Mobile Wallet - Evan Asawaka

KERICONF26 Day 2 · 40:15

0:00 Evan Asawaka | Mobile Wallet | KERI Conference 2026

0:04 We have been developing a web

0:07 wallet for KERI essentially just as

0:11 you know more wallets more platforms

0:14 better.

0:15 Initially Sam [Smith] set out

0:18 these goals where we wanted to create a

0:22 fully web native wallet because

0:26 currently the Locksmith application is a

0:28 desktop application.

0:31 Core wallet, we wanted

0:34 it to run entirely in the browser

0:37 with no like server or anything running

0:40 KERIpy on the back end. Which,

0:44 proved to be a challenge in fact.

0:46 Again, we wanted everything to

0:48 happen in the browser, so you can have

0:50 all of your keys locally created and

0:52 stored on your device. Don't have to

0:54 worry about them being stored on some

0:55 server. Then we could just send you

0:58 this application and you would get

1:02 your in-browser wallet

1:05 and we also wanted it to be

1:06 persistent because that would be a

1:08 little bit useless if it wasn't.

1:10 Some challenges: Running Python in a

1:13 WebAssembly was the first big hurdle.

1:18 because currently

1:19 Python is run on CPython which is a

1:23 C-written interpreter.

1:26 The cryptography had to work in the

1:28 browser and this basically meant that

1:31 KERIpy couldn't drag LMDB into the

1:34 web path because LMDB relies on MMAP

1:37 which is not supported in

1:38 WebAssembly.

1:41 And, again, we want this to be

1:43 not a one tab, one reload type of

1:45 wallet. We want it to actually be like a

1:47 production grade wallet that we can

1:48 deploy where you can just take the

1:50 files, serve them yourself, even if you

1:52 wanted to, and be able to have your own

1:54 identifiers that you can manage from a

1:57 browser and not have to download an

1:59 application on specific

2:01 architectures. So getting Python into

2:03 the browser was a interesting

2:06 challenge. We found Piodide which is

2:09 essentially the Python interpreter

2:12 compiled to WebAssembly which allows it

2:14 to run in the browser which

2:18 means that you can then run any Python

2:20 native packages

2:22 and for all the non-Python native

2:24 packages that was a medium challenge

2:27 And then we have PyScript as like

2:28 the browser bridge so you can launch off

2:30 web workers in the browser and it

2:31 interfaces with like the browser

2:33 database so you can have again that

2:34 persistent storage

2:37 which is exactly what I put on my

2:38 slides.

2:41 To do this we had to again go through

2:44 the dependencies of KERIpy get them

2:46 to work in the browser which started

2:48 with pysodium which is

2:51 a python wrapper for Libsodium which is

2:54 a C library. So I had to take Libsodium

2:57 compile it to target WebAssembly and

3:00 then I changed some of the code in

3:03 Pysodium so that it loaded the packaged

3:05 Libsodium that I created, called it pychloride

3:07 because it's like you know

3:09 sodiumchloride… that was Sam's idea.

3:12 I'll give credit where credit due.

3:14 Blake3 is written in Rust. I had to compile this

3:18 WebAssembly and also in an

3:22 attempt to get ready for future proofing

3:24 we took this pyoqs which is an open

3:27 quantum secure safety library for

3:32 key creation and

3:35 made it WebAssembly compatible. So that

3:37 will be coming in the future hopefully

3:40 before quantum computers.

3:44 So in KERIpy itself we had to make it

3:47 WebAssembly safe, which meant creating a

3:50 second database backing which used

3:53 indexedDB which runs in the browser. We

3:55 created 'webdber' instead of 'lmdber'

3:58 which means we're no longer relying on

4:00 the MMAP LMDB

4:02 And we also had to make it so that the

4:04 imports don't randomly import lmdb so

4:08 that it works in the browser. And again,

4:10 this webdber allowed us to create like a

4:13 persistent storage in the browser that

4:15 can survive when you press reload on

4:17 accident and then you lose all your keys

4:19 because that would suck.

