Wallets & ownership

Know what your signature authorizes.

A wallet must help you review the payment, protect custody and distinguish evidence from spendable funds.

CONTENT REVIEWED / 4 OCTOBER 2026

Review the currency, region and inputs

Before signing, verify the pinned currency and regional identity, recipient, amount, fee, actual input owners and current input availability. Pending reservations reduce the budget for another request. A cached balance or a downloaded proposal cannot authorize spending.

The ground client asks native software to review complete authenticated history at the signing height. Its clicked pending review and separate caller head survive response loss; exact recovery cannot create a new signature.

Each owner approves independently

A group proposal fixes its ordered actual owners and input IDs, payment intent, refund conservation and one expiry. Construction does not sign or reserve. Each owner rechecks current native inputs and retains only their own partial approval and reservations. Every actual owner is required before normal native acceptance.

Verify the recipient’s state

The recipient needs more than the sender’s ‘sent’ label. It must distinguish source inclusion and finality, custody during transport, unique import, maturity, local spend and onward export eligibility. A historical proof can establish a certified old record while the current output is already spent or quarantined.

Keep the complete custody history

Native encrypted ground custody binds a key to its exact currency, region, owner and purpose. Passwords enter through the local native path, never this website. The backup includes the complete owner journal; fresh-directory restore requires a separately retained latest head and native history checks.

An interrupted restore target stays closed. Encrypted backups remain private. Common rollback of all state and heads, concurrent copied keys, hardware custody and recovery across devices are not qualified.

Learn with a separate test fixture

Published wallet and node experiments use fresh private directories and worthless fixture assets. Do not reuse a real payment key or migrate old balances into an incompatible candidate. Follow the exact package’s guide and keep keys, journals, heads, sessions and recovery files out of public reports.