Install
The SDK is available on npm. It requires Node.js 24 or later for Node usage.chat.mjs and run it with node chat.mjs.
E2EE
End-to-end encryption (E2EE) is disabled by default inInferenceClient. Set e2ee: true to enable it for a model with supported model attestation. When enabled, the SDK verifies the required attestation evidence, encrypts supported Chat fields to a key from the verified model evidence, and decrypts the response automatically.
Verification
InferenceClient verifies the Gateway and every returned NEAR model-attestation candidate before sending an E2EE Chat Completion. Call verifyResponse() after a completion to verify its response signature with the request and response bytes captured by the client.
verifyResponse() is explicit. For a streaming completion, consume the entire stream first, then call it with the completion ID so the SDK can verify the exact response bytes.Set a TCB policy
By default, the SDK accepts the Intel TCB statusesUpToDate and OutOfDate. To require UpToDate, apply a policy to both the Gateway and model evidence:
Runtime behavior
For Node, import from@nearai/inference-sdk/node. It verifies the Gateway TLS peer and binds later requests to the verified Gateway identity. For a browser or application proxy, import from @nearai/inference-sdk; browser Fetch cannot read the TLS peer certificate, so that entry point does not perform Gateway TLS binding.
For a manual verification flow or a custom policy, see Verification.
OHTTP
Setohttp: true to encapsulate Chat requests and responses with OHTTP. OHTTP uses the SDK’s default Ed25519 signing algorithm; it is not compatible with signingAlgo: 'ecdsa'.
verifyResponse() calls stay the same. Before sending Chat, the SDK verifies the Gateway’s signed OHTTP configuration; a missing or invalid configuration blocks the request. OHTTP encapsulates the exchange to the Gateway, while E2EE encrypts supported Chat fields to the verified model key.
OHTTP applies only to Chat. Attestation and signature requests remain regular HTTPS. The configured endpoint or proxy must expose
/ohttp at the same origin. Authorization and custom headers sent on the outer request, along with the client’s network address, are not hidden by OHTTP.Examples
See the Inference SDK examples and setup instructions for runnable projects.- InferenceClient: streaming and non-streaming Chat, response verification, and Gateway image provenance checks.
- OpenAI SDK integration: use
InferenceClient.fetchwith the OpenAI client. - Manual verification and E2EE: work directly with attestation, encryption, and signature-verification helpers.