Medusa Docs

Reference

Security & wallet safety

Know what Medusa asks you to sign and which secrets you should never provide.

Wallet ownership verification

Medusa links wallets by asking the wallet to sign a challenge that proves control of the public address. Solana can use message signing or the hardware-wallet transaction-signing path. Robinhood Chain uses an EVM personal-sign challenge.

Never provide these secrets

  • Seed or recovery phrase.
  • Private key.
  • Wallet export file or secret-key JSON.
  • Discord password.
  • OAuth client secrets or Medusa backend credentials.

A legitimate Medusa linking flow does not need a recovery phrase

If any website or person asks for your seed phrase in order to connect a wallet to Medusa, do not provide it.

Discord and X authorization

Discord is the primary dashboard login. X can be connected separately from Profile and disconnected without changing the Discord login used to access Medusa.

Admin safety

  • Give delegated server administration only to people who need day-to-day configuration access.
  • Remember that Billing, Team and ownership remain Owner responsibilities.
  • Use Check wallet before changing a production rule during troubleshooting.
  • Use Verification Logs to preserve an evidence-based troubleshooting path.
Still need help? Follow the troubleshooting checklist before escalating the issue.Open troubleshooting →