# Fix list: Seedance on BytePlus ModelArk From Anchor Terminal's listing at https://www.anchorterminal.com/tools/seedance-on-byteplus-modelark, the October 2026 research run, assessed 9 October 2026. Grade C, 59.3 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Seedance on BytePlus ModelArk: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 36 out of 100, up to 12.8 more on the total Why it scored 36: No status page was found on the site footer, the docs, the trust centre or llms.txt (0), so there is no incident record to read (0). Rate limits are published per model, 600 task creations a minute and 10 concurrent tasks for enterprise accounts on Seedance 2.5 and 2.0, 180 and 3 for individuals, 15 and 1 at 4K, plus per-second limits on retrieve, list and delete. BytePlus calls them theoretical maximums that are not guaranteed (15). The error list has 18 entries under 429 and a burst traffic guide recommends exponential backoff. The Go SDK retries and reads a retry-after value, but the docs name no Retry-After header and no idempotency key. Failed generations are not charged (11). An SLA exists for the BytePlus MLP Service at 99.5 per cent a month. It does not name ModelArk, so it is not counted (0). Seedance 2.5 is described as fully available with no preview label (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Payments & pricing, 20 out of 100, up to 10 more on the total Why it scored 20: No x402, MPP or L402 found (0). Per-token prices for every Seedance model and worked per-second examples are published without a login (20). No free quota is listed for video models, and Seedance 2.5 and 2.0 need a USD 30 balance, savings plan or resource pack before activation (0). A person registers, adds funds, activates the model and creates the key in the console (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Schema & documentation, 61 out of 100, up to 6.3 more on the total Why it scored 61: No OpenAPI or similar file was found. The reference pages link an API Explorer that is drawn by script, which we could not read (0). www.byteplus.com/llms.txt is a short site index, and docs.byteplus.com has no llms.txt or published Markdown twin (3). The create-task reference states which models accept each field, which input modes cannot be mixed, and when to use `frames` over `duration` or set `omni_reference_task_type` (17). Fields carry types, ranges, defaults and per-model values. `content` is a mixed array of text, image, video, audio and draft items, and a legacy mode reads parameters from the prompt text (13). cURL, Python and Java examples in the tutorial, and an error page of about 120 rows with HTTP status, code, message and meaning (15). A versioned `/api/v3` path, dated model IDs, and pages for product updates, model releases, deprecations and an API schema notice. Product updates are dated by month only and stop at August 2026 (13). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 4. Security & auth, 79 out of 100, up to 3.7 more on the total Why it scored 79: Model reading of the checklist (credential, training, retention, operator visibility, programme). API keys belong to a resource project, can be limited to named model IDs or endpoints and to an IP allowlist, and can be disabled or deleted. No expiry or rotation setting was found (28). The service terms say BytePlus will not use customer data to train models unless the customer opts in, and the data processing page and training FAQ agree (20). Task records last 7 days and video URLs 24 hours, DELETE removes a finished task record, and content that triggers the filter is kept 180 days. No general retention period for inputs was found (10). Keys show a last-used time and billing per key, and the console has usage statistics. The inference security audit page says it applies only to Skylark models (8). The trust centre lists ISO 27001, SOC 2 and other certifications for BytePlus as a whole, and the Go SDK repository's SECURITY.md points to the ByteDance security centre and a bounty policy. No security.txt, and no disclosure policy on byteplus.com itself (13). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 5. Transparency & trust, 63 out of 100, up to 3.2 more on the total Made of editorial 67, provenance 59. Why it scored 63: Closed models under the Customer Agreement (effective 30 September 2026) and the Service Specific Terms, which are public and dated. The Go SDK is Apache-2.0. Two cited documents, the General Terms for AI Services and the ModelArk Terms, returned no text to our reader (15). The service terms, the ModelArk data processing page and the training FAQ agree that customer data is not used for training without opt-in. Filter-triggered content is kept 180 days, and no general retention period for inputs is stated. A Data Processing Addendum is incorporated, which we did not open (20). A deprecation policy with a 30 day minimum and dated timetables for each batch (18). Processing locations are named as Malaysia, Indonesia and the EU/EEA, and a sub-processor list effective 24 September 2026 promises 15 days' notice of changes, but it has no ModelArk row (14). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Endpoint on the vendor's domain: ark.ap-southeast.bytepluses.com is not on byteplus.com (0 of 15) - Terms of service: published, but our reader couldn't read it (7 of 10) - Privacy policy: published, but our reader couldn't read it (7 of 10) - Status page: not found (0 of 10) - security.txt: not found (0 of 10) ## 6. Agent ergonomics, 85 out of 100, up to 2.4 more on the total Why it scored 85: Create returns only a task ID, the task object is small, and `callback_url` posts each status change so an agent need not poll (25). The list call pages with `page_num` and `page_size` up to 500 and filters by status, task ID, model and service tier, and `resolution`, `ratio` and `duration` size the output (20). Error codes come with a meaning and a suggested fix. On Seedance 2.5 some constraint errors arrive only after the task leaves the queue unless `omni_reference_task_type` is set (17). No idempotency key was found. Only successful videos are charged, a queued task can be cancelled with DELETE and a running one cannot (8). Only `model` and `content` are required, and official SDKs exist for Python, Go and Java (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 7. Maintenance & community, 75 out of 100, up to 2.2 more on the total Why it scored 75: Model reading. The Go SDK tagged v0.9.0 on 17 September 2026, 22 days before this check, and the create-task reference was updated on 8 October 2026 (30). The deprecation policy promises at least 30 calendar days' notice. `seedance-1-5-pro-251215` got 64 days, from 8 September to 11 November 2026, after about 11 months on sale and with no automatic migration, and a Seedance 1.0 lite model went in the May 2026 batch. The minimum is short (12 of 20). Monthly product updates, model release and deprecation pages, with support by console ticket and a Discord server we did not test (11 of 15). Current official SDKs for Python, Go and Java (15). The Go SDK is Apache-2.0 with a CI workflow and eight tags since 17 August 2026. It is below 1.0 and replaced an older SDK that the docs still need for some APIs (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - Lead correction. The batch lead named Seedance 1.0 lite, pro, pro-fast and 1.5 pro. The current line-up is Dreamina Seedance 2.5 and the 2.0 series, a 1.0 lite model was deactivated in May 2026 and 1.5 pro stops on 11 November 2026 - Every docs.byteplus.com page body is drawn by script. We read the Markdown each page embeds in its own HTML response and fetched no script bundle or data feed. About 30 pages were read on that host, more than the brief's handful - unchecked: General Terms for AI Services and the ModelArk Terms page, which returned no document to our reader - unchecked: the Data Processing Addendum, linked from the Customer Agreement and not opened - unchecked: whether the SLA for the BytePlus MLP Service covers ModelArk inference. It does not name ModelArk - unchecked: the ModelArk product page on www.byteplus.com and the API Explorer on api.byteplus.com, both drawn by script, so a downloadable API description may exist that we did not see - unchecked: whether a status page exists behind the console sign-in. None is linked from any public page read - unchecked: release dates and download counts for the Python and Java packages, and GitHub stars. PyPI's robots.txt closes its JSON pages and the GitHub API was not used - unchecked: the International Availability page, which lists the territories where the models are sold - Whether the ByteDance bounty policy named in the SDK repository covers the BytePlus ModelArk service - The model list marks `seedance-1-5-pro-251215` as Retired while the deprecation page keeps it running until 11 November 2026 - The Customer Agreement (section 3.5) bars use for competitive purposes. No clause on automated access, scraping or benchmarking was found in the Customer Agreement or the website Terms of Service. This matters before any probe is run - www.byteplus.com/llms.txt carries a line addressed to automated agents about avoiding account and internal paths. It was treated as data, and robots.txt already closes those paths ## Weaknesses - No status page was found on byteplus.com, the docs or the trust centre, and no SLA was found that names ModelArk inference - No OpenAPI file was found. The reference pages are drawn by script and docs.byteplus.com has no llms.txt - No free quota is listed for video models, and Seedance 2.5 and 2.0 need a USD 30 balance, savings plan or resource pack before activation - The service terms say BytePlus model services are not available in the United States, and resale of the video API needs written authorisation - `seedance-1-5-pro-251215`, released in December 2025, shuts down on 11 November 2026 with no automatic migration - The Customer Agreement bars use for competitive purposes. No clause on automated access or benchmarking was found, which matters before any probe is run ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - POST to `/api/v3/contents/generations/tasks` on ark.ap-southeast.bytepluses.com, then poll GET `/contents/generations/tasks/{id}` or pass `callback_url`. Callbacks need an answer within 5 seconds - Download the result at once. Video URLs last 24 hours, task records 7 days, and a Seedance 2.5 URL allows 100 downloads - Pass `resolution`, `ratio` and `duration` in the request body. Parameters appended to the prompt as `--rs` or `--dur` are weakly validated and may be ignored - On Seedance 2.5 set `omni_reference_task_type` to `edit` or `extend` so constraint errors arrive at submission. With `auto` they arrive after the task leaves the queue - Do not send reference images or video with real human faces to Seedance 2.5 or 2.0. Only a queued task can be cancelled with DELETE ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.