{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "sign-in-with-ethereum",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/sign-in-with-ethereum/",
  "collection": "ethereum",
  "title": "Sign-In with Ethereum: what a wallet login proves",
  "description": "Learn what an EIP-4361 wallet login authenticates and why domain, nonce and time checks matter when verifying a sign-in message.",
  "aliases": [
    "Sign In with Ethereum",
    "SIWE wallet login"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T19:27:58.939Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "Sign-In with Ethereum uses a structured message and wallet signature to authenticate control of an Ethereum account to a service. EIP-4361 includes the requesting domain, URI, chain ID, nonce and issue time so the verifier can bind the signature to a particular login context. A valid login does not by itself prove a real-world identity or make the service trustworthy.",
    "claimId": "sign-in-with-ethereum-quick-answer",
    "sourceIds": [
      "x425-eth-eip4361"
    ]
  },
  "keyFacts": [
    {
      "label": "Context",
      "value": "The message includes domain, URI and chain ID.",
      "sourceIds": [
        "x425-eth-eip4361"
      ],
      "id": "context",
      "claimId": "sign-in-with-ethereum-fact-context"
    },
    {
      "label": "Replay protection",
      "value": "A verifier checks the nonce and applicable time constraints.",
      "sourceIds": [
        "x425-eth-eip4361"
      ],
      "id": "replay-protection",
      "claimId": "sign-in-with-ethereum-fact-replay-protection"
    },
    {
      "label": "Purpose",
      "value": "SIWE authenticates an account for an offchain session.",
      "sourceIds": [
        "x425-eth-eip4361"
      ],
      "id": "purpose",
      "claimId": "sign-in-with-ethereum-fact-purpose"
    }
  ],
  "prerequisites": [
    "ethereum-wallet-requests"
  ],
  "sections": [
    {
      "id": "message",
      "heading": "Read the login context before signing",
      "sourceIds": [
        "x425-eth-eip4361"
      ],
      "paragraphs": [
        "EIP-4361 defines a human-readable message encoded for Ethereum message signing. The account, requested domain, resource URI and issue time are part of that message. Optional expiration and not-before fields can constrain when it is valid.",
        "The verifier must check both the signature and the message context. Recovering an address from an arbitrary signed string is not the same as fully validating a SIWE login."
      ]
    },
    {
      "id": "example",
      "heading": "A signature for one site should not log in to another",
      "sourceIds": [
        "x425-eth-eip4361"
      ],
      "paragraphs": [
        "Suppose a login challenge identifies the service you intended and a fresh nonce. A second site receiving the same signature should not accept it for its own domain. A used or mismatched nonce should likewise fail the intended replay checks.",
        "This depends on correct verification by the application. A wallet’s ability to sign the message is not a guarantee that every website implements the standard correctly."
      ]
    },
    {
      "id": "authority",
      "heading": "Account authentication has limits",
      "sourceIds": [
        "x425-eth-eip4361",
        "x425-eth-eth-security"
      ],
      "paragraphs": [
        "Successful verification establishes the account authorization relevant to the message and session. It does not demonstrate a legal name, ownership of an offchain item or that the site’s later transaction requests are safe.",
        "Distinguish the sign-in message from other signatures. A later permit, order or transaction can grant asset-related authority even if the first interaction was only a login."
      ]
    }
  ],
  "faq": [
    {
      "question": "Does a SIWE login normally send an Ethereum transaction?",
      "answer": "The standard authenticates through an offchain signed message and verification. That login signature is separate from a transaction submitted for onchain execution.",
      "sourceIds": [
        "x425-eth-eip4361"
      ]
    },
    {
      "question": "Can a contract account use Sign-In with Ethereum?",
      "answer": "EIP-4361 includes contract-account verification considerations. The verifier must use the account’s applicable validation method and the chain specified in the message.",
      "sourceIds": [
        "x425-eth-eip4361"
      ]
    }
  ],
  "claims": [
    {
      "id": "sign-in-with-ethereum-quick-answer",
      "articleSlug": "sign-in-with-ethereum",
      "statement": "Sign-In with Ethereum uses a structured message and wallet signature to authenticate control of an Ethereum account to a service. EIP-4361 includes the requesting domain, URI, chain ID, nonce and issue time so the verifier can bind the signature to a particular login context. A valid login does not by itself prove a real-world identity or make the service trustworthy.",
      "sourceIds": [
        "source-bafbb5becc12abdd"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-bafbb5becc12abdd",
          "locator": "Message format; verifying messages; security considerations"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Read ERC4361 message fields, origin verification, relying-party steps and contract-account validation. Domain/URI/nonce/time/context checks are required alongside signature validity. Contract validation tied to chain ID; account authentication not legal identity or an asset permission."
