Security

The library enforces most of these rules. You are responsible for the rest: secret handling, pricing, and any custom repository.

Why a receive-only NWC code is the only wallet credential

An NWC code is a connection string. It holds a client secret that the wallet created for this connection, plus a relay. The wallet decides which methods that secret may call.

A receive-only connection can create invoices and list incoming payments. It cannot pay anyone. The secret might leak through a compromised server, a .env file in git, or a log line. An attacker who gets it can create invoices payable to you and read your history. They cannot drain the wallet.

OpenReceive has no code path that sends payments. The spend-capable override above only widens what a leaked code could do from some other NWC client.

What preflight proves

On boot, OpenReceive asks the wallet what this connection may do. Node adapters do this on the first request instead. It checks three things:

  1. It can make_invoice and list_transactions.
  2. It speaks an encryption mode the library supports.
  3. It does not advertise spend methods.

If any check fails, your application does not start. Await the adapter’s ready promise in a deploy health check. Tests can inject a fake wallet and skip NWC entirely.

What receive-only does not cover

Further reading