Self-Host & Verify
Don't trust us — verify. This page explains how to compare wallet.qwertycoin.org with the official public source and how to run the Qwertycoin Web Wallet with your own restricted QWC node.
qwertycoind endpoint through a same-origin, allowlisted RPC gateway. A static local copy is enough to inspect the frontend; a fully working self-hosted wallet also needs that gateway and a synced QWC node.
Option 1 — Verify the live site
Every deployed wallet file is SHA-256 hashed in the repository's MANIFEST.txt. Compare the manifest served by wallet.qwertycoin.org with the official repository, then verify the checked-out files:
# 1. Clone the official wallet repository
git clone https://github.com/qwertycoin-org/wallet.qwertycoin.org.git
cd wallet.qwertycoin.org
# 2. Fetch the manifest from the live wallet
curl -fsS https://wallet.qwertycoin.org/MANIFEST.txt \
-o ../live-manifest.txt
# 3. Confirm GitHub and the live site publish the same manifest
cmp MANIFEST.txt ../live-manifest.txt
# 4. Verify every deployed file against the signed-off hashes
sha256sum -c ../live-manifest.txt
cmp prints nothing when both manifests are identical. sha256sum must report OK for every file. Any other result means the checked-out source and live deployment do not match.
To verify one QWC-specific file, such as the browser wallet engine:
curl -fsS https://wallet.qwertycoin.org/js/qwc-wallet-engine.js \
| sha256sum
grep 'js/qwc-wallet-engine.js' MANIFEST.txt
The two SHA-256 values must match exactly.
Option 2 — Run the frontend locally
The frontend itself has no build step. Clone the official repository and serve it with any static file server:
Clone the repo
git clone https://github.com/qwertycoin-org/wallet.qwertycoin.org.git
cd wallet.qwertycoin.org
Serve locally
python3 -m http.server 8080
Open http://localhost:8080/verify in your browser. Do not open the HTML files through a file:// URL: the QWC WebAssembly worker uses origin-relative paths.
Understand the local limit
The Python server only serves static files. It does not execute the repository's Cloudflare Pages Functions, so network sync and transaction relay through /api/proxy are unavailable. Use this mode for source inspection and interface testing. Use Option 3 for a complete wallet stack.
Option 3 — Full self-hosted stack
A complete Qwertycoin setup has three parts: the static Web Wallet, its restricted same-origin RPC gateway, and a synced QWC full node (qwertycoind). QWC wallet scanning runs locally in the browser; no separate light-wallet server receives your view key.
Build Qwertycoin Core
There are currently no official Qwertycoin v2 binary releases. Build from the official Qwertycoin Core repository and review its platform-specific instructions:
git clone --recursive https://github.com/qwertycoin-org/qwertycoin.git
cd qwertycoin
git submodule update --init --recursive
make release
Run a restricted QWC RPC
Start qwertycoind with unrestricted RPC on localhost only and a separate restricted wallet RPC on port 8198. Keep the restricted endpoint behind your firewall or an authenticated/TLS reverse proxy:
./build/release/bin/qwertycoind \
--p2p-bind-ip 0.0.0.0 \
--p2p-bind-port 8196 \
--rpc-bind-ip 127.0.0.1 \
--rpc-bind-port 8197 \
--rpc-restricted-bind-ip 127.0.0.1 \
--rpc-restricted-bind-port 8198 \
--zmq-rpc-bind-port 8199
Never expose unrestricted RPC port 8197 to the public internet. The Web Wallet needs only the restricted sync and transaction-relay methods enforced by its gateway.
Run the wallet gateway and frontend
The wallet repository includes Cloudflare Pages Functions that allow only the QWC RPC paths required by the browser wallet, apply request/response limits and reject mining or daemon-administration methods. Point both gateway upstream lists at your restricted RPC, then run the Pages development server:
# In the wallet repository, configure your restricted QWC upstream in:
# functions/_qwcRpcProxy.js
# functions/api/proxy.js
# Local-only upstream: http://127.0.0.1:8198
npx wrangler pages dev .
Open the URL printed by Wrangler. For an internet-facing deployment, protect the restricted RPC with HTTPS and keep the browser on the same origin as the gateway. Review the allowlists in both Function files before deployment; do not replace them with an unrestricted pass-through proxy.
What you're trusting in each setup
| Setup | Frontend | RPC path | Wallet secrets |
|---|---|---|---|
| wallet.qwertycoin.org | Cloudflare Pages | Official restricted QWC gateway | Browser only |
| Local frontend only | Your machine | No local gateway | Browser only |
| Full self-hosted | Your machine | Your restricted qwertycoind |
Browser only |
Questions or issues
For a normal bug or documentation discrepancy, open an issue in the official wallet repository. Report vulnerabilities privately through GitHub Security Advisories; do not publish wallet-security details in a public issue.