Session and Replay Protection
This page is intentionally limited to public-safe guidance.
Public Protection Model
- Authentication uses one-time nonce-based proof of wallet control.
- Access/session tokens are short-lived and scoped by use case.
- Replay attempts are rejected by server-side nonce/token state checks.
Public Integration Advice
- Always request fresh auth material when validation fails.
- Do not reuse expired or consumed session artifacts.
- Treat repeated auth/session failures as security signals, not normal retries.
