v1

latestOpenAPI 3.1.0Apache-2.02026-07-1783444.0 KB
confidential-embeddings

Handler for confidential embeddings requests

This endpoint processes embedding requests with additional confidential computing guarantees. It forwards the request to the embeddings service and returns an encrypted response that can only be decrypted by the client.

Arguments

  • request_metadata - Extension containing request context like stack ID and encryption details
  • state - Application state containing service URLs and shared resources
  • payload - The embedding request body as JSON

Returns

Returns a Result containing either:

  • Json<Value> - The encrypted embeddings response
  • AtomaServiceError - Error details if the request processing fails

Errors

Returns AtomaServiceError::InternalError if:

  • The embeddings service request fails
  • Response processing or encryption fails
  • Stack compute unit updates fail

Example Request

{
    "model": "text-embedding-ada-002",
    "input": "The quick brown fox jumps over the lazy dog"
}
post/v1/confidential/embeddings

Request body

ciphertextstring required

The encrypted payload that needs to be processed (base64 encoded)

client_dh_public_keystring required

Client's public key for Diffie-Hellman key exchange (base64 encoded)

model_namestring required

Model name

node_dh_public_keystring required

Node's public key for Diffie-Hellman key exchange (base64 encoded)

noncestring required

Cryptographic nonce used for encryption (base64 encoded)

num_compute_unitsinteger nullable

Number of compute units to be used for the request, for image generations, as this value is known in advance (the number of pixels to generate)

plaintext_body_hashstring required

Hash of the original plaintext body for integrity verification (base64 encoded)

saltstring required

Salt value used in key derivation (base64 encoded)

stack_small_idinteger required

Unique identifier for the small stack being used

streamboolean nullable

Indicates whether this is a streaming request

Response

Confidential embeddings generated successfully

ciphertextstring required

Encrypted response body (base64 encoded)

noncestring required

Nonce used for encryption (base64 encoded)

response_hashstring nullable

Hash of the response body (base64 encoded)

signaturestring nullable

Signature of the response body (base64 encoded)

Example response

{
  "usage": {
    "completion_tokens": 12,
    "prompt_tokens": 9,
    "prompt_tokens_details": {
      "cached_tokens": 1
    },
    "total_tokens": 21
  }
}