4:19 – Can I ask you can I ask you a question?

4:23 So is that

4:26 from a technical perspective? Is

4:28 there an abstract class for that or is

4:30 that not implemented with an

4:32 abstract?

4:33 – Yeah, we created a base spacer

4:36 Or wait not for basers. No,

4:39 for the database we made a second

4:41 class, just for this one.

4:43 – Okay. So it's like what is it

4:44 called, duck typing or something?

4:46 – Yeah, we duck typed it all the same

4:48 functions just with indexedDB.

4:53 – I mean maybe we can come back to this

4:55 but do you mind if I ask a question?

4:56 Go ahead.

4:57 – I'm not familiar with KERIpy so I

4:59 understand none of the words on

5:01 Oh, okay.

5:02 – Except for like just from like a

5:05 more of a web-centric mentality like

5:07 how is it storing data?

5:11 – We're using PyScript's API,

5:14 actually which is one of the reasons why

5:15 we chose to use it. They have a storage

5:17 API that exposes a couple

5:20 useful functions that we can then use to

5:24 store our data persistently.

5:26 – What is WebDBer?

5:28 WebDBer is the ducktyped

5:30 class

5:32 for LMDer and KERIpy. KERIpy is the

5:35 core KERI repository

5:37 that implements

5:40 the protocol.

5:41 – We can talk more after.

5:44 This is like basically the

5:45 nitty-gritty of…

5:46 – This is some of the KERIpy

5:49 internals

5:50 of the library itself. – WebDBer is a

5:53 KERIpy concept.

5:55 – So is HIO.

5:56 – HIO is a separate library. It's an

5:58 asynchronous library that [inaudible]

6:02 Yeah, Sam had to extend HIO actually

6:04 for this to be possible because the

6:07 browser and JavaScript uses

6:09 asynchronous calls and HIO did not

6:13 before and so Sam had to add an

6:15 asynchronous interface into HIO we can

6:17 then use to persist our database.

6:19 – So are all these changes now

6:22 today committed into

6:24 KERIpy?

6:25 – It's on a branch but yeah.

6:30 So this is how it

6:31 works. We have the UI. It's just like a

6:34 very basic JavaScript shell which

6:35 launches our PyScript web workers that

6:39 then call into KERIpy and HIO which

6:40 allow us to run Python in the browser

6:42 and those call out to indexedDB which

6:43 stores it persistently.

6:50 Keys are created in browser… survives.

6:53 No server side key management. Don't

6:55 worry guys, here comes the demo.

6:58 – Before you get the demo guys…

6:59 Shoot.

7:01 – What you guys do about Keeper? How

7:03 are you encrypting keys?

7:06 Made a web keeper

7:07 that interfaces with…

7:10 [inaudible] the encryption before putting it

7:13 in indexedDB.

7:15 Yeah, I think so.

7:18 I could look at the code. I can tell you

7:19 what I did. I don't know. I did a lot

7:22 of this like a couple months ago.

7:26 – So if I wanted to make my own

7:28 database implementation, I would make a

7:31 ducktyped class for another data store.

7:35 – Correct. And then you'd have to

7:39 create like a baser for that class and a

7:41 keeper for that class.

7:43 – Really?

7:43 Probably. Yeah.

7:47 Anyway,

7:49 here's it running in the web.

7:53 So, I just copied Locksmith's UI

7:55 because that felt intuitive.

7:58 Again, this is just being hosted

8:00 locally. Eventually, I think we're going

8:01 to want to deploy like a the KERI

8:04 Foundation will want to deploy like a,

8:05 you know, basic rate-limited version for

8:07 the features that require witness and

8:09 watcher access. So, I have some vaults.

8:12 See, I was testing some vaults out.

8:19 All right, let's create a vault.

8:21 Open the vault.

8:23 We can create local identifiers. I'll

8:26 make one for Evan. Oh, those are emojis.

8:47 [inaudible]

8:51 And I was trying to get this working

8:52 last night. Those might work. I created

8:54 the plug-in page.

