Sign in with Solana Using Gem Wallet
Sign in with Solana lets a compatible app authenticate your Solana wallet by asking Gem Wallet to sign a structured message. It proves that you control the selected address without requiring a password or exposing your Secret Phrase.
Signing an authentication message is not an on-chain transaction, so it does not send SOL or require a network fee. A signature can still authorize access or another action in the requesting app, so review it carefully.
Signing is not harmless simply because no crypto moves immediately. Reject requests from an unexpected or unverified website and never enter your Secret Phrase to complete a sign-in.
Before You Sign Inâ
- Open the dApp from its official website.
- Verify the complete domain in your browser.
- Select its Connect or Sign in option.
- Choose WalletConnect and Gem Wallet.
- Confirm that the request you receive was triggered by your action.
If you are not certain that the website is legitimate, cancel the request and follow WalletConnect Domain Verification in Gem Wallet.
Review the Request in Gem Walletâ
Gem Wallet identifies a supported request with the title Sign In with Solana. Before selecting Confirm, verify:
- App and domain â they match the website you intentionally opened.
- Wallet â the selected Gem Wallet contains the Solana address you intend to use.
- Network â the request is for Solana.
- Address â it is the account you expect to authenticate.
- Statement â it describes an action you understand.
- URI and resources â any displayed links belong to the expected service.
- Validity period â the request is not expired or scheduled for an unexpected time.
Gem Wallet validates the structure of supported Sign in with Solana messages, including the address, domain, network, nonce, links, and timestamps. This validation can reject malformed requests, but it cannot guarantee that an otherwise valid website or request is trustworthy.
Approve or Reject the Sign-Inâ
Select Confirm only when the app, domain, wallet, network, and message all match your intent. Gem Wallet may ask you to authenticate on your device before signing.
Close the request if:
- You did not initiate it.
- The domain or app name is unfamiliar.
- The selected wallet is wrong.
- The statement or requested resources are unclear.
- The request creates urgency or promises a reward.
- The dApp asks for your Secret Phrase or private key.
Rejecting the message does not move funds or approve the sign-in.
After Signing Inâ
Return to the dApp and confirm that it opened the account or session you expected. Signing in does not automatically approve later transactions. Review every transaction, token approval, and message request separately in Gem Wallet.
When finished, open Gem Wallet > Settings > WalletConnect, select the connection, and choose Disconnect if you no longer use it.
Disconnecting ends the WalletConnect session, but it cannot undo a message already signed or revoke token permissions already recorded on-chain.
If the Request Was Suspiciousâ
- Reject any request that is still open.
- Close the website.
- Disconnect its session in Settings > WalletConnect.
- Review recent activity for transactions or approvals you also confirmed.
- Revoke suspicious token approvals on the affected network.
Follow What to Do After Connecting to a Malicious dApp for the complete response. If you entered your Secret Phrase or private key, treat the wallet as compromised and follow the Secret Phrase exposure guide.
Sign-In Checklistâ
- Start from the dApp's verified website.
- Expect the title Sign In with Solana.
- Verify the app, domain, wallet, address, and Solana network.
- Read the statement, links, and validity details.
- Reject unexpected or unclear requests.
- Disconnect the WalletConnect session when it is no longer needed.