        ]
      }
    },
    {
      "id": "sign-in-with-ethereum-fact-context",
      "articleSlug": "sign-in-with-ethereum",
      "statement": "Context: The message includes domain, URI and chain ID.",
      "sourceIds": [
        "source-bafbb5becc12abdd"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-bafbb5becc12abdd",
          "locator": "Message format; verifying messages; security considerations"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Read ERC4361 message fields, origin verification, relying-party steps and contract-account validation. Domain/URI/nonce/time/context checks are required alongside signature validity. Contract validation tied to chain ID; account authentication not legal identity or an asset permission."
        ]
      }
    },
    {
      "id": "sign-in-with-ethereum-fact-replay-protection",
      "articleSlug": "sign-in-with-ethereum",
      "statement": "Replay protection: A verifier checks the nonce and applicable time constraints.",
      "sourceIds": [
        "source-bafbb5becc12abdd"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-bafbb5becc12abdd",
          "locator": "Message format; verifying messages; security considerations"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Read ERC4361 message fields, origin verification, relying-party steps and contract-account validation. Domain/URI/nonce/time/context checks are required alongside signature validity. Contract validation tied to chain ID; account authentication not legal identity or an asset permission."
        ]
      }
    },
    {
      "id": "sign-in-with-ethereum-fact-purpose",
      "articleSlug": "sign-in-with-ethereum",
      "statement": "Purpose: SIWE authenticates an account for an offchain session.",
      "sourceIds": [
        "source-bafbb5becc12abdd"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-bafbb5becc12abdd",
          "locator": "Message format; verifying messages; security considerations"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Read ERC4361 message fields, origin verification, relying-party steps and contract-account validation. Domain/URI/nonce/time/context checks are required alongside signature validity. Contract validation tied to chain ID; account authentication not legal identity or an asset permission."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "x425-eth-eip4361",
      "label": "Sign-In with Ethereum",
      "publisher": "Ethereum Improvement Proposals",
      "url": "https://eips.ethereum.org/EIPS/eip-4361",
      "locator": "Message format; verifying messages; security considerations",
      "note": "Domain, URI, chain ID, nonce and time-bound authentication sessions.",
      "version": "EIP-4361",
      "checkedAt": "2026-10-02T18:55:24.817Z",
      "contentSha256": "0530d2eb496ab9f9061474a68a4b1e280692c46c533f1a5f1541a1a741aed663",
      "recordId": "source-bafbb5becc12abdd"
    },
    {
      "id": "x425-eth-eth-security",
      "label": "Ethereum security and scam prevention",
      "publisher": "ethereum.org contributors",
      "url": "https://ethereum.org/en/security/",
      "locator": "Wallet security; common scams; hardware wallets",
      "note": "Primary community guidance on wallet secrets, phishing, malicious sites and transaction checking.",
      "version": "Documentation snapshot retrieved 2 October 2026; response hash recorded separately",
      "checkedAt": "2026-10-02T18:55:24.140Z",
      "contentSha256": "1372ff086ae3f53ded99c8dfe308346a457574d41c04dc587de119a64080b448",
      "recordId": "source-83ec2d5a18d94ce1"
    }
  ],
  "related": {
    "articles": [
      "ethereum-wallet-requests",
      "eip-712-typed-data",
      "ethereum-dapp-connection-errors"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and separate automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Sign-In with Ethereum: what a wallet login proves.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/sign-in-with-ethereum/"
}
