Quickstart
In the app
- Open the app. The attestation panel verifies the enclave before anything else happens: a fresh nonce, the TDX quote checked against Intel's root, the keyset bound to your nonce.
- Pick a model. Only models RedPill serves inside a TEE are listed.
- Choose a route. Your key sends requests from your tab straight to
api.redpill.ai; Hermetic never sees the key, the question or the answer. Protocol relay forwards your exact bytes with the protocol's key and stores nothing. - Talk. Under every answer, the app shows whether the enclave's receipt verified: signature, request hash, response hash, and the upstream the gateway checked.
- Close the session. Download the receipt and, once the registry is live, seal it on Robinhood Chain.
In your own code
The checks the app runs come from open-source libraries you can use directly.
pnpm add @phala/aci-verifier
import { verifyService } from "@phala/aci-verifier";
const { verdict, lines } = await verifyService("https://api.redpill.ai");
console.log(verdict.line);
// VERIFIED (4 pass, 1 skipped) when run from a browser, which cannot read TLS keys
for (const l of lines) console.log(l.status, l.id, l.title);
To check one answer, send the request, keep the exact bytes, and fetch the receipt the gateway names in the x-receipt-id header:
import { reportTranscript, receiptTranscript } from "@phala/aci-verifier";
const nonce = [...crypto.getRandomValues(new Uint8Array(32))].map((b) => b.toString(16).padStart(2, "0")).join("");
const report = await (await fetch(`https://api.redpill.ai/v1/aci/attestation?nonce=${nonce}`)).json();
const att = await reportTranscript(report, nonce);
const body = JSON.stringify({ model: "z-ai/glm-5.3", messages, max_tokens: 1024 });
const res = await fetch("https://api.redpill.ai/v1/chat/completions", {
method: "POST",
headers: { authorization: `Bearer ${KEY}`, "content-type": "application/json" },
body,
});
const text = await res.text();
const receipt = await (await fetch(`https://api.redpill.ai/v1/aci/receipts/${res.headers.get("x-receipt-id")}`, {
headers: { authorization: `Bearer ${KEY}` },
})).json();
const check = await receiptTranscript(receipt, att.verification.keyset!, att.verification.workloadKeysetDigest!, body, text);
console.log(check.verdict.line);
A Hermetic SDK that wraps these steps, builds the session receipt and seals it is on the roadmap.