> ## Documentation Index
> Fetch the complete documentation index at: https://docs.datafdn.org/llms.txt
> Use this file to discover all available pages before exploring further.

# CDR SDK Reference Overview

> A detailed description of every function in the CDR SDK

<Note>
  This reference tracks the Aeneid release of `@piplabs/cdr-sdk` (`v0.2.1`),
  available on npm.
</Note>

The CDR SDK (`@piplabs/cdr-sdk`) provides a TypeScript client for interacting with the DATA Foundation's Confidential Data Rails system. It handles threshold encryption, vault management, and on-chain access control.

| Language                                                       | Package                                                                                         | GitHub                                                                                                 |
| -------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------ |
| <Icon icon="screwdriver-wrench" iconType="solid" /> TypeScript | <Icon icon="box-open" iconType="solid" /> [npm](https://www.npmjs.com/package/@piplabs/cdr-sdk) | <Icon icon="arrow-up-right-from-square" iconType="solid" /> [Code](https://github.com/piplabs/cdr-sdk) |

***

<Card title="Step-by-Step Guide" icon="house" href="/developers/cdr-sdk">
  Learn CDR through a series of tutorials with the CDR SDK Integration Guide.
</Card>

## CDRClient

The main entry point. Provides access to three sub-clients:

```typescript theme={null}
import { CDRClient } from "@piplabs/cdr-sdk";

const client = new CDRClient({
  network: "testnet",
  publicClient, // viem PublicClient
  walletClient, // optional viem WalletClient
  apiUrl: "http://172.192.41.96:1317", // DATA Foundation API REST endpoint
  // minThresholdRatio: 0.67, // optional threshold override, in [0, 1]
});

client.observer; // read-only queries
client.uploader; // encryption & vault allocation
client.consumer; // decryption & read requests
```

## Current Surface Area

* `observer`: vaults, fees, DKG state, validator registrations, and validator
  attestations
* `uploader`: `uploadCDR`, `uploadFile`, `allocate`, `write`, and
  `encryptDataKey`
* `consumer`: `accessCDR`, `downloadFile`, `read`, `collectPartials`, and
  `decryptDataKey`
* `crypto`: low-level TDH2, ECIES, and SGX attestation verification helpers

The client also exposes high-level aliases:

* `createVault` as an alias for `uploadCDR`
* `readVault` as an alias for `accessCDR`
* `createFileVault` as an alias for `uploadFile`
* `readFileVault` as an alias for `downloadFile`

## State Backends

The client reads from two backends:

| Backend                  | Configured by  | Purpose                                                                         |
| ------------------------ | -------------- | ------------------------------------------------------------------------------- |
| EVM                      | `publicClient` | CDR contract state: vaults, fees, `maxEncryptedDataSize`, operational threshold |
| DATA Foundation API REST | `apiUrl`       | DKG state: active round, global public key, threshold, validators, attestations |

The `apiUrl` is a required parameter. See
[Runtime Configuration](/developers/cdr-sdk/advanced-configuration#dkg-state-and-the-data-foundation-api-endpoint)
for operational guidance and the optional `minThresholdRatio` override.

## Attestation Utilities

The SDK also exposes SGX helper functions in the crypto module:

* `parseSgxQuote()` to read `MRENCLAVE`, `MRSIGNER`, and `securityVersion` from
  a quote
* `verifyAttestation()` to validate those fields against your expected values

Use them together with `observer.getValidatorAttestations()` when your
application wants an explicit validator enclave allowlist check.

## Sub-Clients

<CardGroup cols={3}>
  <Card title="Observer" icon="eye" href="/sdk-reference/cdr/observer">
    Read-only queries for vault data, fees, and DKG state.
  </Card>

  <Card title="Uploader" icon="lock" href="/sdk-reference/cdr/uploader">
    Encrypt data, upload encrypted files, and write to CDR vaults.
  </Card>

  <Card title="Consumer" icon="lock-open" href="/sdk-reference/cdr/consumer">
    Request decryption, download encrypted files, and recover plaintext.
  </Card>
</CardGroup>

## Crypto Utilities

<CardGroup cols={2}>
  <Card title="Crypto" icon="key" href="/sdk-reference/cdr/crypto">
    Low-level TDH2 and ECIES cryptographic primitives.
  </Card>
</CardGroup>
