Solana CLI Best Practices
A condensed summary of the 25 most important Solana CLI practices drawn from every page in this section.
Search across all documentation pages
A condensed summary of the 25 most important Solana CLI practices drawn from every page in this section.
Pin Agave and CLI versions: Install Agave 4.1.1 so solana --version reports CLI 3.0.10 - mismatched toolchains cause deploy and RPC surprises (Solana CLI Basics).
Verify config before every session: Run solana config get and confirm RPC URL, keypair path, and commitment match the cluster you intend to touch.
Separate keypairs per cluster: Never reuse a mainnet-funded key as your default on devnet scripts - reduces accidental mainnet spends.
Never commit keypair JSON: Add *-keypair.json and id.json paths to .gitignore; load production keys from secrets managers only (Keypairs with solana-keygen).
Record seed phrases offline: Backup BIP39 phrases when creating keys - disk loss without a phrase is unrecoverable.
chmod 600 key files: Restrict secret key files to your user on Unix hosts before funding wallets.
Use devnet for faucet workflows: Fund with solana airdrop only on devnet/testnet; mainnet requires real SOL (Airdrops & Balances).
Leave fee headroom: Keep at least 0.01 SOL on active dev wallets - rent and priority fees consume more than the base 5,000 lamports.
Double-check recipient pubkeys: Test with a dust transfer before large payouts - base58 typos are irreversible (Sending SOL & Transactions).
Use finalized commitment for treasury ops: Set --commitment finalized when confirming high-value transfers on mainnet.
Inspect before you debug code: Run solana account and solana program show to verify owners, data length, and upgrade authority (Inspecting Accounts & Programs).
Align program IDs everywhere: declare_id!, Anchor.toml, and deploy keypair must share one pubkey before deploy (Deploying Programs).
Build release artifacts for deploy: Use anchor build / cargo build-sbf release output - debug .so files waste rent and CU.
Fund deploys for programdata rent: Large programs need more lamports than a 2 SOL devnet airdrop - check balance before program deploy.
Transfer upgrade authority deliberately: Move authority to multisig on mainnet; use --final only when immutability is intended.
Use spl-token for tokens: Native solana transfer never moves SPL balances - use spl-token transfer with --fund-recipient (spl-token CLI).
Know which layer scales the amount: the spl-token CLI takes UI amounts and applies the mint's decimals for you - pass 2.5, not 2500000. Multiply by 10^decimals only when you build instruction data yourself.
Stream logs in a second terminal: Pair solana logs with local validator or devnet RPC while iterating on program errors (Logs & Debugging).
Capture failed transaction JSON: solana transaction <SIG> --output json-compact preserves logMessages for tickets and CI artifacts.
Prefer provider RPC for reliability: Public endpoints rate-limit; use dedicated devnet/mainnet URLs in solana config set --url.
Export config for CI carefully: solana config get --json is fine for RPC URLs - never commit paths to production keypairs in shared repos.
Confirm signatures explicitly in scripts: Use solana confirm -v and check exit codes instead of assuming --no-wait submissions landed.
Dump program binaries to verify deploys: solana program dump plus hash compare catches wrong-cluster or wrong-artifact deploys.
Revoke mint authority after launch: spl-token authorize <MINT> mint --disable when fixed supply is a requirement.
Document cluster in runbooks: Every ops doc should state RPC URL, commitment, and CLI version so on-call actions match developer machines.
Running mainnet commands with a mainnet-funded default keypair while believing you are on devnet - always solana config get first.
Prefer a shared devnet treasury plus per-engineer keys for auditability. Never share mainnet upgrade authority keys.
Anchor wraps the same deploy and keypair files - CLI hygiene directly protects anchor deploy outcomes.
Pinned toolchain, funded payer, matching program ID, release build, devnet dry-run, multisig upgrade authority plan.
Rotate when engineers leave or keys touch shared CI logs. Devnet keys are low stakes but good habit for mainnet discipline.
Stack versions: This page was written for Agave 4.1.1, Solana CLI 3.0.10, Anchor 0.32.1, anchor-lang 0.32.1, Rust 1.91.1, @solana/kit 7.0.0, Surfpool 0.12.0, and LiteSVM 0.6.x.
Reviewed by Chris St. John·Last updated Jul 16, 2026