This guide uses source checks from Sep 26, 2026. Provider and gateway prices can change; preserve the checked date with every forecast.
Why This Topic Matters Now
The Sep 25 report identified Chinese AI API cost governance and GDPR-aware deployment as durable Tier 1 and Tier 2 needs, but a procurement page can become vague when it tries to promise compliance, reliability, or a permanent price. The better question is whether a buyer can reproduce the decision from dated sources and route-specific evidence.
This checklist is written for engineering, security, and procurement teams evaluating an OpenAI-compatible gateway. It separates five review layers: commercial rate evidence, capability and route evidence, data boundaries, operational controls, and rollback. AIWave's public endpoints provide a concrete evidence pattern, while the external standards and provider documentation define questions rather than automatic approval.
Source Facts Checked Today
AIWave /api/pricing was checked from production on Sep 26, 2026 and returned HTTP 200, success=true, 73 live route rows, pricing_version a42d372ccf0b5dd13ecf71203521f9d2, auto_groups=['default'], group_ratio default=1 and vip=0.9, with the public OpenAI-compatible POST path /v1/chat/completions. The public /api/v1/pricing endpoint returned HTTP 200 with 56 dated USD rows, pricing_version 83f77abde81ee3a096a672ed959ccc096f5d37a45c177ae8e03229456b5415a5, checked=2026-09-10, and updated_at=2026-09-18. Use the live response for route availability and the dated JSON for a forecast; they are not one interchangeable rate table.
The dated AIWave pricing JSON checked in this run lists 56 USD model rows. Examples include deepseek-v4-pro at $1.914 input, $0.0637362 cache-hit input, and $5.742 output; qwen3.5-plus at $0.4463422255 input and $2.6780533528 output; glm-5 at $1.55 input, $0.40000075 cache-hit input, and $4.96 output; and kimi-k3 at $4.50 input, $0.90 cache-hit input, and $22.50 output per 1M tokens, with these rows effective 2026-08-27. These are dated gateway base rates, not a permanent commercial offer.
The live response checked on Sep 26, 2026 reports current route rows, enabled groups, endpoint metadata, and group ratios default=1 and vip=0.9. It answers a different procurement question from the dated table: can the named route be seen and what account-group context applies now? Keep the live version and the dated version in the approval packet.
The European Commission data protection overview and NIST AI Risk Management Framework were checked on Sep 26, 2026. They are useful external references for governance questions, but neither page approves a particular gateway. Reviewers still need route scope, contract terms, data classification, incident ownership, and a testable rollback decision.
Planning Matrix
A source-dated planning matrix keeps the page useful for engineers and procurement reviewers. It turns a search query into an auditable route decision instead of a loose model preference.
| Review layer | Question | Evidence to request |
|---|---|---|
| Commercial | Which row and unit are quoted? | Model ID, source date, version, account group |
| Capability | Does the route accept this request? | Endpoint test, schema, limits, finish state |
| Privacy | What data crosses the boundary? | Classification, retention scope, contract |
| Operations | How are failures and limits handled? | Status, rate policy, receipts, owner |
| Security | How are keys and logs controlled? | Secret policy, redaction test, rotation |
| Rollback | What happens after a route change? | Previous route, fixture, stop and switch-back |
Implementation Pattern
The implementation pattern keeps credentials as placeholders, pins the AIWave base URL, records the model, and leaves room for route-specific controls. Production applications should move credentials into environment or secret storage.
from dataclasses import dataclass
from openai import OpenAI
@dataclass
class ReviewRecord:
model: str
pricing_checked_at: str
live_version: str
static_version: str
data_class: str
rollback_owner: str
record = ReviewRecord(
model="glm-5",
pricing_checked_at="2026-09-26",
live_version="a42d372ccf0b5dd13ecf71203521f9d2",
static_version="83f77abde81ee3a096a672ed959ccc096f5d37a45c177ae8e03229456b5415a5",
data_class="redacted-internal",
rollback_owner="platform-on-call",
)
client = OpenAI(api_key="YOUR_API_KEY_HERE", base_url="https://aiwave.live/v1")
print({"review": record, "next": "run bounded fixture"})
Turn the Query Into a Contract
For an AI API procurement review, define the request shape, model ID, data class, output ceiling, timeout, retry ceiling, owner, and source date before the first trial. A short contract gives engineering, security, and finance the same object to review when a provider changes a route or billing field.
Separate Live Routes From Dated Rates
The live AIWave pricing response answers which route rows and endpoint types are available at check time. The public pricing JSON is a dated USD snapshot for forecasting. Store both URLs, versions, checked dates, model IDs, and account-group context instead of presenting a volatile source as a permanent quote.
Use a Small Acceptance Set
A useful canary covers a normal request, a malformed request, a repeated prefix, a long output, a disconnect, and a deliberate stop condition. Record request ID, model ID, status, token usage, finish reason, retry count, and reviewer outcome. This turns a search result into evidence that can survive a route update.
Keep Data and Credentials Bounded
OpenAI-compatible clients reduce integration work, but they do not choose the right data boundary. Keep the credential server-side, use a visible placeholder in examples, redact fixtures, and attach a data-class decision to every route policy. Do not let a feature flag or model alias silently widen what crosses the API.
Make Recovery Observable
Retry only failures that are safe to retry and cap every fallback. Preserve the original request ID, mark the stop reason, and distinguish provider errors from client validation, policy rejection, and budget stops. Silent loops hide both reliability failures and billing variance.
Use AIWave's Evidence Layer
Use the Models docs, Chat Completions docs, live pricing API, dated Pricing JSON, Status, and Trust. Recheck the live route table before rollout, the dated pricing JSON before a budget review, the status page before a launch window, and the trust page before procurement. Keep each checked date visible in the record.
Release Gate
Promotion is ready when the provider source is dated, the AIWave route is rechecked, the acceptance set passes, the billing fields are understood, and a named owner can stop or reverse the change. If a field is unknown, label the work as a trial rather than production.