Skip to content

CLI release notes: formats

Every Candle CLI release note carries a Formats line. It says whether the release changes anything the CLI keeps on disk (vault.enc, tee-wallets.enc, the files beside the vault, config.json, and the names it stores secrets under) and whether an older CLI still reads what this one writes. Check it before you run two CLI versions against one vault, restore a backup on an older machine, or pin a bot to an older release.

The full notes for each release are on its GitHub release. This page keeps the Formats lines together, newest first.

  • candle mcp (the MCP server this CLI bundles) gains candle_get_portfolio: balances and prices for the account’s embedded and TEE wallets on Solana and on Hood. Vault and external wallets stay on candle portfolio, which reads them over your own RPC. The same server’s candle_get_profile_pnl now describes per-chain P&L: chain on each open position and wallet row, and pnl.byChain with each chain’s own figures. This is the portfolio command surface from #1538. A server that predates it omits hood, chain and byChain.
  • Two other bundled-server text changes landed after 0.11.12 and ship in this binary. They are already on the standalone @candledottv/mcp npm package: candle_get_profile_pnl describes pnl.byWallet (#1501, MCP 0.10.3), and candle_token_forensics says a Hood token Candle did not launch names its launch account for pons.family and pools.trade, with no record of earlier coins (#1537, included in MCP 0.10.4).

Formats: none. No change to vault.enc, tee-wallets.enc, config.json or the secret store.

  • Bridging between Solana and Hood in candle swap: a TEE wallet swaps a base asset on one chain for a base asset on the other (SOL or USDC on Solana, ETH or USDG on Hood), through Relay, into the same key’s TEE wallet on the other chain. No Candle fee. --to <tee> picks the destination when the key has more than one on that chain, candle swap status <id> --wait follows a bridge until it fills, refunds or fails, and tee sweep refuses a wallet while a bridge from or to it is still open. Vault to vault is vault fund, then candle swap across, then tee sweep. Bridging is off on the server until Candle turns it on; until then a cross-chain swap is refused before anything is signed.
  • vault promote --to-key and tee rebind report trade readiness by the rule the server uses: only a cap of zero stops an asset, and a missing cap or transaction limit is unlimited, so a key with no caps no longer warns that it cannot trade. A Hood wallet is checked against its ETH and USDG caps.
  • candle mcp (the MCP server the CLI runs) now describes clientSwapId on the swap tool as a durable idempotency key. A retry of the same request with the same id, amount and slippage replays the stored result instead of swapping again, so after a timeout an agent retries with the same id rather than stopping. A confirmed first leg of a bridge is replayed with its hash and is not run a second time.

Formats: a swap’s local operation record (the file candle swap status reads) can carry an optional bridge field for a bridge; older CLIs ignore it. No change to vault.enc, tee-wallets.enc, config.json or the secret store.

  • Only the limits a key’s owner set apply. A TEE trade or swap needs neither a per-asset cap nor a USD transaction limit; a missing one is unlimited, and a limit that is set still binds. candle doctor and the swap readiness checks follow the same rule.
  • The automatic stop after five consecutive buys of the same token is removed. Trade-rate, failed-sell and owner-set loss limits stay.

Formats: none. No change to vault.enc, tee-wallets.enc, config.json or the secret store.

  • Key signers: candle tee signer new, keys signer approve, keys signer move, and vault promote --to-key and tee rebind onto a key that has a signer. See Key signers.
  • Hood TEE wallets in the CLI: EVM promote, fund, sweep, demote and swap on Hood. See Hood TEE wallets.
  • candle keys access changes a key’s access level in place.
  • A default Solana RPC, a per-profile RPC setting, and a prompt when the public RPC rate-limits you.
  • A key can hold up to 1,000 wallets (the Max plan’s linked-wallet cap), read from the server, and a rebind that adds no wallet is never refused for size.
  • candle wallet close-empty closes the embedded wallet’s empty token accounts and reclaims their rent.

Formats:

  • vault.enc version 4, one way. A vault moves to version 4 on the write that creates its first Hood TEE wallet (an EVM promote, or vault restore --phrase --evm-tee-count of 1 or more), and never moves back. 0.11.9 and every older CLI refuse a version 4 vault with VAULT_VERSION_UNSUPPORTED. A vault with no Hood TEE wallet keeps its version 2 or 3 header byte for byte and still opens in older CLIs. Before creating a Hood TEE wallet, update every machine that opens that vault or its backups.
  • New file vault.evm-record.sealed beside the vault, and <copy>.evm-record.sealed beside a backup. Older CLIs do not read it or copy it.
  • config.json gains keySigners (the key-signer index and pins) and publicRpcNotice. Older CLIs ignore both and keep them when they write the file.
  • Secret store: new refs key_signer_<prefix>_<spkiSha256>. Older CLIs ignore them. A wallet owned by a key signer trades only from a CLI that has this release: an older CLI looks only for the wallet’s own wallet_signer_<id>, and a tee rebind or keys signer move onto a key signer deletes that slot once the move is read back.
  • tee-wallets.enc is unchanged.

EVM vault keys (vault new-key --chain evm, vault transfer on Hood or any EVM chain), and tee rebind pointers.

Formats: no version change. EVM keys are new entries in the existing version 2 and 3 index, which already allowed them, so older CLIs open the vault. Older CLIs predate the check that stops Solana-only commands from being pointed at an EVM key, so run commands that name an EVM key only from 0.11.9 or later. tee-wallets.enc, config.json and the secret store are unchanged.

candle transfer, keys create --access, wallets trust, and a security key can authorize adding another factor.

Formats: none. No change to vault.enc, tee-wallets.enc, config.json or the secret store.

candle lp, portfolio and pnl with LP valuation, vault promote --to-key, and vault transfer from a promoted wallet.

Formats: tee-wallets.enc sweep records can now have kind lp-close, an addition. Older CLIs open the file and carry the record through unchanged; how they display an lp-close record has not been checked. vault.enc, config.json and the secret store are unchanged.

The unlock menu, tee rebind, the promote confirmation, and security keys in sealed backups.

Formats:

  • The vault’s state file (vault.state.json) gains four optional backup fields that tie a backup to the factors it was made with. An older CLI keeps them, but its own vault backup does not update them, so after an older CLI’s backup vault status stops naming which keys the last backup carries. Nothing is lost.
  • A sealed backup copy now keeps security-key envelopes as well as the passphrase. The copy’s version is unchanged, and older CLIs already open a vault with security-key envelopes.
  • vault.enc itself, tee-wallets.enc, config.json and the secret store are unchanged.

vault list, vault promote-batch, and a working install for GitHub CLI users.

Formats: none. promote-batch writes the same index fields a single promote does.

vault rename, the label uniqueness guard, and the backup transcript.

Formats: none. A rename rewrites an existing label field; the version is unchanged.

vault.enc version 3 (the external branch, for candle external and candle sign) predates 0.11.4. A CLI from before it refuses a version 3 vault with VAULT_VERSION_UNSUPPORTED; a vault that never used the external branch stays version 2.