API
Proxyless API
The proxyless API lets you call Privatemode through an OpenAI-compatible HTTPS endpoint without installing the Privatemode SDK or running the proxy.
Use the proxyless API
- for evaluating Privatemode without setting up client-side software.
- if remote attestation isn't required and setting up client-side software in your environment is difficult.
Warning
The proxyless API provides memory encryption but no client-side remote attestation. You trust Privatemode's zero data retention policy without a technical enforcement. Use the Privatemode SDK or proxy if you need cryptographically verifiable protection against access by Edgeless Systems.
Connection settings
Create an API key in the Privatemode portal, then configure your client:
| Setting | Value |
|---|---|
| OpenAI-compatible base URL | https://proxyless-api.privatemode.ai/v1 |
| API key | Your Privatemode API key |
| Model | A supported Privatemode model, such as glm-latest |
Send your first request
Set your API key in the environment:
export PRIVATEMODE_API_KEY="<your-api-key>"curl --fail-with-body https://proxyless-api.privatemode.ai/v1/chat/completions \
-H "Authorization: Bearer ${PRIVATEMODE_API_KEY}" \
-H "Content-Type: application/json" \
-d '{
"model": "glm-latest",
"messages": [
{"role": "user", "content": "Hello Privatemode!"}
]
}'The response contains the assistant's reply in choices[0].message.content.
Install the OpenAI Python client:
pip install openaiCreate a Python file with the following code and run it:
import os
from openai import OpenAI
client = OpenAI(
api_key=os.environ["PRIVATEMODE_API_KEY"],
base_url="https://proxyless-api.privatemode.ai/v1",
)
response = client.chat.completions.create(
model="glm-latest",
messages=[{"role": "user", "content": "Hello Privatemode!"}],
)
print(response.choices[0].message.content)Privatemode doesn't use OpenAI services. The OpenAI client sends requests to the Privatemode base URL you configure.
Use an existing integration
For tools that support a custom OpenAI-compatible provider, configure the base URL, API key, and model from the connection settings above.
If you're adapting an example that uses http://localhost:8080/v1, replace that base URL with https://proxyless-api.privatemode.ai/v1 and configure your API key.
Prompt caching
By default, the proxyless API uses prompt caches scoped to API keys by deriving a cache salt from the request's API key. Requests using the same API key will share a prompt cache, while using a different API key will result in a different cache being used.
If multiple users share an API key, they also share its cache scope. For finer isolation, provide a private cache_salt per user or conversation.
For more information, see Prompt caching and Prompt cache security.
Security
TLS protects requests and responses in transit and terminates inside a confidential computing environment. Memory encryption protects data during processing from the underlying infrastructure.
Your application verifies a TLS certificate, not attestation evidence for the endpoint's code or configuration. Edgeless Systems controls the deployment and its TLS credentials, so you trust Edgeless Systems to operate the service as described.
With the SDK or a proxy you run in your own trusted environment, attestation verification and encryption happen on your side instead. See the API quickstart for that setup and the security overview for its guarantees.
Implementation details
The proxyless API is implemented using the Privatemode proxy, operated by Edgeless Systems inside a confidential computing environment:
- Your application sends an HTTPS request to the hosted proxy. TLS terminates inside the proxy's confidential computing environment, where the request is available in plaintext.
- The hosted proxy verifies the Privatemode backend and encrypts the prompt before forwarding it for inference.
- The hosted proxy decrypts the inference response and returns it to your application over HTTPS.
The proxy deployment manifest is public for transparency. Publishing it doesn't provide client-side attestation of the running endpoint.