Rust SDK quickstart
Add tenzro-sdk to a Rust project, connect to Tenzro Network 1, read chain state and balances, and give your service a hardware-rooted identity.
This quickstart connects a Rust program to Tenzro Network 1 with the tenzro-sdk crate, reads chain state and a TNZO balance, and sets up signing the Network 1 way: from a TPM, a Secure Enclave or a passkey, never from a key file.
Prerequisites
- Rust stable and Cargo.
- The
tenzroCLI for step 5 (see CLI reference).
1. Create a project
cargo new tenzro-hello && cd tenzro-hello
cargo add tenzro-sdk
cargo add tokio --features full
cargo add anyhow2. Connect
Build an SdkConfig with the JSON-RPC endpoint and connect. In src/main.rs:
use tenzro_sdk::{SdkConfig, TenzroClient};
#[tokio::main]
async fn main() -> anyhow::Result<()> {
let config = SdkConfig::builder()
.endpoint("https://rpc.tenzro.xyz")
.timeout(30_000)
.max_retries(3)
.build()?;
let client = TenzroClient::connect(config).await?;
let info = client.node_info().await?;
println!("node {} with {} peers", info.version, info.peer_count);
Ok(())
}Use http://localhost:8545 as the endpoint if you run your own node. If you have a Tenzro API key for higher limits or tenant routes, add .api_key("tnz_...") to the builder (see API keys).
3. Read chain state
Extend main:
let height = client.block_number().await?;
let stats = client.network_stats().await?;
let supply = client.total_supply().await?;
println!("height: {height}");
println!("network: {stats:?}");
println!("TNZO supply (wei): {supply}");cargo runnode 1.x.x with 24 peers
height: 48213
network: NetworkStats { available: true, peers_connected: 24, .. }
TNZO supply (wei): 1000000000000000000000000000These are open methods: anyone can call them with no account and no signature. The total supply is fixed at 1,000,000,000 TNZO (18 decimals).
4. Read a balance
Create a passkey wallet in the console wallet and fund it by transferring TNZO to its address from another wallet or account, then read it back:
let addr = "0x<your-account-address>";
let bal = client.token().get_token_balance(addr, None).await?;
println!("native: {} wei", bal.native.balance_wei);
println!("svm view: {} (9 decimals)", bal.svm_wtnzo.balance_base_units);native: 25000000000000000000 wei
svm view: 25000000000 (9 decimals)One native TNZO balance backs the EVM, SVM and DAML views of the account.
5. Give your service a hardware-rooted identity
Methods that move money or change state are owner methods: the node accepts them only when the paying account signs. On Network 1 that signature comes from hardware.
For a service or agent that runs on its own machine, give the machine an identity rooted in its TPM 2.0 (or Secure Enclave on a Mac):
tenzro hardware
tenzro setup --path network --mode consume --operator autonomous--operator autonomous requires a usable TPM 2.0 or Secure Enclave. The machine's DID is derived from its device key, and its signing keys are derived from the hardware on demand, used in memory and wiped. There is no key file to copy, back up or leak. A machine without a usable TPM runs under a person's delegated authority instead: --operator self, backed by that person's passkey.
For an operation a person must approve, the person signs with their passkey. From a terminal:
tenzro passkey sign --account-address 0x<account> --op-hash-hex <32-byte-hash> \
--rpc https://rpc.tenzro.xyzThis opens the approval in the browser, where the passkey produces the WebAuthn signature and the wallet adds the ML-DSA-65 leg. From Rust, the same check is available through client.passkey_rpc(), whose sign call verifies a hybrid passkey signature against the account.
Next steps
- The full SDK surface: SDK and SDK reference.
- Which methods are open, owner or admin: RPC access.
- How hardware-rooted keys work: Hardware-rooted keys.
- The same quickstart in TypeScript: TypeScript SDK quickstart.