CLI release notes: formats
Every Candle CLI release note carries a Formats line. It says whether the release changes anything the CLI keeps on disk (vault.enc, tee-wallets.enc, the files beside the vault, config.json, and the names it stores secrets under) and whether an older CLI still reads what this one writes. Check it before you run two CLI versions against one vault, restore a backup on an older machine, or pin a bot to an older release.
The full notes for each release are on its GitHub release. This page keeps the Formats lines together, newest first.
0.11.13 (2026-10-02)
Section titled “0.11.13 (2026-10-02)”candle mcp(the MCP server this CLI bundles) gainscandle_get_portfolio: balances and prices for the account’s embedded and TEE wallets on Solana and on Hood. Vault and external wallets stay oncandle portfolio, which reads them over your own RPC. The same server’scandle_get_profile_pnlnow describes per-chain P&L:chainon each open position and wallet row, andpnl.byChainwith each chain’s own figures. This is the portfolio command surface from #1538. A server that predates it omitshood,chainandbyChain.- Two other bundled-server text changes landed after 0.11.12 and ship in this binary. They are already on the standalone
@candledottv/mcpnpm package:candle_get_profile_pnldescribespnl.byWallet(#1501, MCP 0.10.3), andcandle_token_forensicssays a Hood token Candle did not launch names its launch account for pons.family and pools.trade, with no record of earlier coins (#1537, included in MCP 0.10.4).
Formats: none. No change to vault.enc, tee-wallets.enc, config.json or the secret store.
0.11.12 (2026-09-30)
Section titled “0.11.12 (2026-09-30)”- Bridging between Solana and Hood in
candle swap: a TEE wallet swaps a base asset on one chain for a base asset on the other (SOL or USDC on Solana, ETH or USDG on Hood), through Relay, into the same key’s TEE wallet on the other chain. No Candle fee.--to <tee>picks the destination when the key has more than one on that chain,candle swap status <id> --waitfollows a bridge until it fills, refunds or fails, andtee sweeprefuses a wallet while a bridge from or to it is still open. Vault to vault isvault fund, thencandle swapacross, thentee sweep. Bridging is off on the server until Candle turns it on; until then a cross-chain swap is refused before anything is signed. vault promote --to-keyandtee rebindreport trade readiness by the rule the server uses: only a cap of zero stops an asset, and a missing cap or transaction limit is unlimited, so a key with no caps no longer warns that it cannot trade. A Hood wallet is checked against its ETH and USDG caps.candle mcp(the MCP server the CLI runs) now describesclientSwapIdon the swap tool as a durable idempotency key. A retry of the same request with the same id, amount and slippage replays the stored result instead of swapping again, so after a timeout an agent retries with the same id rather than stopping. A confirmed first leg of a bridge is replayed with its hash and is not run a second time.
Formats: a swap’s local operation record (the file candle swap status reads) can carry an optional bridge field for a bridge; older CLIs ignore it. No change to vault.enc, tee-wallets.enc, config.json or the secret store.
0.11.11 (2026-09-28)
Section titled “0.11.11 (2026-09-28)”- Only the limits a key’s owner set apply. A TEE trade or swap needs neither a per-asset cap nor a USD transaction limit; a missing one is unlimited, and a limit that is set still binds.
candle doctorand the swap readiness checks follow the same rule. - The automatic stop after five consecutive buys of the same token is removed. Trade-rate, failed-sell and owner-set loss limits stay.
Formats: none. No change to vault.enc, tee-wallets.enc, config.json or the secret store.
0.11.10 (2026-09-26)
Section titled “0.11.10 (2026-09-26)”- Key signers:
candle tee signer new,keys signer approve,keys signer move, andvault promote --to-keyandtee rebindonto a key that has a signer. See Key signers. - Hood TEE wallets in the CLI: EVM promote, fund, sweep, demote and
swapon Hood. See Hood TEE wallets. candle keys accesschanges a key’s access level in place.- A default Solana RPC, a per-profile RPC setting, and a prompt when the public RPC rate-limits you.
