Agent skill

Solana Token Extensions

by solanabr in solanabr/ai-kit

Helps choose, combine and create Token-2022 mint and account extensions on Solana with the spl-token CLI, @solana/kit or Anchor, and integrate the resulting mints.

MITAuto-check passedBackend & APIs

Install Solana Token Extensions

skills CLI
$ npx skills add solanabr/ai-kit --skill token-extensions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install solanabr/ai-kit token-extensions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/solanabr/ai-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/token-extensions .claude/skills/token-extensions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
token-extensions
GitHub stars
108
Token cost
~3.5k tokens
SKILL.md length
1,286 words
Files
9 (incl. references)
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Helps choose, combine and create Token-2022 mint and account extensions on Solana with the spl-token CLI, @solana/kit or Anchor, and integrate the resulting mints.

  • Works in 4 steps: Create the account, owned by Token-2022,… → Each extension's initialize instruction.… → InitializeMint2 (or InitializeMint). → …
  • Choosing which Token-2022 extensions fit a new token design
  • SKILL.md covers Pick the extensions, Combinations, Create a mint and Token accounts and transfers, plus 2 more sections
  • Calls bash

What it does

The skill starts with picking extensions, because fixed-size mint extensions can only be set before InitializeMint. TokenMetadata, TokenGroup and TokenGroupMember can be initialized later, but only if their pointer was set at creation. A table maps each extension to its purpose and authorities, covering transfer fees, transfer hooks, metadata and group pointers, permanent delegate, default account state for KYC gating, pausable and permissioned burn, and each row links to a reference page.

References go deeper on account extensions, confidential transfers, displaying amounts, fees, issuer controls, metadata and groups, transfer hooks and which extension sets venues such as Orca accept. The skill records the program ID and the library versions it was checked against on 2026-09-30, and warns that newer releases may rename things, so names should be verified before use. Interest-bearing, scaled UI and soulbound tokens are among the use cases it names.

When your agent uses it

  • Choosing which Token-2022 extensions fit a new token design
  • Creating a mint with transfer fees, metadata or a permanent delegate
  • Adding a transfer hook that runs your own program on each transfer
  • Checking whether an extension mint will work with a trading venue

Example prompts

  • “Create a Token-2022 mint with a transfer fee using the spl-token CLI.”
  • “Which extensions do I need for a soulbound credential token?”
  • “Add a transfer hook that checks an allowlist on every transfer.”
  • “Can I add metadata to an existing mint later, or must I decide at creation?”

Requirements

  • The spl-token CLI, @solana/kit or Anchor, depending on how you build

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Create the account, owned by Token-2022, with space for the fixed-size extensions only: ExtensionType::try_calculate_account_len::(&types)…
  2. Each extension's initialize instruction. On an initialized mint these fail with AlreadyInUse, so fixed-size extensions can't be added later.
  3. InitializeMint2 (or InitializeMint).
  4. TokenMetadata, TokenGroup and TokenGroupMember. They grow the mint but move no lamports, so fund the mint for its final size in step 1…

What it can do on your machine

Read from SKILL.md and the folder at commit 85b204f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • solana.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Solana Token Extensions loads about 3.5k tokens when it runs, and up to ~19k if it reads all its reference files. Until then it costs about 82 tokens; SKILL.md has 1,286 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~19k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from solanabr/ai-kit at commit 85b204f, republished under its MIT licence (© solanabr). 1,286 words, ~3,507 tokens.

Download SKILL.mdSave it as .claude/skills/token-extensions/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
token-extensions
description
Token-2022 (Token Extensions) on Solana. Pick, combine and create mint and account extensions with the spl-token CLI, @solana/kit or Anchor, and integrate extension mints. Use for transfer fees, hooks, metadata, groups, pausable, permanent delegate, soulbound, interest-bearing, scaled UI or confidential tokens.
user-invocable
true

Token Extensions (Token-2022)

Program TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb. Checked on 2026-09-30 against the mainnet program (spl-token-2022 v11.0.0, per its verified build), spl-token-2022-interface 3.1.2, spl-token-cli 5.6.1, @solana-program/token-2022 0.19.0 on @solana/kit 8, and anchor-lang / anchor-spl 1.2.0. Newer releases may rename things; check before relying on a name from memory.

