Made on this device · held by nobody else

One key.
Four chains.
Nobody’s but yours.

I wanted to give one person a key that would open a great deal and that nobody could ever take away. It turned out to cost nothing to give it to everyone. So here it is.

Touch the sensor and thirty-two bytes come into existence in this browser. They become four addresses, on Sui, Ethereum, Solana and Bitcoin, that can take money from the first second. The secret behind them never leaves the machine in your hand. We cannot hand it over, freeze it or lose it. We cannot get it back for you either. That trade is the whole of it.

One key · 4 chain keys · 6 wallets · 24 words

  • Sui
  • Ethereum
  • Solana
  • Bitcoin
  • SUI
  • ONE
  • ETH
  • FET
  • SOL
  • BTC

Four keys, six wallets: ONE is a coin at your Sui address and FET an ERC-20 at your Ethereum one, so neither needs a key of its own.

The offer

A key is a gift, and this one is for everyone

Most things you are given online, someone else still holds. This is not one of those. Here is what the gift is, and what it is not.

Yours in seconds

Tap once and a real address exists. Not a demo, not a placeholder. It can take a payment the second it appears, and that is exactly why the next thing you do is write the key down. An address is worth nothing without the key that opens it.

Free to hold. Free to get back.

No fee to keep a key, no fee to restore one, and neither sits behind an account. That is the only sense in which any of this is free. Moving money still costs gas, and the sponsored path takes 1% on top of it.

We never see it

The secret is made in your browser and never leaves it. We cannot pass it to anyone, cannot freeze it, and cannot restore it for you. Those are not three promises. They are one fact read from three sides.

Sign-in, and who you are

One secret answers both: the address that takes money, and the identity that proves you are the same person tomorrow. The separate sign-in key is wired in your wallet. Once your key is kept somewhere that lasts you can enrol it and sign in with it, and it holds no money. The sign-in page itself still uses the funded address, so this is reachable, not yet universal.

Open source standard paths: built, not yet in production

A gift that only opens at one.ie still has our name on it. So new keys derive by the standard paths any wallet understands. That is built and lands with the next release. The offline recovery tool is out: words in, addresses and a signer out, on any machine, with no server of ours in the path. How to recover a key.

You cannot be locked out

Two roots, and paper is one of them. There is no support queue that can restore you, and none that can lock you out either. The same property, both directions.

Authority

The key is not only what you spend. It is what you may decide.

ONE answers every question about authority with one rule: walk up the tree and take the first answer. A parent decides for its children. Siblings cannot reach each other. The key makes that rule physical, and Sui is where it stops needing a server to be true.

In ONE

  • An actor is a person or an agent. Same verbs, same authority.
  • A parent group contains a child, and ownership inherits down.
  • controls(actor, group) is the walk up, answered by the first ancestor.
  • A delegation is scoped, and it does not nest.
  • Revoke ends the grant. Nothing is clawed back.

With the key, on Sui

  • The identity derives from the same secret as the address, so a key is provably its actor.
  • The parent's secret derives the child's. The child cannot derive back. The arrow only points down.
  • The parent's address owns the child's ceiling object; changing it from anywhere else aborts.
  • A child key cut for one purpose cannot spawn a sibling.
  • Revoking flips a flag on an object the parent owns. The child keeps its key and can sign nothing that matters.

Two ledgers, and nothing yet checks they agree. The walk lives in ONE and the ceiling lives on chain. The read that must answer “may this agent spend this?” by consulting both, and refusing when they disagree, is designed and not built. Until it is, the mirror is a schema and an intention, and this page will not call it a guarantee.

The lifecycle

The life of a key, in six steps

One secret at the top. Everything after it is something that secret makes.

  1. Mint. One secret, made where you stand

    Thirty-two random bytes come into existence in this browser, from this device's own generator or from a passkey only this device can answer. No server is asked for anything. This is the only step that is about a secret. Every step after it is about what the secret makes.

  2. Derive. One secret becomes who you are and four addresses

    The same bytes give you a public identity and four chain keys: Sui, Ethereum, Solana, Bitcoin. Think of the root as a mould, not a key. It cuts keys and signs nothing itself. One child signs you in and another spends, so a signature you are tricked into giving at the front door opens the front door and nothing more. That split is wired in your wallet once your key is kept. The sign-in page itself still uses the funded address, so it is reachable today and not yet universal.

