Sign in and Verified Dev

What the sign in signature proves, who counts as a token's creator, and what can stop you from verifying.

Verified Dev means the wallet that signed in is the token's creator of record, read from the chain right now. It is how we stop anyone else from setting up a page or a split for your coin.

How sign in works

  1. Connect

    Connect your wallet in the Studio. We see your public address only.

  2. Sign a message

    Your wallet shows a plain text message with our domain, your address, a one time code and an expiry. Signing it is free. It is a message, not a transaction, and it moves no funds.

  3. We check it

    Our server checks that the signature is valid, that the message is exactly ours, written for this site, not expired (it lasts 10 minutes) and not used before.

  4. A session starts

    A signed cookie keeps you signed in for 24 hours. You can sign out at any time.

A signature proves a wallet, not a dev.Signing in proves you control a wallet and nothing else. For anything that belongs to a coin, we read the chain again at that moment and compare.

Who counts as the creator

Where the token launchedCreator of recordWhere we read it
pump.funThe creator in the bonding curve accountThe curve, and the PumpSwap pool after graduation
StonkFun, Bonk.fun and other Raydium LaunchLab coinsThe pool creatorThe LaunchLab pool account
Meteora Dynamic Bonding Curve coinsThe pool creatorThe Meteora virtual pool account
Any other tokenThe metadata update authority, or the mint authorityOnly when that authority is a wallet and not a program

The developer that Jupiter lists for a token is shown for information only. It is never used to decide who can edit.

What can stop you

  • A creator that is a program, a multisig vault or another address that cannot sign a message cannot verify yet.
  • Ledger wallets may not be able to sign in. Message signing on Ledger depends on the wallet app, and there is no transaction based fallback yet.
  • If a token's creator of record changes, the old wallet stops being verified at once, because we read the chain every time.

Editors

The creator can add up to 10 editor wallets to a team page. An editor can change the page's content. Only the creator can change the editors or add more tokens to the page.

What it costs

Signing in is free. A one time 0.1 SOL onchain attestation, written with the Solana Attestation Service, is planned as part of Verified Dev. It is not built and not charged yet.

Cookies

Two cookies, both httpOnly and SameSite Lax, and secure in production: a nonce cookie that lasts 10 minutes while you sign, and a session cookie that lasts 24 hours. Neither is used for anything else.