Links into the kit's ext/ directory, here and in the references, need its full install; in a plugin install, read the same paths in solana-foundation/solana-dev-skill.

Pick the extensions

Fixed-size mint extensions can only be set before InitializeMint, so pick them up front. TokenMetadata, TokenGroup and TokenGroupMember can be initialized later, but only if their pointer was set at creation. Venues accept different sets; Orca's rules are in programs.

Extension (mint)Use it forAuthorityToken accounts getRead
TransferFeeConfigA fee withheld on every transferfee config, withdraw withheldTransferFeeAmountfees
TransferHookYour program runs on every transferhook authority (sets the program id)TransferHookAccounttransfer-hooks
MetadataPointer + TokenMetadataName, symbol, URI and fields stored on the mintpointer authority, metadata update authoritymetadata-groups
GroupPointer + TokenGroupA collection parent mintpointer authority, group update authoritymetadata-groups
GroupMemberPointer + TokenGroupMemberA mint inside a collectionpointer authority; group update authority co-signsmetadata-groups
PermanentDelegateIssuer can transfer or burn from any accountpermanent delegateissuer-controls
DefaultAccountStateNew accounts start frozen (KYC gating)freeze authorityissuer-controls
PausableStop transfers, mints and burnspause authorityPausableAccountissuer-controls
PermissionedBurnBurning needs an extra authoritypermissioned-burn authorityissuer-controls
NonTransferableSoulbound: holders can't transfernoneNonTransferableAccount, ImmutableOwnerissuer-controls
MintCloseAuthorityClose the mint once supply is 0close authorityissuer-controls
InterestBearingConfigDisplayed amount accrues interestrate authoritydisplay-amounts
ScaledUiAmountDisplayed amount = raw × multipliermultiplier authoritydisplay-amounts
ConfidentialTransferMint (+ ConfidentialTransferFeeConfig, ConfidentialMintBurn)Encrypted balances and amountsconfidential authority, auditor keyConfidentialTransferAccount, opt-in per accountconfidential

Holder-side account extensions (ImmutableOwner, MemoTransfer, CpiGuard), account sizing and Reallocate: account-extensions. Accepting any Token-2022 mint in a program, and CPIs from Anchor: programs.

Combinations

CombinationResult
ConfidentialTransferFeeConfig without both TransferFeeConfig and ConfidentialTransferMintRejected at InitializeMint: InvalidExtensionCombination
TransferFeeConfig + ConfidentialTransferMint without ConfidentialTransferFeeConfigRejected: InvalidExtensionCombination
ConfidentialMintBurn without ConfidentialTransferMintRejected: InvalidExtensionCombination
NonTransferable + ConfidentialTransferMint without ConfidentialMintBurnRejected: InvalidExtensionCombination
InterestBearingConfig + ScaledUiAmountRejected: InvalidExtensionCombination
DefaultAccountState Frozen without a freeze authorityRejected: MintCannotFreeze
NonTransferable + TransferFeeConfig or TransferHookAccepted, but pointless: every transfer fails with NonTransferable
NonTransferable + PermanentDelegateThe delegate can burn but not transfer
TransferHook + ConfidentialTransferMintConfidential transfers call the hook with amount = u64::MAX
Pausable, while pausedTransferChecked, MintTo and burns fail with MintPaused

Tooling gaps: anchor-spl 1.2.0 has no helpers for ScaledUiAmount, PermissionedBurn or the confidential extensions (it builds on spl-token-2022-interface 2.x, which has no PermissionedBurn), and spl-token-cli 5.6.1 can't initialize ConfidentialMintBurn.

spl-token-cli 5.6.1 can't act for a multisig extension authority. set-interest-rate, set-transfer-fee, set-transfer-hook, initialize-metadata, update-metadata, initialize-group, update-group-max-size, initialize-member and update-confidential-transfer-settings reject --multisig-signer. pause, resume and update-ui-amount-multiplier accept it but ignore it and send an under-signed transaction. Build those instructions with Kit or Rust instead.

