Command line

evergreen extend

Builds a TTL extension and simulates it. Submitting is a separate, explicit decision that needs a flag, a named secret variable and a fee cap — and it is testnet only.

It simulates unless you insist

Running extend with no submission flags builds the operation, simulates it against the network and tells you what would happen. Nothing is signed and nothing is sent. --dry-run exists so a script can state that intention rather than rely on the absence of a flag, and it is mutually exclusive with --submit.

Simulation success does not mean the TTL changed. It means the network accepted the shape of the operation. Until you submit, nothing on chain has moved.

The guards

GuardWhat it prevents
simulate by defaultA command that submits because a flag was forgotten.
--submit requiredSubmission as a side effect of any other option.
--secret-env NAMEA secret in shell history, in a process list, or in a committed script. The value is never an argument, and there is no .env auto-loading.
--max-fee-stroops NAn unbounded fee. The cap is an aggregate in integer stroops and it is mandatory with --submit.
explicit payerSilent use of some default account. Supply --source-account or EVERGREEN_SOURCE_ACCOUNT; there is no fallback payer.
testnet passphrase checkA mainnet submission from a mislabelled config. The passphrase is compared, not a label trusted.
--include-code opt-inExtending Wasm shared with contracts you cannot see, without meaning to.
no auto restore or fundingThe tool quietly spending more than the operation you asked for.
no replacement sendA double submission after an uncertain result. An unconfirmed result is reported, not retried.

Usage

usage: evergreen extend <contract-id> --ledgers N [--source-account G...] [--keys-file path] [--include-code] [--json] [--submit --secret-env NAME --max-fee-stroops N] --dry-run simulate only and say so. This is already the default; the flag exists so a script can state its own safety rather than rely on an absence. Mutually exclusive with --submit. Testnet only. Default: simulate, never sign or submit. Supply a public payer with --source-account or EVERGREEN_SOURCE_ACCOUNT; there is no fallback payer. --ledgers N adds N ledgers to each selected entry's current remaining TTL. The operation target is capped at max_entry_ttl - 1; capping is reported. Selects instance by default. A keys file adds explicit data keys: { "dataKeys": ["base64 XDR LedgerKey", ...] }. Storage is not enumerated. --include-code explicitly includes Wasm shared with potentially unseen consumers. --submit requires an exported secret variable NAME and an aggregate fee cap in integer stroops. Never put the secret itself in arguments. No .env auto-loading. No automatic restore or funding. No replacement send after uncertain results. Exit 0: complete simulation, no-op, or verified live result; 2: error or partial/ unconfirmed result. Simulation success does not mean TTL changed.

Printed by evergreen extend --help, read from packages/cli/src/extend.ts at build time.

What gets extended

The instance entry by default. A keys file adds explicit data keys, in the same shape the scanner takes — { "dataKeys": ["base64 XDR LedgerKey", ...] }. Storage is never enumerated, so what you do not name is not touched.

--ledgers N adds N to each selected entry’s current remaining TTL. The protocol wants an absolute target, so the CLI computes it for you and caps it at max_entry_ttl - 1, saying so when it does.

What the exit code means here

0 is a complete simulation, a no-op, or a verified live result. 2 is an error, or a partial or unconfirmed result. There is no exit code that means “probably worked”. Exit codes

Next Output The human report, and --json for machines.