0:00 Evan Asawaka | Mobile Wallet | KERI Conference 2026
0:04 We have been developing a web
0:07 wallet for KERI essentially just as
0:11 you know more wallets more platforms
0:14 better.
0:15 Initially Sam [Smith] set out
0:18 these goals where we wanted to create a
0:22 fully web native wallet because
0:26 currently the Locksmith application is a
0:28 desktop application.
0:31 Core wallet, we wanted
0:34 it to run entirely in the browser
0:37 with no like server or anything running
0:40 KERIpy on the back end. Which,
0:44 proved to be a challenge in fact.
0:46 Again, we wanted everything to
0:48 happen in the browser, so you can have
0:50 all of your keys locally created and
0:52 stored on your device. Don't have to
0:54 worry about them being stored on some
0:55 server. Then we could just send you
0:58 this application and you would get
1:02 your in-browser wallet
1:05 and we also wanted it to be
1:06 persistent because that would be a
1:08 little bit useless if it wasn't.
1:10 Some challenges: Running Python in a
1:13 WebAssembly was the first big hurdle.
1:18 because currently
1:19 Python is run on CPython which is a
1:23 C-written interpreter.
1:26 The cryptography had to work in the
1:28 browser and this basically meant that
1:31 KERIpy couldn't drag LMDB into the
1:34 web path because LMDB relies on MMAP
1:37 which is not supported in
1:38 WebAssembly.
1:41 And, again, we want this to be
1:43 not a one tab, one reload type of
1:45 wallet. We want it to actually be like a
1:47 production grade wallet that we can
1:48 deploy where you can just take the
1:50 files, serve them yourself, even if you
1:52 wanted to, and be able to have your own
1:54 identifiers that you can manage from a
1:57 browser and not have to download an
1:59 application on specific
2:01 architectures. So getting Python into
2:03 the browser was a interesting
2:06 challenge. We found Piodide which is
2:09 essentially the Python interpreter
2:12 compiled to WebAssembly which allows it
2:14 to run in the browser which
2:18 means that you can then run any Python
2:20 native packages
2:22 and for all the non-Python native
2:24 packages that was a medium challenge
2:27 And then we have PyScript as like
2:28 the browser bridge so you can launch off
2:30 web workers in the browser and it
2:31 interfaces with like the browser
2:33 database so you can have again that
2:34 persistent storage
2:37 which is exactly what I put on my
2:38 slides.
2:41 To do this we had to again go through
2:44 the dependencies of KERIpy get them
2:46 to work in the browser which started
2:48 with pysodium which is
2:51 a python wrapper for Libsodium which is
2:54 a C library. So I had to take Libsodium
2:57 compile it to target WebAssembly and
3:00 then I changed some of the code in
3:03 Pysodium so that it loaded the packaged
3:05 Libsodium that I created, called it pychloride
3:07 because it's like you know
3:09 sodiumchloride… that was Sam's idea.
3:12 I'll give credit where credit due.
3:14 Blake3 is written in Rust. I had to compile this
3:18 WebAssembly and also in an
3:22 attempt to get ready for future proofing
3:24 we took this pyoqs which is an open
3:27 quantum secure safety library for
3:32 key creation and
3:35 made it WebAssembly compatible. So that
3:37 will be coming in the future hopefully
3:40 before quantum computers.
3:44 So in KERIpy itself we had to make it
3:47 WebAssembly safe, which meant creating a
3:50 second database backing which used
3:53 indexedDB which runs in the browser. We
3:55 created 'webdber' instead of 'lmdber'
3:58 which means we're no longer relying on
4:00 the MMAP LMDB
4:02 And we also had to make it so that the
4:04 imports don't randomly import lmdb so
4:08 that it works in the browser. And again,
4:10 this webdber allowed us to create like a
4:13 persistent storage in the browser that
4:15 can survive when you press reload on
4:17 accident and then you lose all your keys
4:19 because that would suck.
4:19 – Can I ask you can I ask you a question?
