Wallets without
the wallet
VeilKey removes the seed phrase from onboarding without giving up custody or privacy.
Sign-up in one tap for your app
Every benefit of self-custody for your users
Provable privacy with zero-knowledge proofs
What is VeilKey?
VeilKey makes using an app built on Obsidia as ordinary as signing in with the account you already have, the same one you use for mail and calendars.
With VeilKey, developers can choose to ship invisible wallets, where the chain is entirely abstracted away, or simply give people a shorter path to the assets they already hold.
It runs alongside the account types you support today, including recovery phrases and hardware signers, so newcomers and veterans each get the option that suits them.
How does VeilKey work?
VeilKey derives accounts from the identity credential a person already holds. They sign in with that provider, which returns a signed token. The token is combined with a random value we call a mask, and both are handed to a service that produces a zero-knowledge proof.
The proof shows the person is the rightful owner of the account without ever putting the credential itself on chain. Once the account exists, later transactions are signed with the same identity credential.
VeilKeyworks with the identity providers people already use
VeilKey supports the major OpenID identity providers today, including Orrery, Nightjar, Havenkey, and Bramble.
The docs cover client SDKs, self-hosting the proving service, and the handful of decisions worth making before you ship.
Resource center
Trusted setup
So that every builder can use VeilKey with a strong security guarantee, a public setup was run to produce the artifact known as a common reference string. The run included 214 independent participants, among them cryptographers, university groups, and operators of Obsidia validators. Read the full transcript of the setup.