Security
Keep your ICP account safe
Best practices for Internet Identity, device recovery, category XFT custody, and protecting your Betable balances — honey badger on watch.
Last updated: August 21, 2026
Passkeys protect you — recovery keeps you in.
Betable never holds your Internet Identity credentials. Sign-in uses passkeys (device biometrics / PIN) — not a crypto wallet seed you paste into websites. Recovery is separate: backup passkeys, an optional recovery phrase from II, and/or email recovery when enabled on identity.ic0.app.

Internet Identity (not a seed wallet)
- Passkeys sign you in with Face ID, Touch ID, Windows Hello, or a security key. The private key stays on the authenticator — Betable never sees it.
- Add more than onepasskey/device in the II manage page so one lost phone doesn't lock you out.
- Optional recovery phrase from Internet Identity is a backup authenticator (historically 24 words) — write it offline. It is not the same as an ICP ledger seed, and you should never paste it into Betable or any random site.
- Email recovery (when registered on II) can help from a new device via a one-time code — still treat email as phishable; pair it with passkeys.
- Bookmark identity.ic0.app and betable.fun. Fake II popups are a common attack.
Use the same Internet Identity
- Add this computer to the same Internet Identity on id.ai (or iCloud Keychain). Do not create a second II — Betable will not merge two accounts. Wallet shows only the connected session.
- Account menu → Use on another device for the steps. If an old two-identity link is still on-chain, unsync it there; each principal keeps its own balance.
- Never share recovery material between people. Same II on phone and desktop is enough to trade — no in-app pairing.
Approvals & spends
- Check amounts, market side, and price before confirming orders. Trading spends real ICP.
- Review ICRC allowances if you deposit from an external wallet. Don't approve unlimited spends to unknown principals.
- Verify canister IDs on Status.
Trading keys & categories
- API / trading keys can place orders as you — generate them only from Wallet, rotate if leaked, and never paste private material into chat or random sites.
- Category ownership is an NFT-backed right. Treat transfers and licenses like high-value assets — details in XFT & category ownership below.
- Cancel only works on open or partially filled orders; filled shares stay. Claim winnings/refunds after settle — then withdraw if you want ICP off Betable.
XFT & category ownership
- On Betable, category rights live in XFTs / labels on Afta Cash (and related ICP label infrastructure) — not in a Betable username. Control follows the live on-chain XFT, including after transfers or reclaim under a new id.
- You custody the controlling principal, devices, approvals, operator grants, and bag/vault access. Betable does not hold your keys and cannot reverse a protocol reclaim out of goodwill.
- Renew before expiry. Labels and licenses can expire (registration / labelExpire / license windows). Renew on Afta / XFT interfaces in time — missing renewal can forfeit category control and fee streams.
- Reclaim after expiry is expected protocol behavior. If an expired label is reclaimed or re-minted by someone else, category rights move with the live XFT. That outcome is notBetable's responsibility.
- Bags, vaults, DAB/fund tokens, and operators are powerful and risky — verify principals, unlock dates, and who you grant licenses to before signing.
- UI lists of "your categories" can lag chain state. When in doubt, verify ownership on Afta / the XFT canister. Full legal terms: User Agreement §5 — Category XFTs.
Backup checklist
- At least two passkeys / devices on your II.
- Recovery phrase (if you created one) written offline in two places — never in screenshots or chat.
- Email recovery registered only if you control that inbox.
- Know which principal owns your categories / XFTs and trading balance — and when labels expire so you can renew.
- Report issues via Support.

Recovery lives with you
If you lose every passkey and every recovery method, neither Betable nor DFINITY support can “reset” your identity. Plan backups before you need them.
Quick guards
Never paste II recovery into apps
Register a second passkey
Email recovery only on identity.ic0.app
Double-check approve & order sizes
Same II on every device — don’t share keys
Use trading keys only you control
Bookmark betable.fun + identity.ic0.app
Honey badger don't care — but you should.