listening for routes
LIEND GitBookTrust

Trust

Security

Non-custodial design, explicit origins and no invented balances.

Non-custodial

LIEND never takes custody of keys. Authentication is a signed message. Execution, when it exists, is a user-approved transaction from the connected wallet.

Origins and cookies

The API allowlists exact App and extension origins. It does not trust every vercel.app host. Session secrets stay server-side.

Storage

Production persistence is Postgres. Device credentials and extension sessions are stored as hashes. Pairing identifiers are not themselves credentials.

Truthful empty states

If the API, the App origin or the database is missing, the UI says so. LIEND does not invent a mint, a holder threshold or a Pump.fun coin page.