Use a client-generated nonce
Generate 32 random bytes in the client and encode them as 64 hexadecimal characters. Retain the value until verification completes.Find the quote for your path
Verify the signer binding
For a NEAR-operated report requested withinclude_tls_fingerprint=true, the verified quote binds the signer identity, TLS certificate fingerprint, and nonce.
signing_address is algorithm-specific:
Always compare both
signing_address and signing_algo. Do not compare identities across algorithms.
Read NEAR report data
For NEAR-operated reports, quote report data is 64 bytes. The final 32 bytes are the client nonce. The first 32 bytes bind the signing identity:- Without TLS binding, they are the decoded signing identity, zero-padded on the right to 32 bytes. Decode
signing_addressfrom hex after removing any0xprefix. An ECDSA address occupies 20 bytes; an Ed25519 public key occupies all 32 bytes. - With TLS binding, they are
SHA-256(decoded signing identity || decoded tls_cert_fingerprint), where the fingerprint is the raw 32-byte SHA-256 of the certificate’s SPKI, not its hex text. Compare the quote-bound fingerprint with the peer certificate observed on the same TLS connection.
Check the configuration measurement
info.tcb_info.app_compose is the measured configuration. Hash its exact UTF-8 bytes without parsing or reserializing it. The verified quote’s MRCONFIGID is 48 bytes: 01, then that SHA-256 hash, then 15 zero bytes.
jq -j: jq -r appends a newline and produces a different hash. For a gateway report, read .gateway_attestation.info.tcb_info.app_compose.
Replay the RTMR3 event log
event_log is a list of events. The gateway returns it as a JSON string; decode it first. Replay only the events whose imr is 3, in order:
- Compute each event’s digest as
SHA-384(event_type as 4 little-endian bytes || ":" || event as UTF-8 || ":" || hex-decoded event_payload). - If the event carries a non-empty
digest, require it to equal the computed digest. Some reports return an emptydigest; use the computed one. - Start from 48 zero bytes and extend once per event:
RTMR3 = SHA-384(RTMR3 || digest).
app-id and compose-hash.
Verify GPU evidence when present
nvidia_payload, when present, is a JSON string. Decode it and send the resulting JSON object unchanged to NVIDIA NRAS; do not wrap it in another JSON property. For a NEAR AI Cloud response, save each model_attestations[] candidate as a separate report file and run this check for every candidate before accepting it.
["JWT", "<token>"]. Decode that JWT’s payload and require x-nvidia-overall-att-result to be boolean true. Reject missing or malformed GPU evidence, a nonce mismatch, or any other verdict. This minimal flow relies on the TLS-authenticated NRAS verdict; apply local JWT/EAT validation separately if your policy requires it. Define in advance whether missing GPU evidence is acceptable for your workload policy.
Check a report in code
These helpers run the quote, debug-mode, nonce, signer, configuration, and RTMR3 checks described above on one NEAR report. They usedcap-qvl to verify the quote and read report data and measurements from the verified quote. Run them on gateway_attestation, on every model_attestations[] candidate, or on a direct model report. Pass peer_spki_sha256 only when you observed the peer certificate on the same TLS connection that returned the report. GPU evidence is checked separately, as described above.
- Python
- Node.js
Requires Python 3.9 or later.
dcap-qvl fetches quote collateral from Phala’s PCCS by default. To use Intel’s PCS instead, pass INTEL_PCS_URL from the same package as the second argument to get_collateral_and_verify or getCollateralAndVerify.