Passkeys and the smart account
VaultKeepR replaces the usual email-and-password signup with a passkey and an ERC-4337 smart account. This page describes how the pieces fit, based on the public @vaultkeepr/smart-account package.
Passkeys
Section titled “Passkeys”When you register a biometric passkey, the app provisions a smart account in the background. You do not provide an email address and you do not connect an external wallet such as MetaMask. The passkey (WebAuthn) stays on your device and signs the operations that matter.
The smart account
Section titled “The smart account”The @vaultkeepr/smart-account package implements a Kernel smart account with a Pimlico paymaster, shared across web, extension, iOS, and Android clients. Identity comes from one of two sources:
initIdentityFromPassword(password, salt): the identity is derived from your master password on device, with no seed phrase exposure.initIdentityFromSigner(signer): for a wallet you already have connected.
getIdentityAddress returns the smart account address. clearIdentity wipes the in-memory state. Signatures for on-chain writes go through the user’s smart account.
Gas fees
Section titled “Gas fees”All blockchain network fees required to record or claim your vault are sponsored by the Pimlico paymaster. Using the Base L2 blockchain costs nothing directly; there is no gas bill for the user.
Wallet signatures and delegations
Section titled “Wallet signatures and delegations”For users who link a wallet or an NFC hardware key, authentication works by proving control of an address with a signature over a fixed message (EIP-4361 schemas, in @vaultkeepr/wallet-messages). When an NFC tag is configured, its seed derives an on-device hidden wallet that acts as a smart wallet without talking to any third-party app.
Optional delegations cache a signature for a short time so unlock or autosave does not prompt the wallet on every action. While a delegation is active, treat the device as trusted: anyone with access to the unlocked session, or malware on the device, may use those credentials.
What this does not cover
Section titled “What this does not cover”The passkey flow is implemented in the private clients, so the exact enrollment screens and settings live there. The public package documents the identity lifecycle (identity.ts), the Kernel account (kernel.ts), signer derivation (owner.ts, secretKey.ts), the on-chain vault pointer writes (onChainSync.ts), and the VaultKeeperCidRegistry bindings (cidRegistry.ts). The package ships as TypeScript source and is meant to be consumed through a bundler.