What to prepare before you start

When working with Connection requests, it helps to understand how it connects with Domain checks and Account scope.

A practical DApp Connections workflow can be divided into preparation, review, execution and verification. Prepare by checking your device and network environment. Review the relevant Connection requests, Domain checks, Account scope, Session permissions and Disconnecting. Execute only the request you currently understand, then verify the outcome through transaction history or public on-chain data. Repeating these stages helps prevent familiarity with an interface from turning into automatic approval of important actions.

Treat every transfer, signature and approval as a separate decision. A DApp that was safe to use previously does not make every future request automatically trustworthy. Reviewing Connection requests, Domain checks and Account scope one by one helps you confirm that the address, network, amount, approval target or signed content matches what you actually intend to do. If a request is not understandable, declining it is safer than approving it simply to complete a flow.

In practice, Connection requests rarely exists in isolation. It may affect the outcome together with Domain checks, or behave differently because the state of Account scope has changed. Compare interface information with public on-chain data where possible and keep the purpose of the current action clear. If a request involves a signature, approval or asset transfer, approve only what you can explain; otherwise exit and verify the source again.

Complete the core flow in order

When working with Domain checks, it helps to understand how it connects with Account scope and Session permissions.

Treat every transfer, signature and approval as a separate decision. A DApp that was safe to use previously does not make every future request automatically trustworthy. Reviewing Connection requests, Domain checks, Account scope, Session permissions and Disconnecting one by one helps you confirm that the address, network, amount, approval target or signed content matches what you actually intend to do. If a request is not understandable, declining it is safer than approving it simply to complete a flow.

Risk note

Important: seed phrases and private keys remain under the user’s control, and official personnel will not ask for them. Verify the address, network and amount before sending. On-chain transactions generally cannot be reversed by a wallet provider. Third-party DApps and smart contracts may be risky, so review approval targets and permission scope and consider revoking permissions you no longer need.

imtoken will not ask you to enter a seed phrase, private key, recovery phrase or verification code into a web page. If a DApp Connections flow suddenly asks for recovery material, remote-control access or sensitive screenshots, stop and verify the source from a known entry point. Recovery materials are controlled by the user, and anyone who gains access to them may gain control of the associated wallet.

In practice, Domain checks rarely exists in isolation. It may affect the outcome together with Account scope, or behave differently because the state of Session permissions has changed. Compare interface information with public on-chain data where possible and keep the purpose of the current action clear. If a request involves a signature, approval or asset transfer, approve only what you can explain; otherwise exit and verify the source again.

Quick review

  • Confirm that information related to Connection requests belongs to the network or request you are actually using.
  • Confirm that information related to Domain checks belongs to the network or request you are actually using.
  • Confirm that information related to Account scope belongs to the network or request you are actually using.
  • Confirm that information related to Session permissions belongs to the network or request you are actually using.

What to review at every step

When working with Account scope, it helps to understand how it connects with Session permissions and Disconnecting.

imtoken will not ask you to enter a seed phrase, private key, recovery phrase or verification code into a web page. If a DApp Connections flow suddenly asks for recovery material, remote-control access or sensitive screenshots, stop and verify the source from a known entry point. Recovery materials are controlled by the user, and anyone who gains access to them may gain control of the associated wallet.

A practical DApp Connections workflow can be divided into preparation, review, execution and verification. Prepare by checking your device and network environment. Review the relevant Account scope, Session permissions and Disconnecting. Execute only the request you currently understand, then verify the outcome through transaction history or public on-chain data. Repeating these stages helps prevent familiarity with an interface from turning into automatic approval of important actions.

In practice, Account scope rarely exists in isolation. It may affect the outcome together with Session permissions, or behave differently because the state of Disconnecting has changed. Compare interface information with public on-chain data where possible and keep the purpose of the current action clear. If a request involves a signature, approval or asset transfer, approve only what you can explain; otherwise exit and verify the source again.

Common mistakes and better responses

When working with Session permissions, it helps to understand how it connects with Disconnecting and Connection requests.

A practical DApp Connections workflow can be divided into preparation, review, execution and verification. Prepare by checking your device and network environment. Review the relevant Connection requests, Domain checks, Account scope, Session permissions and Disconnecting. Execute only the request you currently understand, then verify the outcome through transaction history or public on-chain data. Repeating these stages helps prevent familiarity with an interface from turning into automatic approval of important actions.

Treat every transfer, signature and approval as a separate decision. A DApp that was safe to use previously does not make every future request automatically trustworthy. Reviewing Session permissions, Disconnecting and Connection requests one by one helps you confirm that the address, network, amount, approval target or signed content matches what you actually intend to do. If a request is not understandable, declining it is safer than approving it simply to complete a flow.

In practice, Session permissions rarely exists in isolation. It may affect the outcome together with Disconnecting, or behave differently because the state of Connection requests has changed. Compare interface information with public on-chain data where possible and keep the purpose of the current action clear. If a request involves a signature, approval or asset transfer, approve only what you can explain; otherwise exit and verify the source again.

Verify the result after completion

When working with Disconnecting, it helps to understand how it connects with Connection requests and Domain checks.

Treat every transfer, signature and approval as a separate decision. A DApp that was safe to use previously does not make every future request automatically trustworthy. Reviewing Connection requests, Domain checks, Account scope, Session permissions and Disconnecting one by one helps you confirm that the address, network, amount, approval target or signed content matches what you actually intend to do. If a request is not understandable, declining it is safer than approving it simply to complete a flow.

imtoken will not ask you to enter a seed phrase, private key, recovery phrase or verification code into a web page. If a DApp Connections flow suddenly asks for recovery material, remote-control access or sensitive screenshots, stop and verify the source from a known entry point. Recovery materials are controlled by the user, and anyone who gains access to them may gain control of the associated wallet.

In practice, Disconnecting rarely exists in isolation. It may affect the outcome together with Connection requests, or behave differently because the state of Domain checks has changed. Compare interface information with public on-chain data where possible and keep the purpose of the current action clear. If a request involves a signature, approval or asset transfer, approve only what you can explain; otherwise exit and verify the source again.