Skip to main content

libertai-confidential-inference

Talk to LibertAI inference running in a confidential VM, having first established what it is.

pip install libertai-confidential-inference openai
from openai import OpenAI
from libertai_confidential import connect

tee = connect(model="qwen3.8-27b-tee")
client = OpenAI(api_key=key, base_url=tee.base_url, http_client=tee.http_client)

answer = client.chat.completions.create(
    model="qwen3.8-27b-tee",
    messages=[{"role": "user", "content": "..."}],
)

Requests go straight to the enclave. Nothing in between can read the prompt, LibertAI included — an intermediary that could would defeat the point.

Pass tee.http_client as well as tee.base_url: an ordinary client would reach the same address without proving anything about it. It is an httpx2.Client when that is installed — which is what openai 3.x expects — and an httpx.Client otherwise, so it fits whichever SDK you have. To build your own instead, tee.ssl_context is the context it is pinned to:

client = httpx2.Client(verify=tee.ssl_context, timeout=600)

You need an API key

Every request is checked inside the enclave by the libertai-models gateway before it reaches the model, so a connection that verifies will still answer 401 until LibertAI has issued you a key. Attestation and authorisation are separate: verifying tells you who you are talking to, the key is what buys you an answer.

What a connection proves

The server is an AMD SEV-SNP guest whose TLS certificate carries a signed attestation report. connect fetches that certificate on a throwaway connection, and only once it has established all of the following does it pin it as the sole trust anchor for the client that carries requests:

  1. AMD endorses the report — ARK → ASK → VCEK → report. AMD's roots are compiled in, so trust ends at AMD rather than at whoever served the certificate. Only the per-chip VCEK is fetched, and it is self-authenticating.
  2. The guest is not debuggable — otherwise the host could read its memory and every other check would be decorative.
  3. The report commits to the key being served — otherwise a genuine report could be relayed in front of an attacker's key.
  4. The launch measurement is one the deployment published — this is what ties the peer to a specific image, model and set of serving flags.

A peer that fails is never sent a prompt, and a peer that passes cannot be swapped for another afterwards.

What it does not prove

  • That the workload deserves trust. The measurement pins which image booted, not what it does. The manifest names the source_commit the images were built from; the point of publishing it is that anyone can rebuild them and check that the measurement is the one they get.
  • That the platform is patched. A chip running vulnerable firmware still gets a valid VCEK. Firmware currency is policy, so it is a caller's decision: pass tcb_floor=TcbFloor(...) to set one, and raise it when AMD publishes an advisory.

Discovery

connect(model=...) reads a manifest published as a signed Aleph aggregate. No node is trusted along the way: the manifest is verified against the publisher's signature, each item_hash names a V-PROGRAM message whose content the client re-hashes, and the measurements come from there. Which machine runs it and at which address are hints from an untrusted scheduler — point a client at the wrong host and attestation fails.

Use connect(item_hash=...) to pin one deployment and skip discovery entirely.

One implementation of the checks

Hashing, signature recovery and report verification live in a Rust core shared with the JavaScript client, so there is nothing for the two to disagree about.

Metadata

Release files for libertai-confidential-inference 0.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for libertai-confidential-inference 0.0.1
File Size Uploaded
libertai_confidential_inference-0.0.1.tar.gz 43.0 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for libertai-confidential-inference 0.0.1
File
libertai_confidential_inference-0.0.1-cp39-abi3-win_amd64.whl CPython 3.9 abi3 Windows x86-64 Details
libertai_confidential_inference-0.0.1-cp39-abi3-manylinux_2_34_x86_64.whl CPython 3.9 abi3 Linux glibc 2.34+ x86-64 Details
libertai_confidential_inference-0.0.1-cp39-abi3-manylinux_2_34_aarch64.whl CPython 3.9 abi3 Linux glibc 2.34+ ARM64 Details
libertai_confidential_inference-0.0.1-cp39-abi3-macosx_11_0_arm64.whl CPython 3.9 abi3 macOS 11.0+ ARM64 Details
libertai_confidential_inference-0.0.1-cp39-abi3-macosx_10_12_x86_64.whl CPython 3.9 abi3 macOS 10.12+ x86-64 Details

Total release size: 2.5 MB

Release files / libertai_confidential_inference-0.0.1.tar.gz

Download URL libertai_confidential_inference-0.0.1.tar.gz
Size 43.0 kB
Tags Source
SHA-256 checksum
How to use checksums
d1d0284622fbab6e09ba6c04053e9fa4a4ddf323f2ee75e6aa066f3c0c65a680
BLAKE2b-256 checksum
How to use checksums
c03112ee6af7226a0c4d1c3cda0c3abd08d3ea8bac8f21cc8d6d4c2079c2dc5b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release files / libertai_confidential_inference-0.0.1-cp39-abi3-win_amd64.whl

Download URL libertai_confidential_inference-0.0.1-cp39-abi3-win_amd64.whl
Size 390.0 kB
Tags CPython 3.9 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
5d49ac10bc7e95df70118572e31a6a0ed305db45d627e7615070448f6e5b5045
BLAKE2b-256 checksum
How to use checksums
5d4794bc118582ab755e10fdaccb892db9cb601d3585214c1a903a7c06263158
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release files / libertai_confidential_inference-0.0.1-cp39-abi3-manylinux_2_34_x86_64.whl

Download URL libertai_confidential_inference-0.0.1-cp39-abi3-manylinux_2_34_x86_64.whl
Size 532.9 kB
Tags CPython 3.9 Linux glibc 2.34+ x86-64 abi3
SHA-256 checksum
How to use checksums
29cccd66dd5a17155b17c3f8ec8cdabc7fc1db2e1192a9d1e3dfb0c8e028ecbd
BLAKE2b-256 checksum
How to use checksums
2fc57e59aa8557d74829085c8e66b915691f248f57e5f2abcde28102c7ab449a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release files / libertai_confidential_inference-0.0.1-cp39-abi3-manylinux_2_34_aarch64.whl

Download URL libertai_confidential_inference-0.0.1-cp39-abi3-manylinux_2_34_aarch64.whl
Size 563.3 kB
Tags CPython 3.9 Linux glibc 2.34+ ARM64 abi3
SHA-256 checksum
How to use checksums
9c9c20934e11f9ac15b1635086ce708bc6954885dd322089571768dd057150e7
BLAKE2b-256 checksum
How to use checksums
47e235c1dd64e63f21da0ca2504849ea41a2a130bb8399177d320f3737c22aa6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release files / libertai_confidential_inference-0.0.1-cp39-abi3-macosx_11_0_arm64.whl

Download URL libertai_confidential_inference-0.0.1-cp39-abi3-macosx_11_0_arm64.whl
Size 500.6 kB
Tags CPython 3.9 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
b877f79bbbd337f113c0f43db0f59739be1d9f987a1e458b876b9a8eecc9643d
BLAKE2b-256 checksum
How to use checksums
134dd5e2cf318717e35b55b6c557495630f1f1bcd02e84890059a7cdef61604c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release files / libertai_confidential_inference-0.0.1-cp39-abi3-macosx_10_12_x86_64.whl

Download URL libertai_confidential_inference-0.0.1-cp39-abi3-macosx_10_12_x86_64.whl
Size 496.9 kB
Tags CPython 3.9 abi3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
3fb7f1b8409030da7989816f52f2d8775fbb5f2c1beade54000332e890507594
BLAKE2b-256 checksum
How to use checksums
a7738d369380ac0be8650a1128b3b86b1a9f3ab33536609f8c970b3dcc4d319d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.0.1 This release

6 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page