Confidential transfers need the ZK ElGamal Proof program enabled on the cluster (on mainnet since epoch 982, and on devnet), a per-account opt-in (Reallocate, then ConfigureAccount with a proof), and an owner who applies pending balances. Decisions and what is out of date in the linked Rust walkthrough: confidential.

Create a mint

One transaction, in this order:

  1. Create the account, owned by Token-2022, with space for the fixed-size extensions only: ExtensionType::try_calculate_account_len::<Mint>(&types) (Rust), getMintLen(types) (web3.js 1.x), or Kit's getMintSize over the list without TokenMetadata, TokenGroup and TokenGroupMember (it counts whatever it is given), with rent from getMintSize over the full list. InitializeMint rejects any other length (InvalidAccountData) and a mint below the rent-exempt minimum (NotRentExempt).
  2. Each extension's initialize instruction. On an initialized mint these fail with AlreadyInUse, so fixed-size extensions can't be added later.
  3. InitializeMint2 (or InitializeMint).
  4. TokenMetadata, TokenGroup and TokenGroupMember. They grow the mint but move no lamports, so fund the mint for its final size in step 1 (Kit's createMint does), or transfer the difference to the mint before the initialize, in an earlier instruction of the same transaction (the CLI does) or in your program before the CPI.

Kit: the plugin's createMint does the sizing, funding and ordering. It doesn't initialize TokenGroupMember, doesn't write additionalMetadata (it only pays rent for it), and skips TokenMetadata when updateAuthority is null (metadata-groups). client is a Kit 8 client with an RPC, a payer and transaction planning and sending (Kit plugins).

ts
import { generateKeyPairSigner } from '@solana/kit';
import { extension, token2022Program } from '@solana-program/token-2022';

const token = client.use(token2022Program());
const mint = await generateKeyPairSigner();
const authority = client.payer.address;
await token.token2022.instructions
  .createMint({
    newMint: mint,
    decimals: 6,
    mintAuthority: client.payer,
    extensions: [
      extension('MetadataPointer', { authority, metadataAddress: mint.address }),
      extension('TokenMetadata', {
        updateAuthority: authority, mint: mint.address,
        name: 'Example', symbol: 'EXM', uri: 'https://example.com/exm.json',
        additionalMetadata: new Map(),
      }),
    ],
  })
  .sendTransaction();

Without the plugin, compose the same steps (space from the filtered list, rent from the full one, as createMint does) with getMintSize, getPreInitializeInstructionsForMintExtensions, getInitializeMintInstruction and getPostInitializeInstructionsForMintExtensions, or call getCreateMintInstructionPlan(client, input).

CLI: spl-token --program-2022 create-token --decimals 6 --enable-metadata then spl-token initialize-metadata <MINT> Example EXM https://example.com/exm.json. After creation the CLI infers the program from the account's owner, so later commands don't need --program-2022, except with --sign-only, where it can't look the account up and defaults to classic Token.

Anchor 1.2.0: init on an InterfaceAccount<'info, Mint> accepts extensions::metadata_pointer::{authority, metadata_address}, extensions::group_pointer::{authority, group_address}, extensions::group_member_pointer::{authority, member_address}, extensions::transfer_hook::{authority, program_id}, extensions::close_authority::authority, extensions::permanent_delegate::delegate and extensions::pausable::authority. The same constraints on an existing mint check the extension's values. TokenMetadata, TokenGroup and TokenGroupMember are CPIs after init (metadata-groups); the other extensions need a manual create-and-initialize sequence (programs).

