gpt-oss-safeguard-20b
OpenAI · released Sep 18, 2025 · openai/gpt-oss-safeguard-20b
- Type
- Open weightsApache License 2.0
- Params
- 21.5B
- Context
- 131K
about 98K words of context
Our take
Written Aug 3, 2026gpt-oss-safeguard-20b is a compact downloadable text model from OpenAI with a permissive Apache licence and measured scores across six Arena categories. Its throughput and pricing vary sharply by host, so picking the right provider matters as much as picking the model.
Choose this for low-cost text inference where a permissive licence matters, or for high-throughput workloads on hosts that deliver it. Use it when you need commercial-use rights, fine-tuning freedom, or redistribution without restriction. Skip it if you need image, video or audio support, if you want verified active-parameter efficiency claims, or if you need consistent speed across any host you might use.
The case for it
- Broad benchmark coverage with stable scores: six Arena categories measured across two dates, with drift under 0.1 points in every one.
- Apache 2.0 licence allows commercial use, fine-tuning and redistribution without restriction.
- Among the cheapest hosted options in its class on select providers.
The case against it
- No disclosed active parameter count, so any efficiency claim is unverified.
- Text-only: no image, video or audio support.
- Throughput varies 7.1× across measured hosts, from 34 to 241 tokens per second.
How good is it?
IntelligencePuzzles, maths, exam questions
Arena Text (overall)119th of 143 · 1317.3
CodingWriting and fixing code on its own
Arena Coding110th of 143 · 1369.6
Arena Coding is the only board that has scored it for this.
AgenticPlanning, calling tools, staying on task
Nobody we watch has scored gpt-oss-safeguard-20b for this. We would take the rating from Arena Agent (IPS).
WritingWe do not rate this
Two boards come close and neither tests writing: Arena Creative Writing asks people which of two replies they prefer, and LiveBench Language tests whether a model understood a passage. So we show where gpt-oss-safeguard-20b placed and give it no mark out of five.
These tests check whether a model follows instructions — a precondition for all the work above, but not a measure of how well that work is done, which is why they get no rating.
Every published score for this model6 scoresEvery figure we hold, from 6 boards, with who ran it and a link to the source — including the boards no rating above is built on.
Can you run it yourself?
- Fits in memory
- weights load entirely on the card
- Spills to system RAM
- some weights offload; much slower
- Too large
- will not load even with offload
- est
- size is calculated; the verdict could change by 10%
Comfortable fit
GeForce RTX 4090 · 24 GB
Room to spare. 7.5 GB spare means a 10% error in the size would not change the answer.
GeForce RTX 5090 · 32 GB
Room to spare. 15.5 GB spare means a 10% error in the size would not change the answer.
Apple M2 (10-core GPU) · 24 GB
Room to spare. 2.7 GB spare means a 10% error in the size would not change the answer.
Memory use by level
Against a 24 GB card.
All 3 sizes here are calculated, not measured. We hold no measured file for this model, so each size comes from the parameter count and every verdict above inherits that uncertainty.
Check against your own machine → · All 71 devices, with every size →
Or rent it from someone else
Cheapest of 14 live listings. Picked at the widest standard context we hold, within one quantisation slice, so the numbers beside it are a price one host actually charges.
- per 1M tokens
- $0.040 in / $0.15 out
- Context served
- 131K
- Throughput
- Not measured
| Provider | In / out per 1M tokens | Context | Throughput | Trains on prompts | Logs prompts | Zero retention |
|---|---|---|---|---|---|---|
| CoreWeavefp4 | $0.030 / $0.13 | 131K | 94 tok/s | No | No | Confirmed |
| DeepInfrabf16 | $0.030 / $0.14 | 131K | 97 tok/s | No | No | Confirmed |
| DeepInfrabfloat16 | $0.030 / $0.14 | 131K | not measured | Unknown | Unknown | Unknown |
| Amazon Bedrock | $0.070 / $0.15 | 131K | 323 tok/s | No | No | Confirmed |
| Novita AI | $0.040 / $0.15 | 131K | not measured | Unknown | Unknown | Unknown |
| Novita AIfp4 | $0.040 / $0.15 | 131K | 120 tok/s | No | No | Confirmed |
| Phala | $0.040 / $0.15 | 131K | 57 tok/s | No | No | Confirmed |
| Amazon Bedrockeu-west-1 | $0.070 / $0.15 | 131K | 71 tok/s | No | No | Confirmed |
| SiliconFlowfp8 | $0.040 / $0.18 | 131K | 50 tok/s | No | No | Confirmed |
| Together AI | $0.050 / $0.20 | 131K | 82 tok/s | No | No | Confirmed |
| Google Vertex AIus-central1 | $0.070 / $0.25 | 131K | 127 tok/s | No | No | Confirmed |
| Fireworks AI | $0.070 / $0.30 | 131K | 89 tok/s | No | No | Confirmed |
| Groq | $0.075 / $0.30 | 131K | 373 tok/s | No | No | Confirmed |
| OpenRouter | $0.075 / $0.30 | 131K | not measured | Unknown | Unknown | Unknown |
Across the 14 listings we hold: 11 say they do not train on prompts, 0 say they do and 3 do not say. 11 appear in the zero-retention registry we check; the rest are unknown to us rather than confirmed either way.
What each host's API supports
From the parameter list each endpoint publishes. Streaming is omitted: nothing we hold reports it, for any model.
- ✓
- Supported
- ✗
- Not supported
- Not published
- host gave no parameter list
| Provider | Tool calling | JSON output | Strict schema |
|---|---|---|---|
| CoreWeavefp4 | ✓ | ✓ | ✓ |
| DeepInfrabf16 | ✓ | ✓ | ✓ |
| DeepInfrabfloat16 | |||
| Amazon Bedrock | ✓ | ✗ | ✗ |
| Novita AI | |||
| Novita AIfp4 | ✗ | ✓ | ✓ |
| Phala | ✗ | ✓ | ✓ |
| Amazon Bedrockeu-west-1 | ✓ | ✗ | ✗ |
| SiliconFlowfp8 | ✗ | ✓ | ✓ |
| Together AI | ✗ | ✓ | ✓ |
| Google Vertex AIus-central1 | ✗ | ✓ | ✓ |
| Fireworks AI | ✓ | ✓ | ✓ |
| Groq | ✓ | ✓ | ✓ |
| OpenRouter | ✓ | ✓ | ✓ |
Tool calling: 7 of 14 listings say yes, 5 say no, 2 publish no parameter list. JSON output: 10 of 14 listings say yes, 2 say no, 2 publish no parameter list. Strict schema: 10 of 14 listings say yes, 2 say no, 2 publish no parameter list.
Models people weigh against gpt-oss-safeguard-20b
When we formed this view
Dates behind this page
Prices last checked 5d ago
What we do not know about this model yet
- We hold no measured file for it, so all 3 sizes on this page are calculated from the parameter count.
- 2 of 14 listings publish no parameter list, so what their API accepts is unknown to us.
- Nothing we hold says whether an endpoint streams, so we do not show it either way.
- 3 of 14 listings do not say whether they train on prompts.
Licence and identifiers
What the licence allowsApache License 2.0, what it allows commercially, and the identifiers you need to pull this model — its Hugging Face repo, our slug and a machine-readable card.
Licence
Apache License 2.0
Fully permissive: commercial use, redistribution, and derivatives allowed. Requires attribution and a copy of the license. Includes an express patent grant.
Identifiers
- Hugging Face
- openai/gpt-oss-safeguard-20b
- Architecture
- Mixture of experts
- Modality record
- text->text
- Catalogue slug
- openai-gpt-oss-safeguard-20b