This experimental report is evidence for the request that returned it. It does not establish deployment evidence for a separate inference request to the same hostname.
Use this page to inspect the model environment reported by a direct https://<MODEL_SLUG>.completions.near.ai endpoint.
Request a fresh report
Generate the nonce in your client as 32 random bytes encoded as 64 hexadecimal characters.
To request evidence for a response signer, add signing_address=<SIGNER> and use the response’s signing_algo. Add include_tls_fingerprint=true only for direct TLS connection binding.
Direct response shape
The root response is the model report. Relevant fields include:
Verify the report
- Verify
intel_quote with an Intel DCAP quote verifier, such as dcap-qvl, and apply your TCB and advisory policy.
- Check the client-generated nonce and signer identity against the verified quote. Read report data from the verified quote; require
request_nonce to match the client nonce and, when report_data is present, require it to match the verified quote. Use signing_algo to interpret that identity and verify response signatures.
- Replay
event_log as described in Replay the RTMR3 event log and require the resulting RTMR3 to equal the RTMR3 in the verified quote.
- If
tcb_info is JSON text, decode it to obtain app_compose. Hash the raw app_compose string without parsing or reserializing it. Require the quote’s 48-byte MRCONFIGID to equal 01, then that SHA-256 hash, then 15 zero bytes. See Check the configuration measurement.
- When GPU evidence is present, follow GPU evidence verification.
- Apply your accepted measurement policy to the verified configuration.
- If source and build provenance are required, continue with direct image provenance.
When a response signature is being verified, match both signing_address and signing_algo. A direct report for another signer is not a substitute, even when the hostname and model name are the same.
Load balancing and freshness
The same direct model hostname can serve more than one instance. Do not assume two independent HTTP requests reached the same instance, or use a report as evidence for a separate completion sent later. Fetch fresh evidence when the signer, certificate, measured configuration, or accepted-attestation-age policy changes.