System One decisions API
Ask typed questions about private text and images and get calibrated probabilities from a model inside Maple's secure enclave. Jev-compatible schema.
POST /v1/systemone answers typed questions about a JSON state, and up to four images, with calibrated probabilities instead of generated text: one masked token per question, read from GLM-5.3 Flash inside a secure enclave. The request and response follow the System One schema TypeSafe’s Jev introduced, so clients built for it work against Maple by changing the base URL and model. Use it where you would otherwise write a classifier, a router or an if statement around an LLM, and where the state is data you do not want leaving an enclave: screens, inboxes, documents, health and money.
This API is experimental. It needs Maple Proxy 0.4.2 or newer and a Maple API key. Jev clients and SDKs that accept a base URL work when pointed at the proxy with model set to glm-5-3-flash. API usage is billed separately from plans; see pricing.
Request
curl http://127.0.0.1:8080/v1/systemone \
-H "Authorization: Bearer $MAPLE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"model": "glm-5-3-flash",
"state": {"ticket": "Payment went through twice and I need one refunded today."},
"questions": {
"is_urgent": {"type": "noul", "instructions": "Does the customer need help today?"},
"intent": {
"type": "choice",
"instructions": "What does the customer want?",
"criteria": {"refund": "money back", "question": "information", "praise": "thanks"}
},
"frustration": {
"type": "score",
"instructions": "How frustrated is the customer?",
"criteria": ["Low", "Medium", "High"]
}
}
}' state is any JSON; it is embedded in the prompt as given. Questions are answered in the order you list them, and choice options are numbered in the order of their keys. Add "images": ["data:image/png;base64,..."] to show up to four images with the state. "temperature": 1 returns raw probabilities instead of calibrated ones.
{
"id": "so_7f3c…",
"model": "glm-5-3-flash",
"answers": {
"is_urgent": {"type": "noul", "noul": 0.94, "temperature": 2.48, "option_mass": 1.0},
"intent": {
"type": "choice", "choice": "refund",
"probabilities": {"refund": 0.86, "question": 0.10, "praise": 0.04},
"confidence": 0.60, "temperature": 2.41, "option_mass": 0.99
},
"frustration": {
"type": "score", "score": 1.2,
"legend": {"0": "Low", "1": "Medium", "2": "High"},
"probabilities": {"0": 0.12, "1": 0.56, "2": 0.32},
"confidence": 0.31, "temperature": 2.48, "option_mass": 0.99
}
},
"usage": {"input_tokens": 612, "output_tokens": 3, "cached_tokens": 0, "requests": 3}
} Question types
| Type | Answer | Limits |
|---|---|---|
noul | noul: probability that the statement is true. Optional criteria: {"true": …, "false": …} describes each side. | |
choice | choice: the most probable option, plus probabilities per option and confidence. | 2 to 255 options |
score | score: the expected level (0-based), plus legend, probabilities per level and confidence. | 2 to 10 ordered levels, lowest first |
Up to 64 questions per request; images up to 4 MiB each and 8 MiB in total. Every answer carries the calibration temperature applied and option_mass, the share of the model’s next-token probability that fell on the offered options. A low option_mass means the question did not fit the state well; check it before trusting a confident-looking answer.
Errors
Schema problems return 422 and size limits 413, each with a fixed message and an x-opensecret-error-code header such as system_one_too_many_questions, system_one_bad_option_count or system_one_state_too_large; the same code is in the body’s error.code. Quota, plan and capacity failures use the same statuses and codes as chat. A request that fails part-way returns no partial answers.
Cost and speed
Usage is billed as GLM-5.3 Flash tokens: one upstream request per question (two for a choice with more than 128 options), each carrying the state and the question, with one output token. A text question on a short state is about 200 input tokens. Measured on a 1080p screenshot with three questions: 1.2 to 2.9 seconds per request and about $0.003, because the image prefix is cached after the first question.
Privacy
The state, the images and the answers are decrypted only inside Maple’s attested enclave and the provider’s confidential-computing enclave, and are never stored. See how Maple’s enclaves work.