What the smart account is
Your vault does not have an owner key. Its owner is a smart account: a small contract on Stellar whose only job is to say yes or no on your behalf. When you press Freeze or Withdraw, your device asks for your fingerprint, face or PIN, the passkey signs that one action, and the smart account checks the signature on the ledger before the vault does anything. The account is the OpenZeppelin smart account, built by us from their audited release line; the selection record explains that choice. It starts with exactly one signer: your passkey. Nothing we hold can sign for it, and the vault has no function that hands ownership to someone else, so the owner you create on day one is the owner forever.Where the passkey lives
A passkey is created and kept by your device or your password manager, never by us. Where it lives decides what losing a device costs you:- A device-bound passkey (for example one kept only on a hardware security key, or in a browser profile that does not sync) lives only on that one device. Lose or wipe the device and the passkey is gone.
- A synced passkey (iCloud Keychain on Apple devices, Google Password Manager on Chrome and Android) is copied to the other devices signed in to that account. Losing one phone does not lose it, as long as that iCloud or Google account survives and you can still sign in to it. If you lose access to that account, you lose the passkey with it.
C. The
page shows it and stores it in this browser. On a new browser the passkey alone may not be
enough for the page to find your account, so copy the address somewhere safe.
Adding a second device
The smart account accepts more than one signer, and a second device is the real protection against loss. When you add one, we add it as a separate rule on the account, so that either device alone can act. We do not add it to the first rule, because two signers on that rule would make every action need both devices, which is the opposite of a backup. Adding a device is itself an owner action: the existing passkey must approve it. That means it has to happen before you lose the first device. After the loss there is nothing left that can approve the change. It also has to happen after the vault is created: the vault is deployed only for a smart account with exactly one rule holding the one passkey, so the page offers the second device once the vault exists, not before.The page offers “Add another device” on testnet. On 2026-10-03 we rehearsed it on the
contract path with software keys, not devices: a second passkey added as its own rule,
approved by the first, then withdrew from the vault on its own. Whether a second-device
enrolment on a real device has been carried out end to end is recorded on
the Stellar page when it happens; until then, treat it as built and
rehearsed, but not yet demonstrated on a device.On 2026-10-04 the owner of the SoW 2 D3 vault tried it from the page with an Android
phone as the second device. It did not reach the ledger: read at testnet ledger 5020737,
that smart account still has one rule with one signer, the passkey it was created with.
Its recovery state is therefore a single synced passkey, which the page shows as
“1 device can sign”.
What we cannot do
- No reset. There is no “forgot my passkey” link, because there is no account on our side that could be reset. The owner is a contract on the ledger.
- No support override. Nobody at A-Identity can sign as your smart account, freeze or withdraw on your behalf, or move your funds out after a loss.
- No custody. We never hold your passkey, a copy of it, or any key that controls the owner. That is the point of the design, and it is also why we cannot help after a loss.
pay() inside
the limits you set: the daily cap, the per-payment ceiling and the allowlist. The vault
also supports a session expiry, but vaults created from this page leave it unset (0,
which means no time limit). It cannot withdraw, cannot change the policy and cannot
unfreeze. If you lose the passkey while the vault is frozen, the agent stays stopped. If
you lose it while the vault is running, the agent keeps spending inside those limits, day
after day, until the vault balance runs out.
