Skip to content
Tenzro
← All tutorials
Tutorial · Quickstarts

TypeScript SDK quickstart

Install tenzro-sdk, connect to Tenzro Network 1, read chain state and balances, and sign with a passkey instead of a private key.

Beginner10 min

This quickstart connects a TypeScript program to Tenzro Network 1 with the tenzro-sdk package, reads chain state and a TNZO balance, and shows how signing works when every key is rooted in hardware.

Prerequisites

  • Node.js 20 or later.
  • A passkey-capable browser for step 4.

1. Install the SDK

bash
mkdir tenzro-hello && cd tenzro-hello
npm init -y
npm install tenzro-sdk
npm install -D typescript tsx @types/node

2. Configure the client

TenzroClient takes two endpoints: endpoint for JSON-RPC and apiEndpoint for the Web API (health, status). Create index.ts:

ts
import { TenzroClient } from "tenzro-sdk";

const client = new TenzroClient({
  endpoint: "https://rpc.tenzro.xyz",
  apiEndpoint: "https://api.tenzro.xyz",
});

const health = await client.health();
console.log("node:", health.status, health.version);

Point both at your own node (http://localhost:8545 and http://localhost:8080) if you run one. You do not need to set a chain ID: the SDK reads it from the node when a transaction needs it.

3. Read chain state

Add:

ts
const height = await client.getBlockNumber();
const finalized = await client.getFinalizedBlock();
const recent = await client.getBlockRange(height - 2, height, 3);

console.log({ height, finalized });
for (const b of recent.blocks) console.log(b.height, b.hash, "txs:", b.tx_count);

Run it:

bash
npx tsx index.ts
node: healthy 1.x.x
{ height: 48213, finalized: 48211 }
48211 0x... txs: 12
48212 0x... txs: 9
48213 0x... txs: 15

finalized is the height covered by a finality certificate: blocks at or below it are final and will not be reverted. All of these reads are open methods, so they need no account or key.

4. Create a wallet and get TNZO

On Network 1 your account is a passkey, not a private key. The quickest way to get one is the console:

  1. Open the console wallet and create a passkey wallet. Your browser asks for a fingerprint, face or PIN, and the network derives your identity from the passkey.
  2. Copy your account address.
  3. Fund the account by transferring TNZO to its address from another wallet or account.

To build the same flow into your own app, follow Build a passkey wallet.

5. Read a balance

ts
const address = "0x<your-account-address>";

const wei = await client.getBalance(address);
console.log("TNZO:", Number(wei) / 1e18);

const views = await client.token.getTokenBalance(address);
console.log(views);
TNZO: 25
{
  address: '0x...',
  native: { balance_wei: '25000000000000000000', decimals: 18 },
  evm_wtnzo: { balance_wei: '25000000000000000000', decimals: 18 },
  svm_wtnzo: { balance_base_units: '25000000000', decimals: 9 },
  daml_holding: { amount_wei: '25000000000000000000', decimals: 18 }
}

There is one native TNZO balance. The EVM, SVM and DAML entries are views of it, not separate funds.

6. Sign with a passkey

Anything that moves money or changes state is an owner method: the node accepts it only with a signature from the paying account. Your SDK code never holds that key. In a browser, the passkey signs; the SDK carries the result to the network:

ts
// `hybridAssert` produces the P-256 WebAuthn assertion and the ML-DSA-65
// signature over the same 32-byte hash in one touch.
// See /tutorials/build-a-passkey-wallet for the implementation.
const { assertion, mlDsaSignatureHex } = await hybridAssert(credentialId, opHash);

const result = await client.passkeyRpc.sign({
  account_address: address,
  op_hash_hex: hex(opHash),
  credential_id_hex: hex(credentialId),
  assertion,
  ml_dsa_signature_hex: mlDsaSignatureHex,
});
console.log(result.verified); // true

Programs that run on a server or an agent host sign with that machine's own TPM 2.0 or Secure Enclave instead of a passkey. Give the machine its identity once with the CLI:

bash
tenzro setup --path network --mode consume --operator autonomous

--operator autonomous requires a usable TPM 2.0 or Secure Enclave; the machine's keys are derived from the hardware on demand and never written to disk. See Hardware-rooted keys.

Next steps