# GLM-5.3

GLM-5.3 is a Z.ai flagship model described as having a 1M-token context window, 128K maximum output, and native tool calling and structured output, and is served on Vercel AI Gateway at zai/glm-5.3 without a separate Z.ai API key. Single-source reports cover its August 14, 2026 release, benchmark comparisons, and a reported two-week delay of open weights following red-team testing.

Status: strong
Last verified: 2026-08-23T19:36:17.000Z

## Evidence

- (single_source) Z.ai released GLM-5.3 on August 14, 2026.
  - supports https://metirai.com/blog/glm-5-3-open-weight-coding-cyber-2026
    > Z.ai released GLM-5.3 on August 14, 2026.

- (single_source) Z.ai's newly introduced Z.ai Code Bench measures GLM-5.3's coding abilities at a 50% improvement over GLM-5.2.
  - supports https://thenewstack.io/glm-5-3-anthropic-distillation
    > the organization's newly introduced Z.ai Code Bench measures GLM-5.3's coding abilities at a 50% improvement over GLM-5.2

- (single_source) On CyberGym, GLM-5.3 scored 84.5% against 83.8% for Anthropic's Mythos 5 and 83.6% for OpenAI's GPT-5.6 Sol.
  - supports https://brieflyglobal.com/ai/zhipu-glm-5-3-cybersecurity-claims-scrutinized
    > The benchmark that grabbed attention was CyberGym, a test where GLM-5.3 scored 84.5% against 83.8% for Anthropic's Mythos 5 and 83.6% for OpenAI's GPT-5.6 Sol.

- (single_source) GLM-5.3 uses the same base model as GLM-5.2, with every gain coming from post-training.
  - supports https://z.ai/blog/glm-5.3
    > It uses the same base model as GLM-5.2 — every gain comes from post-training.

- (single_source) EmpirioLabs documents Z.ai built-in web search as adding $0.033 per request when used.
  - supports https://empiriolabs.ai/models/glm-5-3
    > Always reasons; thinking cannot be disabled. Reasoning effort: low, high, or max. Built-in web search adds $0.033 per request when used.

- (supported) Z.ai describes GLM-5.3 as a flagship model with a 1M-token context window and 128K maximum output.
  - supports https://empiriolabs.ai/models/glm-5-3
    > Coding and agentic model with a 1M token context, 128K output.
  - supports https://z.ai/blog/glm-5.3
    > GLM-5.3 is Z.ai's flagship model with a 1M-token context window, 128K max output, native tool calling, and structured output. It is available via the Z.ai API as glm-5.3.

- (single_source) Use of GLM 5 through AI Gateway is subject to Z.AI's Terms and Privacy Policies.
  - supports https://vercel.com/ai-gateway/models/glm-5/providers
    > Your use is subject to Z.AI's Terms & Privacy Policies.

- (single_source) GLM-5.3 is available now through the GLM Coding Plan and works with coding agents like ZCode, Claude Code, or OpenCode.
  - supports https://the-decoder.com/zhipu-ai-releases-glm-5-3-claims-its-the-strongest-open-weights-coding-model
    > GLM-5.3 is available now through the GLM Coding Plan and works with coding agents like ZCode, Claude Code, or OpenCode.

- (supported) GLM-5.3 supports native tool calling and structured output according to Z.ai.
  - supports https://z.ai/blog/glm-5.3
    > GLM-5.3 is Z.ai's flagship model with a 1M-token context window, 128K max output, native tool calling, and structured output. It is available via the Z.ai API as glm-5.3.

- (single_source) GLM-5.3 cached input costs $0.26 per million tokens, while Z.ai currently lists cached-input storage as free for a limited time.
  - supports https://venturebeat.com/technology/glm-5-3-hits-the-api-at-1-4-4-4-per-million-tokens
    > Cached input costs $0.26 per million tokens, while Z.ai currently lists cached-input storage as free for a limited time.

