Servers
Verify Boot Attestation
Verify boot attestation and return LUKS passphrase.
auth (signed mode) carries the X-Chutes-Signature header, only consulted when the matched measurement is a release candidate: it must be an RSA-SHA256 signature (openssl dgst) over the boot nonce by one of the measurement's authorized operator signing keys, proving possession (see authorize_rc_measurement). Ignored for published measurements, so existing VMs are unaffected.
This endpoint verifies the TDX quote against expected boot measurements and returns the LUKS passphrase for disk decryption if valid. For VMs running version >= 1.3.0, also returns a luks_quote_nonce for the subsequent POST /luks/attest call.
post/servers/boot/attestation
Headers
X-Chutes-Noncestring nullable
X-Operator-Signaturestring nullable
X-Chutes-Hotkeystring nullable
X-Chutes-Signaturestring nullable
Request body
Response
Successful Response