Skip to main content
Every NEAR verification flow starts with a client-generated nonce and a verified quote. HTTP fields are inputs to compare with the quote. They are not a replacement for quote verification.

Use a client-generated nonce

Generate 32 random bytes in the client and encode them as 64 hexadecimal characters. Retain the value until verification completes.
Send this value with the attestation request. Reject a report unless the verified quote contains the same nonce in its request-freshness binding.

Find the quote for your path

Verify the signer binding

For a NEAR-operated report requested with include_tls_fingerprint=true, the verified quote binds the signer identity, TLS certificate fingerprint, and nonce. signing_address is algorithm-specific: Always compare both signing_address and signing_algo. Do not compare identities across algorithms.

Read NEAR report data

For NEAR-operated reports, quote report data is 64 bytes. The final 32 bytes are the client nonce. The first 32 bytes bind the signing identity:
  • Without TLS binding, they are the decoded signing identity, zero-padded on the right to 32 bytes. Decode signing_address from hex after removing any 0x prefix. An ECDSA address occupies 20 bytes; an Ed25519 public key occupies all 32 bytes.
  • With TLS binding, they are SHA-256(decoded signing identity || decoded tls_cert_fingerprint), where the fingerprint is the raw 32-byte SHA-256 of the certificate’s SPKI, not its hex text. Compare the quote-bound fingerprint with the peer certificate observed on the same TLS connection.
This layout applies only to NEAR-operated dstack reports; other providers have their own report-data contracts.

Check the configuration measurement

info.tcb_info.app_compose is the measured configuration. Hash its exact UTF-8 bytes without parsing or reserializing it. The verified quote’s MRCONFIGID is 48 bytes: 01, then that SHA-256 hash, then 15 zero bytes.
Use jq -j: jq -r appends a newline and produces a different hash. For a gateway report, read .gateway_attestation.info.tcb_info.app_compose.

Replay the RTMR3 event log

event_log is a list of events. The gateway returns it as a JSON string; decode it first. Replay only the events whose imr is 3, in order:
  1. Compute each event’s digest as SHA-384(event_type as 4 little-endian bytes || ":" || event as UTF-8 || ":" || hex-decoded event_payload).
  2. If the event carries a non-empty digest, require it to equal the computed digest. Some reports return an empty digest; use the computed one.
  3. Start from 48 zero bytes and extend once per event: RTMR3 = SHA-384(RTMR3 || digest).
Require the result to equal RTMR3 in the verified quote. Recomputing each digest also authenticates the event payloads, such as app-id and compose-hash.

Verify GPU evidence when present

nvidia_payload, when present, is a JSON string. Decode it and send the resulting JSON object unchanged to NVIDIA NRAS; do not wrap it in another JSON property. For a NEAR AI Cloud response, save each model_attestations[] candidate as a separate report file and run this check for every candidate before accepting it.
The request is sent only when the payload nonce matches. The payload goes on standard input because an eight-GPU payload is close to the shell’s argument-size limit. NRAS returns a JSON array whose first entry is ["JWT", "<token>"]. Decode that JWT’s payload and require x-nvidia-overall-att-result to be boolean true. Reject missing or malformed GPU evidence, a nonce mismatch, or any other verdict. This minimal flow relies on the TLS-authenticated NRAS verdict; apply local JWT/EAT validation separately if your policy requires it. Define in advance whether missing GPU evidence is acceptable for your workload policy.

Check a report in code

These helpers run the quote, debug-mode, nonce, signer, configuration, and RTMR3 checks described above on one NEAR report. They use dcap-qvl to verify the quote and read report data and measurements from the verified quote. Run them on gateway_attestation, on every model_attestations[] candidate, or on a direct model report. Pass peer_spki_sha256 only when you observed the peer certificate on the same TLS connection that returned the report. GPU evidence is checked separately, as described above.
Requires Python 3.9 or later.
The helpers raise when the quote’s TCB status is not in your accepted set; the error lists Intel’s advisory IDs. Decide which statuses your verification policy accepts. dcap-qvl fetches quote collateral from Phala’s PCCS by default. To use Intel’s PCS instead, pass INTEL_PCS_URL from the same package as the second argument to get_collateral_and_verify or getCollateralAndVerify.