CPI Best Practices
CPIs extend your program's blast radius. These rules keep invocations minimal, verifiable, and compatible with Agave 4.1.1 limits.
Search across all documentation pages
CPIs extend your program's blast radius. These rules keep invocations minimal, verifiable, and compatible with Agave 4.1.1 limits.
? unless explicitly handling. Avoids silent partial failure assumptions.Only if you still validate accounts and ordering.
As few as possible - profile.
Highest priority.
Separate program id in allowlist.
No arbitrary user programs.
High risk - expert review.
Nest until failure in sim.
Log off-chain from meta.
Whole tx atomic.
Default local CPI testing.
Re-run CPI suite.
Allowlist frozen - plan carefully.
Stack versions: This page was written for Agave 4.1.1, Solana CLI 3.0.10, Anchor 0.32.1, anchor-lang 0.32.1, Rust 1.91.1, @solana/kit 7.0.0, Surfpool 0.12.0, and LiteSVM 0.6.x.
Reviewed by Chris St. John·Last updated Jul 19, 2026