 / 1M tokens | $10 / 1M tokens |
| Billing | Prepaid wallet — top up at billing.adverserial.ai; auto-refill optional | |
| Memberships | Foothold $20/mo · Hacker Manifesto $50/mo · G0DMOD3 $200/mo. Included credits apply to both chat and API; paid wallet usage is separate and opt-in. | |
Context capacity differs by model and serving configuration. The OpenCode example uses a conservative 65,536-token client context budget. For large workloads or dedicated capacity, contact our team.
Claude Code
For Claude Code, Cline, and other Anthropic-dialect clients, use the shim base URL — it sanitizes thinking blocks that the backend parser rejects:
export ANTHROPIC_BASE_URL="https://api.adverserial.ai" export ANTHROPIC_AUTH_TOKEN="sk-YOUR-KEY" export ANTHROPIC_MODEL="lordx64/cyberkimi" export ANTHROPIC_DEFAULT_OPUS_MODEL="lordx64/cyberkimi" export ANTHROPIC_DEFAULT_SONNET_MODEL="lordx64/cyberkimi" export ANTHROPIC_DEFAULT_HAIKU_MODEL="lordx64/cyberkimi" export CLAUDE_CODE_MAX_CONTEXT_TOKENS=1048576 claude
Restart Claude Code after changing these variables. Use /context to check the active budget. The explicit context override prevents an unrecognized custom model ID from falling back to a 200K window.
Kimi Code
Select CyberKimi or CyberGLM at the top of this page, then merge the complete example below into ~/.kimi/config.toml. Repeat with the other model to make both available. Replace an existing block with the same name instead of adding a duplicate.
[providers.cyberkimi] type = "anthropic" base_url = "https://api.adverserial.ai" api_key = "sk-YOUR-ADVERSERIAL-API-KEY" [models.cyberkimi] provider = "cyberkimi" model = "lordx64/cyberkimi" max_context_size = 1048576 capabilities = ["thinking", "always_thinking", "tool_use"] display_name = "CyberKimi"
Replace the API key placeholder with your Adverserial AI key, restart Kimi Code, and choose CyberKimi with /model. The provider value must match a defined [providers.…] block; a model block alone causes “Provider is not configured.” This connection uses the Anthropic protocol and the base URL above without /v1.
Client context budgets: CyberKimi: 750,000 tokens; CyberGLM: 131,072 tokens. CyberKimi’s example uses a conservative budget for current serving capacity; setting 1,048,576 in a client does not increase server capacity. These budgets include conversation and tool context; clients reserve space for responses and compaction.
Configuration reference: Kimi Code configuration files .
Codex CLI
Codex CLI (0.134.0 and later) speaks the OpenAI Responses API — our shim translates it. The clean setup keeps CyberKimi as a profile so your default model stays untouched. In ~/.codex/config.toml add the provider:
[model_providers.cyberkimi] name = "CyberKimi" base_url = "https://api.adverserial.ai/v1" env_key = "ADVERSERIAL_API_KEY" wire_api = "responses"
Then create the profile file ~/.codex/cyberkimi.config.toml:
model = "lordx64/cyberkimi" model_provider = "cyberkimi" model_context_window = 1048576 model_auto_compact_token_limit = 983040
These settings belong at the top level of the profile file. The explicit context window avoids a generic client default; the lower compaction threshold leaves room for the next turn. For older Codex versions, update first. Then start a new session:
export ADVERSERIAL_API_KEY="sk-YOUR-KEY" codex --profile cyberkimi
Codex desktop
For the desktop app, use the user-level ~/.codex/config.toml. Put the model and context settings before any table headers. The macOS example below uses a local key file because apps launched from the Dock may not inherit shell environment variables. Replace /Users/YOU with your actual home directory. If you configured the CLI provider above, replace that provider block and remove its env_key setting before using this auth alternative.
