● Customize · Trust
Security & privacy
what is protected, and how.
How keys, tokens, sessions and player data are handled, and what you must do as the operator.
01Non-custodial
No private key or seed phrase on any server. Deploy, fund and withdraw are signed by your wallet, claims by each player's wallet, through TON Connect. The contract has no upgrade path and no way to change its root, deadline or owner.
02Secrets at rest
- Bot tokens: AES-256-GCM with
ENCRYPTION_KEY, never returned to the admin. - Admin passwords: bcrypt hashes. Sessions: httpOnly
SameSite=Laxcookie, 12 hours,Securein production; admin changes from origins outsideCORS_ORIGINSare refused. - Adsgram callback secret and client report tokens: only SHA-256 hashes are stored; the full URL is shown once.
- Daily puzzle answers: salted hashes, compared in constant time.
- Keep
.envout of Git and out of support messages.
03Player auth and data
- Every player request carries Telegram initData, verified with HMAC against the campaign's own bot token and rejected when older than 24 hours. There is no bypass flag. Re-verification needs a login at most 10 minutes old.
- IPs and user agents are stored only as salted SHA-256 hashes, for anti-bot clustering.
- Admin lists redact usernames, Telegram IDs and wallets. Reveals, bans, overrides, refunds, exports, snapshot actions and configuration changes are written to the audit log, which cannot be edited from the admin.
- Client reports, the Overview and the Fairness Center show aggregates or shortened names only.
- TON Connect analytics are switched off in both apps.
- Production builds ship a Content-Security-Policy that limits API calls to your API origin.
04Rate limits
In memory per API process: per IP burst 120 then 20/s; per player burst 40 then 8/s; admin login 10 tries then 1 per 6 s; public report and airdrop endpoints are rate-limited too (wrong report tokens cost more).
05Your responsibilities
- Create the owner account immediately after the first deploy.
- Keep the API behind the proxy (Compose binds it to 127.0.0.1) and
TRUST_PROXY=trueonly behind a proxy. - Back up the database and
.env; patch the server. - Publish a privacy notice for your players: you are the data controller of what the kit stores (Telegram id, name, username, language, Premium flag, hashed IP and user agent, linked wallet, game activity).
- Get the distributor contract audited before it holds meaningful value.
06Known dependency notes
valibot(a transitive dependency of the admin and the Telegram SDK) has a published ReDoS advisory; player input does not reach it.@tonstudio/parser-runtime(build-time dependency of the Tact compiler) declares no licence; it is not shipped in any app.