Campaign Kit docs
v0.1.0
Get help
● Customize · Trust

Security & privacy
what is protected, and how.

How keys, tokens, sessions and player data are handled, and what you must do as the operator.

01Non-custodial

No private key or seed phrase on any server. Deploy, fund and withdraw are signed by your wallet, claims by each player's wallet, through TON Connect. The contract has no upgrade path and no way to change its root, deadline or owner.

02Secrets at rest

  • Bot tokens: AES-256-GCM with ENCRYPTION_KEY, never returned to the admin.
  • Admin passwords: bcrypt hashes. Sessions: httpOnly SameSite=Lax cookie, 12 hours, Secure in production; admin changes from origins outside CORS_ORIGINS are refused.
  • Adsgram callback secret and client report tokens: only SHA-256 hashes are stored; the full URL is shown once.
  • Daily puzzle answers: salted hashes, compared in constant time.
  • Keep .env out of Git and out of support messages.

03Player auth and data

  • Every player request carries Telegram initData, verified with HMAC against the campaign's own bot token and rejected when older than 24 hours. There is no bypass flag. Re-verification needs a login at most 10 minutes old.
  • IPs and user agents are stored only as salted SHA-256 hashes, for anti-bot clustering.
  • Admin lists redact usernames, Telegram IDs and wallets. Reveals, bans, overrides, refunds, exports, snapshot actions and configuration changes are written to the audit log, which cannot be edited from the admin.
  • Client reports, the Overview and the Fairness Center show aggregates or shortened names only.
  • TON Connect analytics are switched off in both apps.
  • Production builds ship a Content-Security-Policy that limits API calls to your API origin.

04Rate limits

In memory per API process: per IP burst 120 then 20/s; per player burst 40 then 8/s; admin login 10 tries then 1 per 6 s; public report and airdrop endpoints are rate-limited too (wrong report tokens cost more).

05Your responsibilities

  • Create the owner account immediately after the first deploy.
  • Keep the API behind the proxy (Compose binds it to 127.0.0.1) and TRUST_PROXY=true only behind a proxy.
  • Back up the database and .env; patch the server.
  • Publish a privacy notice for your players: you are the data controller of what the kit stores (Telegram id, name, username, language, Premium flag, hashed IP and user agent, linked wallet, game activity).
  • Get the distributor contract audited before it holds meaningful value.

06Known dependency notes

  • valibot (a transitive dependency of the admin and the Telegram SDK) has a published ReDoS advisory; player input does not reach it.
  • @tonstudio/parser-runtime (build-time dependency of the Tact compiler) declares no licence; it is not shipped in any app.