Sensitive actions
| Action | Required handling |
|---|---|
| Google login | Complete the provider sign-in prompt |
| Wallet login | Verify the domain and sign a login message only |
| MCP token | Store it in the client environment; never paste it into chat or source control |
| Exchange API | Use minimum permissions, disable withdrawals, and enter the Secret only in the provider form |
| Wallet transaction | Review the network, contract, amount, and signature |
| Private key or seed | Never display, copy, screenshot, or log it |
Sign-in methods
Google sign-in follows the provider account prompt. Wallet sign-in should normally request a message signature for the NewsLiquid domain. Cancel any unexpected transfer, token approval, or transaction request.
Tokens and credentials
- 01
Use a dedicated token or API key for NewsLiquid.
- 02
Grant only required permissions.
- 03
Keep withdrawal permission disabled.
- 04
Use an IP allowlist when the provider supports and requires it.
- 05
Rotate or revoke a credential after suspected exposure.
- 06
Do not include a secret in copied Markdown, chat, screenshots, or documentation.
Screenshots and sharing
Before sharing, crop or cover account identity, full addresses, balances, positions, API key fragments, QR codes, and transaction details that are not needed. Public news and product controls can remain when they do not reveal account state.
A Daily PNL poster is designed for sharing but still exposes the selected nickname, avatar, date, realized PNL, and market contribution. Review the preview before using Copy image, Download PNG, or Share to X.
If something looks wrong
- 01
Stop the current action
Do not retry a payment, trade, approval, or transfer while status is uncertain.
- 02
Check product history
Review orders, positions, billing, usage, or transaction status.
- 03
Revoke access when needed
Disable the MCP token, exchange API key, or wallet authorization from the authoritative provider.
- 04
Contact support
Provide time, page, error, and non-sensitive identifiers. Never send a private key or full Secret.
