listening for routes
LONSDocs

LONS / PRODUCT DOCUMENTATION

Security

Non-custodial design, explicit origins and no invented balances

Trust

Security

LAST REVIEW / 2026

Non-custodial design, explicit origins and no invented balances

01

Non-custodial

LONS never takes custody of keys. Authentication is a signed message. Execution, when it exists, is a user-approved transaction from the connected wallet

02

Origins and cookies

The API allowlists exact App and extension origins. It does not trust every vercel.app host. Session secrets stay server-side

03

Storage

Production persistence is Postgres. Device credentials and extension sessions are stored as hashes. Pairing identifiers are not themselves credentials

04

Truthful empty states

If the API, the App origin or the database is missing, the UI says so. LONS does not invent a mint, a holder threshold or a pons coin page