Sign in with Solana
windle accounts use Sign-In With Solana (SIWS): you prove you control a wallet by signing a short text message. No password, no email required. Sign-in happens on oauth.windle.fun.
What happens
Section titled “What happens”- You open app.windle.fun. Without a session it sends you to oauth.windle.fun, remembering
where to send you back. Only
*.windle.funaddresses are accepted as a return target. - oauth.windle.fun lists the wallets installed in your browser that support SIWS (for example Phantom, Backpack or Solflare).
- You pick one. The windle API issues a one-time nonce and the exact sign-in fields.
- Your wallet shows you the message and asks you to sign it.
- The API rebuilds the same message from what it issued, checks the signature against your address, checks the domain, nonce and expiry, and marks the nonce as used.
- You get a session and are sent back to where you started.
What you sign
Section titled “What you sign”Your wallet displays a plain-text message in the SIWS format. Its shape (the exact statement wording may differ):
oauth.windle.fun wants you to sign in with your Solana account:<your wallet address>
Sign in to windle
URI: https://oauth.windle.funVersion: 1Chain ID: mainnetNonce: <random one-time value>Issued At: <timestamp>Expiration Time: <timestamp>Check two things before you approve:
- The first line names
oauth.windle.fun. A message for another domain is not a windle sign-in. SIWS lets wallets compare that domain with the site asking for the signature and warn you on a mismatch. - It is text, not a transaction. There are no amounts, no token approvals, no programs to call.
Why it cannot move your funds
Section titled “Why it cannot move your funds”Moving funds on Solana requires your signature on a transaction: a binary message that lists instructions such as “transfer X tokens to Y”, which validators execute. A SIWS signature covers the text above and nothing else.
- The text is not a valid transaction, so the network has nothing to execute.
- The signature is checked once by the windle API and is useless afterwards: the nonce is single-use and the message expires.
- Your private key never leaves your wallet. windle never receives it and cannot sign anything on your behalf.
Your session
Section titled “Your session”After a successful sign-in, the API sets a session cookie:
| Property | Value | What it means |
|---|---|---|
| Name | wl_session |
|
| Domain | .windle.fun |
Shared by windle’s own subdomains, not sent to other sites. |
HttpOnly |
yes | Page scripts can’t read it. |
Secure |
yes | Only sent over HTTPS. |
SameSite |
Lax |
Not sent on most cross-site requests. |
The cookie holds a random opaque token. The session itself is stored on windle’s servers and has an expiry (the API
reports it as expiresAt). Signing out deletes the session on the server, not only the cookie.
A session lets windle know which wallet you are. It cannot sign transactions: any action that moves funds will always come back to your wallet for approval.
Other sign-in methods
Section titled “Other sign-in methods”Email magic links, X and Google sign-in are planned and present in the code, but disabled. Today, SIWS is the only way to sign in.
Troubleshooting
Section titled “Troubleshooting”- “No wallets found”: install a Solana wallet that supports Sign-In With Solana, or enable it for this site.
- “Expired” or “nonce” errors: the message is only valid for a short time and only once. Start again.
- Signed in on the wrong wallet: sign out, switch accounts in your wallet, sign in again.