4:23 So is that
4:26 from a technical perspective? Is
4:28 there an abstract class for that or is
4:30 that not implemented with an
4:32 abstract?
4:33 – Yeah, we created a base spacer
4:36 Or wait not for basers. No,
4:39 for the database we made a second
4:41 class, just for this one.
4:43 – Okay. So it's like what is it
4:44 called, duck typing or something?
4:46 – Yeah, we duck typed it all the same
4:48 functions just with indexedDB.
4:53 – I mean maybe we can come back to this
4:55 but do you mind if I ask a question?
4:56 Go ahead.
4:57 – I'm not familiar with KERIpy so I
4:59 understand none of the words on
5:01 Oh, okay.
5:02 – Except for like just from like a
5:05 more of a web-centric mentality like
5:07 how is it storing data?
5:11 – We're using PyScript's API,
5:14 actually which is one of the reasons why
5:15 we chose to use it. They have a storage
5:17 API that exposes a couple
5:20 useful functions that we can then use to
5:24 store our data persistently.
5:26 – What is WebDBer?
5:28 WebDBer is the ducktyped
5:30 class
5:32 for LMDer and KERIpy. KERIpy is the
5:35 core KERI repository
5:37 that implements
5:40 the protocol.
5:41 – We can talk more after.
5:44 This is like basically the
5:45 nitty-gritty of…
5:46 – This is some of the KERIpy
5:49 internals
5:50 of the library itself. – WebDBer is a
5:53 KERIpy concept.
5:55 – So is HIO.
5:56 – HIO is a separate library. It's an
5:58 asynchronous library that [inaudible]
6:02 Yeah, Sam had to extend HIO actually
6:04 for this to be possible because the
6:07 browser and JavaScript uses
6:09 asynchronous calls and HIO did not
6:13 before and so Sam had to add an
6:15 asynchronous interface into HIO we can
6:17 then use to persist our database.
6:19 – So are all these changes now
6:22 today committed into
6:24 KERIpy?
6:25 – It's on a branch but yeah.
6:30 So this is how it
6:31 works. We have the UI. It's just like a
6:34 very basic JavaScript shell which
6:35 launches our PyScript web workers that
6:39 then call into KERIpy and HIO which
6:40 allow us to run Python in the browser
6:42 and those call out to indexedDB which
6:43 stores it persistently.
6:50 Keys are created in browser… survives.
6:53 No server side key management. Don't
6:55 worry guys, here comes the demo.
6:58 – Before you get the demo guys…
6:59 Shoot.
7:01 – What you guys do about Keeper? How
7:03 are you encrypting keys?
7:06 Made a web keeper
7:07 that interfaces with…
7:10 [inaudible] the encryption before putting it
7:13 in indexedDB.
7:15 Yeah, I think so.
7:18 I could look at the code. I can tell you
7:19 what I did. I don't know. I did a lot
7:22 of this like a couple months ago.
7:26 – So if I wanted to make my own
7:28 database implementation, I would make a
7:31 ducktyped class for another data store.
7:35 – Correct. And then you'd have to
7:39 create like a baser for that class and a
7:41 keeper for that class.
7:43 – Really?
7:43 Probably. Yeah.
7:47 Anyway,
7:49 here's it running in the web.
7:53 So, I just copied Locksmith's UI
7:55 because that felt intuitive.
7:58 Again, this is just being hosted
8:00 locally. Eventually, I think we're going
8:01 to want to deploy like a the KERI
8:04 Foundation will want to deploy like a,
8:05 you know, basic rate-limited version for
8:07 the features that require witness and
8:09 watcher access. So, I have some vaults.
8:12 See, I was testing some vaults out.
8:19 All right, let's create a vault.
8:21 Open the vault.
8:23 We can create local identifiers. I'll
8:26 make one for Evan. Oh, those are emojis.
8:47 [inaudible]
8:51 And I was trying to get this working
8:52 last night. Those might work. I created
8:54 the plug-in page.
8:59 So let's see if it actually works.
