Skip to main content
This page currently tracks documentation changes we can verify directly, since we don’t yet have a confirmed, complete SDK release history to publish. If you need details on a specific past SDK release, ask in the developer Telegram — we’ll backfill verified entries here as we confirm them.

Documentation

2026-09-21

  • Confirmed against the testnet-v1.0.11 release (current SDK 5.19.0): updated Member Delegation for the breaking grant-shape change below — the “What a grant can say” table and both code samples now show one function per grant row.

2026-09-18

  • Confirmed against the testnet-v1.0.10 release (current SDK 5.16.0): documented the full agent lifecycle — createAgent (now with an initialCredits option), fundAgent, deleteAgent, updateAgent, deregisterAgent — in the SDK section below, Register an Organization-owned Agent, and Register a Public Agent.
  • Added a copy-paste AI-coding-assistant prompt pair (Claude-flavored and OpenAI-flavored) for self-service agent credit funding — see Using AI Coding Assistants.
  • Added resolveTrustAnchor() and the new required rtmr1_allowlist field to Verify the trust anchor — RTMR1, not RTMR3, is now the meaningful rootfs-integrity measurement.
  • Documented the organisation usage-report / call-count methods (getOrgUsageReport, getOrgWorkflowExecutionsForWindow, getOrgActivityCountForWindow), getDelegation’s new grantee_kinds, countAgentsByContract/countAllAgentsByContract, and setDefaultQuotas/updateQuotas in the SDK & API Reference.
  • Marked the ap2 (ap2/mandate) host interface removed in Host API and the reference page — the interface and its linker world were deleted from the runtime in this release.
  • Updated Common Errors for the new JSON error envelope on all 4xx/5xx responses (not just contract-level bad_requests), the rewritten egress-denied message, and the agent-credit-transfer error table.

2026-09-08

  • Renamed “Agent Auth” to Member Delegation throughout — the underlying vocabulary shift (agent_auth→member_delegation, script→contract) is covered in the SDK section below — and moved the page from overview/ to get-started/ to match its nav group and URL slug.
  • Documented the audit-log CSV export methods (see the SDK section below) and added the Read your organization’s activity log and Running the code samples in this guide tip pages, plus Verify the trust anchor and a stateless invoke() guide on the Member Delegation page.
  • SDK & API Reference: added setEnvironment’s sandbox value, split tenant.contracts.execute() from client.executeAndDecode() (they’re on different objects), filled in tenant.maps’ delete/entrySet/entryGet/getStatus methods, and corrected the outbox/ap2 WIT host interfaces from “coming soon” to “Available” (both are live, CI-tested capabilities).
  • Fixed several stale references caught while re-verifying every page against the confirmed testnet-v1.0.9 release: a duplicated code sample in Quickstart, outdated host-interface version numbers in Write your first TEE contract, and a broken link left over from the Member Delegation page move.

2026-07-06

  • Added Quickstart — a single page to get an authenticated call working before touching contract code.
  • Filled in the previously-empty ADK Tour and Member Delegation pages.
  • Added this Changelog and the SDK & API Reference page.
  • Fixed a duplicate “Step 4” between the Invoke and Test walkthrough pages.
  • Expanded Common Errors with generic-HTTP-500 triage guidance and a table of common integration gotchas (tenant DID double-encoding, baseUrl handling).
  • Added a warning about contract version-shadowing on re-registration to Register your TEE contract.

SDK

Delegation grants: one function per grant, unified scopes (breaking) — confirmed live on testnet (testnet-v1.0.11, 2026-09-18)

A member-delegation-update / OrgDataClient.setDelegation grant’s shape changed, and the node’s decoder rejects the old shape outright rather than accepting it silently:
  • functions: string[] → function: string. A grant now confers exactly one function. Authorising several functions on the same contract means several grant rows — the SDK’s new fanOutGrant(base, functions) helper builds that array for you from a shared base. The contract keeps at most one grant per (grantee, contract_id, function); a later write for the same triple replaces the earlier row.
  • scopes: string[] + read_scopes: string[] → one scopes: { path, access }[] list. access is a list of verbs ("read" | "write" | "delete") — only "read" is enforced today. Build a read-only list with the new readOnlyScopes(paths) helper. A grant written under the old shape may still echo its read_scopes value as legacy_read_scopes on a read; new writes never set it.
  • updateMemberDelegation’s read-merge-write key is now (grantee, contract_id, function), not (grantee, contract_id) — keying on the pair alone would let granting a second function on an already-granted contract silently drop the first function’s row.
  • The org delegation edge (OrgDataClient.setDelegation) moved to the same function + scopes shape; it still carries no version_req/allowed_hosts/window.
SDK version at this release: 5.19.0 (not the 5.17.0 some intermediate PR descriptions cite — two more minor bumps landed between that PR and the tagged release; always cite the tag’s own package.json). See Member Delegation for the updated grant examples.
client/mcp/t3n-mcp’s getDelegationInstructions still advises the retired shape as of this release — a known gap on the MCP side, not fixed here. If you’re driving delegation through the MCP sidecar rather than the SDK directly, use the shape on this page, not what that tool currently prints.

