PHOENIX
A great phoenix of fire rising over a moonlit cornfield, sparks trailing from its wings

Chapter two

The member's guide

Everything you do in Phoenix, step by step: signing in with two-factor, linking a wallet on a computer or a phone, and looking after your account. It takes a couple of minutes, and you never hand over anything that could move your funds.

Before you start

What you need

  • Your Discord account. You sign in to Phoenix with it, so there is no new password to remember.
  • An authenticator app on your phone. Google Authenticator, Microsoft Authenticator, Authy, 1Password or the one you already use; they are free. Every Phoenix account has two-factor, so a stolen Discord login is never enough to get into yours.
  • A wallet. MetaMask, Rabby, Coinbase Wallet or another browser wallet for Ethereum and the chains like it (Base, Polygon, Arbitrum and the rest); Phantom, Solflare or Backpack for Solana. On a phone, the wallet's own app.
  • Nothing else. Linking with a signed message costs nothing: no gas, no fee, no transaction.
Step one

Sign in with Discord

  1. Open Phoenix

    Go to Phoenix's front page and press Sign in with Discord.

  2. Check what Discord asks

    Discord shows a page asking whether Phoenix may know who you are and which servers you are in. That is all it asks for. Press Authorize.

  3. The second step: your code

    Discord sends you back to Phoenix, which asks for the six-digit code from your authenticator app. The very first time it shows Set up two-factor instead: see Two-factor below. You have ten minutes for this step; after that, sign in with Discord again.

  4. Land on your dashboard

    Your Phoenix dashboard opens, with your Discord name at the top. Its panels: Your wallets, Cold wallets, Two-factor, Passkeys, Your Phoenix servers (servers you are in that use Phoenix), Your servers (any you own or manage), Discord Linked Roles and Your account.

You stay signed in on that browser for up to twelve hours, or until you have been away for two. After that, sign in again the same way: Discord, then your code.

Your second lock

Two-factor

Every Phoenix account has two-factor, for everyone, with no switch to turn it off. Signing in takes your Discord login and a code from an authenticator app on your phone, so someone who steals one of them still cannot get in.

  1. Get an authenticator app

    Google Authenticator, Microsoft Authenticator, Authy, 1Password, or the one you already use.

  2. Add Phoenix to it

    The first time you sign in, Phoenix shows Set up two-factor with a QR code. In your app press + (or Add) and scan it. On the same phone, press On this phone? Open in my authenticator app instead, or choose "enter a setup key" in the app and type the key Phoenix shows (Copy copies it).

  3. Type the code it shows

    Type the six digits your app shows for Phoenix and press Turn on two-factor. Codes change every 30 seconds.

  4. Save your recovery codes

    Phoenix shows ten recovery codes, once. Press Download or Copy all and keep them somewhere safe and offline, like a password manager or on paper. Tick the box and press Open my dashboard.

From then on, every sign in asks for the current code from your app. Each code works once.

A passkey instead of typing the code. On your dashboard, Passkeys, press Add a passkey, type a code from your app, and let your phone or computer make one (Face ID, a fingerprint, Windows Hello or a security key). At the next sign in, press Use a passkey instead. You can add up to five; your authenticator stays as the backup, and removing a passkey takes a current code.

Lost your phone?
At the code step, press Lost your phone? Use a recovery code and type one of your recovery codes. Each one works once. Then set up your new phone (below).
New recovery codes
On your dashboard, Two-factor, New recovery codes: type a code from your app, and Phoenix shows ten new ones. The old ones stop working. Do this when you are running low; the panel says how many are left.
Move to a new authenticator
A new phone or a new app: Two-factor, Move to a new authenticator. Type a code from your current app (or a recovery code if the old phone is gone), add Phoenix to the new app, and type its code. Phoenix then signs you out on every other device and gives you new recovery codes.
Lost the phone and every code?
Ask Phoenix's admins in your server. They can reset your two-factor once they are sure it is you, and your next sign in sets it up again.

Turn on Discord's own two-factor too. In Discord, User Settings, My Account, Password and Authentication. It protects your Discord account everywhere, not just in Phoenix. Phoenix's admins must have it.

On a phone

Linking from your phone

On a phone, your wallet usually lives in its own app, and a normal phone browser cannot reach it. The wallet's app has a browser built in, and that is where you link.

  1. Start the link as usual

    Press one of the link buttons. If Phoenix finds no wallet in the browser you are using, the second step says so and offers Open in MetaMask (for Ethereum, Base and Polygon) and Open in Phantom.

  2. Open Phoenix in your wallet's app

    Tap the button for your wallet. Your phone opens the wallet's app on Phoenix's page. If you use another wallet app, open its built in browser and go to Phoenix's address yourself.

  3. Sign in with Discord again

    The wallet's browser is a separate browser, so sign in with Discord once more inside it, and type your authenticator code. Then link as described above.

The dashboard fits a phone held upright or sideways. You can also add Phoenix to your home screen from your browser's share menu; it has its own icon.

Your wallets

Unlinking

Press Unlink beside a wallet and confirm. It leaves your account at once. A role that wallet earned you leaves after the next two checks, unless another of your linked wallets still qualifies.