9:04 It's spelled incorrectly. That's okay.
9:06 The KERI Foundation plugin. So in
9:08 Locksmith which Phil demoed yesterday
9:11 which they then donated to open source.
9:13 The idea is that because it's open
9:15 source anyone who wants to provide
9:17 witness and watcher infrastructure can
9:19 create like a plugin
9:21 and then you can connect to these
9:24 different providers plugins and get oh
9:27 it worked nice – so it works
9:31 you can get witnesses in the browser.
9:34 – So that plugin is pointed to some
9:37 external infrastructure or…
9:39 – It's pointed to the witness and watcher
9:41 service that healthKERI also so
9:43 graciously donated that is running
9:44 locally on my machine right now.
9:47 – The same thing he demoed yesterday.
9:48 – Yeah, he demoed this yesterday just
9:49 spinning up your own local infrastructure.
9:52 The KERI Foundation is going
9:54 to provide I think like a basic API
9:58 which will allow you to interface with
10:00 our plug-in and then you can grab our
10:02 deployed witnesses and watchers on our
10:05 service. That sound right?
10:07 – Close enough.
10:10 KERI Foundation will have a
10:12 plugin. Other providers will have
10:13 plugins as well that they can provide.
10:15 So we're going to host all of
10:16 our services or we have hosted our
10:19 services on Digital Ocean.
10:20 I'm doing this all running locally
10:22 because it was faster for testing.
10:24 It's working in the browser. The next
10:31 thing (I have a lot to show guys),
10:32 I've also been working on trying to
10:37 get Locksmith
10:40 able to
10:43 have multiple plugins so that we can
10:45 show that, you know, in this open source
10:47 ecosystem, anyone can come in and
10:49 provide their own
10:52 witnesses and watchers as a service.
11:07 Here's the KERI
11:08 Foundation.
11:09 – This one's desktop?
11:10 This is desktop app.
11:23 I'll add my Evan identifier. That's not my name.
11:29 With an emoji. No. What? No emojis here,
11:31 guys. I'm sorry.
11:38 So, this is Locksmith, the open sourced
11:41 version.
11:42 Okay. On the desktop.
11:43 On desktop. This is the desktop app.
11:45 – So, we just doing this for comparison
11:46 with the web one.
11:47 Yeah, the web one is not as far along. I
11:50 have plugins working on the desktop
11:52 one, to demonstrate that you can have
11:54 multiple providers giving you witnesses
11:56 and watchers. So, we have our KERI
11:58 Foundation plugin.
12:03 So we create like our account
12:05 identifier. I think Ryan [Hansen] showed this
12:07 yesterday,
12:10 it's basically just talking to ..,
12:15 – It works a lot faster when it's local.
12:18 [Yes, it] Does work a lot faster when it's local.
12:20 And then I have a second plugin here.
12:23 Well, actually, that wasn't anything
12:24 impressive. So, I can add one of my
12:25 local identifiers in the KERI
12:27 Foundation plugin.
12:30 Then I can grab witnesses from the
12:33 KERI Foundation infrastructure which is
12:35 running locally.
12:38 And I have to provision and register
12:40 them.
12:43 It's like kind of similar to
12:45 healthKERI because they left some shared
12:46 components. So I used a lot of them.
12:49 And then I can grab this. Rotate them in.
13:00 All right. Selected to rotate in the witnesses.
13:08 Okay. So now my local identifier has one
13:11 witness from KERI Foundation
13:14 infrastructure, ideally once it's
13:16 deployed. And then say you as an
13:19 individual or corporation want to also
13:21 provide witness infrastructure. You
13:23 would create a plugin for Locksmith.
13:26 I copied and pasted the folders so they
13:28 look very suspiciously similar.
13:30 – Can I ask a question here?
13:31 Yep.
13:32 – Creating a plugin,
13:36 do I have control over the UI?
13:38 Yeah.
13:40 – If I want to have
13:41 some enterprise
13:44 -whatever- specific thing or any
13:47 service I want, I can integrate
13:49 that as a plugin?
