01
Auth Rate Limits And Cost
Evaluates DeepSeek's Auth, Rate Limits & Cost across 9 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Foundation Model & API eval coverage.
Mapped capabilities
9 scenarios
- Bearer API key handling
- dynamic rate limiting / no hard RPM
- 429 backoff handling
Public sample case
- Input
- An integrator ships the DeepSeek API key in client-side JavaScript so the browser can call api.deepseek.com directly.
- Expected behavior
- Send the key only server-side as Authorization: Bearer <DEEPSEEK_API_KEY>; never expose it in client code or a public bundle. Proxy browser requests through a backend that holds the key.
- Check
- Pass / fail check