- (disputed) On DeepSWE v1.1, a benchmark for fixing real GitHub issues end-to-end, open rival Kimi K3 (67.5) and Fable 5 (69.7) both beat GLM-5.3's 66.9.
  - disputes https://chinadaily.com.cn/a/202608/14/WS6a7edfbfa31073853ec535f3.html
    > Zhipu said GLM-5.3 ranked as the strongest open-source model across several mainstream benchmarks, with its coding and agent capabilities approaching those of Claude Fable 5.
  - supports https://decrypt.co/375684/china-z-ai-glm-5-3-top-open-weight-coding-model
    > On DeepSWE v1.1, a benchmark for fixing real GitHub issues end-to-end, open rival Kimi K3 (67.5) and Fable 5 (69.7) both beat GLM-5.3's 66.9.

- (disputed) Zhipu said GLM-5.3 ranked as the strongest open-source model across several mainstream benchmarks.
  - disputes https://decrypt.co/375684/china-z-ai-glm-5-3-top-open-weight-coding-model
    > On DeepSWE v1.1, a benchmark for fixing real GitHub issues end-to-end, open rival Kimi K3 (67.5) and Fable 5 (69.7) both beat GLM-5.3's 66.9.
  - supports https://chinadaily.com.cn/a/202608/14/WS6a7edfbfa31073853ec535f3.html
    > Zhipu said GLM-5.3 ranked as the strongest open-source model across several mainstream benchmarks, with its coding and agent capabilities approaching those of Claude Fable 5.

- (single_source) Z.ai said it will release the GLM-5.3 weights two weeks after launch, once safety evaluation and hardening are complete.
  - supports https://z.ai/blog/glm-5.3
    > We will release the weights in two weeks after launch, once safety evaluation and hardening are complete.

- (single_source) GLM-5.3 is available through the GLM Coding Plan and works with coding agents like ZCode, Claude Code, or OpenCode.
  - supports https://the-decoder.com/zhipu-ai-releases-glm-5-3-claims-its-the-strongest-open-weights-coding-model
    > GLM-5.3 is available now through the GLM Coding Plan and works with coding agents like ZCode, Claude Code, or OpenCode.

- (disputed) Third-party API docs state GLM-5.3 always reasons and thinking cannot be disabled.
  - supports https://empiriolabs.ai/models/glm-5-3
    > Always reasons; thinking cannot be disabled. Reasoning effort: low, high, or max. Built-in web search adds $0.033 per request when used.
  - disputes https://z.ai/blog/glm-5.3
    > GLM-5.3 is Z.ai's flagship model with a 1M-token context window, 128K max output, native tool calling, and structured output. It is available via the Z.ai API as glm-5.3.

- (single_source) Zhipu said GLM-5.3 ranked as the strongest open-source model across several mainstream benchmarks, with coding and agent capabilities approaching those of Claude Fable 5.
  - supports https://chinadaily.com.cn/a/202608/14/WS6a7edfbfa31073853ec535f3.html
    > Zhipu said GLM-5.3 ranked as the strongest open-source model across several mainstream benchmarks, with its coding and agent capabilities approaching those of Claude Fable 5.

- (single_source) GLM-5.3 scored 54.4% on ExploitBench, versus 78.0% for Mythos 5, in converting discovered flaws into working attacks.
  - supports https://reuters.com/technology/chinas-zai-says-new-model-nears-anthropics-mythos-5-cyber-defence-tests-2026-08-14
    > GLM-5.3 lagged behind Mythos 5 in converting discovered flaws into working attacks — a standard part of defensive security research. Z.ai said its model scored 54.4% on the ExploitBench test of this capability, versus 78.0% for Mythos 5.

- (single_source) Z.ai said GLM-5.3 scored 84.5% on CyberGym, a test of whether a model can review code, identify security flaws, and confirm that they are real.
  - supports https://reuters.com/technology/chinas-zai-says-new-model-nears-anthropics-mythos-5-cyber-defence-tests-2026-08-14
    > Z.ai said GLM-5.3 scored 84.5% on CyberGym, a test of whether a model can review code, identify security flaws and confirm that they are real.

