SDK
createPasskeyWallet
client.createPasskeyWallet creates a smart-account wallet whose admin authority is a passkey (Face ID, Touch ID, Windows Hello, hardware security key). The private key never leaves the device's secure hardware.
Browser by default (uses navigator.credentials) โ or any JavaScript runtime that supplies WebAuthn functions: in React Native, Expo, or Capacitor, pass your native passkey library's functions via the webAuthn option and users get the platform's real Face ID / fingerprint passkeys โ see Use the SDK in a mobile app.
import { createClient, BNB } from "@altananetwork/sdk";
const client = createClient({ chains: [BNB] });
const wallet = await client.createPasskeyWallet({
name: "MyApp",
rpId: "myapp.example",
});
// wallet.signer is a PasskeySigner. Use it like any other signer.Same as createWallet: the wallet is counterfactual until the first execute, which is when the admin (P-256) public key gets registered in Keystore.
Parameters
type ClientCreatePasskeyWalletOptions = {
/** Label shown in the OS passkey prompt (e.g. "MyApp"). */
name: string;
/** Relying-Party ID. Defaults to the current origin's host. */
rpId?: string;
/**
* WebAuthn overrides for runtimes without the browser API. Pass your
* native passkey library's create/get functions (React Native, Expo,
* Capacitor). Outside a browser, `rpId` becomes required โ use the
* associated domain your passkey library is configured with. The same
* `getFn` is used for EVERY later signature, so keep it on the signer
* (`signerFromPasskey(credential, { webAuthn })` after rehydration).
* Note: porto requires assertion responses to include `userHandle`.
*/
webAuthn?: { createFn?: ...; getFn?: ... };
};The chains the wallet is provisioned on come from the client (createClient({ chains })). For wallet execution, use BNB or ETHEREUM; BASE is exported for the L2 Keystore cache used by cross-chain verification.
Returns
A standard CreateWalletResult whose signer is a PasskeySigner.
Notes
- The wallet address is embedded in the passkey's userHandle at creation time. This is what makes
recoverFromPasskeywork later: the device knows which wallet each saved passkey belongs to. - Authorization on the chain side uses P-256 (secp256r1) signatures, matching WebAuthn. Keystore is signature-scheme agnostic, so it stores the P-256 public key the same way it stores secp256k1 keys.
- The user sees a single biometric prompt per signature. No seed phrases, no extension required.
Example: full passkey app flow
import { createClient, BNB } from "@altananetwork/sdk";
const client = createClient({ chains: [BNB] });
async function loginOrSignup() {
try {
// Returning user: pick from saved passkeys
return await client.recoverFromPasskey({ rpId: "myapp.example" });
} catch {
// New user: create one
return await client.createPasskeyWallet({
name: "MyApp",
rpId: "myapp.example",
});
}
}
const wallet = await loginOrSignup();
await client.execute({
wallet,
signer: wallet.signer,
calls: { to: "0x...", value: 0n },
});