Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

APIGen and xLAM are related Salesforce AI Research projects, not one turnkey product called “APIGen-XLAM.” APIGen generates and verifies function-calling data; xLAM is a family of models trained for tool use. Together, they offer useful material for research and prototyping—but the public releases are research-oriented, and the xLAM-1b-fc-r model card lists a non-commercial license. Enterprises should not treat them as a supported, commercially cleared replacement for Salesforce Agentforce or a production integration platform.

What APIGen and xLAM each do

Tool-calling agents need to map a request to an available function, supply valid arguments, and respond appropriately when information is missing or a tool fails. Training those behaviors takes examples that connect user intent, tool definitions, calls, and outcomes. Hand-authoring examples is costly; unchecked synthetic examples can include invalid arguments or calls that do not match the request.

Salesforce’s research addresses different parts of that problem:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • APIGen is a pipeline for generating and verifying function-calling examples. Its original release used a library of executable APIs; Salesforce’s early description reported 3,673 APIs across 21 categories. Those figures describe that release, not a universal or current API inventory. The APIGen paper and Salesforce’s project description explain the approach.
  • xLAM means “Large Action Model.” It is Salesforce AI Research’s model family for selecting and invoking tools or APIs from instructions. The public repository describes the research releases and their resources.
  • APIGen-MT extends the data-generation work to multi-turn interactions. Associated xLAM-2-fc-r models were trained using that data. Salesforce announced the work in 2025; see its APIGen-MT overview and the research paper.

In short: APIGen is a data pipeline, xLAM is a model family, and APIGen-MT is a later multi-turn data pipeline. None of those names means that a complete, supported enterprise agent platform has been released.

How the original APIGen pipeline works

APIGen’s central idea is to put checks between synthetic generation and dataset inclusion. In broad terms, the pipeline:

  1. Collects executable tools. The original work starts from a library of API or function definitions and implementations.
  2. Generates instructions. The system creates natural-language tasks that can be addressed with the available tools.
  3. Produces candidate calls. A language model proposes structured function calls and arguments for those tasks.
  4. Checks format. Outputs are assessed against expected structure and schemas.
  5. Checks execution. Where possible, the proposed call is run. This can expose missing fields, incompatible types, or calls that do not execute.
  6. Checks semantics. Reviewers assess whether the call actually addresses the instruction and fits the tool description.
  7. Filters and assembles examples. Examples are retained according to the pipeline’s checks for use in training or evaluation.

These checks improve the quality of generated data; they do not prove that every retained call is safe or correct in every business context. Execution can show that a call runs, not that it is authorized, appropriate, reversible, or based on the right interpretation. Results depend on the available implementations, schemas, test conditions, and semantic review.

What is in the xLAM family?

Salesforce released function-calling variants as well as larger action-oriented models. The following specifications are listed in the xLAM-1b-fc-r model card; repository details can change, so verify the exact model revision and card before building against them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Model Approx. parameters Listed context length Role
xLAM-1b-fc-r 1.35B 16K Compact function-calling model
xLAM-7b-fc-r 6.91B 4K Larger function-calling model
xLAM-7b-r 7.24B 32K General/action model
xLAM-8x7b-r 46.7B total 32K Larger mixture-style model
xLAM-8x22b-r 141B total 64K Large general/action model

Parameter count and context length do not establish accuracy, latency, or cost for a particular workload. Salesforce’s papers report benchmark results, but organizations should test their own tools, schemas, permissions, and failure cases. The xLAM paper provides research context; benchmark performance is not a guarantee for a particular CRM, ERP, payments, healthcare, or government workflow.

What APIGen-MT adds

Single-turn function calling is not the whole of agent behavior. A task may require the agent to ask for missing information, gather details over several exchanges, obey policies, and sequence actions. APIGen-MT uses generated task blueprints, simulated users, APIs, policies, and iterative LLM review to produce multi-turn trajectories. Salesforce says its 2025 release includes a 5,000-trajectory dataset and xLAM-2-fc-r models. The APIGen-MT project site and NeurIPS paper describe the work.

