This page currently tracks documentation changes we can verify directly, since we don’t yet have a confirmed, complete SDK release history to publish. If you need details on a specific past SDK release, ask in the developer Telegram — we’ll backfill verified entries here as we confirm them.
Documentation
2026-09-21
- Confirmed against the
testnet-v1.0.11release (current SDK5.19.0): updated Member Delegation for the breaking grant-shape change below — the “What a grant can say” table and both code samples now show one function per grant row.
2026-09-18
- Confirmed against the
testnet-v1.0.10release (current SDK5.16.0): documented the full agent lifecycle —createAgent(now with aninitialCreditsoption),fundAgent,deleteAgent,updateAgent,deregisterAgent— in the SDK section below, Register an Organization-owned Agent, and Register a Public Agent. - Added a copy-paste AI-coding-assistant prompt pair (Claude-flavored and OpenAI-flavored) for self-service agent credit funding — see Using AI Coding Assistants.
- Added
resolveTrustAnchor()and the new requiredrtmr1_allowlistfield to Verify the trust anchor — RTMR1, not RTMR3, is now the meaningful rootfs-integrity measurement. - Documented the organisation usage-report / call-count methods (
getOrgUsageReport,getOrgWorkflowExecutionsForWindow,getOrgActivityCountForWindow),getDelegation’s newgrantee_kinds,countAgentsByContract/countAllAgentsByContract, andsetDefaultQuotas/updateQuotasin the SDK & API Reference. - Marked the
ap2(ap2/mandate) host interface removed in Host API and the reference page — the interface and its linker world were deleted from the runtime in this release. - Updated Common Errors for the new JSON error envelope on all 4xx/5xx responses (not just contract-level
bad_requests), the rewritten egress-denied message, and theagent-credit-transfererror table.
2026-09-08
- Renamed “Agent Auth” to Member Delegation throughout — the underlying vocabulary shift (
agent_auth→member_delegation,script→contract) is covered in the SDK section below — and moved the page fromoverview/toget-started/to match its nav group and URL slug. - Documented the audit-log CSV export methods (see the SDK section below) and added the Read your organization’s activity log and Running the code samples in this guide tip pages, plus Verify the trust anchor and a stateless
invoke()guide on the Member Delegation page. - SDK & API Reference: added
setEnvironment’ssandboxvalue, splittenant.contracts.execute()fromclient.executeAndDecode()(they’re on different objects), filled intenant.maps’delete/entrySet/entryGet/getStatusmethods, and corrected theoutbox/ap2WIT host interfaces from “coming soon” to “Available” (both are live, CI-tested capabilities). - Fixed several stale references caught while re-verifying every page against the confirmed
testnet-v1.0.9release: a duplicated code sample in Quickstart, outdated host-interface version numbers in Write your first TEE contract, and a broken link left over from the Member Delegation page move.
2026-07-06
- Added Quickstart — a single page to get an authenticated call working before touching contract code.
- Filled in the previously-empty ADK Tour and Member Delegation pages.
- Added this Changelog and the SDK & API Reference page.
- Fixed a duplicate “Step 4” between the Invoke and Test walkthrough pages.
- Expanded Common Errors with generic-HTTP-500 triage guidance and a table of common integration gotchas (tenant DID double-encoding,
baseUrlhandling). - Added a warning about contract version-shadowing on re-registration to Register your TEE contract.
SDK
Delegation grants: one function per grant, unified scopes (breaking) — confirmed live on testnet (testnet-v1.0.11, 2026-09-18)
A member-delegation-update / OrgDataClient.setDelegation grant’s shape changed, and the node’s decoder rejects the old shape outright rather than accepting it silently:
functions: string[]→function: string. A grant now confers exactly one function. Authorising several functions on the same contract means several grant rows — the SDK’s newfanOutGrant(base, functions)helper builds that array for you from a shared base. The contract keeps at most one grant per(grantee, contract_id, function); a later write for the same triple replaces the earlier row.scopes: string[]+read_scopes: string[]→ onescopes: { path, access }[]list.accessis a list of verbs ("read" | "write" | "delete") — only"read"is enforced today. Build a read-only list with the newreadOnlyScopes(paths)helper. A grant written under the old shape may still echo itsread_scopesvalue aslegacy_read_scopeson a read; new writes never set it.updateMemberDelegation’s read-merge-write key is now(grantee, contract_id, function), not(grantee, contract_id)— keying on the pair alone would let granting a second function on an already-granted contract silently drop the first function’s row.- The org delegation edge (
OrgDataClient.setDelegation) moved to the samefunction+scopesshape; it still carries noversion_req/allowed_hosts/window.