model = "lordx64/cyberkimi" model_provider = "cyberkimi" model_context_window = 1048576 model_auto_compact_token_limit = 983040 [model_providers.cyberkimi] name = "CyberKimi" base_url = "https://api.adverserial.ai/v1" wire_api = "responses" [model_providers.cyberkimi.auth] command = "/bin/cat" args = ["/Users/YOU/.codex/cyberkimi-key"]
Then:
(umask 077; printf '%s' 'sk-YOUR-KEY' > ~/.codex/cyberkimi-key) chmod 600 ~/.codex/cyberkimi-key
Fully quit the app (⌘Q) and relaunch. Use only one authentication method per provider: auth and env_key cannot be combined. The key file must exist at the exact absolute path in args. To switch back, restore your previous top-level model, provider, and context settings, then relaunch.
Configuration references: Codex profiles and custom providers · Context and compaction settings .
OpenCode
opencode speaks plain OpenAI chat completions, so it works through the shim directly. Add a custom provider in ~/.config/opencode/opencode.json (global) or opencode.json in your project root:
{
"$schema": "https://opencode.ai/config.json",
"provider": {
"cyberkimi": {
"npm": "@ai-sdk/openai-compatible",
"name": "CyberKimi",
"options": {
"baseURL": "https://api.adverserial.ai/v1",
"apiKey": "sk-YOUR-KEY"
},
"models": {
"lordx64/cyberkimi": {
"name": "CyberKimi",
"limit": { "context": 65536, "output": 8192 }
}
}
}
},
"model": "cyberkimi/lordx64/cyberkimi"
}Two things bite people here: the top-level model must carry the provider prefix
(cyberkimi/lordx64/cyberkimi), and the file must be plain ASCII —
a smart quote (“ instead of ") makes the
config fail to parse entirely. Restart opencode after saving.
Hermes Agent
Hermes (Nous Research's agent CLI) accepts any OpenAI-compatible endpoint as a "custom provider", so CyberKimi slots in with three touches. All config lives in ~/.hermes/:
1. Register the provider in ~/.hermes/config.yaml (append anywhere — top-level
providers: mapping takes a list or a dict entry):
providers:
cyberkimi:
base_url: "https://api.adverserial.ai/v1"
key_env: "ADVERSERIAL_API_KEY"2. Put your key in ~/.hermes/.env (never inline it in the YAML — config.yaml is not redacted in logs):
ADVERSERIAL_API_KEY=sk-YOUR-KEY3. Point the default model at it (one-time, persists across sessions):
hermes config set model.provider cyberkimi
hermes config set model.default "lordx64/cyberkimi" --forceOr per-session without touching the default:
hermes --provider cyberkimi -m "lordx64/cyberkimi" chat4. Sanity-check the link once:
hermes -z "Reply with exactly: OK"169.254.169.254) at startup; on a non-AWS
box that probe hangs and the agent appears to freeze with zero output. Add
AWS_EC2_METADATA_DISABLED=true to ~/.hermes/.env once —
the probe is skipped and startup is instant.Verified end-to-end on 2026-09-13: config wizard clean (hermes doctor),
one-shot prompt answered, default provider selected, and the interactive chat TUI running
against lordx64/cyberkimi.
Errors
| CODE | MEANING |
|---|---|
| 401 | Missing or revoked key |
| 403 "Use of API key is not enabled" | You're calling the chat platform's API — end-user keys only work via api.adverserial.ai |
| 402 / wallet message | Wallet empty — top up at billing.adverserial.ai/topup |
| finish_reason=length, empty content | Reasoning ate the token budget — raise max_tokens |
| 503 | Upstream unavailable — retry with backoff and a bounded retry count |
FAQ
How is CyberKimi specialized? CyberKimi builds on Kimi K3 with guardrails relaxed for cybersecurity and additional cybersecurity domain tuning for authorized security work.
Do you store inference or chat session logs? No. Privacy first: we do not store inference logs or chat session logs, and customer prompts are not used to train CyberKimi.
Team plans? Enterprise tier: dedicated capacity, private weight deployment, SSO — contact@adverserial.ai.
