Looks like we can enter private keys not generated on 2XPT as well
https://talkimg.com/images/2025/04/11/xm5Pd.jpeg
I'd probably just create a burner wallet that could easily let me view private keys— for convenience's sake— if I wanna play. Or perhaps op could let players drop an address and a signed message from it (sign of ownership) as an alternative login. Maybe it'd feel less threatening for other folks too.
In any case, promising concept op. Good luck!
You are 100% correct, the private-key never leaves your browser, its only used to sign a message.
Feel free to debug in browser, i will have API spec out soon as well.
Let us know how we could make sure you don't keep a copy of the private key if it's generated from your platform. Because it's impossible to use our existing private keys. Keep sharing more information on this thread. Let's try to figure out how your platform works.
You can make sure using browser debug tools, or console, or wireshark.
Easiest way would be to inspect your browser and check for requests.

https://i.ibb.co/8gDKccw1/refugee.png