Skip to main content
If you use a passkey wallet, every order is signed by your passkey — which means a Face ID, Touch ID, or PIN prompt each time you trade. That is fine for a deposit. It is exhausting for trading. A session key fixes it. You approve once, and orders sign silently after that.

What a session key is

A session key is a P-256 keypair generated inside your browser, held non-extractably, that your passkey authorises your Safe to accept for placing orders only. Once it is unlocked, placing an order costs no prompt at all. It is deliberately narrow: The session key is not a Safe owner. All it can do is make your Safe accept a Calibri order signature — and only when the exchange itself is the caller. Withdrawals and redemptions still require your passkey, always.
An unlocked session key is roughly equivalent to being logged in on any exchange: whoever holds the device can trade. The meaningful difference is that this one provably cannot move your money out, where a normal logged-in session usually can.

How to set one up

1

Unlock trading

On the order form, choose Unlock trading. Your browser generates the keypair and never releases the private half.
2

Approve with your passkey

One Face ID / Touch ID / PIN prompt authorises the key on your Safe. This is an on-chain authorisation; Calibri relays it and pays the gas.
3

Trade

Orders now sign silently until the key expires, locks, or you revoke it.
If your device or browser doesn’t support passkeys, the app simply keeps prompting per order — the original behaviour, and always a valid fallback.

When it stops working

Three separate things end a session, and they are not the same: You can revoke one key or all of them at once. Revoke-all is the emergency path and works no matter how many keys exist.
Revoking is immediate on-chain, but it does not cancel orders that key already placed. They stay resting, and a fill will then fail to settle, because settlement checks the grant. Cancel resting orders yourself before revoking if you want the exposure closed.Expiry behaves differently and deliberately so: an order signed while the key was live still settles normally after the key expires. Expiry limits what can be placed, not what can be settled — otherwise a 30-day key would strand every longer-dated order it ever signed.

Lost or stolen device

Revoke the session key. It takes effect on-chain the moment it lands, and your funds were never reachable by that key in the first place — a session key cannot withdraw. Your passkey remains the only thing that can move money.

How long a key lasts

You choose, in Settings → Quick trading: 1 day, 7 days, or 30 days. The choice applies to the next key you authorise — it cannot shorten a grant that already exists on-chain, so to cut one short, revoke it and authorise a new one. Whatever you pick, the key still locks after 15 minutes idle and still cannot withdraw.

For API clients

A session key is a browser convenience, and it stays in the browser: it is generated as a non-extractable key so that no script — ours or anyone’s — can read it out. That is what makes it safe to leave unlocked, and it also means it cannot be copied to a server. So if you use a passkey wallet: To trade from your own code, add a second signing key to your wallet (Settings → Wallet → Signing keys) and sign with that. It is an owner of the same Safe, so it can place orders, withdraw and redeem — and it is a key you hold, so a script can use it. See Signing keys. Orders signed that way are still signature_type: 3 with maker == signer == your Safe; only the signature differs — see Signed orders and Authentication.
A second signing key can do everything your passkey can, including removing your passkey. A session key cannot — that is the trade you are making when you choose one over the other.
They also interact: while a signing wallet is connected, it signs your orders and quick trading is not offered. An already-unlocked session key still signs first, since it needs no prompt at all.
A session key stays in the browser by design, not by omission: it is generated non-extractable so that no script — ours or anyone’s — can lift it, which is what makes it safe to leave unlocked. A key a server could use has to be one you deliberately add and can remove, which is what a signing key is. Other markets reach the same place by holding an exportable key on your behalf from the start: see how this compares.

Your wallet options

Passkey wallet vs your own wallet.

Signed orders

How an order is authorised and validated.

The Safe

What the Safe is and what can act on it.

Redeeming winnings

Still passkey-only.

Withdrawing without Calibri

The exit that does not need us.

Signing keys

A second key that can sign for your wallet.