Subnets
Create subnets, add validators, transfer ownership, and convert to L1 blockchains
Platform CLI supports creating subnets, transferring ownership, and converting them to L1 blockchains.
Create a Subnet
platform-cli subnet create --key-name mykey --network fujiCreating new subnet...
Owner: P-fuji1abc123...
Submitting transaction...
Subnet created successfully!
Subnet ID: 2QYfFcfZ9...The subnet owner is the wallet address used to create it. You need P-Chain AVAX balance to create subnets.
Transfer Subnet Ownership
Transfer ownership to a new P-Chain address:
platform-cli subnet transfer-ownership \
--subnet-id 2QYfFcfZ9... \
--new-owner P-fuji1xyz789... \
--key-name mykeyAdd a Validator (Permissioned Subnet)
Add a validator to a permissioned subnet (AddSubnetValidatorTx). The node must already be a primary network validator, and the subnet owner key authorizes the transaction.
platform-cli subnet add-validator \
--subnet-id 2QYfFcfZ9... \
--node-id NodeID-BFa1paAAAA... \
--weight 100 \
--duration 336h \
--key-name mykeyThe validation period must fall within the node's primary network validation window. --weight is the validator's sampling weight on the subnet (not a stake amount). To add validators to a subnet that has already been converted to an L1, use l1 register-validator instead.
Convert Subnet to L1
Convert a permissioned subnet to an L1 blockchain. This operation is irreversible.
Auto-Discovery Mode
Provide validator node addresses and let the CLI fetch NodeID and BLS credentials:
platform-cli subnet convert-to-l1 \
--subnet-id 2QYfFcfZ9... \
--chain-id 3RZgGdaH1... \
--manager 0x1234567890abcdef1234567890abcdef12345678 \
--validators 127.0.0.1:9650,127.0.0.1:9652 \
--validator-balance 1.0 \
--key-name mykeyManual Mode
Provide validator data explicitly (all lists must be comma-separated and aligned by index):
platform-cli subnet convert-to-l1 \
--subnet-id 2QYfFcfZ9... \
--chain-id 3RZgGdaH1... \
--manager 0x1234... \
--validator-node-ids NodeID-A...,NodeID-B... \
--validator-bls-public-keys 0xabc...,0xdef... \
--validator-bls-pops 0x111...,0x222... \
--validator-balance 1.0 \
--key-name mykeyValidator Owners
Each initial validator has two P-Chain owners. The P-Chain cannot change them after the conversion.
| Owner | Flag | Permission |
|---|---|---|
| Remaining balance owner | --validator-remaining-balance-owner | Receives the validator's remaining balance when the validator is disabled or removed |
| Deactivation owner | --validator-deactivation-owner | Can disable the validator (l1 disable-validator) |
Both owners default to the P-Chain address of your key, with threshold 1. To set other owners, give 1 address for all validators, or 1 address per validator in the same order as --validators or --validator-node-ids:
platform-cli subnet convert-to-l1 \
--subnet-id 2QYfFcfZ9... \
--chain-id 3RZgGdaH1... \
--manager 0x1234... \
--validators 127.0.0.1:9650,127.0.0.1:9652 \
--validator-remaining-balance-owner P-fuji1abc... \
--validator-deactivation-owner P-fuji1def...,P-fuji1ghi... \
--key-name mykeyThe CLI prints both owners of each validator before it submits the transaction.
An empty owner has threshold 0, so any funded P-Chain key can disable the validator and spend its remaining balance. The CLI refuses to issue an empty owner unless you set --allow-empty-owners. Do not use that flag on a real L1. Versions before v2.2.0 set both owners to empty on every conversion.
Mock Validator (Testing)
For local testing, generate a mock validator with random BLS credentials:
platform-cli subnet convert-to-l1 \
--subnet-id 2QYfFcfZ9... \
--chain-id 3RZgGdaH1... \
--mock-validator \
--key-name mykey \
--rpc-url http://127.0.0.1:9650Is this guide helpful?