5.19.0 (not the 5.17.0 some intermediate PR descriptions cite — two more minor bumps landed between that PR and the tagged release; always cite the tag’s own package.json). See Member Delegation for the updated grant examples.
client/mcp/t3n-mcp’s getDelegationInstructions still advises the retired shape as of this release — a known gap on the MCP side, not fixed here. If you’re driving delegation through the MCP sidecar rather than the SDK directly, use the shape on this page, not what that tool currently prints.Agent lifecycle: create with initial credits, fund, update, delete, deregister — confirmed live on testnet (testnet-v1.0.10, 2026-09-15)
The agent lifecycle is now complete end to end. All of the below dispatch through tee:organisation/contracts or tee:agent-registry/contracts and are gated by contract-version preflights that throw (not silently no-op) against an older node.
createAgent(orgDid, name, options?)mints an org-owned agent and, since5.16.0, acceptsoptions.initialCreditsto pre-fund it in the same transaction, from the organisation’s own T3N balance. A freshly created agent otherwise starts with zero credit and its first metered call fails. Needstee:organisation/contracts≥ 0.7.0 forinitialCredits; the call throws rather than creating an unfunded agent silently against an older contract.fundAgent(agentDid, amount, options?)(new in5.16.0) tops up an agent’s balance any time after creation — from the caller’s own balance by default, or fromoptions.fromOrg’s balance (requires you to adminfromOrg, and the agent must actually be a member of it). Returns{ seqNo }, the ledger transaction’s sequence number. See Common Errors for the full authorisation-refusal table — refusals are always identity-based first, balance-based second.deleteAgent(orgDid, agentDid)(5.8.0) tears down an org-owned agent — sweeps every org-data row it holds and deletes its registry record in one transaction. Its API keys stop authenticating immediately: the delete removes the key’s principal (its DID-classification row), not each key individually. Needstee:organisation/contracts≥ 0.20.0.updateAgent(orgDid, agentDid, { agentUri?, ownerDid? })(5.8.0) is an admin-side edit of an agent’s registry record; at least one ofagentUri/ownerDidis required. Needstee:organisation/contracts≥ 0.20.0.deregisterAgent(agentDid?)(5.8.0) is how an agent removes its own registry footprint (registry record + any hosted cards). OmitagentDidto act on the caller’s own session. Needstee:agent-registry/contracts≥ 1.7.0.
t3n binary: t3n agent create --org <did> --name <name> [--initial-credits <n>], t3n agent fund --agent <did> --amount <n> [--note <text>] [--from-org <did>], t3n agent delete --org <did> <agent-did>, t3n agent update --org <did> <agent-did> [--uri <url>] [--owner <did>], t3n agent deregister [<agent-did>].
Known gap: there is currently no self-service way to fund an organisation’s own balance — only a cluster operator can. A brand-new org starts at zero, so --initial-credits / { initialCredits } on a fresh org fails with an insufficient-credit error; that’s expected, not a bug.
Trust anchor: resolveTrustAnchor(), the RTMR1 measurement, and SEV-SNP support — confirmed live on testnet (testnet-v1.0.10, 2026-09-15)
resolveTrustAnchor(env, opts?)is a new one-call convenience overfetchTrustedManifest— same verification, less boilerplate. Recommended default for constructingT3nClient’strustAnchor.TrustAnchorgained a requiredrtmr1_allowlistfield. The node now measures rootfs integrity via dm-verity + a Unified Kernel Image, landing in RTMR1 — this is the real signal going forward.rtmr3_allowlistis kept for backward compatibility only (the boot script no longer extends RTMR3). See Verify the trust anchor.- Attestation is now vendor-aware: TDX and AMD SEV-SNP. New optional trust-manifest fields
sev_snp_measurement_allowlist/sev_snp_product, and new SDK exportsverifyDkgAttestation(vendor-dispatching),verifySevSnpReport,detectQuoteVendor,sevSnpVcekUrl,fetchSevSnpCollateral— additive, alongside the existing TDX-onlyverifyTdxQuote.resolveTrustAnchor/fetchTrustedManifesthandle either vendor transparently; most integrations against the shared testnet/production clusters won’t need the lower-level exports directly. Ships as part of the same release’s AWS bare-metal SEV-SNP deployment support (trinity#2183).
