Skip to content

docs(keychain): update keychain docs for the 2.0.0 release - #2224

Merged
dev-jodee merged 3 commits into
mainfrom
docs/keychain-v2
Oct 1, 2026
Merged

dev-jodee merged 3 commits into
mainfrom
docs/keychain-v2

Conversation

@dev-jodee

@dev-jodee dev-jodee commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Problem

The Keychain docs under /docs/tools/keychain describe the 1.x library: Rust and TypeScript only, a single SolanaSigner trait, two Fordefi modes and the Accretion audit. solana-keychain 2.0.0 adds Python and Go at parity, splits signers into capability traits, makes Crossmint sending-only, gives Fordefi three modes, adds a Rust-only Ledger backend and ships after an OtterSec audit of all four languages. Many snippets no longer compile against 2.0.

Summary of Changes

  • tools/keychain/index.mdx: four languages, OtterSec audit with Ledger out of scope, Python and Go columns and a Ledger row in the backend table, fixed Rust quick start, Python and Go quick starts, links to the security model and migration guide.
  • New getting-started/python.mdx and getting-started/go.mdx, modeled on the Rust and TypeScript pages and added to the sidebar.
  • getting-started/rust.mdx and getting-started/typescript.mdx: snippets fixed against 2.0, capability sections, missing backends (Openfort, Utila, Ledger in Rust; Memory, GCP KMS, Openfort, Utila in TS), Fordefi's three modes, BROADCAST_UNCONFIRMED handling.
  • choosing-a-backend.mdx and production-best-practices.mdx: capability caveat on swapping backends, Ledger row, kms:GetPublicKey, no blind retries on broadcasting backends, a section on unconfirmed broadcasts.
  • adding-signers.mdx: updated in place for 2.0 (capability traits, message-byte signing with verification, _remote feature, seven umbrella touchpoints), plus Python, Go and security requirement sections.
  • Keychain mentions in payments/developer-tools, tools/production-readiness, core/transactions/signing-in-production, clients/official/rust and clients/official/javascript; Python and Go SDK table rows.
  • Cookbook sign-with-keychain softened for sending and modifying backends; @solana/keychain-memory bumped to ^2.0.0.

English only; translations follow through the Lingo workflow.

Lockfile refreshed against the published @solana/keychain-memory and @solana/keychain-core 2.0.0, both added to minimumReleaseAgeExclude since they are newer than the age cutoff. Two page descriptions also lost their colons, which broke YAML frontmatter parsing in fumadocs-mdx.

Fixes # n/a


Change classification (SDLC §2)

  • Critical — auth, secrets/key handling, fund movement, deploy/CI
    security gates, or anything that changes who can do what
  • Standard — production-facing, non-critical (features, API/route
    changes, dependency updates, monitoring/config)
  • Low — no security impact (docs, tests, dev tooling, content)

Security checklist

  • No secrets, tokens, or credentials in source, env files, or CI logs
    (use Doppler / NEXT_PUBLIC_* only for values safe to ship to the
    browser).
  • Input from users or external services is validated before use; no
    dangerouslySetInnerHTML / unsanitized HTML on untrusted input.
  • New or updated dependencies are justified below, and pnpm audit
    passes (no new High/Critical advisories).
  • Errors are handled explicitly — no silent failures on production paths.
  • For Critical changes: a trust-boundary / threat-model note is
    included below, and a second reviewer has been requested.

New dependencies: none. Updated: @solana/keychain-memory ^1.4.0 to ^2.0.0 in packages/docs-examples, to match the docs; pnpm audit reports no advisories on any keychain path.

Threat-model note: n/a

Covers four languages, the OtterSec audit, capability-split signers,
Fordefi's three modes, Crossmint as sending-only and the Ledger backend.
Adds Python and Go getting-started pages, fixes snippets that no longer
compile against 2.0, and bumps the cookbook example to keychain-memory 2.0.
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
solana-com-docs Ready Ready Preview Oct 1, 2026 4:16pm UTC
5 Skipped Deployments
Project Deployment Actions Updated
solana-com Skipped Skipped Oct 1, 2026 4:16pm UTC
solana-com-accelerate Skipped Skipped Oct 1, 2026 4:16pm UTC
solana-com-breakpoint-2 Skipped Skipped Oct 1, 2026 4:16pm UTC
solana-com-media Skipped Skipped Oct 1, 2026 4:16pm UTC
templates Skipped Skipped Oct 1, 2026 4:16pm UTC

Request Review

amilz
amilz previously approved these changes Oct 1, 2026

@amilz amilz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM: docs-only refresh of Keychain docs for 2.0.0 (Python/Go pages, capability traits, Fordefi modes, Ledger, OtterSec audit). Before merging: publish @solana/keychain-memory 2.0.0 (npm currently has only 2.0.0-beta.1) and refresh pnpm-lock.yaml; every lint/test failure comes from ERR_PNPM_OUTDATED_LOCKFILE.

Refresh the lockfile for the published 2.0.0 and exempt the two keychain
packages from the minimum release age. Also reword two keychain page
descriptions whose colons broke YAML frontmatter parsing.
@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 3/5

[Low risk] Documentation updates for keychain library release.

The PR does not appear safe to merge until the Fordefi native-manual example shows how to broadcast the transaction that was actually inspected while retaining reconciliation details.

Summary

The PR updates Keychain documentation for 2.0 across Rust, TypeScript, Python, and Go, including signer capabilities, backend guidance, and the example dependency. The latest changes fix the Go GCP KMS example’s constructor-error ordering and revise the Python Fordefi native-manual example, but the latter still lacks a safe path for broadcasting the inspected transaction.

Reviews (2) · Last reviewed commit: "docs(keychain): check GCP KMS error befo..."

Comment thread apps/docs/content/docs/en/tools/keychain/getting-started/python.mdx Outdated
Comment thread apps/docs/content/docs/en/tools/keychain/getting-started/python.mdx Outdated
Comment thread apps/docs/content/docs/en/tools/keychain/getting-started/go.mdx
amilz
amilz previously approved these changes Oct 1, 2026
@vercel
vercel Bot temporarily deployed to Preview – templates October 1, 2026 16:13 Inactive
@vercel
vercel Bot temporarily deployed to Preview – solana-com-media October 1, 2026 16:13 Inactive
@vercel
vercel Bot temporarily deployed to Preview – solana-com-accelerate October 1, 2026 16:13 Inactive
@vercel
vercel Bot temporarily deployed to Preview – solana-com October 1, 2026 16:13 Inactive
@vercel
vercel Bot temporarily deployed to Preview – solana-com-breakpoint-2 October 1, 2026 16:13 Inactive
@dev-jodee
dev-jodee merged commit 9ffaccc into main Oct 1, 2026
34 of 35 checks passed
@dev-jodee
dev-jodee deleted the docs/keychain-v2 branch October 1, 2026 16:22

This branch was successfully deployed

1 active and 5 inactive deployments
Preview – solana-com-docs — 750b070c Deployed Oct 1, 2026 by vercel[bot]
Preview – solana-com — 750b070c Deployed Oct 1, 2026 by vercel[bot]
Preview – solana-com-breakpoint-2 — 750b070c Deployed Oct 1, 2026 by vercel[bot]
Preview – templates — 750b070c Deployed Oct 1, 2026 by vercel[bot]
Preview – solana-com-media — 750b070c Deployed Oct 1, 2026 by vercel[bot]
Preview – solana-com-accelerate — 750b070c Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants