[ WALLETS ]
Embedded wallets for every app
Drop-in wallets with email OTP, social login, passkey transaction authorization, spend policies, gasless transactions, and multi-chain support. Your users get a wallet in seconds — no seed phrases, no extensions, no friction.
[ CHAINS ]
Six chains, one wallet
Every user gets a wallet on each supported chain, with per-chain address derivation and the custody model shown on each one.
Ethereum
Base, Optimism, Arbitrum, Polygon
Bitcoin
Mainnet
Solana
Mainnet, Devnet
XRP Ledger
30+ tx types
Cardano
Native assets
Tron
TRC-20
[ FEATURES ]
Everything you need to embed wallets
From auth to signing to spend controls to fiat ramps — one SDK, one integration.
Email OTP Login
Passwordless login via 6-digit code. Users enter their email, verify, and get a wallet provisioned on first login. No passwords, no seed phrases.
Social Login
Google, Apple, and Discord OAuth. ID tokens verified server-side with audience and issuer validation. One-tap sign-in creates a wallet instantly.
Passkey Tx Authorization
Users approve transactions with biometric passkeys (Face ID, Touch ID, Windows Hello). TX digest binding ensures the passkey prompt matches the exact transaction.
Sign in with 1Claw
Full OAuth 2.0 + PKCE consent flow. Your app requests scoped wallet access — users approve once, your backend gets tokens with refresh support.
Spend Policies
Per-app and per-user: to_allowlist, to_denylist, max_value_per_tx, daily_limit, allowed_chains, allowed_tokens, max_transactions_per_day. Enforced server-side before signing.
Multi-chain Wallets
Ethereum (+ L2s), Bitcoin, Solana, XRP, Cardano, and Tron from a single wallet. EVM supports EIP-1559, EIP-4844, and EIP-7702 transaction types.
Gasless Transactions
ERC-4337 Smart Accounts with Pimlico paymaster sponsorship. Users never hold ETH for gas. Works on Ethereum, Base, Optimism, Arbitrum, and Polygon.
DEX Swaps
Token swaps via 0x DEX aggregator built into the wallet. Best-price routing across DEXes. One-click swap from the embedded widget or programmatic via SDK.
Fiat On/Off Ramps
Coinbase Onramp and MoonPay integration. Users buy crypto with cards or bank transfer directly into their wallet. Sell flows for offramp.
Custody your users choose
Managed wallets under HSM-wrapped envelope encryption, or self-custody: passkey-owned Safes on EVM and 2-of-2 threshold keys on Solana. Every wallet says which it is.
Platform API
Bootstrap templates auto-provision vaults, agents, signing keys, and wallets for your users. One API call to onboard a user with full wallet infrastructure.
React Component or Headless
Use <OneclawEmbeddedWallet /> for a full UI (Send, Swap, Receive, Buy) or go headless with useOneclawWallet() for complete programmatic control.
[ CUSTODY ]
Enterprise-grade key custody without the complexity
Every wallet carries a custody label that says who can sign with it, enforced in code. Managed wallets are envelope-encrypted under HSM-wrapped keys and signed server-side after policy; self-custody wallets have no key 1Claw can use alone. No seed phrases, no browser extensions, and the same spend policies, approvals and sanctions screen on every model.
Managed wallets (custody: server)
Per-key AES-256-GCM envelope encryption with the wrapping key in Google Cloud KMS HSMs (FIPS 140-2 Level 3). Never readable by your app or the general secrets API; export is human-only with re-authentication and an audit trail.
Passkey-owned Safes on EVM (custody: passkey_owner)
A Safe whose only owner is the user's passkey. The transaction hash is the WebAuthn challenge, verified on-chain via RIP-7212 on Base, Optimism, Arbitrum and Polygon. No private key exists — 1Claw relays, it cannot sign.
Self-custody Solana (custody: client_tss)
2-of-2 FROST threshold keys: one share with 1Claw, one wrapped under the user's passkey PRF output. Neither party can sign alone.
TEE signing (optional)
Managed-wallet signing inside AMD SEV-SNP Confidential VMs (Shroud), with the node's attestation token published for verification. Keys are plaintext only inside the enclave, for the duration of the signature.
[ QUICKSTART ]
From zero to wallet in five lines of code
Install @1claw/wallet-react, wrap your app in the provider, and drop in the widget. Email OTP, social login, multi-chain wallets, send, swap, receive, and buy — all included out of the box.
- Full UI or headless — useOneclawWallet() for programmatic control
- CSS theming via custom properties
- Built-in toast notifications and skeleton loading
- Props: appId, theme, chains, features, socialProviders
import { OneclawWalletProvider, OneclawEmbeddedWallet }
from "@1claw/wallet-react";
export default function App() {
return (
<OneclawWalletProvider appId="plt_...">
<OneclawEmbeddedWallet
chains={["ethereum", "solana", "bitcoin"]}
features={["send", "swap", "receive", "buy"]}
/>
</OneclawWalletProvider>
);
}
[ PLATFORM API ]
Auto-provision everything with bootstrap templates
One API call provisions a user with a vault, agent, policies, signing keys, and wallets across all chains. Define your template once — every new user gets the same infrastructure automatically.
{
"vault": { "name": "user-wallet" },
"agents": [{ "name": "wallet-signer",
"signing_keys": [
{ "chain": "ethereum" },
{ "chain": "solana" },
{ "chain": "bitcoin" }
]
}],
"policies": [...]
}
[ DX ]
Developer experience
SDK, MCP, CLI, and React components. Pick the integration that fits your stack.
TypeScript SDK
Pure TypeScript, zero runtime dependencies. Agent-first with auto-token refresh, key-only auth, and full type coverage from the OpenAPI spec.
MCP Server
Model Context Protocol integration so AI agents can manage wallets, submit transactions, and check balances via tool calls.
Deposit Destinations
Generate unique inbound payment addresses per user or per transaction. Track deposits with webhooks and auto-attribute to the correct account.
Internal Accounts & Ledger
Gas-free instant transfers between named sub-accounts within your app. Double-entry bookkeeping with overdraft protection and idempotency.
[ WHY 1CLAW ]
Built for agents and developers
Purpose-built for AI agent wallets — not retrofitted from a human-first product. Every feature designed for programmatic access with human oversight.
Signatures = on-chain signing · Executions = HTTP/GraphQL binding calls. Wallet sends and swaps count toward your plan's signatures/mo quota (Free: 100, Pro: 20,000, Team: 200,000). Signatures are metered monthly; over quota is billed per signature (not a % of tx value). Intents API (on-chain signing) is available on all plans.
[ GUIDES ]
Set it up for your stack
Practical walkthroughs for the tools people most often wire this into.
[ COMPARE ]
How this compares
Capability-by-capability against the alternatives, including where the alternative is the better choice. Provisioning wallets for end users or agents, key custody models, and what happens when an autonomous process holds funds.
Ready to embed wallets?
Create a platform app, get your plt_ key, and start embedding wallets today. Pro plan and above.
Already have a platform app? Go to Embedded Wallets hub →