Simulated conversations can broaden training coverage, but they cannot guarantee that the resulting behavior matches a company’s real users, policies, or legacy systems. Treat the dataset as a research resource, not a substitute for validation on representative enterprise tasks.

“Open source” does not settle commercial use

Public availability is not the same as a permissive commercial license or a production support commitment. Keep these release components distinct:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Code and papers: Public research material is available through the xLAM repository and linked publications.
  • Weights and model terms: The xLAM-1b-fc-r model card lists CC-BY-NC-4.0 and additional terms from the DeepSeek model license. It also describes the release as research-oriented and says it was not specifically designed or evaluated for every downstream use. Review the exact card and underlying terms for the particular checkpoint.
  • Datasets: Dataset availability and terms may differ from model terms. The repository says some data is only partially released, so do not assume the full internal training corpus is public.
  • Production support: A public repository and research paper do not imply an SLA, regulatory certification, commercial indemnification, guaranteed compatibility with Salesforce editions, or access to Salesforce’s internal serving and safety systems.

Because the cited model license is non-commercial, do not assume that internal use, a customer-facing service, redistribution, or a paid derivative is permitted. Ask counsel to review the precise model, base-model, and dataset terms before commercial deployment. The license on one checkpoint should not be generalized to every release without checking its own documentation.

Trying xLAM-1B locally

The model card documents a Transformers route. These examples are starting points, not a pinned production installation; behavior can vary with library versions, hardware, and model-card revisions.

pip install transformers torch
from transformers import pipeline

pipe = pipeline(
    "text-generation",
    model="Salesforce/xLAM-1b-fc-r"
)

messages = [
    {"role": "user", "content": "Who are you?"}
]

output = pipe(messages)
print(output)

For an OpenAI-compatible endpoint, the model card documents a vLLM serving path:

pip install vllm openai argparse jinja2
vllm serve "Salesforce/xLAM-1b-fc-r"

It also documents a module-based server form with port 8001:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
python -m vllm.entrypoints.openai.api_server 
  --model Salesforce/xLAM-1b-fc-r 
  --served-model-name xlam-1b-fc-r 
  --dtype bfloat16 
  --port 8001

Once the server is listening on port 8001, for example, a client can send a request to its chat completions route:

curl -X POST "http://localhost:8001/v1/chat/completions" 
  -H "Content-Type: application/json" 
  -d '{
    "model": "xlam-1b-fc-r",
    "messages": [
      {"role": "user", "content": "Find the order and issue a refund if it is eligible."}
    ],
    "max_tokens": 512,
    "temperature": 0.3
  }'

Use the port and served model name configured on your server; they need to agree with the client request. A model response is a proposed action, not evidence that an order exists or that a refund is authorized. Do not connect a first test to a live refund system. Use a harmless mock tool, inspect the output, and validate its structure before any execution.

For local or edge experimentation, Salesforce also provides a GGUF build of the 1B function-calling model. Its model page documents llama.cpp commands such as llama serve -hf Salesforce/xLAM-1b-fc-r-gguf:Q4_K_M and llama cli -hf Salesforce/xLAM-1b-fc-r-gguf:Q4_K_M. Quantization reduces resource requirements at a possible cost to output fidelity; test it against real schemas and argument patterns. See the GGUF model page.

A safer enterprise architecture

Use xLAM as a component that proposes a tool and arguments—not as an autonomous executor or security boundary. A controlled flow looks like this:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
User request
   ↓
Identity, policy, and authorization checks
   ↓
xLAM proposes a tool call
   ↓
Strict schema validation
   ↓
Approval or confirmation for sensitive actions
   ↓
Tool/API execution with scoped credentials
   ↓
Result validation and audit logging
   ↓
User-visible response

The model should never hold unrestricted credentials. Keep execution behind controls that can enforce least privilege, rate limits, idempotency, approval, and audit requirements. APIGen and xLAM do not replace an API gateway, IAM, secrets management, service catalog, schema registry, observability, transaction handling, or data-loss prevention.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Where agents fail—and controls to test