Agent lifecycle: create with initial credits, fund, update, delete, deregister — confirmed live on testnet (testnet-v1.0.10, 2026-09-15)

The agent lifecycle is now complete end to end. All of the below dispatch through tee:organisation/contracts or tee:agent-registry/contracts and are gated by contract-version preflights that throw (not silently no-op) against an older node.
  • createAgent(orgDid, name, options?) mints an org-owned agent and, since 5.16.0, accepts options.initialCredits to pre-fund it in the same transaction, from the organisation’s own T3N balance. A freshly created agent otherwise starts with zero credit and its first metered call fails. Needs tee:organisation/contracts ≥ 0.7.0 for initialCredits; the call throws rather than creating an unfunded agent silently against an older contract.
  • fundAgent(agentDid, amount, options?) (new in 5.16.0) tops up an agent’s balance any time after creation — from the caller’s own balance by default, or from options.fromOrg’s balance (requires you to admin fromOrg, and the agent must actually be a member of it). Returns { seqNo }, the ledger transaction’s sequence number. See Common Errors for the full authorisation-refusal table — refusals are always identity-based first, balance-based second.
  • deleteAgent(orgDid, agentDid) (5.8.0) tears down an org-owned agent — sweeps every org-data row it holds and deletes its registry record in one transaction. Its API keys stop authenticating immediately: the delete removes the key’s principal (its DID-classification row), not each key individually. Needs tee:organisation/contracts ≥ 0.20.0.
  • updateAgent(orgDid, agentDid, { agentUri?, ownerDid? }) (5.8.0) is an admin-side edit of an agent’s registry record; at least one of agentUri / ownerDid is required. Needs tee:organisation/contracts ≥ 0.20.0.
  • deregisterAgent(agentDid?) (5.8.0) is how an agent removes its own registry footprint (registry record + any hosted cards). Omit agentDid to act on the caller’s own session. Needs tee:agent-registry/contracts ≥ 1.7.0.
CLI equivalents ship in the same t3n binary: t3n agent create --org <did> --name <name> [--initial-credits <n>], t3n agent fund --agent <did> --amount <n> [--note <text>] [--from-org <did>], t3n agent delete --org <did> <agent-did>, t3n agent update --org <did> <agent-did> [--uri <url>] [--owner <did>], t3n agent deregister [<agent-did>]. Known gap: there is currently no self-service way to fund an organisation’s own balance — only a cluster operator can. A brand-new org starts at zero, so --initial-credits / { initialCredits } on a fresh org fails with an insufficient-credit error; that’s expected, not a bug.

Trust anchor: resolveTrustAnchor(), the RTMR1 measurement, and SEV-SNP support — confirmed live on testnet (testnet-v1.0.10, 2026-09-15)

  • resolveTrustAnchor(env, opts?) is a new one-call convenience over fetchTrustedManifest — same verification, less boilerplate. Recommended default for constructing T3nClient’s trustAnchor.
  • TrustAnchor gained a required rtmr1_allowlist field. The node now measures rootfs integrity via dm-verity + a Unified Kernel Image, landing in RTMR1 — this is the real signal going forward. rtmr3_allowlist is kept for backward compatibility only (the boot script no longer extends RTMR3). See Verify the trust anchor.
  • Attestation is now vendor-aware: TDX and AMD SEV-SNP. New optional trust-manifest fields sev_snp_measurement_allowlist / sev_snp_product, and new SDK exports verifyDkgAttestation (vendor-dispatching), verifySevSnpReport, detectQuoteVendor, sevSnpVcekUrl, fetchSevSnpCollateral — additive, alongside the existing TDX-only verifyTdxQuote. resolveTrustAnchor/fetchTrustedManifest handle either vendor transparently; most integrations against the shared testnet/production clusters won’t need the lower-level exports directly. Ships as part of the same release’s AWS bare-metal SEV-SNP deployment support (trinity#2183).