8:59 So let's see if it actually works.

9:04 It's spelled incorrectly. That's okay.

9:06 The KERI Foundation plugin. So in

9:08 Locksmith which Phil demoed yesterday

9:11 which they then donated to open source.

9:13 The idea is that because it's open

9:15 source anyone who wants to provide

9:17 witness and watcher infrastructure can

9:19 create like a plugin

9:21 and then you can connect to these

9:24 different providers plugins and get oh

9:27 it worked nice – so it works

9:31 you can get witnesses in the browser.

9:34 – So that plugin is pointed to some

9:37 external infrastructure or…

9:39 – It's pointed to the witness and watcher

9:41 service that healthKERI also so

9:43 graciously donated that is running

9:44 locally on my machine right now.

9:47 – The same thing he demoed yesterday.

9:48 – Yeah, he demoed this yesterday just

9:49 spinning up your own local infrastructure.

9:52 The KERI Foundation is going

9:54 to provide I think like a basic API

9:58 which will allow you to interface with

10:00 our plug-in and then you can grab our

10:02 deployed witnesses and watchers on our

10:05 service. That sound right?

10:07 – Close enough.

10:10 KERI Foundation will have a

10:12 plugin. Other providers will have

10:13 plugins as well that they can provide.

10:15 So we're going to host all of

10:16 our services or we have hosted our

10:19 services on Digital Ocean.

10:20 I'm doing this all running locally

10:22 because it was faster for testing.

10:24 It's working in the browser. The next

10:31 thing (I have a lot to show guys),

10:32 I've also been working on trying to

10:37 get Locksmith

10:40 able to

10:43 have multiple plugins so that we can

10:45 show that, you know, in this open source

10:47 ecosystem, anyone can come in and

10:49 provide their own

10:52 witnesses and watchers as a service.

11:07 Here's the KERI

11:08 Foundation.

11:09 – This one's desktop?

11:10 This is desktop app.

11:23 I'll add my Evan identifier. That's not my name.

11:29 With an emoji. No. What? No emojis here,

11:31 guys. I'm sorry.

11:38 So, this is Locksmith, the open sourced

11:41 version.

11:42 Okay. On the desktop.

11:43 On desktop. This is the desktop app.

11:45 – So, we just doing this for comparison

11:46 with the web one.

11:47 Yeah, the web one is not as far along. I

11:50 have plugins working on the desktop

11:52 one, to demonstrate that you can have

11:54 multiple providers giving you witnesses

11:56 and watchers. So, we have our KERI

11:58 Foundation plugin.

12:03 So we create like our account

12:05 identifier. I think Ryan [Hansen] showed this

12:07 yesterday,

12:10 it's basically just talking to ..,

12:15 – It works a lot faster when it's local.

12:18 [Yes, it] Does work a lot faster when it's local.

12:20 And then I have a second plugin here.

12:23 Well, actually, that wasn't anything

12:24 impressive. So, I can add one of my

12:25 local identifiers in the KERI

12:27 Foundation plugin.

12:30 Then I can grab witnesses from the

12:33 KERI Foundation infrastructure which is

12:35 running locally.

12:38 And I have to provision and register

12:40 them.

12:43 It's like kind of similar to

12:45 healthKERI because they left some shared

12:46 components. So I used a lot of them.

12:49 And then I can grab this. Rotate them in.

13:00 All right. Selected to rotate in the witnesses.

13:08 Okay. So now my local identifier has one

13:11 witness from KERI Foundation

13:14 infrastructure, ideally once it's

13:16 deployed. And then say you as an

13:19 individual or corporation want to also

13:21 provide witness infrastructure. You

13:23 would create a plugin for Locksmith.

13:26 I copied and pasted the folders so they

13:28 look very suspiciously similar.

13:30 – Can I ask a question here?

13:31 Yep.

13:32 – Creating a plugin,

13:36 do I have control over the UI?

13:38 Yeah.

13:40 – If I want to have

13:41 some enterprise

13:44 -whatever- specific thing or any

13:47 service I want, I can integrate

13:49 that as a plugin?

