SDK
Use a JavaScript or Python library when you are building an application. Supply your API key; the SDK handles allocation, Room verification, encryption and signed responses.
Start with the Quickstart for a complete first request. JavaScript runs in a server-side Node.js process; Python requires Python 3.10 or later. Keep long-lived keys in a trusted process, never in browser code distributed to users.
JavaScript
npm install https://api.turboprivate.ai/sdk/javascript.tgz openai
import OpenAI from 'openai'
import { connect } from '@turboprivate/sdk'
const room = await connect({
apiKey: process.env.TURBOPRIVATE_API_KEY,
model: 'gemma-4-26b-a4b',
controls: { effort: 'low' },
})
try {
const openai = new OpenAI({ baseURL: room.baseURL, apiKey: room.apiKey })
const result = await openai.chat.completions.create({
model: room.model,
messages: [{ role: 'user', content: 'Explain this diff.' }],
})
console.log(result.choices[0].message.content)
console.log(room.settings)
} finally {
await room.close()
}
The SDK runs the encrypted client and a credentialed loopback adapter in this Node process. The room itself remains remote.
For multi-turn conversations, retain and resend the required history in your application. See Context & caching for a two-turn example, stable prompt structure and cache usage counters.
Python
pip install https://api.turboprivate.ai/sdk/python.tgz
import os
from turboprivate import TurboPrivate
with TurboPrivate(
api_key=os.environ["TURBOPRIVATE_API_KEY"],
model="gemma-4-26b-a4b",
controls={"effort": "low"},
) as client:
result = client.chat.completions.create(
messages=[{"role": "user", "content": "Explain this diff."}],
)
print(result["choices"][0]["message"]["content"])
print(client.settings)
assert client.last_receipt_verified
Pass stream=True for an iterator of decrypted Chat Completions chunks.
Local compatible wires
The JavaScript SDK and turboprivate connect expose a random-token-protected listener on 127.0.0.1:
| method | local path | protocol |
|---|---|---|
| POST | /v1/messages | Anthropic Messages, streaming and non-streaming |
| POST | /v1/responses | OpenAI Responses |
| POST | /v1/chat/completions | OpenAI Chat Completions |
| GET | /v1/models | The room's one model and declared modalities |
The tpl_… token prevents another local account from spending through that listener. It is not a service API key.
Controls, streaming and errors
- Controls: read names, values, aliases and defaults from
/api/config. Standing room controls can be overridden for one request with the declared wire field. Invalid explicit values return 400. - Streaming: all three local wire formats stream. Keep-alives cover a long first-token wait.
- Reconnect: an SDK may replace a disappeared room only before any response chunk reaches the caller. It never joins partial answers from two rooms.
- Errors: status and error meaning pass through so client retry policy can distinguish authentication, balance, availability and request errors.
- Receipts: clients verify signed responses and expose the verification result. A valid room signature is not, by itself, proof of confidential hardware.
Verify your session
See Privacy proofs for exporting evidence, offline verification and the limits of each result. A verified response signature is not a hardware-confidentiality guarantee.