Use Tinfoil's verifiably-private open models from the omp coding agent. Inference runs inside hardware secure enclaves that even Tinfoil cannot read into.
-
Install the plugin:
omp plugin install @tinfoilsh/omp-provider
-
Start omp and set your API key:
/loginPick Tinfoil and paste your key from the Tinfoil dashboard. For headless use, set
TINFOIL_API_KEYinstead. -
Pick a Tinfoil model with
/model.
The plugin uses the tinfoil SDK to
verify the inference enclave: it checks the enclave's attestation, confirms the
running code against the release digest signed in Sigstore, and binds the
attested key to the live connection. Every request body is then encrypted
end-to-end with HPKE, so only the verified enclave can read it.
Run /tinfoil at any time to verify again from scratch and print the verification
document, with a per-step breakdown when a step failed.
The plugin also refuses to send requests while PI_REQ_DEBUG=1. That setting
makes omp write request bodies to disk, and omp records them before this plugin
encrypts them. Unset the variable, or set TINFOIL_ALLOW_REQ_DEBUG=1 to accept
plaintext prompt logs and continue.
| Variable | Default | Purpose |
|---|---|---|
TINFOIL_API_KEY |
(none) | Your tk_… key, for headless workflows. Not needed if you use /login. Overrides the stored key. |
TINFOIL_ALLOW_REQ_DEBUG |
(unset) | Set to 1 to allow requests while PI_REQ_DEBUG=1, which writes your prompts to disk in the clear. |

