Skip to main content

Connected and verified wallets

Connecting a wallet tells the app an address. Signing in proves control of that address at that time. It does not prove a person's identity or a refund claim.

LabelWhat your team knows
No wallet proof is attached.
The app reported an address the user chose to share.
Templ checked the wallet's sign-in message and signature.

Read the sign-in message​

The user signs in through the widget's sign-in card. The message names the site and . Check that the site matches the app you meant to use.

https://app.example.com wants you to sign in with your Ethereum account:
<your wallet address>

Sign in to this protocol's support on Templ. This does not send a transaction.

URI: https://app.example.com
Version: 1
Chain ID: <selected network ID>
Nonce: <one-time code>
Issued At: <issue time>
Expiration Time: <expiry time>
Resources:
- https://usetempl.com/rooms/<workspace ID>

Sign In With Solana In testing

Templ checks the site, network, one-time code, expiry and workspace. The sign-in sends no transaction, charges no network fee and grants no token approval. Never share a private key or recovery phrase.

Ask for wallet proof​

Your team can ask a user to verify before a sensitive step. The user chooses whether to sign in. A connected wallet remains unverified until that proof passes.

Keep a guest's case​

When a guest verifies from their own , Templ moves that case to the proved wallet. If the wallet already has a case, both stay linked. This step grants no team access and merges no accounts.

Smart-wallet sign-in In testing

For developers​

The widget uses Sign-In with Ethereum (SIWE, ERC-4361) or Sign In With Solana (SIWS). Each challenge binds domain, URI, chain, nonce, expiry and the workspace resource. SIWS names Solana mainnet. Its signature uses strict padded base64. The guest's own bearer must redeem the proof that moves their case. Keep replay, revocation and origin checks. Contract-wallet signatures fail closed without their supported verification.

Sources​

Read the widget guide, Security and Spot fake support. The developer reference covers the integration.

In testing means the feature is built and not yet open to every workspace.