PHOENIX
A gloved hand pressing a golden signet ring onto parchment, a seal of flame shaped like a phoenix blooming from the page

Chapter one

How Phoenix works

A Discord account on one side, the wallets its owner holds on the other, and one signed message to tie them together. Here is the whole journey, and exactly what Phoenix sees along the way.

The journey

From Discord to your roles

This is the whole path a member takes. Every step is Built. A server's own managers and Phoenix's owners switch it on, and until they do, Phoenix changes nothing in that server.

  1. Press Verify in your server Built

    Each server that uses Phoenix has a verify channel with a Verify button. Everything Phoenix says to you there is private: nobody else in the server sees it.

  2. Prove you are a person Built

    A quick picture check inside Discord, drawn fresh by our server for every try, and a limit on how new a Discord account can be, if the server sets one. Passing can give you the server's first role, then a Link a wallet button brings you to the web steps below.

  3. Sign in with Discord Built

    On Phoenix's site you press Sign in with Discord. Discord asks whether Phoenix may read two things: who you are, and the list of servers you are in. Phoenix reads them once, then hands the Discord login token straight back to be cancelled. It keeps no Discord token at all.

  4. Type your authenticator code Built

    Every Phoenix account has two-factor. After Discord, Phoenix asks for the six-digit code from the authenticator app on your phone (or your passkey, if you added one); the first time, it helps you set the app up and gives you ten recovery codes. Until the code is in, the sign in opens nothing else, so a stolen Discord login is never enough.

  5. Solve the browser's puzzle Built

    Before each wallet link your browser solves a small proof of work: a few seconds of number crunching that it does on its own. One person never notices it; someone trying to link ten thousand wallets pays for every one.

  6. Sign one message with your wallet Built

    Phoenix writes a short message naming this site, your wallet and your Discord account. Your wallet shows it, you sign it, and Phoenix checks the signature. That proves you hold the wallet. It is not a transaction.

    Rather not connect your wallet to any site? Two other ways prove it too: send an exact tiny amount from the wallet to itself and give Phoenix the transaction's hash (only the chain's fee is spent; the coins stay in the wallet), or put a code Phoenix gives you in the wallet's OpenSea bio. A server can choose which of the three it accepts.

  7. Rise with your roles Built

    Back in Discord, press Check my roles. Phoenix reads what your wallets hold straight from the chains and gives you the roles your server's rules say you have earned. It keeps checking every few hours and whenever you change a wallet. A role leaves only after two checks in a row say it is no longer earned, and never because a chain did not answer.

The one signature

What you sign

This is the shape of the message, written by our server for you alone. It follows the Sign-In with Ethereum standard (and the same shape for Solana), which is why wallets show it clearly and can warn you if the site in it is not the site you are on.

phoenixcheck.net wants you to sign in with your Ethereum account:
0x1234...your wallet...abcd

Link this wallet to Discord user @yourname (id 123456789012345678) in Phoenix. Signing proves you hold this wallet. It is not a transaction: it costs nothing, moves nothing and approves nothing.

URI: https://phoenixcheck.net/phoenix/
Version: 1
Chain ID: 1
Nonce: (a random code, used once)
Issued At: (now)
Expiration Time: (ten minutes from now)
  • It works once. A message is good for one signature and ten minutes, then it is spent.
  • It names you. Your Discord name and id are in it, so a signature cannot be reused for someone else.
  • It names this site. If a page anywhere else shows you this message, it is not Phoenix.
Wallets and chains

Which wallets work

Ethereum and the chains like it

MetaMask, Rabby, Coinbase Wallet and the other browser wallets that announce themselves the standard way. Ethereum, Base, Polygon, Arbitrum, Optimism, ApeChain, Avalanche, Blast, Zora, Linea, Scroll, BNB Chain, Abstract, Berachain, Unichain and ZKsync Era share one address, so one link covers all sixteen.

Solana

Phantom, Solflare and Backpack.

On a phone, the wallet usually lives in its own app. Phoenix offers buttons that reopen the page inside the MetaMask or Phantom app, where the wallet can sign. The member's guide walks through it.

Cold wallets never connect. If a vault delegates to one of your linked wallets on delegate.xyz, Phoenix finds it on the chain and counts what it holds as yours. You can turn that off on your dashboard, and a server can too.

Each Discord account can link up to ten wallets. If a wallet you link was already linked to another Discord account, it moves to you, because only the wallet's holder could have signed. That lets the real owner take back a wallet someone else claimed.

What Phoenix keeps

Only what it needs

Kept, sealed

  • Your Discord name and id, and when you first and last signed in.
  • Your authenticator's key, so Phoenix can check your codes, and your recovery codes only as one-way fingerprints that cannot be turned back into the codes.
  • Each wallet you linked, its chain, how you proved it, and when you linked and last proved it.
  • A passkey's public key, if you added one (never anything that could sign as you).
  • For each server you verified in: when you passed its picture check, your last check, the roles Phoenix gave you there and their last changes.
  • A short history: when you joined, linked, moved or unlinked a wallet, turned on or moved two-factor or used a recovery code, and anything an admin did to your account. Wallets appear in it only shortened.

Never kept

  • Any Discord token. The login token is cancelled the moment Phoenix has read your name and server list. The one exception is yours to choose: if you turn on Linked Roles, Phoenix keeps that one connection's token, sealed, so it can tell Discord when your wallets change. Turning it off cancels it.
  • Your server list. It is held only for as long as you stay signed in, in the server's memory, to show the servers you run.
  • Keys, seed phrases, or anything that could move your funds. Phoenix never asks for them.

All of it lives in one file on our own server, encrypted with AES-256-GCM. You can download everything Phoenix holds on you, or delete it, from your dashboard at any time.

Under the bonnet

The pieces

The site
The pages at phoenixcheck.net/phoenix/: this guide, your dashboard, each server's page for its managers, and the admin panel.
The server
Our own code, on our own host. It checks every signature, every puzzle and every request, and writes the sealed file.
The bot
Phoenix's Discord bot. It posts a server's Verify panel, answers its buttons privately, gives and takes roles, and posts each role change to the server's mod log if it has one. It also answers /phoenix.
The chains
Phoenix reads holdings directly from 17 chains (the sixteen above and Solana), never from another verification service.