13:50 Totally. And you probably want to

13:52 again because this is fully open source

13:54 to get it like contributed to the… you

13:56 could either contribute it like upstream

13:58 to like the one in the KERI

14:00 Foundation repo or you could just clone

14:01 it and deploy it as your own

14:02 application.

14:06 – Okay. As an

14:10 example, when we first did the plug-in

14:12 concept, we were thinking just SaaS

14:14 providers would put a plug-in here so

14:16 that you'd get watchers and witnesses

14:18 from anyone. But then we found usecases

14:20 for the enterprise credential

14:23 issuance platform that we're building.

14:25 The user interface is a plug into

14:26 Locksmith and it just made sense because

14:28 if you're building any kind of user

14:30 interface that could use KERI, it's a

14:33 great place to put it.

14:35 As long as you're like writing Python and

14:36 PythonScript.

14:40 Or writing Claude [laughter]

14:45 – As long as you can. I don't like it.

14:49 – All right. So, I'm creating my test

14:52 infrastructure account. I'm not going to

14:53 scan this one. And then I can go to my

14:56 identifiers. I can grab the same local

14:59 Evan identifier. You can see and it has

15:01 the witnesses. It doesn't have all the

15:03 the fancy schmancy tooling, that

15:04 healthKERI showed, quite yet.

15:07 Now I have four witness servers

15:11 running for this one. I can add four

15:14 witnesses here.

15:31 Okay. And then I can rotate in these

15:32 witnesses. I can also rotate

15:35 the other witness, but I'm not going to

15:36 do that.

15:42 My authenticator has two seconds left.

15:44 I'm using Google authenticator on my

15:46 phone, so no onePassword copying like

15:48 Phil was showing yesterday for me.

15:57 I missed a digit.

16:02 All right, there you go. They're in. So

16:04 now I have again it took it sequence

16:06 number is two because I rotated in two

16:07 sets of witnesses from two different

16:09 providers and there are five total

16:11 witnesses witnessing my local

16:13 identifier. So, it works. [applause]

16:20 Sweet. And then,

16:22 I've been trying to make it easy

16:26 for anybody who wants to create a plugin,

16:28 to create their own plugin. I was

16:30 thinking, I've had many different

16:32 approaches as to how I best thought

16:34 this possible. So, my newest approach

16:36 was to create just like a templating

16:38 folder basically that would kind of

16:42 just give you like a one UI page that

16:44 you could use as a template so that it

16:47 would Claude could actually be smart

16:48 when he does it. Yeah.

16:50 – Sam introduced the concept of

16:55 what was it called? Observer registrar. I

16:58 still need to figure out what all

17:00 that is. But so similarly here the

17:05 plugin you could I suppose manage

17:07 those kinds of things as well?

17:10 – Eventually, yes. I think the observer

17:12 and the registrar stuff.

17:14 – Are they just extensions of witnesses

17:15 and watchers? I guess I don't know…

17:18 – They monitor a different thing.

17:20 – Those monitor your

17:22 credentials. – So, but if I wanted to make

17:25 a plugin for that, I could mention…

17:30 – Probably.

17:31 – Yeah, I don't we haven't gone down that

17:32 road yet. So…

17:35 – Wait, sorry, what was the question?

17:37 If the plugin could be used for

17:40 helping implement the registrars and

17:43 observers.

17:43 – Yeah, absolutely. I mean, it would

17:45 just be the user interface into

17:47 those. So if you stand up a SaaS platform

17:49 that has APIs to allow you to stand up

17:51 registrars and observers that absolutely

17:53 you could add it to your interface here

17:55 in your plugin to reserve those for you.

18:00 – Which is similar to the witness and watchers

18:01 you have to services out there. – Exactly.

18:04 – It's just UI to connect manage

18:07 the relationship.

18:08 – That's exactly right.

18:10 – Yep. Sweet.

