Skip to content

wallet-cli-4.14.0

Latest

Choose a tag to compare

@gummy789j gummy789j released this 21 Sep 10:20
0790286

Notice

Non-mandatory upgrade

This release is TypeScript-only in substance: the Java REPL carries the version bump and
documentation touch-ups and no behavior change. If you are upgrading the TypeScript CLI from 4.13.0
or earlier, the legacy_derivation guidance in the
4.13.1 release note
still applies.

New Features

Change

  1. x402 — pay x402-protected HTTP endpoints from the wallet. A new command family lets an agent call an endpoint that answers 402 Payment Required, pick a payment route the endpoint offers on the selected network, sign the authorization with the active account and repeat the request with it; a facilitator settles on chain, so there is no --wait. x402 pay <url> takes the usual HTTP shape (--method, --header, --body / --body-file -) plus spend controls that are enforced before anything is signed: --max-amount / --max-raw-amount, --token / --asset, --scheme exact|exact_gasfree, and --max-gasfree-fee for a payment drawn from the account's GasFree balance instead of its token balance. --dry-run reports the route that would be paid; --out writes the paid response to a new file, refusing an existing one before the first request. x402 serve runs a local paywall (with --daemon for a background server), x402 roundtrip starts one, pays it once and exits, and provider-list / provider-show / endpoint-list / update-catalog browse a cached provider catalog. Every failure says whether money may have moved — error.details.phase, paymentStatus (not_sent / unknown / settled), retryPayment, candidateTxHash, and on TRON the one-time Permit2 approval that was signed — so a script never pays twice on a rumor; the SDK's own spend refusal surfaces as amount_exceeds_limit / no_matching_requirement at exit 1, and a rate-limited facilitator as provider_rate_limited with retryAfterSeconds. Permit2, EIP-3009 and GasFree deadlines are checked before and after the signer returns, and the TRON approve the bridge signs is pinned to approve(Permit2, MaxUint256) on the named token with zero call value, so a substituted transaction is refused before the device prompt. (#1002, #1007, #1008, #1010, #1011, #1013, #1021, #1022)

  2. bai — check and recharge a B.AI account with stablecoins. bai usage-summary, bai usage-records (cursor-paged: meta.pagination.hasMore / nextCursor, passed back with --cursor) and bai recharge-orders read the account; bai recharge <amount> [--token] [--to <email|address>] [--network tron|bsc|base] pays a recharge order with an x402 payment from the active account and reports the transaction to B.AI. The paying address must be bound to the B.AI account: recharge checks the binding on every run and, when it is missing, signs B.AI's binding message and binds it first, stopping with no order and no payment on any failure; --dry-run reports bindingRequired and what would be paid without binding, ordering or signing. When B.AI cannot confirm the credit in time the command still succeeds with creditStatus: "unconfirmed" and the transaction hash — the payment went through — and bai report-recharge <txHash> reports it again without paying. The personal API key is a new secret config key: config baiApiKey --api-key-stdin reads it from stdin only (config baiApiKey <key> on argv is invalid_option), saves it locally without contacting B.AI, and every bai command without one stops with bai_credentials_missing at exit 2; a wrong key is bai_auth_failed. (#1002, #1017, #1018, #1020)

  3. 8004 — read and manage ERC-8004 Agent identities. Eight commands work against the Identity Registry on tron, nile, shasta, bsc, bsc-testnet, base and base-sepolia (Ethereum and Sepolia fail with unsupported_network_capability): show and operator-check read without a wallet, and register <uri>, update, transfer, approve, add-operator and remove-operator sign with the active account under the usual transaction options (--wait, --sign-only, --build-only, and on TRON --fee-limit, --permission-id, --expiration). Agent ids may carry their canonical network (tron:3448148188:172, eip155:97:42) and are checked against the selected network with chain_id_mismatch. Authorization is decided during fee estimation, before signing: the registry's revert is decoded into not_authorized or agent_not_found, and any other revert is execution_reverted with error.details.revertData — TRON constant-call revert data, which TronWeb used to discard, is now preserved at the transport boundary for this. Receipts group the Agent fields under data.identity, with chain-read values (agentId, newURI, newOwner, approved) present only with --wait. (#1002, #1008)

  4. Machine-interface and packaging refinements around the new families. Long-running x402 and bai commands report progress on stderr — ⏳ … lines in text mode, one {"type":"activity"} line per step in JSON mode — which is informational and never carries the outcome. The config view now masks tronlinkSecretId and gasfreeApiKey as ******** alongside the secrets it already hid, and reading an unset key returns only key. delete on an HD wallet that has TRON sub-accounts always prints the legacy-derivation warning first, since without the password it cannot tell which path created them; the warning does not stop the deletion. The npm tarball now packages docs/troubleshooting/, so the recovery guide that five packaged documents link to ships with the package, and verify:package fails the build on any dangling in-package link. The --json-schema catalog, error-code index and every command page were re-synced for the new surface. (#1009, #1011, #1013, #1019, #1022)

Bug Fixes

Change

  1. Ledger on TRON: TIP-712 signatures were unverifiable, and large contract calls could not be signed at all. The TRON app's TIP-712 APDU returns the recovery byte as parity (00 / 01), and typed-data sign passed it through unchanged, so a contract ecrecover expecting 1b / 1c rejected every Ledger-signed typed-data message; the byte is now normalized to 27 / 28, while raw transaction signatures keep their unchanged wire format. Separately, hw-app-trx refuses to pack a transaction whose data field exceeds 250 bytes — a contract send with a long argument list failed with Too many bytes to encode. before any APDU was sent. The CLI now catches exactly that pre-transport error and falls back to signing the transaction's SHA-256 hash via signTransactionHash, after the same integrity checks as full signing, printing a warning that the device cannot display the details so the user must verify the transaction on the computer before approving. A device rejection, transport failure or cancelled operation is never retried as a hash. (#1015, #1016)

  2. A mined TRON contract call was reported as confirmed without an execution result. The confirmation normalizer only inspected the nested receipt.result: a top-level result: "FAILED" was ignored, a numeric receipt result was coerced away, and a receipt with no result at all defaulted to success, so a reverted call could come back as stage: confirmed. Both failure locations are now honored, and for contract call / deploy / TRC20 sends the poller keeps waiting until the receipt carries an execution result (native transfers and stakes, which legitimately omit it, are unchanged). In the same area, the pre-flight resource estimate for a payable call now passes --value through to energy estimation instead of estimating a zero-value call, and energyPriceSun reports the current price rather than the node's raw price-history string. (#1002, #1013, #1022)

Integrity Check

All jar files available in this release are signed via this GPG key:

From the download listings below you should see links to the downloadable jar files as well as sig signature files. To verify the authenticity of any jar file, grab the jar and sig files with the same prefix name and then execute the verification process: GPG signature verification