Saul Carlin
@smc
Here's how this works: 1. Your device securely stores a passkey 2. This passkey controls your XMTP ID, just like a private key controls your crypto wallet
1 reply
1 recast
5 reactions
Saul Carlin
@smc
3. You log into your inbox app with your XMTP ID and another identity you own (e.g. Solana wallet) 4. Both identities sign a message to prove ownership and agreement
1 reply
0 recast
1 reaction
Saul Carlin
@smc
5. XMTP publishes the message onchain for anyone to verify the link. You can also use XMTP with only a passkey. Or multiple passkeys, so you can access the same inbox from any app/device.
1 reply
0 recast
0 reaction
boscolo.eth
@boscolo.eth
With this approach is the passkey associated with a specific web domain?
1 reply
0 recast
1 reaction
Saul Carlin
@smc
Yes—we validate passkeys using WebAuthn, with each passkey tied to a specific origin domain
0 reply
0 recast
1 reaction