NVIDIA Attestation SDK (nvTrust)
NVIDIANVIDIA's attestation tooling for confidential computing on its GPUs and NVSwitches. It collects hardware evidence from a GPU running in confidential-computing mode and verifies it, locally or through NVIDIA's remote attestation service, so a relying party can confirm what hardware and firmware ran a workload. The C++ SDK and nvattest CLI (NVAT) succeed the Python guest tools of the original nvTrust repository.
Scored as both repositories: NVAT is the maintained successor, and the nvTrust Python SDK reached end of support on 2026-09-15, so its PyPI package is not declared. Tagged independently verifiable: the evidence is signed by the GPU and checked against NVIDIA's certificate chain, not the operator's word.
Openness
5 medium confidence- license
- Apache-2.0(OSI
- source
- public(C++ SDK, CLI, Rust bindings and the legacy Python guest tools)
- core features withheld
- no
Both repositories are published under Apache-2.0 and hold the whole toolset: the C++ SDK, the CLI, the Rust bindings and the older Python guest tools. The remote attestation service is an NVIDIA-run verifier offered beside the SDK, which also verifies locally.
- https://raw.githubusercontent.com/NVIDIA/attestation-sdk/main/LICENSE recorded 2026-09-27
Apache License, Version 2.0, full text
- https://raw.githubusercontent.com/NVIDIA/attestation-sdk/main/README.md recorded 2026-09-27
"NVAT (NVIDIA Attestation SDK) is an open-source C++ SDK"; usable "via a C API, a CLI (nvattest), or Rust bindings"; "the successor of the Python-based guest tools in nvTrust"
- https://raw.githubusercontent.com/NVIDIA/nvtrust/main/LICENSE recorded 2026-09-26
Apache License, Version 2.0, full text
- https://ungh.cc/repos/NVIDIA/attestation-sdk/files/main recorded 2026-09-27
Full file listing of NVIDIA/attestation-sdk main, 240 paths; no ee/, enterprise/, commercial/ or proprietary/ directory
- https://ungh.cc/repos/NVIDIA/nvtrust/files/main recorded 2026-09-26
Full file listing of NVIDIA/nvtrust main, 265 paths; no ee/, enterprise/, commercial/ or proprietary/ directory
Adoption
1 low confidenceGitHub stars across the two repositories are the only signal. The SDK ships as native packages from NVIDIA's download page, which publishes no count, and the retired Python package no longer measures current use. A star is not a use.
- https://ungh.cc/repos/NVIDIA/attestation-sdk recorded 2026-09-27
NVIDIA/attestation-sdk: 45 stars, pushed 2026-08-16
- https://ungh.cc/repos/NVIDIA/nvtrust recorded 2026-09-26
NVIDIA/nvtrust: 323 stars, pushed 2026-09-01
Capability
5 high confidenceA relying party checks evidence the GPU itself signs, against NVIDIA's certificate chain, so the claim about what ran does not depend on trusting the operator. That is the strongest check in this category, shared only with the zero-knowledge provers, and the trust it asks for moves to the hardware vendor.
- https://docs.nvidia.com/attestation/attestation-client-tools-sdk/latest/migration_guide.html recorded 2026-09-27
Python SDK to C++ SDK (NVAT) migration: deprecation March 15, 2026, end of support September 15, 2026; the C++ SDK evaluates Rego (Open Policy Agent) policies during attestation
- https://raw.githubusercontent.com/NVIDIA/attestation-sdk/main/README.md recorded 2026-09-27
"nvattest attest --device gpu --verifier local" attests the GPUs attached to a confidential VM
- https://raw.githubusercontent.com/NVIDIA/nvtrust/main/guest_tools/attestation_sdk/README.md recorded 2026-09-26
The SDK supports "Local and Remote GPU Attestation" and "Local and Remote NVSwitch Attestation"; requires an H100 or later GPU that supports Confidential Computing
Verified 2026-09-26