Issuer boundary
Enrollment
Enrollment is the one flow where the issuer observes the Stellar address and checks testnet eligibility.
Before clicking
Install and unlock Freighter, select Stellar Testnet, keep the same account selected for the whole flow, and make sure it holds the minimum native XLM balance displayed on the enrollment page. Read and check the disclosure box; the enrollment button remains disabled until that box is checked.
1. Connect the account
Select Connect Freighter and enroll. Freighter may ask you to allow VeilPass to read the active public address. Approve that request. If VeilPass was already authorized, this first prompt can be skipped automatically; the on-page progress panel still moves to the wallet and network checks.
2. Approve the message
After eligibility passes, Freighter opens a second approval for a readable, one-time enrollment message. Approve it without switching accounts. This is an off-chain SEP-53 message signature, not a Stellar transaction, so it does not transfer XLM or any other asset.
3. Wait for local storage
Keep the enrollment tab open while VeilPass issues the credential, publishes the updated gate root, and saves the credential in this browser. Completion is explicit: the progress panel says Credential stored. Only then open App A or App B for private login.
If no Freighter window appears
Look at the progress panel first. If it says Waiting for Freighter, open the Freighter extension from the browser toolbar, unlock it, confirm Testnet and the selected account, then return to the page. A timeout produces a recovery message and a fresh retry button; do not reuse an old challenge.
Privacy and recovery
The issuer sees the Stellar address and public Testnet balance during enrollment. Host apps do not receive that address. The credential stays in this browser; clearing site data or using another browser requires enrollment again. VeilPass never asks for or stores a secret key.