Sensitive actions

ActionRequired handling
Google loginComplete the provider sign-in prompt
Wallet loginVerify the domain and sign a login message only
MCP tokenStore it in the client environment; never paste it into chat or source control
Exchange APIUse minimum permissions, disable withdrawals, and enter the Secret only in the provider form
Wallet transactionReview the network, contract, amount, and signature
Private key or seedNever display, copy, screenshot, or log it

Sign-in methods

Google sign-in follows the provider account prompt. Wallet sign-in should normally request a message signature for the NewsLiquid domain. Cancel any unexpected transfer, token approval, or transaction request.

Tokens and credentials

  • 01

    Use a dedicated token or API key for NewsLiquid.

  • 02

    Grant only required permissions.

  • 03

    Keep withdrawal permission disabled.

  • 04

    Use an IP allowlist when the provider supports and requires it.

  • 05

    Rotate or revoke a credential after suspected exposure.

  • 06

    Do not include a secret in copied Markdown, chat, screenshots, or documentation.

Screenshots and sharing

Before sharing, crop or cover account identity, full addresses, balances, positions, API key fragments, QR codes, and transaction details that are not needed. Public news and product controls can remain when they do not reveal account state.

A Daily PNL poster is designed for sharing but still exposes the selected nickname, avatar, date, realized PNL, and market contribution. Review the preview before using Copy image, Download PNG, or Share to X.

If something looks wrong

  1. 01

    Stop the current action

    Do not retry a payment, trade, approval, or transfer while status is uncertain.

  2. 02

    Check product history

    Review orders, positions, billing, usage, or transaction status.

  3. 03

    Revoke access when needed

    Disable the MCP token, exchange API key, or wallet authorization from the authoritative provider.

  4. 04

    Contact support

    Provide time, page, error, and non-sensitive identifiers. Never send a private key or full Secret.