v1

latestOpenAPI 3.1.0Apache-2.02026-07-1783444.0 KB
confidential-images

Handles confidential image generation requests

This handler processes image generation requests with confidential computing requirements, tracking metrics and managing the encryption of responses. It follows the same core flow as the standard image generations handler but ensures the response is encrypted according to the client's confidential computing requirements.

Arguments

  • request_metadata - Extension containing request context including encryption metadata
  • state - Application state containing service URLs and shared resources
  • payload - The image generation request body as JSON

Returns

Returns a Result containing either:

  • Ok(Json<Value>) - The encrypted response from the image service
  • Err(AtomaServiceError) - An error if the request processing fails

Metrics

  • Increments IMAGE_GEN_NUM_REQUESTS counter with model label
  • Records request duration in IMAGE_GEN_LATENCY_METRICS histogram

Errors

Returns AtomaServiceError::InternalError if:

  • Image generation request fails
  • Response encryption fails
  • Stack compute units update fails
post/v1/confidential/images/generations

Request body

ciphertextstring required

The encrypted payload that needs to be processed (base64 encoded)

client_dh_public_keystring required

Client's public key for Diffie-Hellman key exchange (base64 encoded)

model_namestring required

Model name

node_dh_public_keystring required

Node's public key for Diffie-Hellman key exchange (base64 encoded)

noncestring required

Cryptographic nonce used for encryption (base64 encoded)

num_compute_unitsinteger nullable

Number of compute units to be used for the request, for image generations, as this value is known in advance (the number of pixels to generate)

plaintext_body_hashstring required

Hash of the original plaintext body for integrity verification (base64 encoded)

saltstring required

Salt value used in key derivation (base64 encoded)

stack_small_idinteger required

Unique identifier for the small stack being used

streamboolean nullable

Indicates whether this is a streaming request

Response

Confidential images generated successfully

ciphertextstring required

Encrypted response body (base64 encoded)

noncestring required

Nonce used for encryption (base64 encoded)

response_hashstring nullable

Hash of the response body (base64 encoded)

signaturestring nullable

Signature of the response body (base64 encoded)

Example response

{
  "usage": {
    "completion_tokens": 12,
    "prompt_tokens": 9,
    "prompt_tokens_details": {
      "cached_tokens": 1
    },
    "total_tokens": 21
  }
}