gpt-oss-safeguard-20b
OpenAI · released Sep 18, 2025 · openai/gpt-oss-safeguard-20b
- Type
- Open weightsApache License 2.0
- Params
- 21.5B
- Context
- 131K
3.6B active per word · about 98K words of context
Our take
Written Sep 30, 2026A downloadable text model with a licence that allows commercial use, changes and redistribution, gpt-oss-safeguard-20b is built for bulk, low-stakes work rather than for writing well. It sits near the bottom of the chat leaderboard we track, so pick it for the bill and the download, not the measured quality.
Use it for high-volume, low-stakes text work — classification, extraction, routing, bulk rewriting — where the bill matters more than answer quality, or run it yourself on a single modern graphics card. Its licence allows commercial use, changes and redistribution (Apache License 2.0). Skip it if you need a model that writes well, follows instructions closely, or turns in code.
The case for it
- The cheapest listed offer sits well under the next hosts up, so bulk text work costs a fraction of what a mid-tier model does.
- Only 3.6 billion of its 21.5 billion parameters are active per token, so memory in use is closer to a small model than a mid-size one.
- The licence allows commercial use, changes and redistribution (Apache License 2.0).
The case against it
- 140th of 168 on Arena Text (overall) as of 25 Sep 2026, and 152nd of 168 on Arena Creative Writing as of 25 Sep 2026 — a preference board that records which answer people liked, not whether it was correct.
- 134th of 168 on Arena Coding as of 25 Sep 2026 and 148th of 168 on Arena Instruction Following as of 25 Sep 2026, so it is not the model to reach for when the task needs code or precise compliance.
- Text in, text out: no image, audio or video input, so anything visual has to be described in words first.
How good is it?
An open text model for answering questions, drafting prose and writing code, though it trails most models on those tasks.
- getting answers to everyday questionsArena Text (overall) · 140th of 168
- drafts, rewrites and editingArena Creative Writing · 152nd of 168
- writing and completing codeArena Coding · 134th of 168
EverydayGeneral questions and everyday reasoning
Arena Text (overall)140th of 168 · 1318
CodingWriting and fixing code on its own
Arena Coding134th of 168 · 1369
Arena Coding is the only board that has scored it for this.
AgenticPlanning, calling tools, staying on task
Not yet scored on Arena Agent.
WritingDrafting and rewriting prose
Arena Creative Writing152nd of 168 · 1240
Arena Creative Writing is the only board that has scored it for this.
These tests check whether a model follows instructions — a precondition for all the work above, but not a measure of how well that work is done.
Every published score for this model6 scoresEvery figure we hold, from 6 boards, with who ran it and a link to the source — including the boards no rating above is built on.
Can you run it yourself?
Comfortable fit
GeForce RTX 4090 · 24 GB
Room to spare. 7.5 GB spare means a 10% error in the size would not change the answer.
GeForce RTX 5090 · 32 GB
Room to spare. 15.5 GB spare means a 10% error in the size would not change the answer.
Apple M2 (10-core GPU) · 24 GB
Room to spare. 2.7 GB spare means a 10% error in the size would not change the answer.
Memory use by level
Against a 24 GB card.
What is quantisation? →This model on every device we track71 devicesThe Q4 build most people download, on each device: what the weights come to, how much context the memory leaves, and whether it runs. Smallest device that runs it first.
Check against your own machine → · Where to rent it hosted →
Or rent it from someone else
Prices checked between 4 hours and 5 days ago — each listing carries its own date.
Amazon Bedrock, through OpenRouter
Cheapest of the 5 listings we can compare like for like — at 131K of context, out of 13 in the table below. 5 cheaper rows there are outside that comparison: a different quantisation.
