Approve account access carefully, understand transaction prompts, and remove site permissions.
Web apps interact with Noir Wallet through the provider injected into the page. A connection request can ask you to authorize one or more wallet accounts for that origin.
When a site requests access:
A connection lets the site read authorized public account data. It does not let the site send ZEC without a separate approval.
Never approve from the website alone. Use the Noir Wallet approval window as the source of truth for the requested action, destination, amount, and account.
Open the connected dApps list in Noir Wallet and remove origins you no longer use. Locking the wallet and disconnecting a site are different actions.
Noir Wallet support will never ask you to paste a recovery phrase into a dApp, support form, or direct message.