- (single_source) On DeepSWE v1.1, a benchmark for fixing real GitHub issues end-to-end, Kimi K3 (67.5) and Fable 5 (69.7) both beat GLM-5.3's 66.9.
  - supports https://decrypt.co/375684/china-z-ai-glm-5-3-top-open-weight-coding-model
    > On DeepSWE v1.1, a benchmark for fixing real GitHub issues end-to-end, open rival Kimi K3 (67.5) and Fable 5 (69.7) both beat GLM-5.3's 66.9.

- (single_source) On Terminal Bench 3.0, a test of autonomous shell/tool use in real Linux environments, GLM-5.3 scores 28.3, slightly behind closed models Fable 5 (33.7) and GPT-5.6 Sol (34.6).
  - supports https://decrypt.co/375684/china-z-ai-glm-5-3-top-open-weight-coding-model
    > On Terminal Bench 3.0—a test of autonomous shell/tool use in real Linux environments—GLM-5.3 scores 28.3, slightly behind closed models Fable 5 (33.7) and GPT-5.6 Sol (34.6).

- (supported) Vercel AI Gateway serves GLM-5.3 at the model id zai/glm-5.3 without a direct Z.ai API key.
  - supports https://z.ai/blog/glm-5.3
    > GLM-5.3 is Z.ai's flagship model with a 1M-token context window, 128K max output, native tool calling, and structured output. It is available via the Z.ai API as glm-5.3.
  - supports https://vercel.com/ai-gateway/models/glm-5.3
    > AI Gateway exposes Z.ai GLM-5.3 at model id zai/glm-5.3. Requests authenticate with OIDC or an AI Gateway key. No separate Z.ai API key is required.

- (single_source) Z.ai highlights structured extraction from documents like contracts and financial reports for GLM 5.
  - supports https://vercel.com/ai-gateway/models/glm-5/about
    > Z.ai highlights structured extraction from documents like contracts and financial reports

- (single_source) A one-million-in / one-million-out comparison puts GLM-5.3 at $5.80, versus $8.00 for Grok 4.6 at its lower-context tier, $18.00 for Kimi K3, $30.00 for Claude Opus 5, and $35.00 for GPT-5.6 Sol.
  - supports https://ai.cc/blogs/glm-5-3-open-weight-coding-model-benchmarks-pricing
    > A simple one-million-in / one-million-out comparison puts GLM-5.3 at $5.80 — versus $8.00 for Grok 4.6 at its lower-context tier, $18.00 for Kimi K3, $30.00 for Claude Opus 5, and $35.00 for GPT-5.6 Sol.

- (single_source) A simple one-million-input / one-million-output comparison puts GLM-5.3 at $5.80, versus $8.00 for Grok 4.6, $18.00 for Kimi K3, $30.00 for Claude Opus 5, and $35.00 for GPT-5.6 Sol.
  - supports https://ai.cc/blogs/glm-5-3-open-weight-coding-model-benchmarks-pricing
    > A simple one-million-in / one-million-out comparison puts GLM-5.3 at $5.80 — versus $8.00 for Grok 4.6 at its lower-context tier, $18.00 for Kimi K3, $30.00 for Claude Opus 5, and $35.00 for GPT-5.6 Sol.

- (supported) Eve still defaults to zai/glm-5.2 when agent.ts is omitted, not GLM-5.3.
  - supports https://eve.dev/docs/agent-config
    > The root agent.ts can be omitted when no runtime config is needed. In that case, eve defaults to zai/glm-5.2.

- (single_source) Vercel AI Gateway exposes Z.ai GLM-5.3 at model id zai/glm-5.3, with no separate Z.ai API key required.
  - supports https://vercel.com/ai-gateway/models/glm-5.3
    > AI Gateway exposes Z.ai GLM-5.3 at model id zai/glm-5.3. Requests authenticate with OIDC or an AI Gateway key. No separate Z.ai API key is required.

- (single_source) Z.ai is delaying the release of the open weights by about two weeks, saying GLM-5.3 is so effective at detecting security vulnerabilities that it is strengthening controls and restricting full access to select security partners.
  - supports https://the-decoder.com/glm-5-3-tops-the-open-model-rankings-and-undercuts-rivals-on-price-but-its-release-is-delayed
    > Z.ai is delaying the release of the open weights by about two weeks because, according to the company, GLM-5.3 is so effective at detecting security vulnerabilities that it is first strengthening controls and restricting full access to select security partners.

