Help/Security

Security

Nodana hosts Phoenixd nodes and provides tools to manage them. This page explains the protections we provide and the steps you can take to keep your account and node secure.

Separate nodes and access

Each hosted node has its own environment and private network. Your node's Phoenixd API requires its own password, separate from the credentials you use to sign in to Nodana or manage nodes through the Nodana API.

Nodana API keys belong to one account and can be limited to the permissions an integration needs. A key without the required permission cannot perform that operation, and it cannot access another account's nodes. See API authentication for the available permissions.

Node passwords

Each node has a restricted Phoenixd password and a full-access password. The restricted password can be used to read node information and create invoices; sending payments requires the full-access password. Both passwords are shown when the node is created so you can save them privately.

When you create a node, choose Limited access or Full access for the Nodana dashboard. Limited access stores the restricted password and supports reading node information and creating invoices in the app. Full access stores the full password and also allows outgoing payments from the app. The same choice is available through the CLI (--full) and API (accessMode). You can still call your node directly with either password regardless of this dashboard setting.

Nodana encrypts the selected password at rest. Both passwords configure the hosted node and are shown to you at creation, but only the selected password remains in the node's account record after provisioning. The recovery seed is not retained there. Encryption protects stored credentials, but Nodana operates the hosted infrastructure and can access it to provide the service.

Infrastructure safeguards

We use encrypted storage for node data and enable automatic backups. We monitor node availability and apply rate limits to the Nodana API and node traffic to help reduce abuse. These measures help protect the service, but they do not guarantee uninterrupted access or recovery from every failure.

Protect your credentials and recovery information

  • Keep API keys and Phoenixd passwords in your backend or a trusted secret store. Do not put them in browser code, public repositories, or support messages.
  • Give each integration only the API key permissions it needs. Revoke and replace a key if you think it has been exposed.
  • Save your node's recovery seed securely and independently of Nodana. Backups are not a replacement for your own recovery information.
  • Use the appropriate Phoenixd password for each integration and avoid sharing full-access credentials where restricted access is enough.

If you suspect that an account, key, password, or recovery seed has been compromised, stop using the affected credential and contact us. Describe what happened without including secrets in your message.

For service availability, visit Nodana System Status.

On this page