18:15 – Okay that was most of the things I

18:16 wanted to show. I mean this is cool

18:18 because it shows the how we are, KERI

18:21 Foundation. We're open source accepting

18:22 multiple providers if possible.

18:25 – What's the status of the

18:27 mobile because we did web and desktop…

18:31 – The mobile is, Jay do you want to take

18:33 this one?

18:34 – I'm sorry?

18:34 – How's the status of

18:36 the mobile? Jay has been working on

18:37 mobile

18:38 – It will be deployed sometime in the near future

18:40 as soon as it gets the account info

18:44 from Sam for the iOS and Android stores.

18:47 – It's the same code though that runs the

18:48 web wallet.

18:50 – It's the same code.

18:51 – So it's just being deployed.

18:52 – It the iOS and Android code are just in

18:55 wrappers that run almost like a pseudo

18:57 browser and we just deploy pretty much

19:00 the same code onto it.

19:02 – So it's the web essentially version.

19:05 – And, it's pretty much

19:07 it's just the web app.

19:09 – So it's doing all the same stuff you said,

19:11 the Wasm and all the WebDBers

19:16 mobile.

19:17 – Yes.

19:19 – Is there a mailbox as part of this?

19:22 – No, not yet.

19:25 Probably.

19:27 – So on either the phone, you know, or

19:29 or a browser page, right? Let's

19:32 say I'm an issuer,

19:35 issue you a credential offer or

19:38 friend.

19:39 And your phone is off or your browser

19:42 is not on at the moment.

19:45 Will there be a mailbox in

19:47 between to pick it up?

19:50 – I would assume it would go

19:52 to your witnesses or something.

19:53 – [Phil Feairheller: ] So that's a common misconception.

19:55 So when we originally deployed

19:57 witnesses, we did make mailboxes a part

19:59 of the witness deployment simply because

20:01 we were moving very fast and had nowhere

20:02 else to hang them. Okay,

20:03 we didn't want to create a whole new

20:05 service at the time. So, we have since

20:07 moved away from that. HealthKERI does

20:09 provide mailboxes as a bespoke thing you

20:11 can reserve and I was going to demo that

20:14 yesterday but ran out of time and then

20:15 and then you just launch a Locksmith

20:18 turn it on say activate this mailbox and

20:20 now you can get messages on it and if

20:22 you miss any messages they're stored

20:23 forward so they sit here.

20:24 – Are those on your platform like you're

20:26 storing?

20:26 – Those are platform. So then …

20:27 – It's a very simple small service. It's

20:29 it's basically if you were to look at

20:30 the code inside of KERIpy you just pull out

20:31 the mailbox stuff. Yeah, because there

20:33 is mailbox up in the right

20:34 – That could be hosted anywhere.

20:35 – Absolutely. It's just like any other resource.

20:37 – Yep.

20:38 Again, we got this code

20:41 recently from HealthKERI. So,

20:43 – Awesome work.

20:44 There's a long

20:46 list of features we're aiming to

20:48 add. So,

20:49 just hit the ones that were priorities

20:51 for the conference first.

20:53 I mean, again, you can always go

20:55 into the open source repos, create

20:56 issues for features you want to see, and

20:58 we can address those as they come in

21:00 as well.

21:03 – Or fork and build.

21:05 Yeah

21:05 - Absolutely.

21:08 – [Karla Mckenna: ] did I understand you correctly

21:10 that you said five witnesses

21:13 were monitoring? Well, five witnesses

21:15 were associated with your identifier? [Yes]

21:17 Okay. That's the same amount of

21:19 witnesses that GLEIF maintains in the

21:22 infrastructure and the same that we

21:25 require from QVIs to contribute to with

21:28 only a small overlap for shared

21:31 resources in effect. Should we be

21:36 also perhaps providing guidance to

21:39 wallet holders? Credential holders?

21:44 Guidance as to how many witnesses

21:47 they should be addressing?

21:48 – True. Well. If there's

21:50 particular requirements for it, then

21:51 yeah, absolutely.

21:52 – Sam's recommendation was

21:54 – Was five?

