Stellar
Mainnet, real money in dust amountsno XLM neededA passkey that owns a spend vault.
Your face or fingerprint becomes a smart account on Stellar. It deploys a vault, sets the limit, watches the vault refuse a payee it does not trust, and keeps the owner's levers: freeze, withdraw, add a device.
This side is Stellar mainnet with real Circle USDC, in dust amounts the server enforces.
You need no wallet, no seed phrase and no XLM. This deployment did not say whether fees are sponsored on Stellar mainnet.
Signing uses smart-account-kit 0.8.0 against OpenZeppelin smart-account contracts.
The backend did not answer for Stellar mainnet, so the caps and contract ids this page needs are unknown. Give it a few seconds and reload.
Create your passkey
Know how you recover it
If you lose every device that holds this passkey, the funds in the vault become unreachable to you, and nobody, including A-Identity, can recover them.
- There is no seed phrase to write down. The passkey is the key, and it stays in the authenticator that made it (or in the password manager that syncs it).
- A synced passkey survives losing one phone; a passkey bound to one device or one security key does not. The page tells you which kind you made.
- Add a second device in step 8 once your vault is deployed. Each device gets its own rule, so either one can sign alone. Not before: the vault deploy checks that this passkey is your account's one signer, and refuses an account that already has a second one.
- Our server holds the vault's operator key. It can call pay() inside the daily cap and per-payment ceiling, and once you turn the allowlist on (signing the limit does) only to payees you allowed. It cannot withdraw, change your limit, unfreeze the vault or add a signer.
- This is mainnet. The amounts are dust by design, and they are real.
Deploy a vault and set its limit
Check who you are about to pay
The on-chain allowlist is binary: ALLOW writes an entry, WARN is a server-side flag and writes nothing, and DENY writes a revoke so pay() reverts with PayeeNotAllowed. Only two of the three verdicts ever touch the ledger.
The agent pays someone untrusted
Any Stellar address that is not on your allowlist. A refused payment moves nothing and costs nothing.
The agent pays someone trusted
Create your passkey account first; on mainnet the trusted payee is your own smart account.
Freeze it, or take the money back
Deploy the vault in step 3 first.
Add another device
Create your passkey account in step 1 first.
Your receipts
Every transaction this page put on Stellar mainnet, in the order it happened. Nothing is listed here without a hash that made a ledger.
No transactions yet. Run step 1 and this fills itself in.
- This side is Stellar mainnet. The USDC is real and the amounts are dust, capped by the server for every visitor.
- A refused payment fails in simulation, so it has no hash.
- The passkey's private key never leaves your authenticator. Our server holds the vault's operator key: it can call pay() inside the cap and ceiling you signed, and with the allowlist on only to payees you allowed. It cannot withdraw, change your limit, unfreeze the vault or add a signer.
- Lose every device with this passkey and the vault's funds are unreachable; nobody, including A-Identity, can recover them.