v3

latestOpenAPI 3.1.02026-08-0419899251.9 KB
Servers

Verify Boot Attestation

Verify boot attestation and return LUKS passphrase.

This endpoint verifies the TDX quote against expected boot measurements and returns the LUKS passphrase for disk decryption if valid. For VMs running version >= 1.3.0, also returns a luks_quote_nonce for the subsequent POST /luks/attest call.

post/servers/boot/attestation

Headers

X-Chutes-Noncestring nullable

Request body

quotestring required

Base64 encoded TDX quote

miner_hotkeystring required

Miner hotkey that owns this VM

vm_namestring required

VM name/identifier

first_bootboolean

True when the VM detected a fresh (re-downloaded) image via its LUKS2 header token

Response

Successful Response

keystring required
luks_quote_noncestring nullable
root_nextstring nullable

New root passphrase the VM should rotate to (None for pre-1.4.0 VMs)

root_confirm_noncestring nullable

Single-use nonce for confirming root passphrase rotation via POST /luks/confirm

vm_auth_ss58string nullable