Z.ai through the Vigil proxy
Z.ai’s API for the GLM models at api.z.ai, OpenAI-compatible. Point your SDK's base URL at Vigil, add one header, and every Z.ai call is logged with its cost, tokens, latency, errors and agent, then forwarded to https://api.z.ai unchanged.
What Vigil records per Z.ai call
One row per call: the model id as Z.ai returned it, input and output tokens, cache reads and writes where the response reports them, latency, the HTTP status and the provider's error code when it fails, and the agent named in the X-Vigil-Agent header. Likely prompt injections and personal data in prompts are flagged on the Errors page. A cost spike is flagged when a call costs over three times the agent's seven-day median.
Cost is computed from the proxy's rate registry, which prices 2 models on this platform today. A model the registry has no row for is logged with its cost left empty, never estimated.
- glm-5.3
- glm-5.3-flash
Setup
Every route has the shape https://api.vigil.tools/{user_id}/{provider}/{path}. For Z.ai the provider segment is zai, so the base URL is https://api.vigil.tools/{user_id}/zai and a request path such as /v1/chat/completions is forwarded unchanged. The proxy stores the origin only, so the path after the segment is whatever your client already uses, /v1 for most OpenAI-compatible APIs.
Two headers: X-Vigil-Key, your Vigil key from the dashboard, and X-Vigil-Agent, the name the dashboard groups this traffic under. Your Z.ai key stays where it was, in ZAI_API_KEY.
import OpenAI from "openai";
const client = new OpenAI({
apiKey: process.env.ZAI_API_KEY, // unchanged
baseURL: "https://api.vigil.tools/{user_id}/zai/v1",
defaultHeaders: {
// MUST be X-Vigil-Key: Authorization already carries your Z.ai key.
"X-Vigil-Key": "vk_your_vigil_key",
"X-Vigil-Agent": "my-agent",
},
});
const completion = await client.chat.completions.create({
model: "<your model id>",
messages: [{ role: "user", content: "Hello!" }],
});Vigil forwards everything after /zai unchanged to https://api.z.ai. The path above is whatever your client already uses — /v1 is the OpenAI-compatible default and is right for most, but some providers prefix it with a product segment. If you get a 404, compare it against the base URL in your Z.ai config: the part after https://api.z.ai is exactly what belongs here.
from openai import OpenAI
client = OpenAI(
api_key=os.environ["ZAI_API_KEY"], # unchanged
base_url="https://api.vigil.tools/{user_id}/zai/v1",
default_headers={
"X-Vigil-Key": "vk_your_vigil_key",
"X-Vigil-Agent": "my-agent",
},
)
completion = client.chat.completions.create(
model="<your model id>",
messages=[{"role": "user", "content": "Hello!"}],
)Vigil forwards everything after /zai unchanged to https://api.z.ai. The path above is whatever your client already uses — /v1 is the OpenAI-compatible default and is right for most, but some providers prefix it with a product segment. If you get a 404, compare it against the base URL in your Z.ai config: the part after https://api.z.ai is exactly what belongs here.
curl https://api.vigil.tools/{user_id}/zai/v1/chat/completions \
-H "content-type: application/json" \
-H "Authorization: Bearer $ZAI_API_KEY" \
-H "X-Vigil-Key: vk_your_vigil_key" \
-H "X-Vigil-Agent: my-agent" \
-d '{
"model": "<your model id>",
"messages": [{ "role": "user", "content": "Hello!" }]
}'Vigil forwards everything after /zai unchanged to https://api.z.ai. The path above is whatever your client already uses — /v1 is the OpenAI-compatible default and is right for most, but some providers prefix it with a product segment. If you get a 404, compare it against the base URL in your Z.ai config: the part after https://api.z.ai is exactly what belongs here.
Replace {user_id} and vk_your_vigil_key with the values on your Connect page. The snippets above are generated by the same code as that page.
Prompt caching on Z.ai
This provider caches automatically, on its own terms. Vigil records what it reports and prices it — there is nothing for Vigil to add to the request.
With optimisation On: the provider caches automatically or not at all; Vigil records cache use and does not change the request. In Shadow, Vigil measures what caching would have saved and changes nothing. Off records the call and nothing more.
Questions
- Does Vigil see or store my Z.ai API key?
- No, not the key itself. Your Z.ai key passes through the proxy with the request and is never written to disk. A call record can keep a short one-way digest of the credential, so that one key’s cache is kept apart from another’s; it cannot be turned back into the key. Vigil identifies you by the X-Vigil-Key header and your user id in the URL.
- Does routing Z.ai through Vigil add latency?
- Some. The proxy runs on Cloudflare’s edge, so the added hop is short, but reading the request body to place cache markers takes time, and there is a bounded lookup for your account state. The dashboard shows total latency per call. For long calls, stream: Cloudflare’s edge closes non-streaming connections after roughly 125 seconds.
- Which Z.ai models does Vigil price?
- 2 models with a published rate in the registry: glm-5.3, glm-5.3-flash. A call to any other Z.ai model is logged and monitored, with its cost left empty rather than guessed.
Other providers: Anthropic · AWS Bedrock · Google Vertex · OpenAI · Google Gemini · Mistral · xAI Grok · DeepSeek · Together AI · Fireworks AI · Groq · Cerebras · Baseten · Moonshot · Cloudflare Workers AI · OpenRouter