Show full SKILL.md (454 more words)Show less

Token accounts and transfers

  • Associated token accounts derive from the token program id. Pass the Token-2022 id (findAssociatedTokenPda({ owner, mint, tokenProgram }), getAssociatedTokenAddressSync(mint, owner, false, TOKEN_2022_PROGRAM_ID)), or you get the address of an account that doesn't exist. web3.js's createAssociatedTokenAccountIdempotentInstructionWithDerivation derives with the classic program id even when you pass Token-2022; derive the address yourself.
  • Token accounts need the extensions their mint requires (table above). Associated token accounts and Anchor's init get them. For an account you create yourself, Kit's getTokenSize counts only the extensions you pass it: account-extensions.
  • Transfer with TransferChecked. Plain Transfer fails with MintRequiredForTransfer when the source account has TransferFeeAmount, TransferHookAccount or PausableAccount, because the program needs the mint to charge the fee, call the hook or check the pause.
  • With a fee, the recipient gets amount - fee: credit the balance delta, not the argument. The fee stays withheld in the recipient's account until anyone harvests it to the mint or the withdraw authority withdraws it; an account holding withheld fees can't close (fees).
  • With a hook, the hook program's ExtraAccountMetaList PDA (seeds ["extra-account-metas", mint]) must exist before the first transfer, and every transfer appends the hook program, that PDA and the extra accounts it lists (Kit: getTransferCheckedWithTransferHookInstructionAsync).
  • A TransferChecked to the same account moves nothing, charges no fee and skips the hook. Confidential transfers have no such shortcut and call the hook.
  • In a program, anchor_spl::token_interface::transfer_checked passes only the four base accounts, so it can't move a hook mint: transfer-hooks.
  • Destinations with MemoTransfer enabled need a memo instruction right before the transfer. Owners with CpiGuard enabled can't sign transfers inside a CPI.

Reading an unknown mint

  • Kit: fetchMint(rpc, address) then mint.data.extensions, an Option of an array tagged by __kind. web3.js 1.x: getExtensionTypes(mint.tlvData) on the result of getMint(connection, address, undefined, TOKEN_2022_PROGRAM_ID). Rust: StateWithExtensions::<Mint>::unpack(&data)? then get_extension_types() or get_extension::<T>(); Anchor: anchor_spl::token_interface::get_mint_extension_data::<T>(&account_info).
  • Match on each tool's own names. Kit's __kind is ScaledUiAmountConfig, PausableConfig and ConfidentialTransferFee where Rust says ScaledUiAmount, Pausable and ConfidentialTransferFeeConfig; web3.js uses ScaledUiAmountConfig and PausableConfig. Under anchor-spl 1.2.0 (interface 2.x), get_extension_types() fails with InvalidAccountData on a PermissionedBurn mint, while get_extension::<T>() still works.
  • Allow-list the extensions you support. PermanentDelegate, TransferHook, Pausable, DefaultAccountState, NonTransferable and TransferFeeConfig each change what your program or UI can rely on; the attack side is in security.md, Token-2022 section.
  • Show balances with the mint's UI conversion when InterestBearingConfig or ScaledUiAmount is present: display-amounts.

© solanabr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (references) in .claude/skills/token-extensions of solanabr/ai-kit.

  • SKILL.md
  • references/account-extensions.md
  • references/confidential.md
  • references/display-amounts.md
  • references/fees.md
  • references/issuer-controls.md
  • references/metadata-groups.md
  • references/programs.md
  • references/transfer-hooks.md

Open the folder on GitHubat commit 85b204f

Compare with similar skills

Solana Token Extensions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Solana Token Extensions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Solana Token Extensions this skillsolanabr/ai-kit108—~3.5kAutomated safety check: PassMIT
Switchboard Oracle SDKinternet-court/internet-court-skill6.4k3 repos~2.9kAutomated safety check: PassApache-2.0
Pyth Network Price Feedsinternet-court/internet-court-skill6.4k2 repos~3.9kAutomated safety check: PassApache-2.0
Payram Crypto PaymentsPayRam/payram-mcp158—~2kAutomated safety check: NotesNone
Swap Tokenscirclefin/skills155—~4.6kAutomated safety check: NotesApache-2.0
Use Usdccirclefin/skills155—~2.4kAutomated safety check: NotesApache-2.0

Similar skills

  • Switchboard Oracle SDK

    internet-court/internet-court-skill

    Covers integrating Switchboard oracles on Solana: pull feeds, oracle quotes, VRF randomness and Surge WebSocket streaming, from both the TypeScript SDK and Rust.

    6.4k GitHub starsUsed in 3 repos~2.9k tokens
    Backend & APIsAuto-check passed
  • Pyth Network Price Feeds

    internet-court/internet-court-skill

    Shows how to read Pyth oracle prices in Solana apps, off-chain through the Hermes client or on-chain from an Anchor program, including confidence and EMA values.

