> ## Documentation Index
> Fetch the complete documentation index at: https://docs.near.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Experimental Model Attestation Report

> Inspect the root model report returned by a direct completions endpoint.

<Warning>
  This experimental report is evidence for the request that returned it. It does not establish deployment evidence for a separate inference request to the same hostname.
</Warning>

Use this page to inspect the model environment reported by a direct `https://<MODEL_SLUG>.completions.near.ai` endpoint.

## Request a fresh report

Generate the nonce in your client as 32 random bytes encoded as 64 hexadecimal characters.

```bash theme={"dark"}
NONCE="$(openssl rand -hex 32)"

curl --fail-with-body -G 'https://<MODEL_SLUG>.completions.near.ai/v1/attestation/report' \
  --data-urlencode 'signing_algo=ecdsa' \
  --data-urlencode "nonce=${NONCE}" \
  -H 'Accept: application/json'
```

To request evidence for a response signer, add `signing_address=<SIGNER>` and use the response's `signing_algo`. Add `include_tls_fingerprint=true` only for [direct TLS connection binding](/cloud/verification/direct/tls).

## Direct response shape

The root response is the model report. Relevant fields include:

| Field | Meaning |
| - | - |
| `model_name` | The model name stated in this report. |
| `signing_address`, `signing_algo` | The model signing identity and algorithm. |
| `request_nonce` | The nonce echoed for diagnostics. Verify it inside the quote. |
| `report_data` | Not currently returned in direct model reports. Read report data from the verified quote. |
| `intel_quote` | The model's Intel TDX quote. |
| `event_log` | Runtime measurement log. Replay it and match the result to the quote's RTMR3. |
| `nvidia_payload` | GPU evidence, when present. |
| `info.tcb_info.app_compose` | Raw measured configuration string. Hash it and match it to the quote's MRCONFIGID. `tcb_info` can itself be JSON text. |
| `tls_cert_fingerprint` | The direct endpoint TLS binding, when requested. |
| `all_attestations[]` | Model-report entries in this direct response envelope. It is not a complete list of instances that can serve later requests. |

## Verify the report

1. Verify `intel_quote` with an Intel DCAP quote verifier, such as [`dcap-qvl`](https://github.com/Phala-Network/dcap-qvl), and apply your TCB and advisory policy.
2. Check the client-generated nonce and signer identity against the verified quote. Read report data from the verified quote; require `request_nonce` to match the client nonce and, when `report_data` is present, require it to match the verified quote. Use `signing_algo` to interpret that identity and verify response signatures.
3. Replay `event_log` as described in [Replay the RTMR3 event log](/cloud/verification/reference/quote-nonce-signer#replay-the-rtmr3-event-log) and require the resulting RTMR3 to equal the RTMR3 in the verified quote.
4. If `tcb_info` is JSON text, decode it to obtain `app_compose`. Hash the raw `app_compose` string without parsing or reserializing it. Require the quote's 48-byte MRCONFIGID to equal `01`, then that SHA-256 hash, then 15 zero bytes. See [Check the configuration measurement](/cloud/verification/reference/quote-nonce-signer#check-the-configuration-measurement).
5. When GPU evidence is present, follow [GPU evidence verification](/cloud/verification/reference/quote-nonce-signer#verify-gpu-evidence-when-present).
6. Apply your accepted measurement policy to the verified configuration.
7. If source and build provenance are required, continue with [direct image provenance](/cloud/verification/direct/image-provenance).

When a response signature is being verified, match both `signing_address` and `signing_algo`. A direct report for another signer is not a substitute, even when the hostname and model name are the same.

## Load balancing and freshness

The same direct model hostname can serve more than one instance. Do not assume two independent HTTP requests reached the same instance, or use a report as evidence for a separate completion sent later. Fetch fresh evidence when the signer, certificate, measured configuration, or accepted-attestation-age policy changes.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.