libertai-confidential-inference
Talk to LibertAI inference running in a confidential VM, having first established what it is.
pip install libertai-confidential-inference openai
from openai import OpenAI
from libertai_confidential import connect
tee = connect(model="qwen3.8-27b-tee")
client = OpenAI(api_key=key, base_url=tee.base_url, http_client=tee.http_client)
answer = client.chat.completions.create(
model="qwen3.8-27b-tee",
messages=[{"role": "user", "content": "..."}],
)
Requests go straight to the enclave. Nothing in between can read the prompt, LibertAI included — an intermediary that could would defeat the point.
Pass tee.http_client as well as tee.base_url: an ordinary client would
reach the same address without proving anything about it. It is an
httpx2.Client when that is installed — which is what openai 3.x expects —
and an httpx.Client otherwise, so it fits whichever SDK you have. To build
your own instead, tee.ssl_context is the context it is pinned to:
client = httpx2.Client(verify=tee.ssl_context, timeout=600)
You need an API key
Every request is checked inside the enclave by the libertai-models gateway
before it reaches the model, so a connection that verifies will still answer
401 until LibertAI has issued you a key. Attestation and authorisation are
separate: verifying tells you who you are talking to, the key is what buys
you an answer.
What a connection proves
The server is an AMD SEV-SNP guest whose TLS certificate carries a signed
attestation report. connect fetches that certificate on a throwaway
connection, and only once it has established all of the following does it pin
it as the sole trust anchor for the client that carries requests:
- AMD endorses the report — ARK → ASK → VCEK → report. AMD's roots are compiled in, so trust ends at AMD rather than at whoever served the certificate. Only the per-chip VCEK is fetched, and it is self-authenticating.
- The guest is not debuggable — otherwise the host could read its memory and every other check would be decorative.
- The report commits to the key being served — otherwise a genuine report could be relayed in front of an attacker's key.
- The launch measurement is one the deployment published — this is what ties the peer to a specific image, model and set of serving flags.
A peer that fails is never sent a prompt, and a peer that passes cannot be swapped for another afterwards.
What it does not prove
- That the workload deserves trust. The measurement pins which image
booted, not what it does. The manifest names the
source_committhe images were built from; the point of publishing it is that anyone can rebuild them and check that the measurement is the one they get. - That the platform is patched. A chip running vulnerable firmware still
gets a valid VCEK. Firmware currency is policy, so it is a caller's decision:
pass
tcb_floor=TcbFloor(...)to set one, and raise it when AMD publishes an advisory.
Discovery
connect(model=...) reads a manifest published as a signed Aleph aggregate.
No node is trusted along the way: the manifest is verified against the
publisher's signature, each item_hash names a V-PROGRAM message whose content
the client re-hashes, and the measurements come from there. Which machine runs
it and at which address are hints from an untrusted scheduler — point a client
at the wrong host and attestation fails.
Use connect(item_hash=...) to pin one deployment and skip discovery entirely.
One implementation of the checks
Hashing, signature recovery and report verification live in a Rust core shared with the JavaScript client, so there is nothing for the two to disagree about.
