2026-10-11 17:10 UTC

Independent testing will determine whether roughly 200 one-token random-number queries can reliably identify LLMs and expose silent model substitution by third-party API relays.

state: expiredheat: lowuncertainty: highconvergesscott: highmodel-fingerprinting llm-apis api-relays

What is this?

A paper titled “One Token Is Enough” reportedly proposes black-box LLM fingerprinting by measuring output distributions from roughly 200 trivial, one-token prompts, including requests for random numbers. The intended use is to verify that a third-party API relay is serving the advertised model rather than silently substituting another one. The supplied search snippets do not identify the paper’s authors or provide direct experimental results, so the method’s reliability and ability to distinguish closely related or changing model versions remain unestablished here.

Why it matters to Scott

The proposed fingerprint independently operationalizes Scott’s model/artifact-provenance concern and could become a practical compliance test for his active LiteLLM/OpenRouter routing and provider-execution benchmarks. If independent testing validates it, it extends his provenance and observability work with a cheap detector for relay substitution; the existing Basalt case also supplies an immediate application and publishing hook.
ip:framework.agent-provenance-stackip:concept.verification-boundarydev:project.remote-execdev:technology.litellmdev:technology.openrouterradar:basalt-hle-claim-dispute
queries asked of Scott's wikis
  • black-box model fingerprinting and identity verification
  • silent model substitution in API gateways and relays
  • probabilistic testing of nondeterministic LLM APIs
  • model provenance and third-party inference trust
  • LLM routing observability and compliance harnesses
  • behavioral drift versus model identity

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟠 redditis your Claude API actually Claude? a paper shows you can verify it with ~200 tiny questions
ClaudeAI
Capital-Door-229303
🟧 echo.paper ⭐The paper, “One Token Is Enough,” introduces a black-box LLM fingerprint based on distributions from trivial one-token prompts such as “nameTomas Bruckner——
🟧 hnWe probed a pinned GPT-5.5 endpoint: every request carried ~1,447 hidden tokensopwizardx10

Interpretation history

Decision trace