vocal

VOCAL / DOCUMENTATION

Everything, on the record.

How sounds become records, how verification works, and how to build with the API.

Your wallet stays yours

VOCAL connects to an existing wallet and requests an authentication signature. It does not create embedded wallets, store seed phrases, receive private keys, or custody funds.

Authentication

Wallet sign-in challenges are bound to the domain, wallet and expiry. A verified signature consumes its nonce once. Sessions expire after 12 hours and are stored in secure HttpOnly cookies. Privy tokens are checked server-side against the application’s JWKS, issuer and audience.

Server-side services

Database, RPC and model credentials remain on the server. Browser clients call scoped VOCAL endpoints; they do not receive provider secrets or a general-purpose RPC proxy.

Content and identity

There is no identity verification or guarantee of token creator reputation. A sound link is not proof of copyright ownership. Public records omit account identifiers; on-chain activity and token creator information remain public on Solana.

Signing transactions

Only approve transactions you understand. The launch handoff opens pump.fun in a new tab. Check the destination domain and review all amounts and permissions in your wallet.