SPL Token Best Practices
Rules for correct, safe SPL Token handling on Agave 4.1.1 - from mint launch through program CPIs and client reads.
Search across all documentation pages
Rules for correct, safe SPL Token handling on Agave 4.1.1 - from mint launch through program CPIs and client reads.
transfer_checked with mint decimals. The unchecked transfer (spl_token::instruction::transfer, anchor_spl::token::{transfer, Transfer}) is deprecated, and Token-2022 rejects it on transfer-fee mints.token::mint on every TokenAccount. Stops vault deposits of wrong assets.new_with_signer. Missing seeds is the top vault transfer failure.token_interface when accepting Token-2022. Classic Token program constraint rejects extension mints.float * 1e6 for production payment amounts.--fund-recipient or idempotent create). Transfers fail without destination token account.spl-token CLI amounts are UI amounts. Pasting a raw value into mint, transfer, burn, or approve overspends by 10^decimals.Revoke mint authority after final mint, if fixed supply is promised.
transfer_checked in all Anchor programs handling multiple mints.
Read mint authorities on-chain, supply, and program ID - never UI badges alone.
Yes for consumer onboarding when users lack SOL for rent - budget explicitly.
Token-2022 only when you need extensions; classic Token has widest compatibility today.
Surfpool 0.12.0 or LiteSVM 0.6.x with devnet mints before mainnet launch.
Always sync_native after lamport deposit; unwrap dust after DeFi.
Parse Token program instructions plus periodic getTokenAccountsByOwner reconciliation.
Decimals and program are fixed - plan migration as new mint + holder migration if needed.
Yes for DAO emissions - document timelock and on-chain pubkey.
Stack versions: This page was written for Agave 4.1.1, Solana CLI 3.0.10, Anchor 0.32.1, anchor-lang 0.32.1, Rust 1.91.1, @solana/kit 7.0.0, Surfpool 0.12.0, and LiteSVM 0.6.x.
Reviewed by Chris St. John·Last updated Jul 16, 2026