What you can do
The capability catalogue: every major thing this SDK does, with the functions that do it. Skim it once to learn the shape of the surface, then use Advanced clients and OAuth for detail.
Application API
Section titled “Application API”Start with TasraClient and the deployment’s public manifest. The SDK includes wallet and credential adapters; apps do not need a separate Ethereum or cryptography library for this path.
| Goal | SDK operation |
|---|---|
| Connect and inspect a deployment | new TasraClient({manifest}), TasraClient.fromManifest, check |
| Create a ready slot with an access commitment | slots.create and a durable store |
| Create DIDs, credentials and presentations | identities.create, credentials.issue, verify, policy, present, authorize |
| Share an Ethereum account | wallets.fromSlot and named transfer |
| Encrypt documents for authorized holders | slots.bls, encrypt, decrypt |
| Sign a document independently | slots.frost, sign |
| Require distinct people to approve one signature | setApprovalPolicy, identityApprover, approveWithCredential, slot.approvals |
| Keep private state in Node | createFileStore from tasra-sdk/app/node |
Complete runnable applications demonstrate these operations. The keeper threshold and the number of human approvals are separate policies.
Advanced and compatibility APIs
Section titled “Advanced and compatibility APIs”The following capabilities remain available for integrations needing explicit protocol control or older deployment interfaces. Check deployment compatibility before choosing a managed-session or direct committee route.
- Open a managed session —
createTasraClient({nodes, verifier, identity})thenclient.openSession(slot, auth)returns aSessionthat holds the JWT + assembled key, auto-renews the JWT, re-assembles on rotation, and exposesencrypt/decrypt/sign/signDigest/close. - …or open one from just a slot id, endpoints resolved from chain — the chain-driven
surface in
tasra-sdk/chain:createTasraSlotClient(JWT path) andcreateCommitteeSlotClient(committee path) discover the keeper nodes from the slot’s on-chain committee and choose the verifier from the on-chain verifier set — no hardcoded node/verifier URLs. - Assemble a key from the fleet — fetch BLS shards from
k-of-nkeykeeper-nodes and Lagrange-assemble the master secret key in-process (the local-decrypt model — the nodes reveal their shards and you reconstruct the key), or leave the key on the fleet and decrypt over the threshold so it’s never reconstructed.fetchMpk,fetchAndAssembleKey - Encrypt / decrypt envelopes — ChaCha20-Poly1305 over a BLS12-381 G2 ElGamal
KEM, in a versioned
[KK]<base64>wire envelope.encryptEnvelope,decryptWithMasterKey,toBytes/fromBytes,buildTasraText/parseTasraPost - Sign — FROST-Ed25519 (custody one-shot + client-coordinated shard-delivery,
with local aggregation) and threshold ECDSA for EVM EOAs.
signCustody,signWithShardDelivery,signEoaDigest,aggregateFrostSignature - Decrypt over the threshold — node-coordinated custody or client-side
share-combine that never assembles the key.
decryptCustody,decryptWithShardDelivery,combineDecryptShares - Obtain & refresh DCQL-gated JWTs — the full verifier credential lifecycle:
redeem a credential or renewal for a JWT, present signed VCs, mint admin
credentials, create/revoke renewals, and revoke a holder’s slot access (re-keying
the slot).
redeemCredential,redeemRenewalToken,createRenewal/revokeRenewal,issueAdminCredential,verifyVpJwt/verifyPresentation,revokeSlotUser - Authorize with your own identity provider — no wallet, no credentials: a
user’s DPoP-bound OAuth access token from your Keycloak / Auth0 tenant authorizes the
operation through a Verifier Agent
oauthsession.createOauthSession,submitOauthResponse,waitForSession,auth0DpopSigner,createDpopKey— see the OAuth + DPoP section. - Evaluate DCQL policy — validate a rule before paying for a slot, or test a
subject against a rule client-side; a generic, opaque-scope evaluator mirroring
the reference implementation crate.
validateDcql,evaluateDcql,selectDcql - Assemble compound committee authorization tokens — per-request
verifier-committee selection, canonical hashing, ed25519 quorum verification,
verifier-set Merkle proofs.
selectVerifierCommittee,compoundTokenHash,assembleCompoundToken,verifyCompoundToken, … - Create on-chain Key Slots — sovereign, self-signed (see
tasra-sdk/chain:createTasraWriteClient().createSlot). Confirm the selected network’s creation and usage charges.httpFaucetcalls a compatible faucet supplied by the network; it does not discover a faucet or fund an account automatically. - Read & write on-chain + network-service state — the
tasra-sdk/chainsubpath.
Next: choose a client · the full API surface · prerequisites
