Chainvara
Embedded wallets

Give every user a wallet they truly co-own

Each of your users gets a Solana wallet whose key is generated jointly by their device and the Chainvara vault. Your backend relays the calls but can never sign alone, and the device checks every transaction before adding its share.

My wallet

12.48 SOL

Withdraw

0.25 SOL → 7xK…f3Q

Matches what you confirmed

Enter your PIN

Signed on this device

What makes it safe

Core

Device + vault (2-of-2)

The user's share stays on their device, locked with their PIN (PBKDF2 and AES-GCM). The vault keeps the other share.

Your policy applies

Withdrawals follow your organization's policy and approvals before the device is asked to sign.

Exact-transaction check

The device SDK decodes the transaction and refuses anything that differs from what the user confirmed.

One-file SDK

A single ES module with FROST in WebAssembly, published with its SHA-256. No other dependency.

How it works

  1. 1

    Relay from your backend

    Forward the device's two calls with your API key and the user's ID from your own session.

  2. 2

    Create the wallet in the app

    createEmbeddedWallet runs key generation and returns the share to lock on the device.

  3. 3

    Sign withdrawals

    Once a transfer is approved, signEmbeddedTransfer adds the user's share to exactly that transaction.

In your app

import { createEmbeddedWallet, lockShare } from
  "https://www.chainvara.com/sdk/chainvara-embedded.js";

const { wallet, share } = await createEmbeddedWallet({ relay, externalUserId });
const locked = await lockShare(share, pin);

Works best with

Ready to see Chainvara in action?

Start free on test networks. Move to production when your controls are in place.