Node Security
4 min
use this page when your payments setup is node backed or when your team also operates voltage infrastructure nodes what protects the node direct node control is not granted by payments api keys it is controlled by node specific security material seed phrase recovery material for the lnd wallet store offline and never share node password used to unlock or decrypt node sensitive material in voltage voltage cannot recover it client side encrypted backups seed and macaroon backups are encrypted before voltage stores them macaroons lnd native credentials for direct node api access tls/cert material used with node api endpoints node password boundary team write can manage infrastructure settings, but it does not automatically reveal seed phrases, decrypted macaroons, lndconnect , or other node sensitive material dashboard access vs decrypted node access infrastructure dashboard permissions are team level, but some node sensitive fields and actions remain hidden or unavailable until the user provides the node password auto unlock some nodes may be configured for operational auto unlock treat auto unlock as an operational convenience, not as a replacement for controlling access to the node password, seed, and macaroons recovery warning if you recover a node from seed outside voltage, do not run two active lnd instances from the same seed coordinate recovery carefully before restarting or reusing the original node static channel backup recovery is a last resort recovery path and closes channels keep channel backup material available if you operate channels directly direct node access direct node access happens through the node endpoint plus lnd credentials see macaroons for how admin, read only, invoice, and custom macaroons change what an integration can do