{"_id":"@concrete-security/private-ai-sdk","_rev":"3-59c1e5c61bf1dcf3d1c2d5d76fcd7ffe","name":"@concrete-security/private-ai-sdk","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@concrete-security/private-ai-sdk","version":"0.1.0","license":"MIT","_id":"@concrete-security/private-ai-sdk@0.1.0","maintainers":[{"name":"jfrery","email":"contact@concrete-security.com"}],"dist":{"shasum":"9afa8ae24d59aef62d5a39259f03631d2ac55cef","tarball":"https://registry.npmjs.org/@concrete-security/private-ai-sdk/-/private-ai-sdk-0.1.0.tgz","fileCount":6,"integrity":"sha512-wZIOUWwMKp/DeKl4eb7gPXoAW32e6DwylDGVtS7bWjBfaizCXrqGklqsfeefzuyOfmbBjfh4y57SZ1yzuSnUzQ==","signatures":[{"sig":"MEUCIEOjs/tCPbIN+hB2aJLcqqLSMZngWglSCpDKutED0mtkAiEAuQ1MYNAYn0ayhIEdhO9yQ+o5xx97U2HpnZ/YthaPI38=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":11425},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"abca4f51e6e62f3199c4fcb77a1973e2915b65a8","scripts":{"test":"node test/index.test.mjs","build":"tsc"},"_npmUser":{"name":"jfrery","email":"contact@concrete-security.com"},"_npmVersion":"11.9.0","description":"AI SDK provider with aTLS for Trusted Execution Environments","directories":{},"_nodeVersion":"22.22.0","dependencies":{"@concrete-security/atlas-node":"0.3.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.0","@types/node":"^25.2.3"},"_npmOperationalInternal":{"tmp":"tmp/private-ai-sdk_0.1.0_1772185944274_0.6979896404862895","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@concrete-security/private-ai-sdk","version":"0.1.1","license":"MIT","_id":"@concrete-security/private-ai-sdk@0.1.1","maintainers":[{"name":"jfrery","email":"contact@concrete-security.com"}],"homepage":"https://github.com/concrete-security/atlas#readme","bugs":{"url":"https://github.com/concrete-security/atlas/issues"},"dist":{"shasum":"83823a563e9f050d19f3cc32e50d9ea8cdeee86c","tarball":"https://registry.npmjs.org/@concrete-security/private-ai-sdk/-/private-ai-sdk-0.1.1.tgz","fileCount":6,"integrity":"sha512-QB9rq1KXL79qAnJmOaFCQD6pOmUPTlHo/c9vX+3LBpCrrqNS9jWO3T3l3TTxOvhC1RrvR/KCPmJ4NJVBkDypLQ==","signatures":[{"sig":"MEUCIQDCH0jQPvwioTXzomVhz8ue1DpjSqWrKk7m3ta3CU1+xwIgL7Xe5eUwTZEsLOkDA8KVHyxEfz5YqPsVL6pAeWz1K8Q=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@concrete-security%2fprivate-ai-sdk@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":11567},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"d37cc8589af8a1f818e179bf352736d234548e61","scripts":{"test":"node test/index.test.mjs","build":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12fa42f7-e3e4-4dd8-8993-165773e4a3a7"}},"repository":{"url":"git+https://github.com/concrete-security/atlas.git","type":"git","directory":"examples/private-ai-sdk"},"_npmVersion":"11.9.0","description":"AI SDK provider with aTLS for Trusted Execution Environments","directories":{},"_nodeVersion":"22.22.0","dependencies":{"@concrete-security/atlas-node":"0.3.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.0","@types/node":"^25.2.3"},"_npmOperationalInternal":{"tmp":"tmp/private-ai-sdk_0.1.1_1772188721753_0.7199629774998757","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-02-27T09:52:24.207Z","modified":"2026-05-07T09:37:54.035Z","0.1.0":"2026-02-27T09:52:24.406Z","0.1.1":"2026-02-27T10:38:41.900Z"},"bugs":{"url":"https://github.com/concrete-security/atlas/issues"},"license":"MIT","homepage":"https://github.com/concrete-security/atlas#readme","repository":{"url":"git+https://github.com/concrete-security/atlas.git","type":"git","directory":"examples/private-ai-sdk"},"description":"AI