Notice
Non-mandatory upgrade
This release is TypeScript-only in substance: the Java REPL carries the version bump and
documentation touch-ups and no behavior change. If you are upgrading the TypeScript CLI from 4.13.0
or earlier, the legacy_derivation guidance in the
4.13.1 release note
still applies.
New Features
Change
-
x402— pay x402-protected HTTP endpoints from the wallet. A new command family lets an agent call an endpoint that answers402 Payment Required, pick a payment route the endpoint offers on the selected network, sign the authorization with the active account and repeat the request with it; a facilitator settles on chain, so there is no--wait.x402 pay <url>takes the usual HTTP shape (--method,--header,--body/--body-file -) plus spend controls that are enforced before anything is signed:--max-amount/--max-raw-amount,--token/--asset,--scheme exact|exact_gasfree, and--max-gasfree-feefor a payment drawn from the account's GasFree balance instead of its token balance.--dry-runreports the route that would be paid;--outwrites the paid response to a new file, refusing an existing one before the first request.x402 serveruns a local paywall (with--daemonfor a background server),x402 roundtripstarts one, pays it once and exits, andprovider-list/provider-show/endpoint-list/update-catalogbrowse a cached provider catalog. Every failure says whether money may have moved —error.details.phase,paymentStatus(not_sent/unknown/settled),retryPayment,candidateTxHash, and on TRON the one-time Permit2approvalthat was signed — so a script never pays twice on a rumor; the SDK's own spend refusal surfaces asamount_exceeds_limit/no_matching_requirementat exit1, and a rate-limited facilitator asprovider_rate_limitedwithretryAfterSeconds. Permit2, EIP-3009 and GasFree deadlines are checked before and after the signer returns, and the TRON approve the bridge signs is pinned toapprove(Permit2, MaxUint256)on the named token with zero call value, so a substituted transaction is refused before the device prompt. (#1002, #1007, #1008, #1010, #1011, #1013, #1021, #1022) -
bai— check and recharge a B.AI account with stablecoins.bai usage-summary,bai usage-records(cursor-paged:meta.pagination.hasMore/nextCursor, passed back with--cursor) andbai recharge-ordersread the account;bai recharge <amount> [--token] [--to <email|address>] [--network tron|bsc|base]pays a recharge order with an x402 payment from the active account and reports the transaction to B.AI. The paying address must be bound to the B.AI account:rechargechecks the binding on every run and, when it is missing, signs B.AI's binding message and binds it first, stopping with no order and no payment on any failure;--dry-runreportsbindingRequiredand what would be paid without binding, ordering or signing. When B.AI cannot confirm the credit in time the command still succeeds withcreditStatus: "unconfirmed"and the transaction hash — the payment went through — andbai report-recharge <txHash>reports it again without paying. The personal API key is a new secret config key:config baiApiKey --api-key-stdinreads it from stdin only (config baiApiKey <key>on argv isinvalid_option), saves it locally without contacting B.AI, and everybaicommand without one stops withbai_credentials_missingat exit2; a wrong key isbai_auth_failed. (#1002, #1017, #1018, #1020) -
8004— read and manage ERC-8004 Agent identities. Eight commands work against the Identity Registry ontron,nile,shasta,bsc,bsc-testnet,baseandbase-sepolia(Ethereum and Sepolia fail withunsupported_network_capability):showandoperator-checkread without a wallet, andregister <uri>,update,transfer,approve,add-operatorandremove-operatorsign with the active account under the usual transaction options (--wait,--sign-only,--build-only, and on TRON--fee-limit,--permission-id,--expiration). Agent ids may carry their canonical network (tron:3448148188:172,eip155:97:42) and are checked against the selected network withchain_id_mismatch. Authorization is decided during fee estimation, before signing: the registry's revert is decoded intonot_authorizedoragent_not_found, and any other revert isexecution_revertedwitherror.details.revertData— TRON constant-call revert data, which TronWeb used to discard, is now preserved at the transport boundary for this. Receipts group the Agent fields underdata.identity, with chain-read values (agentId,newURI,newOwner,approved) present only with--wait. (#1002, #1008) -
Machine-interface and packaging refinements around the new families. Long-running
x402andbaicommands report progress on stderr —⏳ …lines in text mode, one{"type":"activity"}line per step in JSON mode — which is informational and never carries the outcome. Theconfigview now maskstronlinkSecretIdandgasfreeApiKeyas********alongside the secrets it already hid, and reading an unset key returns onlykey.deleteon an HD wallet that has TRON sub-accounts always prints the legacy-derivation warning first, since without the password it cannot tell which path created them; the warning does not stop the deletion. The npm tarball now packagesdocs/troubleshooting/, so the recovery guide that five packaged documents link to ships with the package, andverify:packagefails the build on any dangling in-package link. The--json-schemacatalog, error-code index and every command page were re-synced for the new surface. (#1009, #1011, #1013, #1019, #1022)
Bug Fixes
Change
-
Ledger on TRON: TIP-712 signatures were unverifiable, and large contract calls could not be signed at all. The TRON app's TIP-712 APDU returns the recovery byte as parity (
00/01), andtyped-data signpassed it through unchanged, so a contractecrecoverexpecting1b/1crejected every Ledger-signed typed-data message; the byte is now normalized to 27 / 28, while raw transaction signatures keep their unchanged wire format. Separately,hw-app-trxrefuses to pack a transaction whose data field exceeds 250 bytes — acontract sendwith a long argument list failed withToo many bytes to encode.before any APDU was sent. The CLI now catches exactly that pre-transport error and falls back to signing the transaction's SHA-256 hash viasignTransactionHash, after the same integrity checks as full signing, printing a warning that the device cannot display the details so the user must verify the transaction on the computer before approving. A device rejection, transport failure or cancelled operation is never retried as a hash. (#1015, #1016) -
A mined TRON contract call was reported as
confirmedwithout an execution result. The confirmation normalizer only inspected the nestedreceipt.result: a top-levelresult: "FAILED"was ignored, a numeric receipt result was coerced away, and a receipt with no result at all defaulted to success, so a reverted call could come back asstage: confirmed. Both failure locations are now honored, and forcontract call/deploy/ TRC20 sends the poller keeps waiting until the receipt carries an execution result (native transfers and stakes, which legitimately omit it, are unchanged). In the same area, the pre-flight resource estimate for a payable call now passes--valuethrough to energy estimation instead of estimating a zero-value call, andenergyPriceSunreports the current price rather than the node's raw price-history string. (#1002, #1013, #1022)
Integrity Check
All jar files available in this release are signed via this GPG key:
- PUB: 1254 F859 D2B1 BD9F 66E7 107D F859 BCB4 4A28 290B
- UID: build@tron.network
From the download listings below you should see links to the downloadable jar files as well as sig signature files. To verify the authenticity of any jar file, grab the jar and sig files with the same prefix name and then execute the verification process: GPG signature verification