    6.4k GitHub starsUsed in 2 repos~3.9k tokens
    Backend & APIsAuto-check passed
  • Payram Crypto Payments

    PayRam/payram-mcp

    Self-hosted crypto and stablecoin payment gateway. An agent skill from PayRam/payram-mcp.

    158 GitHub stars~2k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Swap Tokens

    circlefin/skills

    Build browser or server token swaps with Circle App Kit or standalone Swap Kit.

    155 GitHub stars~4.6k tokensUpdated 22 days ago
    Backend & APIsAuto-check: notes
  • Use Usdc

    circlefin/skills

    USDC is Circle's stablecoin deployed across multiple blockchain ecosystems including EVM chains (Ethereum, Base, Arbitrum, Polygon, Arc) and Solana.

    155 GitHub stars~2.4k tokensUpdated 22 days ago
    Backend & APIsAuto-check: notes
  • Multichain non-custodial agent wallet via Finance District - check balances, prices, and best DeFi yields, move funds, swap, and make x402 paid API calls across EVM, Solana, Bitcoin, and Sui.

    767 GitHub stars~1.1k tokensUpdated today
    Backend & APIsAuto-check passed

More from solanabr/ai-kit

  • Solana Kit Skill Packs

    solanabr/ai-kit

    Tells the agent which optional skill pack in the Solana AI kit fits the work at hand when it is not installed yet, and how to offer it to you for approval.

    108 GitHub stars~3.1k tokensUpdated today
    Auto-check: notes
  • Solana Dev

    solanabr/ai-kit

    Routing hub for Solana development. An agent skill from solanabr/ai-kit.

    108 GitHub stars~12k tokensUpdated today
    Auto-check passed

Works with

Questions about Solana Token Extensions

What does Solana Token Extensions do?

Helps choose, combine and create Token-2022 mint and account extensions on Solana with the spl-token CLI, @solana/kit or Anchor, and integrate the resulting mints. The skill starts with picking extensions, because fixed-size mint extensions can only be set before InitializeMint. TokenMetadata, TokenGroup and TokenGroupMember can be initialized later, but only if their pointer was set at creation.

When should I use Solana Token Extensions?

Solana Token Extensions fits situations like: choosing which Token-2022 extensions fit a new token design; creating a mint with transfer fees, metadata or a permanent delegate; adding a transfer hook that runs your own program on each transfer; checking whether an extension mint will work with a trading venue.

How do I install Solana Token Extensions in Claude Code?

Run `npx skills add solanabr/ai-kit --skill token-extensions -a claude-code`. Or copy the skill folder (.claude/skills/token-extensions in solanabr/ai-kit) into .claude/skills/token-extensions in your project. Claude Code loads it when a task matches its description.

How do I install Solana Token Extensions in Codex?

Run `npx skills add solanabr/ai-kit --skill token-extensions -a codex`. Or copy the skill folder (.claude/skills/token-extensions in solanabr/ai-kit) into .agents/skills/token-extensions in your project. Codex loads it when a task matches its description.

Can I use Solana Token Extensions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add solanabr/ai-kit --skill token-extensions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/token-extensions, .gemini/skills/token-extensions, .github/skills/token-extensions and .opencode/skills/token-extensions in your project.

What does Solana Token Extensions need to run?

Going by SKILL.md and its folder, Solana Token Extensions needs the command-line tools its instructions call (bash). Our summary lists: The spl-token CLI, @solana/kit or Anchor, depending on how you build.

Does Solana Token Extensions access the network?

SKILL.md names 1 domain. As links in the text: solana.com. This is read from the text; nothing was executed.

Is Solana Token Extensions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Solana Token Extensions use?

Solana Token Extensions is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Solana Token Extensions use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16k tokens, read only when the agent opens those files.

What are the alternatives to Solana Token Extensions?

Skills that share tags, products or a category with Solana Token Extensions: Switchboard Oracle SDK (internet-court/internet-court-skill, 6.4k stars), Pyth Network Price Feeds (internet-court/internet-court-skill, 6.4k stars), Payram Crypto Payments (PayRam/payram-mcp, 158 stars) and Swap Tokens (circlefin/skills, 155 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Solana Token Extensions?

solanabr (a GitHub organization) maintains it in solanabr/ai-kit, which has 108 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 8, 2026.

Source: solanabr/ai-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.