Skip to main content
Calibri never holds your money. Your USDC lives in a Gnosis Safe that only you control, on-chain. You can withdraw from it even if Calibri is offline. There are two ways to set that up: Both end in the same place: your own Safe, holding your own USDC. They differ only in what owns the Safe. Either way the operator relays your signed orders and pays the gas.

Passkey wallet — no seed phrase, no extension

A passkey wallet is the simplest way to hold your own funds. You approve a prompt with Face ID, Touch ID, or your device PIN, and that’s the whole setup — no browser extension, no app to install, and no seed phrase to write down. There is no private key. Your Safe is owned by a signer contract derived from a WebAuthn credential that lives in your device’s secure hardware. The credential can produce signatures but cannot be exported, and Calibri never holds a key for your account. How it works when you enrol:
1

Create the passkey

Your device generates the credential and hands Calibri only the public half. The private half never leaves your authenticator.
2

Your address is derived immediately

Both the signer contract and your Safe address are computed deterministically from that public key. Your deposit address exists the moment you enrol, before anything is on-chain.
3

Nothing is deployed yet

The contracts are only deployed when your first deposit arrives — and the operator pays for that deployment, not you.
4

Trading

Each order is signed by the passkey and verified on-chain against the signer contract. To avoid a prompt on every order, unlock a session key once and orders sign silently after that — withdrawals and redemptions still require your passkey.
Your passkey is your wallet. Calibri cannot recover it, reset it, or sign on your behalf — that is what makes the wallet yours. Where your passkey is stored decides whether it survives losing your device. Read the next section before you fund anything.

Where your passkey actually lives

This is the part that matters, and it is not the same on every platform. Your passkey is stored by your operating system or password manager, not by Calibri — so whether it syncs, and whether it survives a lost or broken device, is decided by which of these you enrol with.
Windows Hello passkeys do not sync. They are bound to the machine that created them. If that is the only place your passkey exists and the machine is lost, stolen, reset, or dies, your funds are unreachable — permanently, by you and by us. On Windows, either enrol through a syncing password manager, or use the cross-device option below, or choose your own wallet instead.

Using your phone to sign on a desktop

Every major desktop browser supports signing with a passkey held on your phone: you scan a QR code, the phone verifies it is physically nearby over Bluetooth, and your phone’s authenticator approves. The passkey never leaves the phone. This is the practical answer on Windows and on any shared or borrowed machine: enrol the passkey on your phone, where it syncs, and use it from the desktop when you need it.

Before you fund an account

1

Check your passkey syncs

On iPhone or Android it does by default. On Windows Hello it does not — enrol through a password manager or on your phone instead.
2

Make sure you can reach the account it syncs to

Your Apple Account, Google Account, or password-manager vault is now what stands between you and your funds. Make sure it has recovery set up and 2FA you will not lose.
3

Enrol on a second device if you can

A second passkey on a second device is the cheapest insurance available, and there is no other kind for a self-custody wallet.
Passkeys need a device with a platform authenticator and a browser supporting WebAuthn. Broadly: iOS 16+, macOS 13+, Android 9+, and current Chrome, Edge, Safari, or Firefox. If yours does not qualify, use your own wallet instead.

Your own wallet — bring an existing one

If you already use a wallet, connect it and keep signing with what you know. Calibri supports MetaMask, Coinbase Wallet, Rainbow, and any wallet reachable over WalletConnect — including mobile wallets, by scanning a QR code. Here your Safe is owned by your wallet’s address. You approve a signature request in your wallet for each order; the operator relays it and pays the gas, exactly as with a passkey. This path also gives you Sign-In With Ethereum — you can authenticate to Calibri with your wallet instead of an email and password.

Which should I choose?

  • Never used a crypto wallet? Use a passkey wallet — enrolled on your phone, or on a desktop through a password manager. You get the same on-chain guarantees without installing anything or learning wallet software.
  • Already have MetaMask or a mobile wallet? Connect it. You keep your existing signing habits and your existing backup, and you can sign in to Calibri with it too.
  • Windows-only, no phone, no password manager? Use your own wallet. A device-bound Windows Hello passkey is a single point of failure for funds nobody can restore.
Both give you identical control over your funds on-chain. The difference that actually matters is how each one is backed up:
Neither path has a support ticket at the end of it. Self-custody means the backup is yours to keep, and it is the only copy.

Adding a second signing key

A passkey wallet starts with one thing that can authorise it. You can add a second — an Ethereum wallet you hold the key for — which makes your funds recoverable if you lose the passkey, and lets your own code trade, withdraw and redeem. It is the same wallet either way: same address, same balance, same positions. But an added key is a full owner — it can withdraw, and it can remove your passkey — so it is worth reading what you are agreeing to before you do it.

Signing keys

What a second key can do, how to add and remove one, and what happens if it removes your passkey.

Which signature type your wallet gets

Every order you sign carries a signature_type. It tells the exchange how to check your signature, and it comes from the wallet you set up — you never pick it yourself. Sign up with a passkey and you get a passkey wallet in the same step. Sign up with an email address and you have no wallet yet — you set one up afterwards in Settings → Wallet, and that is the moment your type is decided. Add a second signing key to a passkey wallet and you stay on type 3. The extra key lets your own code sign orders. Your wallet is the same wallet.
Read signature_type from GET /api/v2/atlas/account/wallet before you sign, rather than hardcoding a number. It is the same field the web app reads.

Signing an order

What each type requires of the signature itself, and the exact bytes to sign.

How this compares to email wallets elsewhere

Most prediction markets that let you sign up with an email address do it the same way, and it is worth understanding because it is not what Calibri does. The usual pattern — Polymarket’s, through Magic — is that signing up creates an ordinary wallet with an ordinary private key, generated and held by a third-party key service. It is genuinely your key: the exchange cannot sign with it. But the key exists off your device, and you can export it. Their own API clients depend on exactly that: an email user who wants to trade programmatically exports the private key from the key service and imports it into their bot, then signs with signature_type=1. A passkey wallet has no such key to export. Your credential is sealed inside your authenticator, and the Safe is owned by an on-chain signer contract derived from its public half — so there is no private key on our servers, in a vendor’s infrastructure, or anywhere a script can reach. Every signature requires you, in person, unlocking your device. Both are called self-custody, and both are: neither operator can move your money. The difference is what “your key” means. If a key can be exported, then whoever reaches the account that guards it — by phishing, by an email compromise, or by legal process against the key service — can reach your funds. A passkey removes that surface entirely, and the price is the last row of that table.
The difference is who decides. Nobody holds a key on your behalf here; if you want one that a script can use, you add it yourself, knowingly, and you can remove it again. The default stays a wallet with no exportable key at all.
Pick one — an account has a single self-custody wallet. It is fixed when the wallet is created and cannot be switched afterwards: a passkey account cannot add an Ethereum wallet as its funding wallet (linking one makes it a sign-in credential only), and an account already using its own wallet is not offered a passkey wallet. This is deliberate — two wallets on one account means two pots of money, only one of which the app can show you.

Non-custodial overview

The full self-custody model end to end.

The Safe

What the Safe is and how it is made trade-ready.

Signed orders

How an order is authorised in each model.

Session keys

Trade without a passkey prompt per order.

Funding your account

Getting USDC in.