T3nClient | Low-level client — handles the encrypted session, SIWE auth, and execute transport. | Set Up Development Environment |
TenantClient | Tenant-scoped client, built around your authenticated tenantDid. | Set Up Development Environment |
setEnvironment("sandbox" | "testnet" | "production") | Selects which T3N cluster every client resolves its node URL from. Defaults to "testnet" in the public build; sandbox is an alias of testnet. | Quickstart |
loadWasmComponent() | Loads the WASM component all client-side crypto runs inside. | Quickstart |
eth_get_address(key) | Derives an Ethereum address from a key for SIWE-style auth. | Quickstart |
metamask_sign(address, _, key) | EthSign handler — signs the login challenge. | Quickstart |
createEthAuthInput(address) | Builds the input for authenticate(). | Quickstart |
fetchTrustedManifest(env, opts?) | Fetches and signature-verifies the environment’s trust manifest, returning a TrustAnchor. Required on every T3nClient — the constructor throws without it. | Verify the trust anchor |
resolveTrustAnchor(env, opts?) | One-call convenience over fetchTrustedManifest — resolves straight to a ready-to-use TrustAnchor for T3nClient, same verification, less boilerplate for the common case. Vendor-aware (TDX + AMD SEV-SNP) since testnet-v1.0.10. | Verify the trust anchor |
verifyDkgAttestation(...) | Lower-level, vendor-aware attestation check (dispatches to TDX or SEV-SNP verification based on the quote). Most integrations use resolveTrustAnchor/T3nClient instead of calling this directly. | Verify the trust anchor |
verifyTdxQuote(...) / verifySevSnpReport(...) / detectQuoteVendor(...) / sevSnpVcekUrl(...) / fetchSevSnpCollateral(...) | Vendor-specific attestation primitives underneath verifyDkgAttestation. Relevant mainly for a private-cloud cluster on SEV-SNP hardware. | Verify the trust anchor |
client.handshake() | Opens the encrypted session. Must be called before authenticate(). | Quickstart |
client.authenticate(input) | Authenticates and returns your DID — always read did.value rather than constructing it yourself. | Quickstart |
tenant.tenant.me() | Returns the authenticated tenant’s session info, including tenantDid. | Set Up Development Environment |
tenant.maps.create({ tail, visibility, readers, writers }) | Creates a tenant KV map. readers/writers default to deny — set explicitly. | Create Tenant KV Maps |
tenant.maps.update(...) | Updates an existing map’s ACL (e.g. to add a contractId). | Common Errors |
tenant.maps.delete(tail), tenant.maps.entrySet(...), tenant.maps.entryGet(...), tenant.maps.getStatus(...) | Delete a map; seed/read a single entry from outside a contract; check a map’s status. | Seed API key into secrets map |
tenant.contracts.register({ tail, version, wasm }) | Registers a compiled WASM contract under a tenant-local name. | Register your TEE contract |
tenant.contracts.execute(...) | Invokes a registered contract, returning the raw JSON-RPC result. | Invoke your contract |
client.executeAndDecode<T>(...) | Same dispatch as execute, but JSON-decodes the response for you. Lives on the base T3nClient, not tenant.contracts. | Invoke your contract |
member-delegation-update (contract call, signed by the data owner) | Grants an agent access to specific functions on a specific contract, scoped to specific hosts. Read the policy back with member-delegation-get. | Member Delegation |
client.updateMemberDelegation(grant | grant[], options?) | The SDK write for member-delegation-update. One grant confers exactly one function (since testnet-v1.0.11, @terminal3/t3n-sdk 5.19.0) — pass an array, or build one with fanOutGrant, to authorise several. | Member Delegation |
fanOutGrant(base, functions) / readOnlyScopes(paths) | Grant-building helpers: fan a shared grant base out into one row per function; build a read-only scopes list from bare paths. | Member Delegation |
getContractVersion(nodeUrl, contractId) | Looks up the currently registered version of a contract. | Invoke your contract |
