Passkeys & your account
ZeroSignal has no accounts in the usual sense: your passkey is your account.
Passkeys
When you get started, your device creates a passkey, unlocked by your face, fingerprint, or device PIN. Nothing is registered with us: no email, password, phone number, or personal details.
How ZeroSignal's passkeys are different
A passkey normally does one job: it proves it's you. When you sign in, your device signs a one-time challenge with a private key that never leaves it, and the site learns only that the signature checks out. It gives the app no secret, so it can't derive a wallet.
ZeroSignal's passkeys also derive a wallet, using the WebAuthn PRF extension (PRF = pseudo-random function). PRF lets the app ask your passkey to compute a secret: given the same input, it returns the same long, unguessable value every time. Your passkey manager calculates it and never sends it to us. ZeroSignal uses that value as the seed your wallet keys are derived from — the same keys a recovery phrase encodes.
Because the seed is reproducible and tied to the passkey:
- One passkey, both jobs. It signs you in and regenerates your exact wallet locally, every time, so no seed is ever stored on a server, where it could be stolen or leaked.
- Your account rides with the passkey. Any device your manager syncs the passkey to re-derives the same wallet and balance, with nothing to export or re-link.
- Not every manager can do it. PRF is a newer part of the WebAuthn standard. A manager without it can still sign you in elsewhere, but can't produce your seed here, so only the managers below are supported.
The keys are your wallet
The keys control your wallet, which holds your balance and pays for each message. Only you control it, and you can withdraw at any time. See Funding for how money moves in and out.
Where passkeys live
Your passkey manager (for example iCloud Keychain, Google Password Manager, or 1Password) stores your passkeys and, if it syncs, carries them to your other devices.
Supported passkey managers
ZeroSignal works only with passkey managers that implement PRF. These are validated:
| Manager | Availability |
|---|---|
| 1Password | Works everywhere. |
| iCloud Keychain | On iOS 18 / macOS 15 (Safari 18) and later. |
| Google Password Manager | On Android and Chrome. |
| Windows Hello | Windows. |
If you create a passkey in a manager without PRF support, the app tells you and suggests one of these.
If you lose access to your passkey (for example, you lose the only device it was on), a passkey can't be reissued. Save your recovery phrase so you can restore your account and funds on a new passkey. See Recovery.
Why no email?
An email address, a phone number, or a card on file is a record of you that has to be collected, stored, and protected. A passkey needs none of them.