Skip to content

Security

Control starts with clear boundaries.

Walhash provides the interface and monitors the blockchain. Your device holds the keys and signs transactions.

On your device

The recovery phrase is encrypted in browser storage using your local wallet password. Signing happens locally after you unlock the wallet.

On the server

Account details, public wallet descriptors, addresses and transaction records. The server prepares transactions and broadcasts verified signed payloads.

Your recovery backup

Save the recovery phrase safely before using the wallet. On another device, restore the existing wallet with this phrase. Resetting the account password does not restore your keys.

Save your recovery phrase

•••• •••• •••• ••••

Protect account access

Use an account password, then configure two-factor authentication or passkeys in security settings. These protect sign-in; keep your device and recovery phrase secure as well.

Separate controls for API access

Scopes limit what a key can do. IP allowlists limit where it can be used. Optional request HMAC verifies the request signature. None of these replaces local wallet signing.

Webhook HMAC

Verify the webhook HMAC signature before processing an event. Handle retries idempotently so the same payment is not fulfilled twice. IP filtering is a separate protection layer.

Make room for your next move.

Create an account, then set up the wallet on your device and save your recovery phrase.

Create wallet