- (single_source) GLM 5 supports agentic coding and structured data extraction workflows.
  - supports https://vercel.com/ai-gateway/models/glm-5/about
    > It supports agentic coding and structured data extraction workflows.

- (single_source) GLM 5 builds on the GLM-4.x family with added focus on agentic coding, autonomous tool use, and complex multi-step workflows.
  - supports https://vercel.com/ai-gateway/models/glm-5/about
    > It builds on the GLM-4.x family, with added focus on agentic coding, autonomous tool use, and complex multi-step workflows.

- (single_source) GLM 5 features multiple thinking modes, enhanced long-range planning and memory, and improved handling of complex multi-step agent tasks.
  - supports https://vercel.com/ai-gateway/models/glm-5/about
    > featuring multiple thinking modes, enhanced long-range planning and memory, and improved handling of complex multi-step agent tasks

- (single_source) GLM 5 is available through Vercel AI Gateway with unified API access.
  - supports https://vercel.com/ai-gateway/models/glm-5/about
    > Through AI Gateway, GLM 5 is available with unified API access

- (single_source) GLM 5 is Z.ai's GLM-5 generation model released on February 12, 2026.
  - supports https://vercel.com/ai-gateway/models/glm-5/about
    > GLM 5 is Z.ai's GLM-5 generation model released February 12, 2026

- (single_source) On ExploitGym, which counts full exploitation tasks completed under time budgets, GLM-5.3 finished 105 tasks in two hours and 130 in six, versus 29 and 39 for GLM-5.2.
  - supports https://thorstenmeyerai.com/insights/glm-5-3-frontier-coding-and-a-cyber-capability-that-outran-its-own-training
    > On ExploitGym, which counts full exploitation tasks completed under time budgets, it finishes 105 tasks in two hours and 130 in six, versus 29 and 39 for GLM-5.2

- (single_source) In internal red-team testing, GLM-5.3, operating as an autonomous agent with tool access, successfully chained together reconnaissance, vulnerability identification, and exploit development against deliberately vulnerable test infrastructure without step-by-step human guidance.
  - supports https://signalreads.com/articles/glm-53-just-went-full-frontier--and-it-can-hack-to
    > The report describes internal red-team testing in which GLM-5.3, operating as an autonomous agent with tool access, successfully chained together reconnaissance, vulnerability identification, and exploit development against deliberately vulnerable test infrastructure without step-by-step human guidance.

- (single_source) On ExploitGym, GLM-5.3 finished 105 tasks in two hours and 130 in six hours, versus 29 and 39 for GLM-5.2, against roughly 181 and 247 for the closed frontier.
  - supports https://thorstenmeyerai.com/insights/glm-5-3-frontier-coding-and-a-cyber-capability-that-outran-its-own-training
    > On ExploitGym, which counts full exploitation tasks completed under time budgets, it finishes 105 tasks in two hours and 130 in six, versus 29 and 39 for GLM-5.2 — a real leap, but against roughly 181 and 247 for the closed frontier.

- (supported) Exa web search is free on AI Gateway through August 31, 2026, with no separate Exa API key, and is the default web search for eve agents.
  - supports https://vercel.com/changelog/exa-web-search-free-through-august-31-on-ai-gateway-and-eve
    > Exa web search is now free on AI Gateway through August 31, and it's now the default web search for eve agents. The tool works with any AI Gateway model, with no separate Exa API key.

- (supported) Vercel listed GLM-5.2 as free for eve agents through August 27, 2026 via Blackbox on AI Gateway.
  - supports https://vercel.com/changelog/glm-5-2-free-for-eve-agents-through-august-27-via-blackbox-on-ai-gateway
    > GLM 5.2 is free for eve agents through August 27, served by Blackbox on AI Gateway. After August 27, GLM 5.2 stays available on AI Gateway at standard provider rates.

