confidential is the third data mode of the API. It is reserved for running inference in an attested confidential environment. It is not available yet: this page describes how the API behaves until it is.
The value is part of the API contract.data_mode can read standard, zero_retention or confidential in the belarel block, so you can write code that recognizes all three.
You cannot select it. Keys are created as standard or zero_retention only, and POST /v1/keys accepts only those two values for a sub-key.
Calls are refused. If a key in confidential mode makes an inference or embeddings call, the API answers 501 with the code not_implemented. Nothing is sent to a model and nothing is billed.
{
"error": {
"message": "Confidential inference (attested enclave) is not available yet for API keys — use a standard or zero_retention key",
Confidential inference is meant for workloads where you need evidence about where your content is processed, not only a policy about how it is retained: the model would run in an isolated, attested environment, and a call would only be served once that environment has been verified. Until that is available and documented here, treat the mode as a placeholder and make no security decision based on it.