StegWallet · Base App and injected wallets · keys remain in the wallet

Govern the goal before
the transaction reaches signature.

Operate from an ordinary mobile browser, MetaMask, or the Base App browser. A Basename may identify the account for people, but the wallet address and hash-bound records remain canonical.

Runtime boundary: connecting a wallet grants account visibility only. SIWE authentication proves wallet control for the browser session only. A transaction reaches the wallet prompt only after an imported StegWallet signature request passes schema, account, chain, commitment, and authority checks.

1. Connect signing wallet

Uses the injected EIP-1193 provider supplied by Base App, MetaMask, or another compatible wallet. Base mainnet is the first supported chain.

Not connected.
Environment not evaluated.

2. Authenticate browser session

A server-issued EIP-4361 message may be signed only when the configured StegVerse SIWE endpoint is HTTPS and matches this Site origin policy.

SIWE runtime configuration not loaded.

3. Define the goal

Wallet-browser readiness receipt

SIWE session receipt

Goal mandate

4. Review an admitted transaction

Paste the exact stegwallet.signature_request.v1 produced by the StegWallet runtime. Raw route suggestions or ordinary transaction JSON are rejected.

No request loaded.

5. Settlement observation

Domain and authority boundary

stegverse.org HTTPS origin   = durable public application origin
Basename display alias       = onchain identity and payment alias
Base App browser             = distribution and wallet surface
wallet address               = canonical account identity
readiness receipt            != wallet authentication or authority
SIWE session                 = off-chain wallet authentication only
SIWE session                 != trade admissibility or transaction authority
StegWallet ALLOW             = may reach wallet prompt
wallet user approval         = Mode 1 execution authority
HPS delegation receipt       = prerequisite for Mode 2 signer submission
domain / Basename / profile  != execution authority
private key / seed phrase    = never requested