21:55 – It was either one or four

21:58 cuz he says when you

22:00 have three or four as your signing

22:02 threshold for witnesses you can't be

22:04 eclipsed and then if you have one well

22:06 it's less secure because one could

22:08 be compromised.

22:11 – [Phil Feairheller:] I think a mission of the KERI

22:13 Foundation is going to also be to

22:15 provide

22:17 documentation with recommendations and I

22:20 would guess it will grow to span

22:22 ecosystems so like if you

22:25 going to become a QVI

22:26 here's what you will need to consider

22:28 here are the recommendations

22:29 you're going to have to follow if you're

22:31 going to be doing this in healthcare,

22:32 or use other things. I suspect that

22:34 KERI Foundation will be a central

22:36 location for that stuff.

22:37 – [Karla Mckenna: ] Well, I've already got those kinds of

22:40 requirements in the ecosystem governance

22:42 framework for QVIs.

22:44 Because obviously we issue credentials

22:46 to the QVIs.

22:47 But I could put in the credential

22:49 frameworks for the legal entity one, the

22:53 QVRs and OORs, a recommendation of

22:57 how many witnesses should be

23:00 associated with.

23:02 That would be the right place to put.

23:05 - All right. Thank you.

23:10 – Anybody have other questions, things you

23:11 want to say, comments, concerns? Yeah.

23:15 – I just have a general question. I'm

23:17 not very familiar with KERIpy and I'm

23:20 I'm doing my own like very lightweight

23:22 kind of educational JavaScript

23:24 implementation and as soon as

23:26 you try something like that you

23:27 notice how extensive the spec is. So

23:30 it's like one step five.

23:35 So you're doing this in the web

23:37 but you're not reimplementing with

23:39 JavaScript you're wrapping KERIpy. So

23:42 you basically get all the… like how

23:45 much of the spec does KERIpy

23:47 implement

23:48 like pretty much all of it or?

23:51 – [Phil Feairheller: ] So KERIpy as it stands right now in…

23:56 there's three branches 1.2x and 1.3x

24:00 those implement full KERI of KERI and

24:03 ACDC of 1.0

24:05 and KERI has since evolved

24:08 significantly into 2.0. What these guys

24:11 are… well so one of their missions

24:14 besides just put out these tools is to

24:17 take KERIpy and completely upgrade it

24:19 to 2.0. That is still work in progress

24:22 and it is the current main branch on

24:26 KERIpy represents that work.

24:28 So it will of course eventually

24:32 implement certainly the entire KERI

24:34 spec and I would guess the first

24:38 milestone is as much of the ACDC spec

24:40 as is needed to satisfy SEDI.

24:45 So I'm suspecting that's probably Sam's

24:47 big goal for getting KERIpy to where

24:50 it needs to be.

24:51 – But it seems like with this strategy

24:53 whatever the feature completeness is of

24:56 KERIpy you kind of get that for free.

24:58 You get that from this

24:59 except

25:01 is there a distinct UI in the

25:03 browser like do you have like could you

25:06 have a situation where the desktop is

25:08 ahead of the browser because the browser

25:10 hasn't written the HTML templates to…

25:12 – Yes. – Okay.

25:13 – [Feairheller: ] Yep. Those are

25:16 separate UI implementations.

25:18 That could come slightly opposite,

25:21 and I would suspect they'll eventually

25:22 grow to be somewhat separate simply

25:25 because of the paradigm of running

25:26 something in the web and mobile versus a

25:28 desktop app.

25:30 Just like if you look at one password

25:32 looks similar but there's quite a bit of

25:33 difference functionality between their

25:35 plugin and the desktop app.

25:39 – So the Locksmith desktop app is that

25:43 also Python everything?

25:46 – Yes. – And what's the

25:48 PySide6?

25:49 – PySide6.

25:50 Yeah, it's pretty good to work with.

25:58 – And that works cross platform.

26:01 So, Mac and everything.

26:04 – Yeah.

26:05 – Mac, Windows and Linux [inaudible].

26:14 [applause]