curl --request GET \
--url https://cloud-api.near.ai/v1/attestation/report \
--header 'Authorization: Bearer <token>'import requests
url = "https://cloud-api.near.ai/v1/attestation/report"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://cloud-api.near.ai/v1/attestation/report', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://cloud-api.near.ai/v1/attestation/report",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://cloud-api.near.ai/v1/attestation/report"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://cloud-api.near.ai/v1/attestation/report")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://cloud-api.near.ai/v1/attestation/report")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"gateway_attestation": {
"event_log": "<string>",
"info": "<unknown>",
"intel_quote": "<string>",
"report_data": "<string>",
"request_nonce": "<string>",
"signing_address": "<string>",
"signing_algo": "<string>",
"tls_cert_fingerprint": "<string>",
"vpc": {
"vpc_hostname": "<string>",
"vpc_server_app_id": "<string>"
}
},
"model_attestations": [
{}
],
"ohttp_attestation": {
"key_config": "<string>",
"signature": "<string>",
"signing_algo": "<string>",
"signing_key": "<string>"
},
"ohttp_key_config": "<string>",
"tls_certificate": "<string>"
}{
"error": {
"message": "<string>",
"type": "<string>",
"code": "<string>",
"param": "<string>"
}
}{
"error": {
"message": "<string>",
"type": "<string>",
"code": "<string>",
"param": "<string>"
}
}{
"error": {
"message": "<string>",
"type": "<string>",
"code": "<string>",
"param": "<string>"
}
}Get attestation report
Get hardware attestation report for TEE verification. Requires an API key (nearai/infra#193); report retrieval is non-billable — no usage or billing records are created.
curl --request GET \
--url https://cloud-api.near.ai/v1/attestation/report \
--header 'Authorization: Bearer <token>'import requests
url = "https://cloud-api.near.ai/v1/attestation/report"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://cloud-api.near.ai/v1/attestation/report', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://cloud-api.near.ai/v1/attestation/report",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://cloud-api.near.ai/v1/attestation/report"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://cloud-api.near.ai/v1/attestation/report")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://cloud-api.near.ai/v1/attestation/report")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"gateway_attestation": {
"event_log": "<string>",
"info": "<unknown>",
"intel_quote": "<string>",
"report_data": "<string>",
"request_nonce": "<string>",
"signing_address": "<string>",
"signing_algo": "<string>",
"tls_cert_fingerprint": "<string>",
"vpc": {
"vpc_hostname": "<string>",
"vpc_server_app_id": "<string>"
}
},
"model_attestations": [
{}
],
"ohttp_attestation": {
"key_config": "<string>",
"signature": "<string>",
"signing_algo": "<string>",
"signing_key": "<string>"
},
"ohttp_key_config": "<string>",
"tls_certificate": "<string>"
}{
"error": {
"message": "<string>",
"type": "<string>",
"code": "<string>",
"param": "<string>"
}
}{
"error": {
"message": "<string>",
"type": "<string>",
"code": "<string>",
"param": "<string>"
}
}{
"error": {
"message": "<string>",
"type": "<string>",
"code": "<string>",
"param": "<string>"
}
}Authorizations
API key for programmatic access (Authorization: Bearer sk-<api_key>)
Query Parameters
Include TLS certificate fingerprint in the report data. Defaults to false; when true, report_data[..32] = SHA256(signing_address || cert_fingerprint).
Restrict the report to a specific serving tier.
Accepted values: near (NEAR AI's own TEE fleet) or chutes (attested Chutes fallback).
When omitted, the first successfully responding provider is used.
Response
Attestation report retrieved
Response for attestation report endpoint
Show child attributes
Show child attributes
Show child attributes
Show child attributes
OHTTP key attestation payload. Includes an Ed25519 signature over the decoded
key_config bytes so clients can verify the HPKE key is bound to the TEE.
Show child attributes
Show child attributes
Hex-encoded OHTTP key configuration (RFC 9458). Present only when OHTTP_ENABLED=true.
Legacy flat field; mirrors ohttp_attestation.key_config when present.
TLS certificate file (PEM) from TLS_CERT_PATH; report_data binds via SHA256 of these exact bytes