@ldgr/wallet-core
v0.3.0
Published
Browser-safe self-custody primitives shared by LDGR wallet surfaces.
Readme
@ldgr/wallet-core
Browser-safe self-custody primitives shared by LDGR wallet surfaces.
- Supports metadata-only WebAuthn PRF passkey vaults, local recovery-key vaults without protection, and optional PBKDF2-SHA-256/AES-GCM passphrase protection.
- Passkey vaults persist only the credential ID, RP ID, PRF salt, derivation version, and public key. Private signing material is derived again after user verification.
- Keeps the encrypted vault independent from a ledger, so the same key can derive mainnet and testnet addresses.
- Builds canonical signed transfer submissions with exact decimal amounts.
- Derives reusable silent-payment codes, scans bounded public feed pages locally, and reconstructs one-time BIP-340 spend signers only while recovery material is unlocked.
The package does not choose persistence. Applications provide a WalletVaultStore; recovery material must never be logged or sent to LDGR, and unlocked signing sessions remain in memory. Newly created passkeys use discoverable credentials so compatible synced passkeys can be loaded on another device. Older Utilities passkeys still require their recovery key when their credential metadata is unavailable.
Silent-payment applications persist only the raw sequence checkpoint and
SilentPaymentReceipt descriptors. Those descriptors contain no private key;
createSilentPaymentSigner re-derives the matching spend key after unlock.
scanSilentPaymentRecords reports malformed feed rows through
invalidRecords, keeps valid matches, and advances to the Worker's bounded raw
checkpoint. First-party wallets do not expose this foundation until
multi-address balance and spending UX is complete.
