ZKsync

Own the onboarding journey for your chain

ZKsync SSO is a white-label, enterprise-ready ecosystem wallet that plugs into your existing authentication flows, enabling passkey login, brand-controlled UX, and seamless self-custodial onchain transactions.

ZKsync SSO
ZKsync

Why SSO

Brand-controlled UX
PainRedirects to third-party wallets erode trust and create drop-offs
How SSO helpsFully white-label interface hosted under your domain
Seamless enterprise login
PainOnchain wallets require seed phrases and extensions, blocked by IT policies
How SSO helpsEmbed directly into your existing login flow, every authenticated user gets a self-custodial account instantly
High conversion
PainComplex setup and signature fatigue kill adoption
How SSO helpsPasskey-based onboarding and session keys remove friction
Regulatory readiness
PainCustodial key stores, closed SDKs, and opaque audit trails increase compliance risk
How SSO helpsNon-custodial, open-source, security-audited architecture
No vendor lock-in
PainPer-user fees and proprietary APIs
How SSO helpsMIT-licensed code, fully self-hosted, no recurring licensing costs

Core Capabilities – Everything in One Stack

White-Label Smart Wallet
For your organizationHost the authentication server, dashboard, and UI widgets in-house. Maintain brand integrity, control data, and meet security requirements.
For your usersInteract within your branded environment without third-party redirects.
Passkey-First Onboarding
For your organizationSDK converts biometric login or SSO credentials into a self-custodial account, driving higher adoption. Option: Plug in Dynamic.xyz to offer email and social login that provisions an embedded wallet with a native onchain passkey.
For your usersInstant wallet creation via Face ID, fingerprint, or corporate login. Sign up with email or a social account (via Dynamic.xyz) and start transacting immediately—no extensions or seed phrases.
Session Keys
For your organizationPre-authorize actions with spend/time limits to streamline UX and enforce policy controls.
For your usersExecute transactions without repeated signing requests.
Gas Abstraction
For your organizationSponsor fees or bill in ERC-20 tokens to eliminate a top user drop-off point.
For your usersInteract without managing gas fees.
Enterprise-Grade Security
For your organizationOpen-source ERC-4337/7579 modules with keys stored client-side, simplifying compliance reviews.
For your usersSecure, self-custodial accounts with guardian/social recovery options.
Prividium Integration
For your organizationNative privacy-layer support for confidential transactions.
For your usersSame-wallet experience for both public and private transfers.
Rapid Deployment
For your organizationSDKs, CLIs, and sample apps enable integration within existing enterprise workflows in hours.
For your usersMinimal disruption, continuous UX improvements.

Enterprise-Ready in Practice

icon

Brand-Owned Wallet Experience

  • UI inherits your brand’s fonts, colors, and domains, no loss of trust
  • All touchpoints remain in your environment
icon

Self-Custody + Proven Security

  • Passkeys secure each smart account, keys never leave the device
  • Public audits, open-source code, and onchain logs ease security reviews
icon

One-Tap Onboarding

  • Corporate Single Sign-On or biometrics → fully functional wallet in seconds
  • Eliminates seed-phrase support overhead
  • Add social/email login via Dynamic.xyz → create embedded wallets from email or social sign-in
icon

Friction-Free Transactions

  • Session keys remove signature spam
  • Gas abstraction simplifies billing and eliminates fee barriers
icon

Privacy-Ready

  • Built-in Prividium integration for compliant, confidential transactions that meet enterprise data-protection requirements
  • Seamlessly support both public and private transactions within a single wallet
icon

Fast, Low-Maintenance Deployment

  • Embed in hours
  • Modular, open-sourced stack, no per-user or vendor fees

Technical Overview

View full documentationarrow right
panel icon

Authentication

Passkey login • Biometric/device credentials • Passwordless recovery

panel icon

Smart Accounts

ERC-4337 core • ERC-7579 validators • Upgradeable modules (no address change)

panel icon

Session Keys

Time-bound approvals • Spend/contract limits • One-click revocation

panel icon

Gas Abstraction

Native paymaster • Sponsor fees or bill in tokens • Gasless UX

panel icon

Recovery

Multi-device sync • Guardian/social recovery

panel icon

White-Label Stack

Self-hosted auth server • Custom dashboard • Brandable widgets

panel icon

SDKs & Tools

JS, TS, React Native • Wagmi connector • CLI

panel icon

Security & Compliance

Open-source • Multiple third-party audits

Resources

ZKsync

Own your onboarding.
Protect your brand.

Frequently Asked Questions

An open-source, self-hosted smart-wallet and login layer that turns any authenticated user into a self-custodial on-chain account.

You keep control: no third-party custody, no vendor lock-in, no per-user fees. You own branding, data, deployment, and roadmap.

No. Keys are device passkeys (WebAuthn) and never leave user hardware. Signing happens client-side; the auth server never sees or holds private keys.

Yes. Contracts and server components are public and undergo regular third-party audits.

You host it. PII and auth metadata remain within your environment per your data-residency policies. The wallet layer does not require exporting user PII to third parties.

Teams commonly embed passkey login and wallet creation in hours using the JS SDK and prebuilt UI components. Depth (policy, theming, custom flows) is up to you.

Yes. You can optionally integrate Dynamic.xyz to let users sign up with email or social accounts; Dynamic provisions an embedded wallet on ZKsync secured by a native on-chain passkey.

Yes. You can self-host the auth server and dashboard under your domain and customize the UI to meet brand-governance requirements.

Session keys allow pre-approved actions within time/spend limits (no constant prompts). Paymasters let you sponsor gas, bill in ERC-20s, or offer gasless flows.

Multi-device passkeys plus optional guardian/social recovery patterns. Admin-driven policy can time-box sessions and revoke session keys instantly.

Yes. React Native SDK is available today. Native Swift and Kotlin SDKs are planned for Q4 2025.

Yes. SSO is integrated with Prividium for privacy-first transactions on Prividium chains, enabling confidential transfers within the same wallet UX.

MIT-licensed software, free to deploy. You host it; there are no recurring licensing or per-user fees.

Modular ERC-7579 validators and upgradeable account modules allow new capabilities without changing user addresses, minimizing change-management overhead.