Metadata
Release files for libertai-confidential-inference 0.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| libertai_confidential_inference-0.0.1.tar.gz | 43.0 kB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| libertai_confidential_inference-0.0.1-cp39-abi3-win_amd64.whl | CPython 3.9 | abi3 | Windows x86-64 | Details |
| libertai_confidential_inference-0.0.1-cp39-abi3-manylinux_2_34_x86_64.whl | CPython 3.9 | abi3 | Linux glibc 2.34+ x86-64 | Details |
| libertai_confidential_inference-0.0.1-cp39-abi3-manylinux_2_34_aarch64.whl | CPython 3.9 | abi3 | Linux glibc 2.34+ ARM64 | Details |
| libertai_confidential_inference-0.0.1-cp39-abi3-macosx_11_0_arm64.whl | CPython 3.9 | abi3 | macOS 11.0+ ARM64 | Details |
| libertai_confidential_inference-0.0.1-cp39-abi3-macosx_10_12_x86_64.whl | CPython 3.9 | abi3 | macOS 10.12+ x86-64 | Details |
Total release size: 2.5 MB
Release files / libertai_confidential_inference-0.0.1.tar.gz
| Download URL | libertai_confidential_inference-0.0.1.tar.gz |
|---|---|
| Size | 43.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d1d0284622fbab6e09ba6c04053e9fa4a4ddf323f2ee75e6aa066f3c0c65a680
|
|
BLAKE2b-256 checksum How to use checksums |
c03112ee6af7226a0c4d1c3cda0c3abd08d3ea8bac8f21cc8d6d4c2079c2dc5b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency logRelease files / libertai_confidential_inference-0.0.1-cp39-abi3-win_amd64.whl
| Download URL | libertai_confidential_inference-0.0.1-cp39-abi3-win_amd64.whl |
|---|---|
| Size | 390.0 kB |
| Tags | CPython 3.9 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
5d49ac10bc7e95df70118572e31a6a0ed305db45d627e7615070448f6e5b5045
|
|
BLAKE2b-256 checksum How to use checksums |
5d4794bc118582ab755e10fdaccb892db9cb601d3585214c1a903a7c06263158
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency logRelease files / libertai_confidential_inference-0.0.1-cp39-abi3-manylinux_2_34_x86_64.whl
| Download URL | libertai_confidential_inference-0.0.1-cp39-abi3-manylinux_2_34_x86_64.whl |
|---|---|
| Size | 532.9 kB |
| Tags | CPython 3.9 Linux glibc 2.34+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
29cccd66dd5a17155b17c3f8ec8cdabc7fc1db2e1192a9d1e3dfb0c8e028ecbd
|
|
BLAKE2b-256 checksum How to use checksums |
2fc57e59aa8557d74829085c8e66b915691f248f57e5f2abcde28102c7ab449a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency logRelease files / libertai_confidential_inference-0.0.1-cp39-abi3-manylinux_2_34_aarch64.whl
| Download URL | libertai_confidential_inference-0.0.1-cp39-abi3-manylinux_2_34_aarch64.whl |
|---|---|
| Size | 563.3 kB |
| Tags | CPython 3.9 Linux glibc 2.34+ ARM64 abi3 |
|
SHA-256 checksum How to use checksums |
9c9c20934e11f9ac15b1635086ce708bc6954885dd322089571768dd057150e7
|
|
BLAKE2b-256 checksum How to use checksums |
47e235c1dd64e63f21da0ca2504849ea41a2a130bb8399177d320f3737c22aa6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency logRelease files / libertai_confidential_inference-0.0.1-cp39-abi3-macosx_11_0_arm64.whl
| Download URL | libertai_confidential_inference-0.0.1-cp39-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 500.6 kB |
| Tags | CPython 3.9 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
b877f79bbbd337f113c0f43db0f59739be1d9f987a1e458b876b9a8eecc9643d
|
|
BLAKE2b-256 checksum How to use checksums |
134dd5e2cf318717e35b55b6c557495630f1f1bcd02e84890059a7cdef61604c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency logRelease files / libertai_confidential_inference-0.0.1-cp39-abi3-macosx_10_12_x86_64.whl
| Download URL | libertai_confidential_inference-0.0.1-cp39-abi3-macosx_10_12_x86_64.whl |
|---|---|
| Size | 496.9 kB |
| Tags | CPython 3.9 abi3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
3fb7f1b8409030da7989816f52f2d8775fbb5f2c1beade54000332e890507594
|
|
BLAKE2b-256 checksum How to use checksums |
a7738d369380ac0be8650a1128b3b86b1a9f3ab33536609f8c970b3dcc4d319d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.
Transparency log