All docs
Sign-in
Sign in to the console with a Solana wallet signature or an email account. A wallet signature proves the address is yours. It never moves funds.
The console is at app.quantbase.live. There are two ways in, and both end in a session in your browser. Agents and scripts use an API key instead.
With a Solana wallet#
On Log in, choose Continue with and your wallet. QuantBase finds any wallet that supports the Wallet Standard (Phantom, Solflare and Backpack, for example). If none is installed, the page says so.
- Your wallet asks to connect. Approve it.
- Your wallet asks you to sign a sign-in message. It reads like this:
quantbase.live wants you to sign in with your Solana account:
<your address>
Sign in to QuantBase. This request does not trigger a transaction or cost any fees.
followed by a one-time nonce, the time it was issued and an expiry five minutes later. 3. QuantBase checks the signature against your address, checks that the message is exactly the one it issued for that address, unexpired and unused, and then spends the nonce so the same signature cannot be used again.
The first time, this creates your account. After that, the same wallet signs you into the same account.
What a wallet signature does and does not authorise#
It proves you control the address. That is all.
- It is a message, not a transaction. QuantBase never builds, requests or accepts a transaction, and the message begins with a sentence naming the site, which no wallet reads as a transaction.
- It costs nothing and moves no funds. It grants no spending approval and no access to your tokens.
- QuantBase never asks for your seed phrase or private key. Anyone who does, in QuantBase's name, is not QuantBase.
- The message names the site asking for it, a
quantbase.liveaddress. If your wallet shows a QuantBase sign-in request from any other domain, do not sign it.
An account made with a wallet alone starts on the Free (wallet) plan; see Plans. The console has a way to add a sign-in email to a wallet account, which moves it to the full Free plan; it appears only while email-link sign-in is switched on.
With an email account#
Under "Signed up with Google or email before? Continue here." the console shows an email sign-in form, run by Clerk, our sign-in provider. New accounts can be created on the sign-up page, under Create your account. Clerk runs the sign-in itself (for example Google, or an email address); QuantBase receives your account's email address from Clerk.
Email addresses are treated as one identity per mailbox: you+tag@gmail.com
and y.o.u@gmail.com reach the same account as you@gmail.com.
Sessions#
A wallet sign-in creates a session that lasts 30 days. It is held in
__Host- cookies: Secure, HttpOnly for the session itself, bound to the one
host, and never shared with other subdomains. Changes you make in the console
also carry a separate anti-forgery token, so another site cannot act for you
by sending your cookies.
The session secret is stored only as a SHA-256 hash, as are API keys. A database copy is not a set of working sessions.
Sign out everywhere in Settings, under Sessions, ends every wallet session on your account at once, this one included. Log out on Me signs you out.
Email-account sessions are managed by Clerk.
Limits#
Sign-in requests are rate limited per network: 30 wallet sign-in attempts an hour, and a cap on how many new wallet accounts one network can create in a day. A refusal says to wait and try again.
Operator accounts#
Accounts that can reach live trading cannot sign in on the web at all. They use API keys, so no browser session can ever reach a money action.
Evidence, not advice. Signing in gives you access to measurements, nothing more.
This page as Markdown, for agents: /docs/sign-in.md