Authenticate before showing account data.

The browser workspace must remain locked until the server verifies the desktop authentication response. A URL parameter, open app or browser focus change is not proof of identity.

Keep permissions explicit.

The session should grant only the requested access. Sensitive actions require a separate confirmation, and expired or revoked sessions must no longer expose account data.

Keep wallet secrets out of web forms.

This website never asks for a recovery phrase or private key. Use the verified desktop release for its supported recovery and key-management procedures.