client.getAuditEvents(opts?) | Reads a page of the caller’s own audit events (pii_did, limit, cursor). | Changelog |
client.getActivityLog(opts?) | Reads a page of the caller’s organisation’s agent-activity audit log — every member’s activity for an org admin, only the caller’s own (and their agents’) otherwise. Page with before_seq until next_seq is null. | Changelog |
client.exportActivityLog(opts?, poll?) | Exports getActivityLog’s scope/filters to CSV, walked to exhaustion: starts the export, polls, and returns the finished file. One export at a time per caller. | Changelog |
client.startActivityLogExport(opts?) / getActivityLogExportStatus(exportId) / downloadActivityLogExport(exportId) | The three calls exportActivityLog composes — use these instead when a UI must own its own polling (e.g. to survive a page reload). | Changelog |
invoke(opts) | Stateless, single-request agent auth over POST /api/invoke — no handshake, no session. | Member Delegation |
client.createAgent(orgDid, name, options?) | Mints an org-owned agent DID and (optionally, atomically) hosts its card. options.initialCredits pre-funds the new agent from the organisation’s own balance in the same transaction — otherwise the agent starts with zero credit. Needs tee:organisation/contracts ≥ 0.7.0 for initialCredits. | Register an Organization-owned Agent, Changelog |
client.fundAgent(agentDid, amount, options?) | Tops up an agent’s T3N credit balance any time after creation — from the caller’s own balance by default, or from options.fromOrg’s balance (requires admin of fromOrg, and agentDid must be a member of it). Returns { seqNo }. | Register an Organization-owned Agent, Changelog |
client.deleteAgent(orgDid, agentDid) | Tears down an org-owned agent: sweeps every org-data row it holds and deletes its registry record. Its API keys stop authenticating immediately (the delete removes the key’s principal). Needs tee:organisation/contracts ≥ 0.20.0. | Register an Organization-owned Agent, Changelog |
client.updateAgent(orgDid, agentDid, { agentUri?, ownerDid? }) | Admin-side edit of an agent’s registry record. At least one of agentUri / ownerDid is required. Needs tee:organisation/contracts ≥ 0.20.0. | Register an Organization-owned Agent, Changelog |
client.deregisterAgent(agentDid?) | An agent removing its own registry footprint (registry record + any hosted cards). Omit agentDid to act on the caller’s own. Needs tee:agent-registry/contracts ≥ 1.7.0. | Register a Public Agent, Changelog |
orgData.getDelegation(...) | Reads back the delegation policy for an org/contract pair. The reply’s grantee_kinds classifies each grantee as "agent", "human", or "org". | Member Delegation |
orgData.countAgentsByContract(input) / countAllAgentsByContract(input) | Counts agents delegated per contract for an org — one page, or drained to exhaustion (throws rather than silently stopping early). Needs org-data ≥ 2.11.0. | Changelog |
tenant.setDefaultQuotas(opts) | Sets an organisation’s default per-agent quotas (applied to agents that don’t have an explicit override). | Changelog |
tenant.updateQuotas(opts) | Updates quotas for a specific agent, overriding the organisation’s defaults. | Changelog |
createUsageReportClientFromSession(t3n, baseUrl).getOrgUsageReport(input) | Fetches the signed per-organisation usage report (orgDid, fromMs, toMs). Caller must admin orgDid, or the contract refuses with not_org_admin: .... | Changelog |
.getOrgWorkflowExecutionsForWindow(orgDid, fromMs, toMs) | Counts protected-workflow executions (an agent’s calls to z:/y: client contracts, any outcome) over a window of whole UTC days. Throws if the window is wider than the node will scan in one call, rather than returning a silently-partial count. | Changelog |
.getOrgActivityCountForWindow(orgDid, fromMs, toMs) | Counts every call the organisation’s agents made over the window — every contract, every outcome (not just protected workflows). Same window/refusal/truncation rules as getOrgWorkflowExecutionsForWindow. | Changelog |