- A key can hold up to 1,000 wallets (the Max plan’s linked-wallet cap), read from the server, and a rebind that adds no wallet is never refused for size.
candle wallet close-emptycloses the embedded wallet’s empty token accounts and reclaims their rent.
Formats:
vault.encversion 4, one way. A vault moves to version 4 on the write that creates its first Hood TEE wallet (an EVM promote, orvault restore --phrase --evm-tee-countof 1 or more), and never moves back. 0.11.9 and every older CLI refuse a version 4 vault withVAULT_VERSION_UNSUPPORTED. A vault with no Hood TEE wallet keeps its version 2 or 3 header byte for byte and still opens in older CLIs. Before creating a Hood TEE wallet, update every machine that opens that vault or its backups.- New file
vault.evm-record.sealedbeside the vault, and<copy>.evm-record.sealedbeside a backup. Older CLIs do not read it or copy it. config.jsongainskeySigners(the key-signer index and pins) andpublicRpcNotice. Older CLIs ignore both and keep them when they write the file.- Secret store: new refs
key_signer_<prefix>_<spkiSha256>. Older CLIs ignore them. A wallet owned by a key signer trades only from a CLI that has this release: an older CLI looks only for the wallet’s ownwallet_signer_<id>, and atee rebindorkeys signer moveonto a key signer deletes that slot once the move is read back. tee-wallets.encis unchanged.
0.11.9 (2026-09-24)
Section titled “0.11.9 (2026-09-24)”EVM vault keys (vault new-key --chain evm, vault transfer on Hood or any EVM chain), and tee rebind pointers.
Formats: no version change. EVM keys are new entries in the existing version 2 and 3 index, which already allowed them, so older CLIs open the vault. Older CLIs predate the check that stops Solana-only commands from being pointed at an EVM key, so run commands that name an EVM key only from 0.11.9 or later. tee-wallets.enc, config.json and the secret store are unchanged.
0.11.8 (2026-09-24)
Section titled “0.11.8 (2026-09-24)”candle transfer, keys create --access, wallets trust, and a security key can authorize adding another factor.
Formats: none. No change to vault.enc, tee-wallets.enc, config.json or the secret store.
0.11.7 (2026-09-24)
Section titled “0.11.7 (2026-09-24)”candle lp, portfolio and pnl with LP valuation, vault promote --to-key, and vault transfer from a promoted wallet.
Formats: tee-wallets.enc sweep records can now have kind lp-close, an addition. Older CLIs open the file and carry the record through unchanged; how they display an lp-close record has not been checked. vault.enc, config.json and the secret store are unchanged.
0.11.6 (2026-09-23)
Section titled “0.11.6 (2026-09-23)”The unlock menu, tee rebind, the promote confirmation, and security keys in sealed backups.
Formats:
- The vault’s state file (
vault.state.json) gains four optional backup fields that tie a backup to the factors it was made with. An older CLI keeps them, but its ownvault backupdoes not update them, so after an older CLI’s backupvault statusstops naming which keys the last backup carries. Nothing is lost. - A sealed backup copy now keeps security-key envelopes as well as the passphrase. The copy’s version is unchanged, and older CLIs already open a vault with security-key envelopes.
vault.encitself,tee-wallets.enc,config.jsonand the secret store are unchanged.
0.11.5 (2026-09-22)
Section titled “0.11.5 (2026-09-22)”vault list, vault promote-batch, and a working install for GitHub CLI users.
Formats: none. promote-batch writes the same index fields a single promote does.
0.11.4 (2026-09-21)
Section titled “0.11.4 (2026-09-21)”vault rename, the label uniqueness guard, and the backup transcript.
Formats: none. A rename rewrites an existing label field; the version is unchanged.
Before 0.11.4
Section titled “Before 0.11.4”vault.enc version 3 (the external branch, for candle external and candle sign) predates 0.11.4. A CLI from before it refuses a version 3 vault with VAULT_VERSION_UNSUPPORTED; a vault that never used the external branch stays version 2.