Skip to content

Connection permissions

Connecting a site is the smallest permission in the product, and it is routinely mistaken for the largest one. It is worth being precise about.

What a connected site is granted, what it is never granted, and how access endsA site asks to connect. You approve once. The grant is drawn as a boundary with two sides. Inside the boundary the site is granted three things: it can read one selected address on one network, it can read that address's public balance and assets, and it can put a signature request in front of you. Outside the boundary, permanently, sit five things it is never granted: your recovery phrase, your private keys, the ability to move a coin without a fresh approval, your other accounts and other networks, and the contents of pages you visit. A timeline below shows the life of the grant. Approval starts an idle window, chosen from twenty four hours, seven days, thirty days which is the default, or until you disconnect. Each use of the site resets that window, so a site you use daily never expires. A site left alone past the window loses access and has to ask again from the beginning. Disconnecting ends it immediately.ONE APPROVAL, A NARROW GRANT, AND AN END DATEapp.example asks to connect. You approve once, in the wallet, not on the page.The browser reports the origin. The wallet shows you that origin, not a name the page chose.GrantedOne address, on one network.bc1q...4tzqPublic balance and assets at thataddress, which anyone can read anyway.The right to ask you for a signature.Never grantedYour recovery phrase.Your private keys.Moving a coin without a new approval.Your other accounts and networks.The contents of the pages you visit.EVERY SIGNATURE IS ASKED FOR SEPARATELYBeing connected is permission to ask. It is never permission to sign. Each request is its own screen.How the grant endsApprovedidle window startsUsed againwindow resetsLeft idle24h / 7d / 30dAccess endsmust ask again

Being connected is permission to ask. It is never permission to sign. Every signature is its own screen, every time, for the life of the connection.

  • One address, on one network. Not your wallet, not your accounts, not your other networks. The one you selected when you approved.
  • The public data at that address: balance, assets, history. All of this is public on the chain already, and anyone could read it without asking you.
  • The right to put a signature request in front of you.
  • Your recovery phrase.
  • Your private keys.
  • The ability to move a coin without a fresh approval.
  • Your other accounts and other networks.
  • The contents of the pages you visit. The wallet reads the origin the browser reports, not the page.

The approval screen shows the origin the browser reports, not a name the page chose for itself. A page can print any brand it likes in its own body. It cannot change the origin line in the wallet. When you are checking whether you are on the real site, that line is the one to read.

You choose an idle window when you connect. Options are 24 hours, 7 days, 30 days, which is the default, or until you disconnect.

It is an idle window, not an age limit. Each time you use the site, the window restarts. A site you use every day never expires on its own; a site you tried once in March is gone by April.

When the window passes, access ends. The site has to ask again from the beginning, and you get the full approval screen again.

Open Connected sites. You can see every connection, what each one can read, when it was last used, and end any of them, or all of them at once. A site that lost access has to start over.

Disconnecting stops a site from asking for anything new. It does not:

  • reverse a transaction you already approved,
  • revoke a signature you already gave, including a partial signature that someone can still complete (see What a signature authorizes),
  • undo an approval on the chain.

If you are disconnecting because something went wrong, disconnecting is the second step. The first is If your wallet is compromised.