Node Security
Use this page when your Payments setup is Node-backed or when your team uses direct LND access to the node behind Payments.
What protects the node
Direct node control is not granted by Payments API keys. It is controlled by node-specific security material.
- Seed phrase: recovery material for the LND wallet. Store offline and never share.
- Node password: used to unlock or decrypt node-sensitive material in Voltage. Verify current recovery behavior before relying on it.
- Approved encrypted backups: use only the current supported workflow and keep the decryption secret separate from the backup payload.
- Macaroons: LND-native credentials for direct node API access.
- TLS/cert material: used with node API endpoints.
Platform and node permissions
Separate application payment access, read-only monitoring, node administration, fund movement, channel operations, credential export, and recovery access.
Credential separation
Keep node credentials and recovery material in approved systems with the smallest practical operator group.
Recovery and backups
Use only the current approved recovery process for the node type and product flow. Verify the recovery material, owner, storage location, access policy, and last validation date before an incident occurs.
Never place an unencrypted seed, private key, privileged macaroon, or recovery secret in a support ticket, chat, screenshot, shared note, or unapproved backup system.
Direct node access
Direct node access happens through the node endpoint plus LND credentials. See Macaroons for how admin, read-only, invoice, and custom macaroons change what an integration can do. If a privileged credential or recovery item may be exposed, stop using it and follow the current security and support process for containment, replacement, and review.