> ## Documentation Index
> Fetch the complete documentation index at: https://docs.calibri.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Trading without a prompt per order

> Session keys — how a passkey wallet authorises one browser key to sign orders, what that key can and cannot do, and how to revoke it.

If you use a **passkey wallet**, every order is signed by your passkey — which
means a Face ID, Touch ID, or PIN prompt each time you trade. That is fine for a
deposit. It is exhausting for trading.

A **session key** fixes it. You approve **once**, and orders sign silently after
that.

## What a session key is

A session key is a **P-256 keypair generated inside your browser**, held
non-extractably, that your passkey authorises your Safe to accept **for placing
orders only**. Once it is unlocked, placing an order costs no prompt at all.

It is deliberately narrow:

| | |
| - | - |
| **Can** | Sign orders on the Calibri exchange |
| **Cannot** | Withdraw. Redeem winnings. Change approvals. Add a Safe owner. Sign anything for any other contract |

**The session key is not a Safe owner.** All it can do is make your Safe accept a
Calibri order signature — and only when the exchange itself is the caller.
Withdrawals and redemptions still require your passkey, always.

<Note>
  An unlocked session key is roughly equivalent to being logged in on any exchange: whoever holds the device can trade. The meaningful difference is that this one **provably cannot move your money out**, where a normal logged-in session usually can.
</Note>

## How to set one up

<Steps>
  <Step title="Unlock trading">
    On the order form, choose **Unlock trading**. Your browser generates the
    keypair and never releases the private half.
  </Step>

  <Step title="Approve with your passkey">
    One Face ID / Touch ID / PIN prompt authorises the key on your Safe. This is
    an on-chain authorisation; Calibri relays it and pays the gas.
  </Step>

  <Step title="Trade">
    Orders now sign silently until the key expires, locks, or you revoke it.
  </Step>
</Steps>

If your device or browser doesn't support passkeys, the app simply keeps
prompting per order — the original behaviour, and always a valid fallback.

## When it stops working

Three separate things end a session, and they are not the same:

| | What happens | What you do |
| - | - | - |
| **Idle lock** | After a period with no orders (**15 minutes** by default) the key drops out of memory | Unlock again — a single passkey prompt |
| **Expiry** | Grants are issued for a fixed lifetime (**30 days** by default) | Authorise a new key |
| **Revocation** | You revoke it deliberately | Authorise a new key |

You can revoke **one** key or **all** of them at once. Revoke-all is the
emergency path and works no matter how many keys exist.

<Warning>
  Revoking is immediate on-chain, but it does **not** cancel orders that key already placed. They stay resting, and a fill will then fail to settle, because settlement checks the grant. **Cancel resting orders yourself before revoking** if you want the exposure closed.

  Expiry behaves differently and deliberately so: an order signed while the key was live still settles normally after the key expires. Expiry limits what can be *placed*, not what can be *settled* — otherwise a 30-day key would strand every longer-dated order it ever signed.
</Warning>

## Lost or stolen device

Revoke the session key. It takes effect on-chain the moment it lands, and your
funds were never reachable by that key in the first place — a session key cannot
withdraw. Your passkey remains the only thing that can move money.

## How long a key lasts

You choose, in **Settings → Quick trading**: **1 day**, **7 days**, or **30 days**.
The choice applies to the **next** key you authorise — it cannot shorten a grant
that already exists on-chain, so to cut one short, revoke it and authorise a new
one.

Whatever you pick, the key still locks after 15 minutes idle and still cannot
withdraw.

## For API clients

A session key is a **browser** convenience, and it stays in the browser: it is
generated as a non-extractable key so that no script — ours or anyone's — can
read it out. That is what makes it safe to leave unlocked, and it also means it
cannot be copied to a server.

So if you use a **passkey wallet**:

| Over the API | |
| - | - |
| **Reading** — balances, positions, orders, contracts, market data | Works normally |
| **Placing orders** | Not possible. Your passkey signs only in this browser |
| **Withdrawing, redeeming** | Not possible. Owner-only, and your passkey is the owner |

To trade from your own code, **add a second signing key** to your wallet
(Settings → Wallet → Signing keys) and sign with that. It is an owner of the same
Safe, so it can place orders, withdraw and redeem — and it is a key you hold, so a
script can use it. See [Signing keys](/non-custodial/signing-keys).

Orders signed that way are still `signature_type: 3` with `maker == signer == your
Safe`; only the signature differs — see
[Signed orders](/non-custodial/signed-orders) and
[Authentication](/api-reference/authentication).

<Warning>
  A second signing key can do everything your passkey can, including removing your passkey. A session key cannot — that is the trade you are making when you choose one over the other.
</Warning>

They also interact: while a signing wallet is connected, it signs your orders and quick
trading is not offered. An already-unlocked session key still signs first, since it needs
no prompt at all.

<Note>
  A session key stays in the browser by design, not by omission: it is generated non-extractable so that no script — ours or anyone's — can lift it, which is what makes it safe to leave unlocked. A key a server could use has to be one you deliberately add and can remove, which is what a [signing key](/non-custodial/signing-keys) is. Other markets reach the same place by holding an exportable key on your behalf from the start: see [how this compares](/non-custodial/wallets#how-this-compares-to-email-wallets-elsewhere).
</Note>

## Related

<CardGroup cols={2}>
  <Card title="Your wallet options" href="/non-custodial/wallets">
    Passkey wallet vs your own wallet.
  </Card>

  <Card title="Signed orders" href="/non-custodial/signed-orders">
    How an order is authorised and validated.
  </Card>

  <Card title="The Safe" href="/non-custodial/the-safe">
    What the Safe is and what can act on it.
  </Card>

  <Card title="Redeeming winnings" href="/non-custodial/redeeming-winnings">
    Still passkey-only.
  </Card>

  <Card title="Withdrawing without Calibri" href="/non-custodial/withdraw-without-calibri">
    The exit that does not need us.
  </Card>

  <Card title="Signing keys" href="/non-custodial/signing-keys">
    A second key that can sign for your wallet.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.