SDK provider with aTLS for Trusted Execution Environments","maintainers":[{"email":"celia.kherfallah@zama.ai","name":"kcelia"},{"email":"contact@concrete-security.com","name":"jfrery"}],"readme":"# private-ai-sdk\n\nAn [AI SDK](https://sdk.vercel.ai/) provider that wraps any AI SDK (OpenAI, Anthropic, etc.) and replaces its HTTP transport with an **attested TLS (aTLS)** channel. This ensures the model you're talking to runs inside a verified **Trusted Execution Environment (TEE)**.\n\n## Why\n\nStandard HTTPS guarantees encryption in transit, but tells you nothing about _where_ the server runs. A compromised or rogue server can decrypt your prompts.\n\naTLS solves this: before any data is exchanged, the server proves it runs inside a TEE by providing an attestation report. The client verifies this report against a **policy** (expected TEE measurements). If the attestation fails, the connection is rejected.\n\n## Who can use it\n\nAny application built on Vercel's [AI SDK](https://sdk.vercel.ai/) — coding agents, chatbots, RAG pipelines, custom scripts — can use this provider as a drop-in replacement to get secure inference. If it uses `@ai-sdk/*`, it works with private-ai-sdk.\n\nCurrently used by:\n- [**secure-opencode**](https://github.com/concrete-security/secure-opencode) — a fork of OpenCode that offers secure AI coding in the terminal.\n\n## How it works\n\n```\nHost app (e.g. opencode)\n  │\n  │  config: { sdk: \"@ai-sdk/anthropic\", policyFile: \"./cvm_policy.json\" }\n  │\n  ▼\nprivate-ai-sdk\n  │\n  │  1. Loads the policy from file or config\n  │  2. Loads the AI SDK dynamically from the host's node_modules\n  │  3. Creates an aTLS-secured fetch (via @concrete-security/atlas-node)\n  │  4. Returns the SDK provider with fetch replaced by aTLS fetch\n  │\n  ▼\nAI model running inside a TEE\n```\n\nThe host application sees a standard AI SDK provider — the aTLS layer is transparent.\n\n## Usage\n\n### Install\n\n```bash\ncd examples/private-ai-sdk\npnpm install\npnpm build   # compiles to dist/\n```\n\n### Configuration\n\nThe provider is configured through the host application's config. Example with opencode (`.opencode/opencode.jsonc`):\n\n```jsonc\n{\n  \"provider\": {\n    \"my-secure-provider\": {\n      \"npm\": \"file:///path/to/atlas/examples/private-ai-sdk/dist/index.js\",\n      \"api\": \"https://your-tee-endpoint.com/v1\",\n      \"options\": {\n        \"sdk\": \"@ai-sdk/anthropic\",\n        \"policyFile\": \"/path/to/cvm_policy.json\"\n      },\n      \"models\": {\n        \"my-model\": { \"id\": \"openai/model-name\", \"name\": \"My Secure Model\" }\n      }\n    }\n  }\n}\n```\n\n### Options\n\n| Option | Required | Description |\n|--------|----------|-------------|\n| `sdk` | Yes | npm package name of the AI SDK (e.g. `@ai-sdk/anthropic`, `@ai-sdk/openai-compatible`) |\n| `policyFile` | Yes* | Absolute path to a JSON policy file describing the expected TEE configuration |\n| `policy` | Yes* | Alternative: pass the policy object directly instead of a file |\n| `baseURL` | Yes | URL of the AI API running inside the TEE |\n| `target` | No | Override aTLS target `host:port` (derived from `baseURL` by default) |\n\n\\* One of `policyFile` or `policy` is required.\n\n### Tests\n\n```bash\n# Unit tests (no network)\nai-provider % cd examples/private-ai-sdk && node test/index.test.mjs\n```\n","readmeFilename":"README.md"}