Organisation usage & delegation — confirmed live on testnet (testnet-v1.0.10, 2026-09-15)
getOrgUsageReport(input),getOrgWorkflowExecutionsForWindow(orgDid, fromMs, toMs), andgetOrgActivityCountForWindow(orgDid, fromMs, toMs)(viacreateUsageReportClientFromSession) replace an earlier, since-superseded set of call-count helpers shipped and renamed within this same release cycle (getOrgCallCount*,getOrgAgentCallCountForWindow— neither exists attestnet-v1.0.10; don’t reference them).getOrgWorkflowExecutionsForWindowcounts protected-workflow executions (z:/y:client-contract calls, any outcome);getOrgActivityCountForWindowcounts every call, any contract, any outcome. Both require org-admin and both throw (rather than silently truncating) when a window is wider than the node scans in one call.getDelegation()replies now includegrantee_kinds("agent" | "human" | "org"per grantee). NewcountAgentsByContract(input)/countAllAgentsByContract(input)count delegated agents per contract for an org, single-page or drained to exhaustion. Needs org-data ≥ 2.11.0.tenant.setDefaultQuotas(opts)/tenant.updateQuotas(opts)set an organisation’s default per-agent quotas and override them for a specific agent, respectively.
AP2 host interface removed — confirmed on testnet (testnet-v1.0.10, 2026-09-15)
The ap2 (ap2/mandate) WIT host interface — previously listed as “Available” on this site — was removed from the runtime entirely: the interface, its linker world, and the backing KV policy row are gone. A contract that still imports ap2/mandate will fail to instantiate. No replacement has shipped as of this release. See Host API.
Error responses: JSON envelope everywhere, clearer egress denials — confirmed live on testnet (testnet-v1.0.10, 2026-09-15)
Framework-level rejections (malformed query strings, undecodable path segments, oversized request bodies) that used to come back as raw text/plain are now re-encoded into the standard { error, code, request_id } JSON envelope, under the original HTTP status. Separately, the egress-denied error for a member_delegation scope mismatch now names both the rejected host(s) and the actual resolved allowlist, so a scheme/port mismatch is visible directly in the message instead of requiring a guess. See Common Errors.
Delegation vocabulary — already live; the old names are deprecated, not yet removed
Everything that used to be called a grant or agent auth on the request surface is now a delegation. The two edges aremember_delegation (a member
delegating their own authority) and org_delegation (an organisation granting
authority over its contracts).
Client methods
Types
Raw
execute callers — if you build the wire payload yourself rather than
going through a client method, the function names and the body both changed:
camelCase keys (
agentDid, scriptName, validFromSecs) are rejected outright
rather than silently dropped, so a mistyped time-box can no longer be lost on
the wire.
Verdicts — checkDelegation() returns the node’s verdict as received. Grant
kinds are member_delegation / org_delegation (was agent_auth / user_grant)
and the deny codes are member_delegation_not_found / _expired /
_not_yet_valid (was agent_auth_*).
Hackathon integrations have referenced
@terminal3/t3n-sdk versions 3.5.2, 3.9.0, and 3.11.0 in the wild. We haven’t cross-checked these against an official release history yet, so we’re not listing per-version changes here until we can confirm them — a placeholder is worse than an honest gap.Audit log CSV export — confirmed live on testnet (testnet-v1.0.9, 2026-08-27)
Three new T3nClient methods export your organisation’s activity audit log to CSV, built on the existing getActivityLog read:
client.startActivityLogExport(opts?)takes the same scope/filters asgetActivityLogand starts a background export, returning anexport_id. Only one export runs at a time per caller — starting a second while one is in flight is refused.client.getActivityLogExportStatus(exportId)reportspending/ready/failed. Only your own export ids resolve — someone else’s reads as absent, not as a permissions error.client.downloadActivityLogExport(exportId)fetches the finished CSV in one response. Stays fetchable until your next export replaces it.client.exportActivityLog(opts?, poll?)is a convenience wrapper: starts the export, polls until ready (default 1s interval, 5 minute timeout, both configurable viapoll), and returns the file. Use the three calls above directly when a UI needs to own its own polling — e.g. to survive a page reload.
seq_no, timestamp_ms, caller_type, actor, on_behalf_of, org, contract, function, outcome. Notably absent: roles (doesn’t fit a fixed column) and the per-row hash from the JSON read.
getAuditEvents() and getActivityLog() themselves predate this export feature and were already real, public T3nClient methods — they just hadn’t been written up here yet. Both are now in the SDK & API Reference table alongside the export methods.