cloud-api.near.ai terminates at the endpoint bound to gateway_attestation.
Browser Fetch APIs do not expose the peer certificate or its SPKI. A browser client can verify a gateway quote without TLS binding, but cannot establish this TLS connection-binding property.
What this checks
When you requestinclude_tls_fingerprint=true, gateway_attestation.tls_cert_fingerprint is the SHA-256 hash of the gateway certificate’s SubjectPublicKeyInfo (SPKI). The verified quote binds that fingerprint, the gateway signing identity, and the nonce.
This is a gateway check. It does not bind the client connection to an upstream model endpoint.
Verification flow
- Generate a fresh 32-byte nonce in the client.
- Open a TLS connection to
cloud-api.near.aiusing the trust configuration required by your application. - Read the peer certificate from that connection and calculate
SHA-256(SPKI_DER). - Reuse the same open connection to request
/v1/attestation/reportwithinclude_tls_fingerprint=true, the nonce, and the signing algorithm you require. Include the normalAuthorization: Bearer <YOUR_NEAR_AI_CLOUD_API_KEY>header. NEAR AI Cloud gateway report retrieval requires an API key. - Verify
gateway_attestation.intel_quote, then check the nonce, gateway signer, and TLS-fingerprint binding in the verified quote. - Compare the calculated peer SPKI hash with
gateway_attestation.tls_cert_fingerprint.
tls_certificate response field is not a substitute for the peer certificate observed on the connection. A command-line report request alone also cannot establish the same-connection property.
This result applies to the connection used for the evidence request. When it must also cover an inference request, send that request over the same open TLS connection. If the client reconnects, repeat the flow.
Required handling
Do not use a cached fingerprint as evidence for a new connection. Fetch new evidence after a certificate, signer, measurement, or accepted-attestation-age change.