Wallet permissions, explained before connection

How Proliquid wallet permissions work

You can explore Proliquid market intelligence without connecting a wallet. When you enable trading, no funds move and Proliquid cannot withdraw. Your main wallet proves ownership, approves a builder-fee maximum, and creates a wallet-specific Hyperliquid API agent for supported trading actions.

The Proliquid account, connected wallet, and Hyperliquid account do different jobs. Proliquid stores workspace preferences; the wallet authorizes permissions; Hyperliquid holds exchange balances, positions, orders, fills, and margin state. Creating an account or connecting a wallet does not place a trade.

Free to explore · Connect a wallet only when you are ready to trade

  • No wallet required to explore market intelligence
  • No funds move when trading is enabled
  • Explicit builder-fee maximum and wallet-specific API agent
Research stays open; supported trading uses explicit permissions, while withdrawal access is not granted to Proliquid.

Three layers, separate responsibilities

Know what is stored, signed, and executed.

Security starts with an accurate permission model. Proliquid keeps the app workspace, wallet authorization, and Hyperliquid exchange state distinct so each action can be reviewed in context.

Explore

Research before connecting

News, Screener, Funding, Compare, market guides, and product documentation can be reviewed before a wallet is connected.

ValidateConfirm you are on an official Proliquid domain before creating an account or opening the app.

Authorize

Prove control with the main wallet

The wallet connection uses a signed ownership message and, when needed, a separate main-wallet approval for the maximum Proliquid builder-fee rate.

ValidateRead the wallet prompt, active address, builder identity, and maximum fee before signing.

Execute

Use a Hyperliquid API agent

A wallet-specific API agent is stored in the browser and signs supported trading actions without requesting the main-wallet signature for every order.

ValidateTreat the browser and device as part of the security boundary, and recreate the agent when its local data is cleared or invalid.

Control

Separate disconnecting from revoking

Disconnecting ends the current Proliquid wallet session. It does not close positions, cancel open orders, or revoke every exchange-level permission by itself.

ValidateReview live orders and positions first, then use the documented Hyperliquid controls when permissions need to be replaced or revoked.

Safe connection workflow

Review the boundary before you enable trading.

Use the same deliberate sequence on a new browser, device, wallet, or account. A familiar interface is not a substitute for checking the active signer and requested permission.

Read the product guide
  1. Explore the product first

    Open News, market guides, Screener, Funding, and Compare before connecting. Decide whether the workflow is useful before granting a wallet permission.

  2. Verify domain and active wallet

    Confirm the official Proliquid URL, wallet extension, active address, and intended Hyperliquid account before signing any message.

  3. Read every permission

    Review the ownership signature, builder-fee maximum, and API-agent creation separately. Reject any unexpected withdrawal, transfer, or seed-phrase request.

  4. Monitor and clean up

    After trading, review positions, open orders, TWAPs, chases, fills, and permissions. Disconnecting the app is not the same as cancelling exchange activity or revoking access.

The remaining risks

Permission control reduces ambiguity, not trading risk.

A limited execution path still interacts with leveraged markets and a browser security boundary. Wallet hygiene, device security, permission review, and active position monitoring remain your responsibility.

Trading access can still create loss

An API agent used for supported order actions can create or change market exposure. A malicious or mistaken trade can lose capital even when withdrawal is unavailable.

Browser-local state can disappear

Clearing browser data or changing devices can remove locally stored API-agent information and require a new connection, while existing Hyperliquid positions and orders remain active.

Disconnect is not revocation

Ending the Proliquid session does not automatically cancel open orders, close positions, or revoke every Hyperliquid-level approval.

Protocol and market risk remain

Hyperliquid rules, oracle behavior, liquidity, leverage, funding, slippage, liquidation, and third-party software risk are outside any interface-level promise.

Before you trade

Questions about this workflow

Product behavior and limits, explained without trading promises.

Does connecting a wallet to Proliquid move funds?

No. Creating an account, signing the ownership message, approving the builder-fee maximum, or creating the API agent does not by itself place a trade or move funds. Proliquid cannot withdraw. A later order can still change exposure and create trading losses.

What does the Hyperliquid API agent do?

The wallet-specific API agent signs supported Hyperliquid trading actions so the main wallet does not need to sign every order. Proliquid stores the agent per wallet in browser storage; clearing local data or changing devices can require a new agent.

What builder-fee permission does Proliquid request?

The main wallet approves a maximum Proliquid builder-fee rate for supported actions. The executed rate can be lower when a documented VIP tier applies. Hyperliquid exchange fees remain separate.

Does disconnecting revoke access or close positions?

No. Disconnecting ends the current Proliquid session, but it does not close Hyperliquid positions, cancel open orders, or revoke every exchange-level permission by itself. Review the wallet safety guide and Hyperliquid controls before rotating or revoking permissions.

Explore before you authorize

Understand the permission. Then decide whether to connect.

Review live intelligence without a wallet, read the security model, and enable Hyperliquid trading only after the active address, fee cap, and API-agent flow are clear.