Self-Host & Verify

Don't trust us — verify. This page explains how to compare wallet.qwertycoin.org with the official public source and how to run the Qwertycoin Web Wallet with your own restricted QWC node.

The short version: wallet keys, blockchain scanning and transaction signing stay inside your browser. The official site reaches a restricted qwertycoind endpoint through a same-origin, allowlisted RPC gateway. A static local copy is enough to inspect the frontend; a fully working self-hosted wallet also needs that gateway and a synced QWC node.

Option 1 — Verify the live site

Every deployed wallet file is SHA-256 hashed in the repository's MANIFEST.txt. Compare the manifest served by wallet.qwertycoin.org with the official repository, then verify the checked-out files:

# 1. Clone the official wallet repository
git clone https://github.com/qwertycoin-org/wallet.qwertycoin.org.git
cd wallet.qwertycoin.org

# 2. Fetch the manifest from the live wallet
curl -fsS https://wallet.qwertycoin.org/MANIFEST.txt \
  -o ../live-manifest.txt

# 3. Confirm GitHub and the live site publish the same manifest
cmp MANIFEST.txt ../live-manifest.txt

# 4. Verify every deployed file against the signed-off hashes
sha256sum -c ../live-manifest.txt

cmp prints nothing when both manifests are identical. sha256sum must report OK for every file. Any other result means the checked-out source and live deployment do not match.

To verify one QWC-specific file, such as the browser wallet engine:

curl -fsS https://wallet.qwertycoin.org/js/qwc-wallet-engine.js \
  | sha256sum
grep 'js/qwc-wallet-engine.js' MANIFEST.txt

The two SHA-256 values must match exactly.

Option 2 — Run the frontend locally

The frontend itself has no build step. Clone the official repository and serve it with any static file server:

1

Clone the repo

git clone https://github.com/qwertycoin-org/wallet.qwertycoin.org.git
cd wallet.qwertycoin.org
2

Serve locally

python3 -m http.server 8080

Open http://localhost:8080/verify in your browser. Do not open the HTML files through a file:// URL: the QWC WebAssembly worker uses origin-relative paths.

3

Understand the local limit

The Python server only serves static files. It does not execute the repository's Cloudflare Pages Functions, so network sync and transaction relay through /api/proxy are unavailable. Use this mode for source inspection and interface testing. Use Option 3 for a complete wallet stack.

Option 3 — Full self-hosted stack

A complete Qwertycoin setup has three parts: the static Web Wallet, its restricted same-origin RPC gateway, and a synced QWC full node (qwertycoind). QWC wallet scanning runs locally in the browser; no separate light-wallet server receives your view key.

1

Build Qwertycoin Core

There are currently no official Qwertycoin v2 binary releases. Build from the official Qwertycoin Core repository and review its platform-specific instructions:

git clone --recursive https://github.com/qwertycoin-org/qwertycoin.git
cd qwertycoin
git submodule update --init --recursive
make release
2

Run a restricted QWC RPC

Start qwertycoind with unrestricted RPC on localhost only and a separate restricted wallet RPC on port 8198. Keep the restricted endpoint behind your firewall or an authenticated/TLS reverse proxy:

./build/release/bin/qwertycoind \
  --p2p-bind-ip 0.0.0.0 \
  --p2p-bind-port 8196 \
  --rpc-bind-ip 127.0.0.1 \
  --rpc-bind-port 8197 \
  --rpc-restricted-bind-ip 127.0.0.1 \
  --rpc-restricted-bind-port 8198 \
  --zmq-rpc-bind-port 8199

Never expose unrestricted RPC port 8197 to the public internet. The Web Wallet needs only the restricted sync and transaction-relay methods enforced by its gateway.

3

Run the wallet gateway and frontend

The wallet repository includes Cloudflare Pages Functions that allow only the QWC RPC paths required by the browser wallet, apply request/response limits and reject mining or daemon-administration methods. Point both gateway upstream lists at your restricted RPC, then run the Pages development server:

# In the wallet repository, configure your restricted QWC upstream in:
#   functions/_qwcRpcProxy.js
#   functions/api/proxy.js
# Local-only upstream: http://127.0.0.1:8198

npx wrangler pages dev .

Open the URL printed by Wrangler. For an internet-facing deployment, protect the restricted RPC with HTTPS and keep the browser on the same origin as the gateway. Review the allowlists in both Function files before deployment; do not replace them with an unrestricted pass-through proxy.

What you're trusting in each setup

Setup Frontend RPC path Wallet secrets
wallet.qwertycoin.org Cloudflare Pages Official restricted QWC gateway Browser only
Local frontend only Your machine No local gateway Browser only
Full self-hosted Your machine Your restricted qwertycoind Browser only
In every setup: your seed, private spend key and private view key stay in your browser. QWC wallet scanning and transaction signing run locally in the bundled WebAssembly worker. The RPC gateway receives daemon sync requests and signed transaction data, never your wallet keys.

Questions or issues

For a normal bug or documentation discrepancy, open an issue in the official wallet repository. Report vulnerabilities privately through GitHub Security Advisories; do not publish wallet-security details in a public issue.