Organisation usage & delegation — confirmed live on testnet (testnet-v1.0.10, 2026-09-15)

  • getOrgUsageReport(input), getOrgWorkflowExecutionsForWindow(orgDid, fromMs, toMs), and getOrgActivityCountForWindow(orgDid, fromMs, toMs) (via createUsageReportClientFromSession) replace an earlier, since-superseded set of call-count helpers shipped and renamed within this same release cycle (getOrgCallCount*, getOrgAgentCallCountForWindow — neither exists at testnet-v1.0.10; don’t reference them). getOrgWorkflowExecutionsForWindow counts protected-workflow executions (z:/y: client-contract calls, any outcome); getOrgActivityCountForWindow counts every call, any contract, any outcome. Both require org-admin and both throw (rather than silently truncating) when a window is wider than the node scans in one call.
  • getDelegation() replies now include grantee_kinds ("agent" | "human" | "org" per grantee). New countAgentsByContract(input) / countAllAgentsByContract(input) count delegated agents per contract for an org, single-page or drained to exhaustion. Needs org-data ≥ 2.11.0.
  • tenant.setDefaultQuotas(opts) / tenant.updateQuotas(opts) set an organisation’s default per-agent quotas and override them for a specific agent, respectively.

AP2 host interface removed — confirmed on testnet (testnet-v1.0.10, 2026-09-15)

The ap2 (ap2/mandate) WIT host interface — previously listed as “Available” on this site — was removed from the runtime entirely: the interface, its linker world, and the backing KV policy row are gone. A contract that still imports ap2/mandate will fail to instantiate. No replacement has shipped as of this release. See Host API.

Error responses: JSON envelope everywhere, clearer egress denials — confirmed live on testnet (testnet-v1.0.10, 2026-09-15)

Framework-level rejections (malformed query strings, undecodable path segments, oversized request bodies) that used to come back as raw text/plain are now re-encoded into the standard { error, code, request_id } JSON envelope, under the original HTTP status. Separately, the egress-denied error for a member_delegation scope mismatch now names both the rejected host(s) and the actual resolved allowlist, so a scheme/port mismatch is visible directly in the message instead of requiring a guess. See Common Errors.

Delegation vocabulary — already live; the old names are deprecated, not yet removed

Everything that used to be called a grant or agent auth on the request surface is now a delegation. The two edges are member_delegation (a member delegating their own authority) and org_delegation (an organisation granting authority over its contracts). Client methods Types Raw execute callers — if you build the wire payload yourself rather than going through a client method, the function names and the body both changed: camelCase keys (agentDid, scriptName, validFromSecs) are rejected outright rather than silently dropped, so a mistyped time-box can no longer be lost on the wire. Verdicts — checkDelegation() returns the node’s verdict as received. Grant kinds are member_delegation / org_delegation (was agent_auth / user_grant) and the deny codes are member_delegation_not_found / _expired / _not_yet_valid (was agent_auth_*).
Hackathon integrations have referenced @terminal3/t3n-sdk versions 3.5.2, 3.9.0, and 3.11.0 in the wild. We haven’t cross-checked these against an official release history yet, so we’re not listing per-version changes here until we can confirm them — a placeholder is worse than an honest gap.

Audit log CSV export — confirmed live on testnet (testnet-v1.0.9, 2026-08-27)

Three new T3nClient methods export your organisation’s activity audit log to CSV, built on the existing getActivityLog read:
  • client.startActivityLogExport(opts?) takes the same scope/filters as getActivityLog and starts a background export, returning an export_id. Only one export runs at a time per caller — starting a second while one is in flight is refused.
  • client.getActivityLogExportStatus(exportId) reports pending / ready / failed. Only your own export ids resolve — someone else’s reads as absent, not as a permissions error.
  • client.downloadActivityLogExport(exportId) fetches the finished CSV in one response. Stays fetchable until your next export replaces it.
  • client.exportActivityLog(opts?, poll?) is a convenience wrapper: starts the export, polls until ready (default 1s interval, 5 minute timeout, both configurable via poll), and returns the file. Use the three calls above directly when a UI needs to own its own polling — e.g. to survive a page reload.
The exported CSV’s columns are a fixed wire format: seq_no, timestamp_ms, caller_type, actor, on_behalf_of, org, contract, function, outcome. Notably absent: roles (doesn’t fit a fixed column) and the per-row hash from the JSON read.
getAuditEvents() and getActivityLog() themselves predate this export feature and were already real, public T3nClient methods — they just hadn’t been written up here yet. Both are now in the SDK & API Reference table alongside the export methods.