  3. Keep. Somewhere that lasts, before the address appears

    Three places count, and you pick one the moment the key is made: an encrypted file in a folder, the twenty-four words on paper, or a seal behind the fingerprint on this device. Any one is enough. Writing the file takes milliseconds. A browser tab is none of them. A key that lives only in a tab dies with the tab, and the address it made keeps showing a balance nobody can reach. So the rule is narrow: the key is written to a file, to paper or to your fingerprint before the address appears. This page obeys it. Mint, keep, then addresses. It is built and not in production yet.

  4. Register. Only public bytes cross the wire

    Your addresses are registered so money sent to you is recognised as yours. The door that records them takes addresses and cannot take a phrase. It is not built to. The same key names three things at once: who you are, whether you are a person or an agent, and which person an agent belongs to.

    wallet:create and the wallet doors
  5. Receive. A real address, in the first second

    This is the part that is the gift. The address takes a real payment the moment it appears. No ceremony first, and one warning beside it that is simply true: save this key, it is a real key and it can accept payments instantly. Balances are read from the chain, never from us. A reply from us proves nothing about money.

    identity:address
  6. Spend. Credits are how the key buys thinking

    Money in the wallet buys credits, and credits buy work: replies, tool and skill calls, agent runs, storage. They are prepaid, not a balance you withdraw. Then you promise something, stake on it with a signature your own key makes on your own device, and agents go and make it true. A payment landing, and thinking bought with it. That loop is what the key was for.

    credits, billing:topup and tasks:stake

The architecture

Why it is secure

Not because we promise to behave. Because of where the secret is and what each piece is allowed to do. That is not policy. It is physics.

There is nothing on our side to steal

A break-in at ONE reaches no key, because no key was ever sent. Seal one behind your fingerprint later and what we hold is ciphertext whose only opener is the biometric on your device. A dumped database is public addresses and locked boxes.

The root never signs

It derives. Sign-in, spending and every agent get a child key of their own, so one borrowed signature costs one door instead of everything. It is the rule the rest of the design hangs from. Sign-in is where the code is still catching up: the wallet can enrol and use its sign-in child today, and the sign-in page still signs with the address that holds the money.

The claims are on chain. You are not

Proving something about yourself, a passkey, a domain, a checked document, writes a small claim bound to your address that cannot be sold or moved: the method, the level, who issued it, and a scrambled fingerprint of the detail. Never the detail itself. This part is specified and not built yet.

Agents that work for you

Helpers, and why they can never bankrupt you

A helper is a child of your key with a ceiling you own. It signs for itself. It spends only what you allow.

Every helper gets its own key

An agent that works for you is a child of your key. It signs its own work with its own key, and it never holds yours. Because yours can derive its, you can always sweep its money home without asking it.

You hold the ceiling

What it may spend is a separate object on chain that you own and it does not. You set the number, including zero, and you start it low. Proven on testnet today, where the contract itself refuses a caller who is not the owner.

Revoking is not confiscation

Nobody can claw back a key on a blockchain, so nothing here pretends to. Revoking sets the ceiling to zero on an object you own. The agent keeps its key, keeps signing, and cannot spend.

What it earns comes home

A ceiling bounds what an agent may spend, not what it may hold, so a busy agent on a rented server becomes a target worth taking. Earnings are to settle back to your address on a threshold, leaving a working float, which is all a wiped server would then cost you. That sweep is designed and is not built yet.

The price, said plainly

What it costs

Free attaches to the key and the wallets. It does not attach to a transaction, and it does not attach to credits.

The key and the wallets: free

Free under the ONE License. Unlimited use, modification and resale, and it cannot be revoked. One obligation in return: keep the ONE mark and the link to one.ie in whatever you deploy. That is the whole price, and it is how a key somebody recovers years from now can still find the door it opens.

A transaction is not free

Moving money on the crypto rail costs gas plus one percent, deducted on the rail itself. Nothing on this page claims otherwise. Something is deducted, and a sentence that says free about a transaction would be false.

Credits are the priced part

Keys and wallets are free and yours. Credits are a product you buy, prepaid, with no overdraft behind them. Money in the wallet becomes credits, and credits buy the thinking. That line is the one place the word free stops.

The threat model, as a table

What it defends, and what it accepts

Every line on the left is paid for by the line on its right. A page with only a left column is hiding the right one.

Defends A break-in on our servers

Accepts Lose the paper and every device and the money is gone. No reset, no support line, no back door

Defends A phished password. There is no password to give away

Accepts Whoever holds your twenty-four words holds everything. Paper is a copy of the key, not a hint at it

Defends An agent that misbehaves. Its ceiling is the most it can cost

Accepts Sealing a key behind a fingerprint ties it to a platform account. That is why the paper exists

Defends A lost phone. The paper brings the same addresses back

Accepts A key made today restores here. Typed into other wallet software it derives a different, empty address and says nothing. The standard derivation is built and not yet in production

Your side of it

How to use it

  1. Make it here

    One tap. The secret is made in this tab, and the four addresses appear once you have kept it.

  2. Save it before anything else

    Write the twenty-four words by hand, or download the encrypted file, or seal it behind your fingerprint. One of the three, before the address is worth anything to you. That is the whole of your side of this.

  3. Receive

    Give out the address that matches the chain your payer is using. The balance you then see is read from that chain, not from us.

  4. Turn money into work

    Buy credits with what arrives, then spend them on replies, skills, agent runs and storage at one.ie/keys. Keys and wallets are free. Credits are the part you pay for.

  5. Hire a helper and give it a ceiling

    Start the ceiling low. Raise it once the agent has earned it. Drop it to zero the moment it has not.

Four things never to do

  • Never type the twenty-four words into a website, a chat or an email. Nobody from ONE will ever ask for them, and there is no problem that sending them solves.
  • Never keep the only copy as a screenshot. That is a file on a device that syncs.
  • Never store the paper and the device in the same place. One flood should not take both.
  • Never sign something you have not read. A signature is a sentence you cannot unsay.

Recovery

Two roots. Paper is one of them.

One you carry without knowing it. One you can hold in your hand. Either one brings the same four addresses back.

Root one

A fingerprint you already have

The passkey is one of the three places the key can rest. The key itself is random and made once. Your fingerprint opens a sealed copy of it on this device, and the seal is useless without the finger. Lose the device and that copy is gone, which is why there is a second place.

Root two

Twenty-four words on paper

The same thirty-two bytes, written as twenty-four words you can copy onto paper. They are not a backup of the key. They are the key. Type them at one.ie/w/restore and the same four addresses come back. Paper survives a dead laptop.

The catch, said out loud

They are BIP-39 words, and a key made today is not one another wallet can open. A standard wallet takes the phrase through PBKDF2 and BIP-32. ONE takes the entropy those words encode straight into HKDF. Same words, different key. Typed into other software they produce an address that looks perfectly valid and is not yours. Restore them with one of the three tools at one.ie/recover.

The fix is built, not yet in production: new keys derive by the standard paths, so the same words find the same addresses in any wallet, and keys already made keep every address they have. Until that release lands, the words restore your key here, and a different wallet fed the same words lands on an address that is empty and says nothing about it. This page will say otherwise on the day it is true, and not before.

The boundary

What this page does not do

It keeps the key where you put it, and nowhere else

The key is never written to this browser's storage and there is no row for it in any database. What this page does is ask you to keep it before it shows you an address: an encrypted file you save to your own disk, the twenty-four words on paper, or a seal behind your fingerprint. The only thing it records afterwards is a note to itself that a durable copy exists. Never the key. Never anywhere but this browser.

It sends no key

Deriving a key makes no request of its own. The secret is computed in this tab by your browser's own crypto, and no code on this page sends it anywhere. The page loads the way any page does, scripts, styles, one analytics beacon, and none of that carries the key.

It signs nothing

This page makes a key, takes your keep, and then shows the addresses. It moves no funds and signs no transaction. There is nothing here that can spend. To seal a key under your fingerprint, prove the words on paper, and see where you stand in the six steps above, the manager at one.ie/keys is where that happens.