Skip to main content

A connected wallet is not proof

Templ
Templ
Notes from the Templ team

Connecting a wallet shares an address with an app. The address alone does not prove who controls it.

Read the sign-in message​

Signing in proves control of the wallet at that time, for that site. It does not prove a person's identity or their right to a refund.

A standard sign-in message names the site, wallet, network and expiry. The site checks the signature and the message together.

Templ also ties the message to the intended workspace. A message copied from another site or case cannot grant access here.

Ethereum's October 2021 sign-in standard describes these checks. Phantom's August 2023 guide describes a standard sign-in message for Solana.

Check what a signature allows​

Some signatures allow token spending. A sign-in message and a token permission have different effects.

Read the site name and the full message before signing. Stop if the wallet asks for spending permission during a support sign-in.

Templ's support sign-in sends no transaction and costs no network fee. Chat cannot start a payment or a signature.

Never share a private key or recovery phrase.

Use the wallet label​

LabelWhat your team knows
GuestThe user has no wallet proof.
Attached walletThe app reported the wallet. The user chose to share it.
Verified walletThe user signed in with that wallet.

Ask the user to verify before a step that needs proof of wallet control. Keep questions about the failure in the same case.

A guest who verifies later keeps their case linked to the wallet. If that wallet has a case, both stay linked.

Solana sign-in In testing follows the same site and workspace checks.

Smart wallet sign-in

In testing

needs its own supported verification. Do not treat a connected smart wallet as proof.

In testing means the feature is built and not yet open to every workspace. See availability.

Sources​