Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions Plugins/BTCPayServer.Plugins.Blink/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,14 @@ type=blink;server=https://api.blink.sv/graphql;api-key=blink_...;wallet-id=xyz;c
Create an API key on the [Blink dashboard](https://dashboard.blink.sv). For BTCPay receiving you
need at least the `READ` and `RECEIVE` scopes; `WRITE` is additionally required to pay invoices.

> **The API key is stored on this server, and its operator can read it.** BTCPay keeps the key in the
> store's Lightning settings, so whoever operates the server can read it and use it for whatever the key
> is scoped to — a `WRITE` key can spend the account's balance. Grant only the scopes BTCPay needs
> (`READ` + `RECEIVE` to receive; add `WRITE` only if BTCPay must also pay invoices), and if you do not
> operate and trust this server, treat the key as exposed to its operator. A key can be revoked and
> replaced from the Blink dashboard at any time. The non-custodial `ln-address=` path below stores no
> credential and is not affected.

### Non-custodial (Spark) account — receive only

The new Blink non-custodial accounts do not expose an API key or a GraphQL wallet id. Receiving is
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,15 @@
</li>
</ul>
<p class="my-2">Head over to the <a href="https://dashboard.blink.sv" target="_blank" rel="noreferrer noopener" >Blink dashboard</a> and create an api key. The server is optional and will use the default Blink instance.The wallet-id is optional and will use the default wallet otherwise.</p>
<div class="alert alert-warning my-2" role="alert">
<strong>The API key is stored on this server.</strong> BTCPay keeps it in the store's
Lightning settings, so whoever operates the server can read it and use it for whatever the
key is scoped to — a <code>WRITE</code> key can spend the account's balance. Grant the key
only the scopes BTCPay needs: <code>READ</code> and <code>RECEIVE</code> to receive
payments, and <code>WRITE</code> only if BTCPay must also pay invoices. If you do not
operate and trust this server, treat the key as exposed to its operator; a key can be
revoked and replaced from the Blink dashboard at any time.
</div>
<p class="my-2"><strong>Non-custodial (Spark) account</strong> — receive only, no API key:</p>
<ul class="pb-2">
<li>
Expand Down
Loading