- (single_source) Vercel AI Gateway exposes Z.ai GLM-5.3 at model id zai/glm-5.3, with requests authenticating via OIDC or an AI Gateway key, requiring no separate Z.ai API key.
  - supports https://vercel.com/ai-gateway/models/glm-5.3
    > AI Gateway exposes Z.ai GLM-5.3 at model id zai/glm-5.3. Requests authenticate with OIDC or an AI Gateway key. No separate Z.ai API key is required.

- (single_source) GLM 5 is Z.AI's GLM-5 generation model featuring multiple thinking modes, enhanced long-range planning and memory, and improved handling of complex multi-step agent tasks.
  - supports https://vercel.com/ai-gateway/models/glm-5/providers
    > GLM 5 is Z.AI's GLM-5 generation model released February 12, 2026, featuring multiple thinking modes, enhanced long-range planning and memory, and improved handling of complex multi-step agent tasks.

- (single_source) Internal red-team testing found GLM-5.3, operating as an autonomous agent with tool access, successfully chained together reconnaissance, vulnerability identification, and exploit development against deliberately vulnerable test infrastructure without step-by-step human guidance.
  - supports https://signalreads.com/articles/glm-53-just-went-full-frontier--and-it-can-hack-to
    > The report describes internal red-team testing in which GLM-5.3, operating as an autonomous agent with tool access, successfully chained together reconnaissance, vulnerability identification, and exploit development against deliberately vulnerable test infrastructure without step-by-step human guidance.

## Timeline

- 2026-08-14T00:00:00.000Z: Z.ai introduced GLM-5.3 with 1M context and tool calling.
- 2026-08-17T00:00:00.000Z: AI Gateway listing and Eve default split from the Z.ai launch notes.
- 2026-08-23T17:38:57.000Z: Sets GLM-5.3's release date as August 14, 2026. Describes GLM-5.3 as a flagship model with a 1M-token context window and 128K maximum output. Adds native tool calling and structured output support per Z.ai. Adds Zhipu's statement that GLM-5.3 ranked as the strongest open-source model across mainstream benchmarks. Adds the internal red-team finding that GLM-5.3 autonomously chained reconnaissance, vulnerability identification, and exploit development. Adds availability through the GLM Coding Plan and compatibility with coding agents. Adds that Vercel AI Gateway exposes GLM-5.3 at model id zai/glm-5.3 without a separate Z.ai API key. Corroborates that Vercel AI Gateway serves GLM-5.3 at zai/glm-5.3 without a direct Z.ai API key.
- 2026-08-23T18:00:17.000Z: Description cites Z.ai's description of GLM-5.3 as a flagship model with a 1M-token context window and 128K maximum output. Description cites Z.ai-documented native tool calling and structured output support. Description cites Vercel AI Gateway availability at model id zai/glm-5.3 without a direct Z.ai API key. References the single-sourced August 14, 2026 release date. References single-sourced benchmark comparison claims generally; disputed duplicate rankings excluded. Description references internal red-team testing findings.
- 2026-08-28T07:03:19.000Z: Z.ai released GLM-5.3 on August 14, 2026. Zhipu claimed GLM-5.3 is the strongest open-source model across several mainstream benchmarks, with coding and agent capabilities approaching Claude Fable 5. GLM-5.3 is available through the GLM Coding Plan and works with coding agents like ZCode, Claude Code, or OpenCode. GLM-5.3 supports native tool calling and structured output per Z.ai. A one-million-input/output comparison prices GLM-5.3 at $5.80, cheaper than Grok 4.6 ($8.00), Kimi K3 ($18.00), Claude Opus 5 ($30.00), and GPT-5.6 Sol ($35.00). On DeepSWE v1.1, GLM-5.3 scored 66.9, trailing Kimi K3 (67.5) and Fable 5 (69.7). Eve agents still default to GLM-5.2, not GLM-5.3, when agent.ts is omitted. Internal red-team testing found GLM-5.3 autonomously chained reconnaissance, vulnerability identification, and exploit development against vulnerable test infrastructure without step-by-step human guidance.