- per 1M tokens
- $0.070 in / $0.15 out
- Context served
- 131K
- Throughput
- ~241 tok/s
| Provider | In / out per 1M tokens | Context | Throughput | Trains on prompts | Logs prompts | Zero retention |
|---|---|---|---|---|---|---|
| Darkbloomfp8Through OpenRouter | $0.018 / $0.090checked 4 hours ago | 131K33K max reply | 23 tok/s | No | Yesunknown period | Unknown |
| AkashMLfp4Through OpenRouter | $0.020 / $0.10checked 4 hours ago | 131K118K max reply | 37 tok/s | No | No | Confirmed |
| CoreWeavefp4Through OpenRouter | $0.030 / $0.13checked 4 hours ago | 131K118K max reply | 141 tok/s | No | No | Confirmed |
| DeepInfrabf16Direct and through OpenRouter | $0.030 / $0.14checked 4 hours ago | 131K118K max reply through OpenRouter | 88 tok/sthrough OpenRouter | DirectUnknownThrough OpenRouterNo | DirectUnknownThrough OpenRouterNo | DirectUnknownThrough OpenRouterConfirmed |
| DekaLLMbf16Through OpenRouter | $0.029 / $0.14checked 4 hours ago | 131K118K max reply | 17 tok/s | No | No | Confirmed |
| Parasailfp4Through OpenRouter | $0.030 / $0.15checked 4 hours ago | 131K118K max reply | 17 tok/s | No | No | Confirmed |
| Novita AIfp4Direct and through OpenRouter | $0.040 / $0.15checked 4 hours ago | 131K33K max reply through OpenRouter | 48 tok/sthrough OpenRouter | DirectUnknownThrough OpenRouterNo | DirectUnknownThrough OpenRouterNo | DirectUnknownThrough OpenRouterConfirmed |
| Amazon BedrockThrough OpenRouter | $0.070 / $0.15checked 4 hours ago | 131K118K max reply | 241 tok/s | No | No | Confirmed |
| Amazon Bedrockeu-west-1Through OpenRouter | $0.070 / $0.15checked 4 hours ago | 131K118K max reply | 70 tok/s | No | No | Confirmed |
| SiliconFlowfp8Through OpenRouter | $0.040 / $0.18checked 10 hours ago | 131K8K max reply | 67 tok/s | No | No | Confirmed |
| Google Vertex AIus-central1Through OpenRouter | $0.070 / $0.25checked 4 hours ago | 131K33K max reply | 86 tok/s | No | No | Confirmed |
| GroqThrough OpenRouter | $0.075 / $0.30checked 4 hours ago | 131K66K max reply | 690 tok/s | No | No | Confirmed |
| OpenRouterOpenRouter's own listing | $0.075 / $0.30checked 5 days ago | 131K | not measured | Unknown | Unknown | Unknown |
Across the 13 listings we hold: 12 say they do not train on prompts (2 of them only through OpenRouter), 0 say they do and 1 does not say. 11 appear in the zero-retention registry we check (2 of them only through OpenRouter); the rest are unknown to us.
What each host's API supports
From the parameter list each endpoint publishes. Streaming is omitted: nothing we hold reports it, for any model.
| Provider | Tool calling | JSON output | Strict schema |
|---|---|---|---|
| Darkbloomfp8Through OpenRouter | ✓ | ✓ | ✓ |
| AkashMLfp4Through OpenRouter | ✓ | ✓ | ✓ |
| CoreWeavefp4Through OpenRouter | ✓ | ✓ | ✓ |
| DeepInfrabf16Direct and through OpenRouter | ✓ | ✓ | ✓ |
| DekaLLMbf16Through OpenRouter | ✓ | ✓ | ✓ |
| Parasailfp4Through OpenRouter | ✓ | ✓ | ✓ |
| Novita AIfp4Direct and through OpenRouter | ✗ | ✓ | ✓ |
| Amazon BedrockThrough OpenRouter | ✓ | ✗ | ✗ |
| Amazon Bedrockeu-west-1Through OpenRouter | ✓ | ✗ | ✗ |
| SiliconFlowfp8Through OpenRouter | ✗ | ✓ | ✓ |
| Google Vertex AIus-central1Through OpenRouter | ✗ | ✓ | ✓ |
| GroqThrough OpenRouter | ✓ | ✓ | ✓ |
| OpenRouterOpenRouter's own listing | ✓ | ✓ | ✓ |
Tool calling: 10 of 13 listings say yes, 3 say no. JSON output: 11 of 13 listings say yes, 2 say no. Strict schema: 11 of 13 listings say yes, 2 say no.
Models people weigh against gpt-oss-safeguard-20b
When we formed this view
Recent changes
What moved
input −10% ($0.020 → $0.018 per 1M tokens), output −10% ($0.100 → $0.090 per 1M tokens)What moved
first indexed by our pipelineEach date is the day we first saw the change, or the day the maker announced it.
What we do not know about this model yet
- We hold no measured file for it, so all 3 sizes on this page are calculated from the parameter count.
- Nothing we hold says whether an endpoint streams, so we do not show it either way.
- 1 of 13 listings does not say whether it trains on prompts, and 2 answer only through OpenRouter, not for their own listing.
- We hold no batch or off-peak rate for any of its listings.
- We hold a decode speed for it, but no prompt-processing (prefill) figure, so how long the input side of a job takes is unknown to us.
Licence and identifiers
What the licence allowsApache License 2.0, what it allows commercially, and the identifiers you need to pull this model — its Hugging Face repo, our slug and a machine-readable card.
Licence
Apache License 2.0
Fully permissive: commercial use, redistribution, and derivatives allowed. Requires attribution and a copy of the license. Includes an express patent grant.
Identifiers
- Hugging Face
- openai/gpt-oss-safeguard-20b
- Architecture
- Mixture of experts
- Takes in, gives back
- Text in, text out
- Catalogue slug
- openai-gpt-oss-safeguard-20b