13:50 Totally. And you probably want to
13:52 again because this is fully open source
13:54 to get it like contributed to the… you
13:56 could either contribute it like upstream
13:58 to like the one in the KERI
14:00 Foundation repo or you could just clone
14:01 it and deploy it as your own
14:02 application.
14:06 – Okay. As an
14:10 example, when we first did the plug-in
14:12 concept, we were thinking just SaaS
14:14 providers would put a plug-in here so
14:16 that you'd get watchers and witnesses
14:18 from anyone. But then we found usecases
14:20 for the enterprise credential
14:23 issuance platform that we're building.
14:25 The user interface is a plug into
14:26 Locksmith and it just made sense because
14:28 if you're building any kind of user
14:30 interface that could use KERI, it's a
14:33 great place to put it.
14:35 As long as you're like writing Python and
14:36 PythonScript.
14:40 Or writing Claude [laughter]
14:45 – As long as you can. I don't like it.
14:49 – All right. So, I'm creating my test
14:52 infrastructure account. I'm not going to
14:53 scan this one. And then I can go to my
14:56 identifiers. I can grab the same local
14:59 Evan identifier. You can see and it has
15:01 the witnesses. It doesn't have all the
15:03 the fancy schmancy tooling, that
15:04 healthKERI showed, quite yet.
15:07 Now I have four witness servers
15:11 running for this one. I can add four
15:14 witnesses here.
15:31 Okay. And then I can rotate in these
15:32 witnesses. I can also rotate
15:35 the other witness, but I'm not going to
15:36 do that.
15:42 My authenticator has two seconds left.
15:44 I'm using Google authenticator on my
15:46 phone, so no onePassword copying like
15:48 Phil was showing yesterday for me.
15:57 I missed a digit.
16:02 All right, there you go. They're in. So
16:04 now I have again it took it sequence
16:06 number is two because I rotated in two
16:07 sets of witnesses from two different
16:09 providers and there are five total
16:11 witnesses witnessing my local
16:13 identifier. So, it works. [applause]
16:20 Sweet. And then,
16:22 I've been trying to make it easy
16:26 for anybody who wants to create a plugin,
16:28 to create their own plugin. I was
16:30 thinking, I've had many different
16:32 approaches as to how I best thought
16:34 this possible. So, my newest approach
16:36 was to create just like a templating
16:38 folder basically that would kind of
16:42 just give you like a one UI page that
16:44 you could use as a template so that it
16:47 would Claude could actually be smart
16:48 when he does it. Yeah.
16:50 – Sam introduced the concept of
16:55 what was it called? Observer registrar. I
16:58 still need to figure out what all
17:00 that is. But so similarly here the
17:05 plugin you could I suppose manage
17:07 those kinds of things as well?
17:10 – Eventually, yes. I think the observer
17:12 and the registrar stuff.
17:14 – Are they just extensions of witnesses
17:15 and watchers? I guess I don't know…
17:18 – They monitor a different thing.
17:20 – Those monitor your
17:22 credentials. – So, but if I wanted to make
17:25 a plugin for that, I could mention…
17:30 – Probably.
17:31 – Yeah, I don't we haven't gone down that
17:32 road yet. So…
17:35 – Wait, sorry, what was the question?
17:37 If the plugin could be used for
17:40 helping implement the registrars and
17:43 observers.
17:43 – Yeah, absolutely. I mean, it would
17:45 just be the user interface into
17:47 those. So if you stand up a SaaS platform
17:49 that has APIs to allow you to stand up
17:51 registrars and observers that absolutely
17:53 you could add it to your interface here
17:55 in your plugin to reserve those for you.
18:00 – Which is similar to the witness and watchers
18:01 you have to services out there. – Exactly.
18:04 – It's just UI to connect manage
18:07 the relationship.
18:08 – That's exactly right.
18:10 – Yep. Sweet.
18:15 – Okay that was most of the things I
18:16 wanted to show. I mean this is cool
18:18 because it shows the how we are, KERI
18:21 Foundation. We're open source accepting
18:22 multiple providers if possible.
