Skip to main content
Use this guide when your application sends inference requests to https://cloud-api.near.ai.

What you can verify

Gateway attestation

Verify the NEAR AI Cloud gateway deployment before an inference request.

Model attestation

Verify every returned NEAR model-attestation candidate before an inference request.

TLS connection binding

Verify that your live HTTPS connection terminates at the attested gateway.

Response signatures

Verify exact response bytes against the matching preflight signer.

Image provenance

Check that the software images in the attested environment meet your source and build policy.

Verify a completion

  1. Before the completion, request and verify fresh gateway evidence. If your policy requires NEAR model evidence, request it with the canonical model ID and provider=near, verify every returned candidate, and retain the verified results. For Gateway TLS binding, follow the same-connection TLS flow.
  2. Send the completion with the same canonical model ID and x-no-aliasing: true. Retain the exact request and response bytes.
  3. Fetch the completion signature. Its signature_kind selects the verified gateway report or the uniquely matching verified model report; it does not decide which deployment checks your policy required.
Use one explicit signing_algo for the deployment reports and completion signature. Do not rely on endpoint defaults to choose a matching signer. Start with Gateway attestation. The other guides provide the individual checks.