Node Security
4 min
use this page when your payments setup is node backed or when your team uses direct lnd access to the node behind payments what protects the node direct node control is not granted by payments api keys it is controlled by node specific security material seed phrase recovery material for the lnd wallet store offline and never share node password used to unlock or decrypt node sensitive material in voltage verify current recovery behavior before relying on it approved encrypted backups use only the current supported workflow and keep the decryption secret separate from the backup payload macaroons lnd native credentials for direct node api access tls/cert material used with node api endpoints access boundary platform access is separate from direct node control, but it does not automatically reveal seed phrases, decrypted macaroons, lndconnect , or other node sensitive material platform and node permissions separate application payment access, read only monitoring, node administration, fund movement, channel operations, credential export, and recovery access credential separation keep node credentials and recovery material in approved systems with the smallest practical operator group recovery and backups use only the current approved recovery process for the node type and product flow verify the recovery material, owner, storage location, access policy, and last validation date before an incident occurs never place an unencrypted seed, private key, privileged macaroon, or recovery secret in a support ticket, chat, screenshot, shared note, or unapproved backup system direct node access direct node access happens through the node endpoint plus lnd credentials see macaroons for how admin, read only, invoice, and custom macaroons change what an integration can do if a privileged credential or recovery item may be exposed, stop using it and follow the current security and support process for containment, replacement, and review