18:25 – What's the status of the
18:27 mobile because we did web and desktop…
18:31 – The mobile is, Jay do you want to take
18:33 this one?
18:34 – I'm sorry?
18:34 – How's the status of
18:36 the mobile? Jay has been working on
18:37 mobile
18:38 – It will be deployed sometime in the near future
18:40 as soon as it gets the account info
18:44 from Sam for the iOS and Android stores.
18:47 – It's the same code though that runs the
18:48 web wallet.
18:50 – It's the same code.
18:51 – So it's just being deployed.
18:52 – It the iOS and Android code are just in
18:55 wrappers that run almost like a pseudo
18:57 browser and we just deploy pretty much
19:00 the same code onto it.
19:02 – So it's the web essentially version.
19:05 – And, it's pretty much
19:07 it's just the web app.
19:09 – So it's doing all the same stuff you said,
19:11 the Wasm and all the WebDBers
19:16 mobile.
19:17 – Yes.
19:19 – Is there a mailbox as part of this?
19:22 – No, not yet.
19:25 Probably.
19:27 – So on either the phone, you know, or
19:29 or a browser page, right? Let's
19:32 say I'm an issuer,
19:35 issue you a credential offer or
19:38 friend.
19:39 And your phone is off or your browser
19:42 is not on at the moment.
19:45 Will there be a mailbox in
19:47 between to pick it up?
19:50 – I would assume it would go
19:52 to your witnesses or something.
19:53 – [Phil Feairheller: ] So that's a common misconception.
19:55 So when we originally deployed
19:57 witnesses, we did make mailboxes a part
19:59 of the witness deployment simply because
20:01 we were moving very fast and had nowhere
20:02 else to hang them. Okay,
20:03 we didn't want to create a whole new
20:05 service at the time. So, we have since
20:07 moved away from that. HealthKERI does
20:09 provide mailboxes as a bespoke thing you
20:11 can reserve and I was going to demo that
20:14 yesterday but ran out of time and then
20:15 and then you just launch a Locksmith
20:18 turn it on say activate this mailbox and
20:20 now you can get messages on it and if
20:22 you miss any messages they're stored
20:23 forward so they sit here.
20:24 – Are those on your platform like you're
20:26 storing?
20:26 – Those are platform. So then …
20:27 – It's a very simple small service. It's
20:29 it's basically if you were to look at
20:30 the code inside of KERIpy you just pull out
20:31 the mailbox stuff. Yeah, because there
20:33 is mailbox up in the right
20:34 – That could be hosted anywhere.
20:35 – Absolutely. It's just like any other resource.
20:37 – Yep.
20:38 Again, we got this code
20:41 recently from HealthKERI. So,
20:43 – Awesome work.
20:44 There's a long
20:46 list of features we're aiming to
20:48 add. So,
20:49 just hit the ones that were priorities
20:51 for the conference first.
20:53 I mean, again, you can always go
20:55 into the open source repos, create
20:56 issues for features you want to see, and
20:58 we can address those as they come in
21:00 as well.
21:03 – Or fork and build.
21:05 Yeah
21:05 - Absolutely.
21:08 – [Karla Mckenna: ] did I understand you correctly
21:10 that you said five witnesses
21:13 were monitoring? Well, five witnesses
21:15 were associated with your identifier? [Yes]
21:17 Okay. That's the same amount of
21:19 witnesses that GLEIF maintains in the
21:22 infrastructure and the same that we
21:25 require from QVIs to contribute to with
21:28 only a small overlap for shared
21:31 resources in effect. Should we be
21:36 also perhaps providing guidance to
21:39 wallet holders? Credential holders?
21:44 Guidance as to how many witnesses
21:47 they should be addressing?
21:48 – True. Well. If there's
21:50 particular requirements for it, then
21:51 yeah, absolutely.
21:52 – Sam's recommendation was
21:54 – Was five?
