Page bridge
Onboarding
The email account opens on yap-pay.xyz. Yap Signer still generates the username on the device. This page does not create the wallet.
What the page does
/onboardingis the account page. After the wallet exists, Yap Signer signs a pairing proof and opens/onboarding/pair/<session>. The session value is random. The database stores only its hash, plus the public key and username, for 30 minutes. The page takes an email and an account password. An 8-digit code is emailed before the account opens. An email passed in the query is filled in when it is a real address. A forgotten password is replaced from/login/forgotwith another emailed code. That code does not reset the signer vault password.- The code is checked on
/onboarding/verify. The account and the session start after it matches. /onboarding/walletthen asks for the username. The page reads it fromgetStatus. The typed name has to match. A match stores that public username on the account.- If Signer has no wallet yet, the person creates or imports it in the extension, then returns and enters the username Signer shows.
- The operator account pairs the same username on
/devand can clear that pairing there.
Page request
{
source: "yap-app",
type: "YAP_SIGNER_REQUEST",
requestId: "<uuid>",
method: "getStatus",
payload: {}
}Extension status
Same origin. Source yap-signer-extension.
{
source: "yap-signer-extension",
type: "YAP_SIGNER_STATUS",
requestId: "<same id>",
installed: true,
hasWallet: true,
unlocked: true,
username: "swift-fox-ab12"
}After Signer already has a username
The email and the 8-digit code still come first. The username step opens after the code, and the handle that can be saved is the one Signer sent. The account password is stored as a hash. The vault password and the 24-word phrase stay on the device.