Skip to main content
The safest assumption is simple: no legitimate please workflow needs your seed phrase or private key.

Never share

  • Seed phrases or private keys
  • Passwords, passkeys, recovery codes, or one-time codes
  • Signed transactions or signatures you do not understand
  • Provider API keys or trading credentials
  • Screenshots that expose recovery material or sensitive account information
please support will never ask you to send these by email, chat, or screen sharing.

Current public service boundaries

The public please MCP service is stateless and unauthenticated. It does not:
  • create a please user account;
  • connect to a wallet;
  • receive a wallet identifier as part of its tool contract;
  • retain an approval workflow;
  • sign or submit an order;
  • broadcast a blockchain transaction; or
  • custody or move funds.
If a client or website claiming to be please asks for secrets to run a public simulation, stop.

Check the destination

Use the official product at please.xyz. Confirm links and sender addresses carefully; lookalike domains, social accounts, browser extensions, and support messages can imitate a legitimate product. Official support email:

Keep authority bounded

A future transaction-capable service may authorize an action only inside an explicit, bounded policy or through independent approval tied to the exact action. Material, unfamiliar, above-threshold, or changed actions must ask. A prompt, assistant response, plan, quote, or simulation is never authority by itself. Before establishing a policy or approving an exception, review the agent, purpose, funding source, budget, asset, amount, network, recipient, contract, permissions, fees, expiry, and minimum received. Compare any wallet confirmation with the bound plan. Reject the request if they do not match.
Never approve a transaction because a support message, direct message, or caller tells you to. Support does not need control of your wallet to investigate a product issue.

Report a concern

Email hello@please.xyz with the suspicious URL or sender, a description of what happened, and a screenshot if useful. Remove credentials, balances, and personal information you do not want to share.