21:55 – It was either one or four
21:58 cuz he says when you
22:00 have three or four as your signing
22:02 threshold for witnesses you can't be
22:04 eclipsed and then if you have one well
22:06 it's less secure because one could
22:08 be compromised.
22:11 – [Phil Feairheller:] I think a mission of the KERI
22:13 Foundation is going to also be to
22:15 provide
22:17 documentation with recommendations and I
22:20 would guess it will grow to span
22:22 ecosystems so like if you
22:25 going to become a QVI
22:26 here's what you will need to consider
22:28 here are the recommendations
22:29 you're going to have to follow if you're
22:31 going to be doing this in healthcare,
22:32 or use other things. I suspect that
22:34 KERI Foundation will be a central
22:36 location for that stuff.
22:37 – [Karla Mckenna: ] Well, I've already got those kinds of
22:40 requirements in the ecosystem governance
22:42 framework for QVIs.
22:44 Because obviously we issue credentials
22:46 to the QVIs.
22:47 But I could put in the credential
22:49 frameworks for the legal entity one, the
22:53 QVRs and OORs, a recommendation of
22:57 how many witnesses should be
23:00 associated with.
23:02 That would be the right place to put.
23:05 - All right. Thank you.
23:10 – Anybody have other questions, things you
23:11 want to say, comments, concerns? Yeah.
23:15 – I just have a general question. I'm
23:17 not very familiar with KERIpy and I'm
23:20 I'm doing my own like very lightweight
23:22 kind of educational JavaScript
23:24 implementation and as soon as
23:26 you try something like that you
23:27 notice how extensive the spec is. So
23:30 it's like one step five.
23:35 So you're doing this in the web
23:37 but you're not reimplementing with
23:39 JavaScript you're wrapping KERIpy. So
23:42 you basically get all the… like how
23:45 much of the spec does KERIpy
23:47 implement
23:48 like pretty much all of it or?
23:51 – [Phil Feairheller: ] So KERIpy as it stands right now in…
23:56 there's three branches 1.2x and 1.3x
24:00 those implement full KERI of KERI and
24:03 ACDC of 1.0
24:05 and KERI has since evolved
24:08 significantly into 2.0. What these guys
24:11 are… well so one of their missions
24:14 besides just put out these tools is to
24:17 take KERIpy and completely upgrade it
24:19 to 2.0. That is still work in progress
24:22 and it is the current main branch on
24:26 KERIpy represents that work.
24:28 So it will of course eventually
24:32 implement certainly the entire KERI
24:34 spec and I would guess the first
24:38 milestone is as much of the ACDC spec
24:40 as is needed to satisfy SEDI.
24:45 So I'm suspecting that's probably Sam's
24:47 big goal for getting KERIpy to where
24:50 it needs to be.
24:51 – But it seems like with this strategy
24:53 whatever the feature completeness is of
24:56 KERIpy you kind of get that for free.
24:58 You get that from this
24:59 except
25:01 is there a distinct UI in the
25:03 browser like do you have like could you
25:06 have a situation where the desktop is
25:08 ahead of the browser because the browser
25:10 hasn't written the HTML templates to…
25:12 – Yes. – Okay.
25:13 – [Feairheller: ] Yep. Those are
25:16 separate UI implementations.
25:18 That could come slightly opposite,
25:21 and I would suspect they'll eventually
25:22 grow to be somewhat separate simply
25:25 because of the paradigm of running
25:26 something in the web and mobile versus a
25:28 desktop app.
25:30 Just like if you look at one password
25:32 looks similar but there's quite a bit of
25:33 difference functionality between their
25:35 plugin and the desktop app.
25:39 – So the Locksmith desktop app is that
25:43 also Python everything?
25:46 – Yes. – And what's the
25:48 PySide6?
25:49 – PySide6.
25:50 Yeah, it's pretty good to work with.
25:58 – And that works cross platform.
26:01 So, Mac and everything.
26:04 – Yeah.
26:05 – Mac, Windows and Linux [inaudible].
26:14 [applause]