Packages
The TinyCloud js-sdk is a monorepo of layered packages: a platform-agnostic core, service implementations, platform SDKs for Node and the browser, a Rust→WASM crypto bridge, plus a VFS and a CLI. Together they are how an application speaks the protocol — building sign-in, capabilities, and data access without hand-rolling crypto.
Members
@tinycloud/sdk-core— theTinyCloudclass + platform-agnostic model: identity, spaces, manifests, delegations, capabilities.@tinycloud/sdk-services— the service clients: kv, sql, duckdb, hooks, vault, secrets, encryption.@tinycloud/node-sdk—TinyCloudNode,NodeUserAuthorization,PrivateKeySigner(server/Node runtime).@tinycloud/web-sdk—TinyCloudWeb, which wraps aTinyCloudNodefor the browser (wallet signer, session storage).@tinycloud/sdk-rs— the Rust source compiled to WASM (web-sdk-wasm,node-sdk-wasm): the session manager, SIWE/ReCap prep, delegation signing, vault crypto.@tinycloud/share-sdk/@tinycloud/share-envelope— native Share: publishing bearer and addressed links, receiving, sender history, revocation, and the sealed envelope codecs and verifier (see secrets-sharing).@tinycloud/operations— the shared operation contracts and error mapping behind the CLI and MCP.@tinycloud/mcp— the MCP server (tinycloud-mcpfor local stdio,tinycloud-mcp-httpfor the hosted service).vfs— a virtual filesystem abstraction over kv.cli— thetccommand-line interface, which also ships thetc-cliagent skill.
Mechanics
web-sdk and node-sdk are thin platform adapters over the shared sdk-core + sdk-services; the heavy cryptographic operations cross into sdk-rs (WASM). So an app targets web-sdk or node-sdk, gets the same TinyCloud API, and the WASM boundary handles signing/session management identically on both.
Install
The @tinycloud packages are on npm. Current stable: web-sdk/node-sdk/sdk-core 3.0.0, cli 1.0.0, share-sdk 1.0.0, mcp and operations 0.3.3, @openkey/sdk 0.10.2 (betas: SDKs 3.1.0, CLI 1.1.0, MCP 0.4.0). A browser app pulls web-sdk + the OpenKey SDK; a backend pulls node-sdk:
npm install @tinycloud/[email protected] @openkey/sdk # frontend
npm install @tinycloud/[email protected] # backend
npm install -g @tinycloud/[email protected] # optional: the `tc` CLI
npm install -g @tinycloud/mcp # optional: local MCP server
3.0.0 breaking changes (Oct 2026): TinyCloudWeb signs through the wallet's raw EIP-1193 provider (no ethers-style facade; the standalone RPC provider factory is gone), and the legacy broker-backed Share APIs and the plaintext ?tc2 link codec are removed in favor of native Share. The default sign-in session also rose from 7 to 30 days (see session-keys).
web-sdk/node-sdk re-export sdk-core + sdk-services, so you import from a single package per platform. The Getting Started path pins these for you via tinyboilerplate.
Relationships
Implements client access to all services; drives sign-in-flow; exposes data-apis and the delegation-api; installed and scaffolded via getting-started; the WASM layer mints the session keys and SIWE/UCAN tokens validated by cacao-chain-validation.
Status & drift
Shipped (3.0.0 stable as of Oct 4, 2026). Note architecture.md references a legacy web-core package not present in the current workspace; the layout above reflects current packages/. tinyboilerplate still pins the 2.6.3 line.
Sources
js-sdk(v3.0.0=d43e51ea):architecture.md,packages/(sdk-core, sdk-services, node-sdk, web-sdk, sdk-rs, share-sdk, share-envelope, operations, mcp, vfs, cli), packageCHANGELOG.mdfiles for the 3.0.0 breaking changes- npm registry dist-tags (checked Oct 5, 2026)