How to Check a TON Connect Manifest Before Approving

Title TON Connect manifest checks: Learn which details to check in a TON Connect manifest before approving a wallet connection, and what risks to watch

However, the manifest alone cannot guarantee legitimacy or user safety. A convincing or familiar name and icon do not prove an app’s intent, and attackers can leverage these elements to imitate real projects. Users remain responsible for checking the full destination domain displayed by the wallet, reading every wallet prompt carefully, and rejecting unclear or suspicious signing requests. Following TON Connect manifest checks helps reduce risk, but does not replace verifying official sources before continuing.

What the TON Connect Manifest Reveals

The TON Connect manifest acts as the digital identity card for any decentralized app trying to connect with a user's wallet. Before a connection is approved, the wallet displays the manifest’s key fields: app name, icon, the claimed URL, and its privacy or policy context. This is not just visual decoration—these details allow users to judge if the dApp is who it says it is. Relying solely on a familiar logo or a well-designed interface exposes users to phishing—malicious actors can imitate brands or create fake dApps with convincing graphics.

Crucially, users should always cross-check the displayed app name and icon with the official destination domain and project information. The URL field in the manifest should match the known platform or campaign. If there’s any mismatch, or if a wallet prompt seems unexpected, users are advised to immediately halt the process. The policy context—sometimes shown directly, sometimes requiring an extra click—may include privacy rules or permission details that affect what the dApp can do once authorized.

TON Drop Hub take: The manifest is a user’s only line of defense before clicking “Connect” in a wallet. Names and icons alone cannot guarantee authenticity. For any session, treat the manifest screen as a permission checkpoint, and verify the domain and policy context before trust is given.

Steps to Verify dApp Identity in Your Wallet

TON Connect prompts give users key details about a dApp before any connection to a wallet can proceed. Each prompt displays the app’s name, icon, and website URL according to the dApp’s manifest. This information appears directly in the wallet interface so that users can recognize who or what is requesting access. The manifest also defines a policy context, which may outline what data is requested or what permissions the connection involves. No single element—logo, name, or URL—should be relied on by itself to prove legitimacy.

Scammers often copy names and icons, so a convincing appearance does not guarantee safety. Always examine the website URL in the wallet prompt and confirm that it matches the official source for the dApp. If any prompt appears suspicious, or if the domain seems off, reject the connection immediately. Reading all permissions listed in the wallet dialog is critical: never approve any request you do not understand. Rushed approvals can expose personal keys or wallet balances to unauthorized actors.

TON Drop Hub take: Checking all manifest fields including the destination URL gives practical defense against phishing attacks in wallet-connected flows. This step matters far more than visual branding when using DeFi dApps or Telegram Mini Apps linked to TON Connect. Builders must test their own manifests thoroughly, since any mismatch or poor branding risks confusing or alarming users at the critical moment of wallet approval.

Risks If You Skip Manifest and Domain Checks

Skipping manifest and domain checks exposes users to basic but avoidable risks. When using TON Connect, a dApp’s manifest supplies its name, icon, URL, and policy context to the wallet. While this offers a first layer of identification, a visually convincing app name or icon is not proof of authenticity. Attackers can copy branding and submit misleading manifests, making it easy to impersonate legitimate dApps if users don’t verify the true domain and read every wallet prompt closely.

Focusing only on familiar icons or names leaves users open to phishing attacks where a malicious actor sets up a nearly identical front end. The actual destination domain—displayed before approving a wallet connection—is far harder to fake than visual elements. Users can verify that this domain matches the dApp’s official site or trusted communication channels before proceeding.

Another overlooked risk is ignoring wallet prompts during connection or signing requests. Each prompt contains details from the manifest. Rushing through or blindly approving these steps may grant unintended permissions or connect your wallet to an unknown entity. There are no guarantees that any interface using TON Connect is safe without direct cross-verification of the manifest and domain.

TON Drop Hub take: The reality is that manifest checks are only as strong as the user’s attention to detail. Treat every new or unfamiliar app—no matter how professional the icon appears—as an unknown until verifying its domain and all wallet permission texts. This is the only confirmed way to cut through imitators and protect access.

Relying on app names or logos in the TON Connect manifest is not enough to confirm a dApp’s identity before wallet approval. The manifest only supplies basic information—such as the name, icon, domain, and policy context—which can be mimicked by malicious actors. Users must always check the destination URL in the wallet’s prompt, read all requested permissions, and refuse any unclear or suspicious requests.

TON Drop Hub take: The simple habit of inspecting the manifest details and verifying the domain each time you connect a wallet is a key safeguard, especially with new or high-value dApps. Skipping these steps leaves users far more vulnerable to impersonation or outright theft.

For more coverage, see TON guides.

For related TON Drop Hub coverage, see TON guides.

Source reference: original source.