Documentation / Approval Security
LIVE

Approval Security

Approval is bound to one exact intent.

Telegram linking consumes a random, hashed, single-use deep-link token. Telegram webhooks require Telegram's configured secret header and callbacks carry an HMAC signature. The callback user and chat must match the account's link.

Approvals expire, can resolve only once and are recorded with their Telegram identity. A compromised Telegram account remains a risk, so operators should disconnect it and pause affected wallets when needed.