Your account

Your data, in your hands

Your Phoenix account is your Discord account, locked with your authenticator. The Your account panel on your dashboard has three buttons:

Download my data
Saves a file called phoenix-my-data.json with everything Phoenix holds on you: your Discord name and id, your wallets, whether two-factor is on and how many recovery codes are left, your passkeys' names and dates, whether Linked Roles is on, and your account's history. It names nobody else, and it never holds your authenticator's key or your codes.
Sign out everywhere
Ends your Phoenix sign in on every phone and computer at once, this one included. Use it if you signed in on a device that is not yours.
Delete my Phoenix account
Removes your account, every wallet link, and your id from Phoenix's history. To be sure, Phoenix asks you to type DELETE first. If you sign in again later, you start fresh.
In Discord

Verifying in your server Built

This works in a server once its managers and Phoenix's owners have switched it on. Until then, Verify says "Verification is not switched on in this server yet". Everything Phoenix says to you in Discord is private.

  1. Find the verify channel

    Servers that use Phoenix have a channel with a message from Phoenix and two buttons, Verify and Check my roles.

  2. Prove you are a person

    Press Verify. Phoenix shows a picture of five letters and digits, drawn fresh for every try. Press Type the letters, type them in the box, and send. Three wrong answers wait a minute. A server can also ask for a Discord account of a certain age; a newer one is asked to come back later.

  3. Link if you have not

    Phoenix gives you a Link a wallet button to your dashboard, to sign in and link a wallet as above.

  4. Get your roles

    Back in Discord, press Check my roles. Phoenix reads what your linked wallets hold and gives you the roles your server's rules say you have earned. You can also press Check my roles beside the server under Your Phoenix servers on your dashboard.

After that Phoenix keeps checking on its own, every few hours and whenever you link, move or unlink a wallet. A role leaves only after two checks in a row say it is no longer earned, and never because a chain did not answer. Typing /phoenix in a server where Phoenix's bot is installed gets you a private reply with a link to Phoenix.

Linked Roles

Some servers use Discord's own Linked Roles instead: the role's requirements name Phoenix, and you find it under the server's name, Linked Roles. Connecting there, or with Connect to Discord under Discord Linked Roles on your dashboard, lets Discord see three things from Phoenix: whether you are verified (two-factor and a linked wallet), how many wallets you linked, and how long you have had a Phoenix account. Disconnect turns it off.

Staying safe

Five rules

Phoenix will never ask for your seed phrase, your private key, or an approval to spend, and never sends your wallet a transaction to approve. The only transaction it ever mentions is the optional send to itself, which you make yourself, from your wallet to the same address. Anyone who asks for more is not Phoenix, whatever their page looks like.

  • Check the address bar. Today Phoenix lives at phoenixcheck.net/phoenix/. The message you sign names the site too, and your wallet can warn you when they do not match.
  • Phoenix does not send direct messages asking you to verify. Start from your server or from Phoenix's own front page.
  • Read before you sign. The message should name your Discord account and say it is not a transaction. A send to itself goes to the same address it comes from, never anywhere else.
  • Never give anyone your six-digit code or a recovery code. You type them only on Phoenix's own sign in page. Phoenix's admins never ask for them.
  • Use Sign out everywhere if you ever signed in on a shared device.

The security chapter explains how Phoenix keeps your data sealed and bots out.

If something goes wrong

Troubleshooting

"Sign in was cancelled on Discord. Nothing was shared."

You pressed Cancel on Discord's page, or closed it. Nothing was shared with Phoenix. Press Sign in with Discord again when you are ready.

"That sign in link expired or was opened in another browser."

A sign in has to finish in the same browser it started in, within ten minutes. This often happens on a phone when the Discord app opens the link in a different browser. Start again from the browser you want to use.

"Discord did not finish the sign in."

Discord did not hand the sign in back properly. Try again; if it keeps happening, Discord may be having trouble.

"Too many tries from here."

Phoenix limits how often one place can try to sign in, to slow bots down. Wait a few minutes and try again.

"Phoenix is still being set up, so sign in is not open yet."

Phoenix has not been switched on for this site yet. Sign in opens once its owners finish setting it up.

"Phoenix could not save your sign in just now."

Phoenix's server could not write its sealed file for a moment. Try again soon.

"This Discord account has been locked out of Phoenix by its admins."

Phoenix's admins have locked this Discord account, so it cannot sign in. Ask in your server if you think that is a mistake.

"That code did not match."

Type the code your app shows for Phoenix right now (each app can hold many entries). Codes change every 30 seconds. If it keeps failing, your phone's clock may be off: set its date and time to automatic.

"That code was just used."

Each code works once. Wait for the next one to appear in your app, then type that.

"Too many wrong codes."

After five wrong codes in a row, Phoenix makes you wait a little before the next try, longer each time, never more than five minutes. After twenty wrong codes in a day, that account's codes wait up to a day. This keeps anyone from guessing their way in.

"Your sign in ran out before your code was typed."

The code step has to be finished within ten minutes of signing in with Discord. Sign in with Discord again.

Phoenix finds no wallet in my browser

Check that your wallet's extension is installed and unlocked, then press the link button again. On a phone, use Open in MetaMask or Open in Phantom, as in Linking from your phone.

The link buttons are greyed out

You have ten wallets linked, which is the most one Discord account can have. Unlink one you no longer use to make room.

My wallet wants me to approve or pay something

Stop and close it. Linking with Phoenix by a signed message never asks to approve or pay anything, and Phoenix never sends your wallet a transaction. Make sure the address bar shows Phoenix's real address.

Verify says "Verification is not switched on in this server yet."

That server's managers, or Phoenix's owners, have not switched verification on there yet. Nothing is wrong with your account.

Check my roles says a chain could not answer

The chain Phoenix reads was busy for a moment. Nothing was taken away. Try again in a few minutes; Phoenix also tries again on its own.