Skip to content
Tenzro
← All tutorials
Tutorial · Quickstarts

Rust SDK quickstart

Add tenzro-sdk to a Rust project, connect to Tenzro Network 1, read chain state and balances, and give your service a hardware-rooted identity.

Beginner10 min

This quickstart connects a Rust program to Tenzro Network 1 with the tenzro-sdk crate, reads chain state and a TNZO balance, and sets up signing the Network 1 way: from a TPM, a Secure Enclave or a passkey, never from a key file.

Prerequisites

  • Rust stable and Cargo.
  • The tenzro CLI for step 5 (see CLI reference).

1. Create a project

bash
cargo new tenzro-hello && cd tenzro-hello
cargo add tenzro-sdk
cargo add tokio --features full
cargo add anyhow

2. Connect

Build an SdkConfig with the JSON-RPC endpoint and connect. In src/main.rs:

rust
use tenzro_sdk::{SdkConfig, TenzroClient};

#[tokio::main]
async fn main() -> anyhow::Result<()> {
    let config = SdkConfig::builder()
        .endpoint("https://rpc.tenzro.xyz")
        .timeout(30_000)
        .max_retries(3)
        .build()?;
    let client = TenzroClient::connect(config).await?;

    let info = client.node_info().await?;
    println!("node {} with {} peers", info.version, info.peer_count);

    Ok(())
}

Use http://localhost:8545 as the endpoint if you run your own node. If you have a Tenzro API key for higher limits or tenant routes, add .api_key("tnz_...") to the builder (see API keys).

3. Read chain state

Extend main:

rust
let height = client.block_number().await?;
let stats = client.network_stats().await?;
let supply = client.total_supply().await?;

println!("height: {height}");
println!("network: {stats:?}");
println!("TNZO supply (wei): {supply}");
bash
cargo run
node 1.x.x with 24 peers
height: 48213
network: NetworkStats { available: true, peers_connected: 24, .. }
TNZO supply (wei): 1000000000000000000000000000

These are open methods: anyone can call them with no account and no signature. The total supply is fixed at 1,000,000,000 TNZO (18 decimals).

4. Read a balance

Create a passkey wallet in the console wallet and fund it by transferring TNZO to its address from another wallet or account, then read it back:

rust
let addr = "0x<your-account-address>";
let bal = client.token().get_token_balance(addr, None).await?;

println!("native: {} wei", bal.native.balance_wei);
println!("svm view: {} (9 decimals)", bal.svm_wtnzo.balance_base_units);
native: 25000000000000000000 wei
svm view: 25000000000 (9 decimals)

One native TNZO balance backs the EVM, SVM and DAML views of the account.

5. Give your service a hardware-rooted identity

Methods that move money or change state are owner methods: the node accepts them only when the paying account signs. On Network 1 that signature comes from hardware.

For a service or agent that runs on its own machine, give the machine an identity rooted in its TPM 2.0 (or Secure Enclave on a Mac):

bash
tenzro hardware
tenzro setup --path network --mode consume --operator autonomous

--operator autonomous requires a usable TPM 2.0 or Secure Enclave. The machine's DID is derived from its device key, and its signing keys are derived from the hardware on demand, used in memory and wiped. There is no key file to copy, back up or leak. A machine without a usable TPM runs under a person's delegated authority instead: --operator self, backed by that person's passkey.

For an operation a person must approve, the person signs with their passkey. From a terminal:

bash
tenzro passkey sign --account-address 0x<account> --op-hash-hex <32-byte-hash> \
  --rpc https://rpc.tenzro.xyz

This opens the approval in the browser, where the passkey produces the WebAuthn signature and the wallet adds the ML-DSA-65 leg. From Rust, the same check is available through client.passkey_rpc(), whose sign call verifies a hybrid passkey signature against the account.

Next steps