Pairing is how two phones learn each other's keys. Everything after that — every message, every photo — is sealed to those keys, and only those two phones can open it.
One phone shows, the other scans. The code carries a public key and a short-lived nonce; it does not carry anything secret, so it is safe to show in public. Each phone then sends the other its card, sealed.
A contact's page says how the pairing happened, and that is where its confidence comes from.
Scanned in person is the strongest. The code carries a short-lived value that exists nowhere but on that screen, so only a phone that actually read it can answer. A scan completes on its own, in a second or two, and the contact is there when it finishes.
Paired from a code you sent shows as Linked. A code works for whoever holds it, so it is as trustworthy as the way you sent it.
Not paired means no keys have been exchanged and nothing can be sealed.
Pairing proves the phone at the other end holds the keys it claims. It cannot prove who is holding that phone.
Almost always that is fine — you scanned their screen, or you sent a code to a number you know. But before you send something where being wrong would matter, check the person, not the maths. The simplest way costs nothing:
> Call them, or message them on something else, and ask them to read back the last thing you sent.
Only the person you are actually paired with can do that. It needs no codes, no numbers to compare, and it tests the thing you care about — that the conversation on your screen is reaching the person you think it is.
Worth doing when a pairing came from a code that travelled, if the answer changes what you would say next.
A pairing code works for whoever holds it. Send it by any means you would trust with something private — a message on WhatsApp, Signal, iMessage, or your phone's own texting are all end-to-end encrypted or close enough for this.
Not plain email. Email is not encrypted between servers. Most people assume it is; it is not, and it is the one common channel where a code could genuinely be read in transit.
If a code you sent is used by somebody other than the person you meant, CHANNEL tells you and does not write them to that person's card.
If someone reaches you at a verified number or address, or at your handle, you see a request that says who they claim to be. Give them whatever name you like, or none. The name is for you.
Three choices: Accept, Decline, Block. Accepting creates the contact, unverified, and starts the pairing. It completes when both phones are next reachable, and you can leave the screen in the meantime. Their first message follows as soon as it does, sealed, because they had already written it. Blocking refuses this request and anything else from that sender, and it holds after the request is gone. Nobody is told what you chose.
You can verify that contact later from their page. Verification is not needed to talk to them.
English is the reference text; any translation is a convenience. Help is stored on this phone and never contacts anyone.