Configuration
Use Configuration to prepare a direct connection to the LND node behind a Node-backed deployment. Choose REST, WebSocket, gRPC, or a currently supported command-line workflow based on the application and operating environment.
Connection material checklist
Collect the node host or API endpoint, the interface and port exposed for the node, a least-privilege macaroon, and the TLS or certificate material required by the client.
Store connection material in a secret manager or protected runtime configuration. Do not hardcode node hosts, macaroons, private keys, recovery material, or certificate contents in source code.
Confirm the current endpoint and port from the product interface or your Voltage contact before deployment. Historical examples may not match every node or environment.
Choose an interface
REST
Use REST for standard HTTP integrations and operational scripts. Send the macaroon as a hex-encoded value in the Grpc-Metadata-Macaroon header.
Use RESTREST for request encoding, authentication, monitoring patterns, and URL-safe base64 requirements for LND byte fields.
WebSocket
Use WebSocket when the application needs a long-lived stream of node events through the HTTP interface.
Apply the same endpoint, TLS, and macaroon controls used for REST. Implement reconnect, backoff, duplicate-event handling, and an independent state read after reconnect.
gRPC
Use gRPC for generated clients, typed service definitions, streaming calls, and high-throughput server applications.
Use proto files that are compatible with the target LND version. Configure TLS credentials and attach the macaroon as request metadata. Start with a simple node-information call before implementing payment or monitoring streams. See GRPCGRPC.
Command-line administration
Use only the remote connection method and command syntax verified for the target node and client version. Do not copy historical commands or empty certificate paths into production automation.
Authentication
Use the narrowest macaroon that supports the workflow. Separate read-only monitoring credentials from credentials that can create invoices, send funds, change channels, or administer the node.
REST and WebSocket clients generally send the macaroon as a hex string in the Grpc-Metadata-Macaroon header. gRPC clients send the macaroon as metadata, commonly under the macaroon key.
Rotate or revoke credentials when an operator changes, a secret is exposed, or a temporary support workflow ends.
TLS and certificate handling
Validate the node endpoint with the TLS behavior required by the current environment and client library.
Do not disable certificate verification in production. Treat any development-only override as temporary, isolated, and unsuitable for deployment examples.
Because certificate and cipher requirements can vary by LND version and client stack, verify the current behavior before standardizing a production client.
First connection test
Start with a read-only node-information or health call.
Confirm that DNS and network access succeed, TLS validation completes, the macaroon is accepted, the response matches the intended node and network, and errors are logged without exposing credentials.
After the health check succeeds, test the smallest required workflow and verify the result through an independent node or Payments read.
Production checklist
- Keep staging and production endpoints and credentials separate.
- Apply timeouts, bounded retries, backoff, connection reuse, and structured error handling.
- Monitor authentication failures, TLS failures, connection churn, stream reconnects, and unexpected node or network identity.
- Reconcile direct node actions with Payments and treasury records when the same node supports a Payments integration.
Continue
- RESTREST for HTTP request and encoding guidance.
- GRPCGRPC for proto generation, TLS credentials, metadata, and streaming clients.
- Node SecurityNode Security, MacaroonsMacaroons, and Node-backed SetupNode-backed Setup for ownership and access controls.