What this checks
Withinclude_tls_fingerprint=true, the direct report includes tls_cert_fingerprint: the SHA-256 hash of the direct endpoint certificate’s SubjectPublicKeyInfo (SPKI). The verified model quote binds that fingerprint, the model signing identity, and the nonce.
This check applies to the direct model connection. It does not verify a connection to cloud-api.near.ai.
Verification flow
- Generate a fresh 32-byte nonce in the client.
- Open a TLS connection to
https://<MODEL_SLUG>.completions.near.aiusing the trust configuration required by your application. - Read the peer certificate from that connection and calculate
SHA-256(SPKI_DER). - Reuse the same open connection to request
/v1/attestation/reportwithinclude_tls_fingerprint=true, the nonce, and the signing algorithm you require. - Verify the direct report’s Intel TDX quote, then check the nonce, model signer, and TLS-fingerprint binding in the verified quote.
- Compare the calculated peer SPKI hash with
tls_cert_fingerprint.
Required handling
Do not use a cached fingerprint as evidence for a new connection. Fetch new evidence after a certificate, signer, measurement, or accepted-attestation-age change.