  • Malformed or wrong arguments: The right tool can still receive a wrong ID, date, unit, enum, or default. Validate against a strict schema and reject or route invalid calls for repair.
  • Ambiguous requests: “Cancel the order” may require an order number, eligibility check, reason, refund preference, and identity verification. Ask rather than infer consequential details.
  • Destructive side effects: Refunds, cancellations, account changes, permission updates, and outbound messages warrant scoped authorization, previews, approval gates, idempotency keys, and audit trails. Prefer reversible operations where possible.
  • Untrusted tool results: Emails, CRM notes, retrieved pages, and API responses can contain prompt-injection instructions. Treat returned content as data, not policy, and keep system rules and execution controls separate.
  • Real-world complexity: Synthetic examples may not cover undocumented internal APIs, inconsistent legacy schemas, nested objects, permission-dependent actions, long workflows, or partial failures. APIGen’s checks cannot guarantee workload coverage.
  • Serving drift: Chat templates, tokenizer behavior, Transformers or vLLM versions, quantization, and stop-token handling can affect structured output. Pin the exact model revision and dependencies, then test the deployed configuration.

Before a pilot, build a test set from representative, privacy-reviewed tasks. Measure correct tool selection, required and optional argument accuracy, enum and date handling, sequencing, clarification, unsupported-action refusal, tool-error recovery, prompt-injection resistance, and duplicate execution. Also measure latency, throughput, GPU memory, concurrency, operating cost, and audit completeness under the expected workload. Compare against a hosted model or deterministic workflow using the same tests; do not infer a cost or speed advantage from parameter count alone.

When to choose xLAM, another model, or Agentforce

Option Consider it when Main trade-off
Public xLAM research checkpoints You are studying tool use, benchmarking, or prototyping in a controlled environment and have confirmed the applicable license. Research-oriented terms and limited production assurances; self-hosting means owning serving and controls.
Hosted frontier-model APIs You need strong general capabilities quickly and can meet provider and data-governance requirements. External data processing, usage-based fees, and vendor dependency; less control over weights and serving.
Other open-weight models You want a self-hosted general model and can verify the specific release’s license and tool-calling performance. Commercial permissions vary by model; function-calling behavior may need prompting or fine-tuning.
Deterministic workflows Actions are high-risk, repetitive, or must be tightly predictable and auditable. Less flexible language handling, but clearer action sequencing and control.
Salesforce Agentforce You want a commercial Salesforce-native agent platform with platform-level administration and support. It is a commercial platform, not an interchangeable public xLAM checkpoint or general-purpose self-hosted model.

Salesforce has explicitly distinguished its commercial Agentforce models from the public xLAM-1B release, describing the latter as non-commercial and Agentforce as using a more performant model. Do not assume public xLAM checkpoints power Agentforce. See Salesforce’s announcement.

Self-hosting may give an organization more control over where inference runs, but it also makes the organization responsible for security, capacity, monitoring, upgrades, and reliability. Neither self-hosting nor a model’s research benchmark score removes the need to govern data and actions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Enterprise decision checklist

  • Confirm commercial rights for the exact checkpoint, its base model, and any dataset used.
  • Use mock or sandbox tools first; keep credentials and production actions outside the model.
  • Test with your actual schemas, realistic failures, ambiguous requests, and permission boundaries.
  • Require validation, authorization, and human approval where the action’s impact warrants it.
  • Pin model and serving revisions; monitor output validity, errors, latency, and cost after changes.
  • Set data-retention, redaction, logging, and prompt-injection controls for prompts and tool results.
  • Define operational ownership for patching, scaling, incident response, and rollback.

For the current public releases, APIGen is most compelling as a research contribution to scalable, verified function-calling data; xLAM is a useful model family to evaluate in controlled experiments. Commercial deployment requires a separate licensing decision and a complete operating and security layer. Neither should be mistaken for a turnkey enterprise agent product.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.