Skip to main content
GET
Get attestation report

Authorizations

Authorization
string
header
required

API key for programmatic access (Authorization: Bearer sk-<api_key>)

Query Parameters

model
string | null
signing_algo
string | null
nonce
string | null
signing_address
string | null
include_tls_fingerprint
boolean | null

Include TLS certificate fingerprint in the report data. Defaults to false; when true, report_data[..32] = SHA256(signing_address || cert_fingerprint).

provider
string | null

Restrict the report to a specific serving tier. Accepted values: near (NEAR AI's own TEE fleet) or chutes (attested Chutes fallback). When omitted, the first successfully responding provider is used.

Response

Attestation report retrieved

gateway_attestation
object
required

Response for attestation report endpoint

model_attestations
object[]
ohttp_attestation
null | object

OHTTP key attestation payload. Includes an Ed25519 signature over the decoded key_config bytes so clients can verify the HPKE key is bound to the TEE.

ohttp_key_config
string | null

Hex-encoded OHTTP key configuration (RFC 9458). Present only when OHTTP_ENABLED=true. Legacy flat field; mirrors ohttp_attestation.key_config when present.

tls_certificate
string | null

TLS certificate file (PEM) from TLS_CERT_PATH; report_data binds via SHA256 of these exact bytes