LazorKit LogoLazorKit
React SDK

Overview

LazorKit React SDK — passkey smart wallets for web apps.

Drop-in React hook + provider for LazorKit smart wallets on Solana. Users authenticate with a device passkey (Face ID, Touch ID, Windows Hello, security key) through the LazorKit portal — no extension, no seed phrase.

Package

@lazorkit/wallet on npm, current release 3.4.0. Peers: react and react-dom ^18.3.1 or ^19, @solana/web3.js ^1.99, zustand ^5, @solana/wallet-adapter-base and the @wallet-standard packages; no @solana/kit, so it installs next to kit 8. Speaks protocol v2, and v1 for wallets made before it — see Networks & versions.

Why this SDK

  • Passkey auth — synced via iCloud Keychain / Google Password Manager for cross-device continuity.
  • Gasless by default — a Kora paymaster sponsors every transaction. Users never need SOL.
  • Session keys — a single approval mints a scoped Ed25519 signer; subsequent txs are prompt-free.
  • On-chain spending limits — lifetime caps, per-tx caps, recurring windows, program allow/block-lists.
  • Ed25519 authorities — add Admin keys, or Delegate keys bounded by a spending policy.
  • Deferred execution — one approval authorises payloads too big for a single tx.
  • Confirmed sends — every send resolves once its transaction is confirmed.

How it fits together

┌─────────────┐  dialog iframe   ┌─────────────────┐   WebAuthn   ┌──────────┐
│  your app   │─── (or popup) ──▶│ LazorKit portal │─────────────▶│  passkey │
│  (React)    │◀── signature ────│ portal.lazor.sh │              │ (device) │
└──────┬──────┘                  └─────────────────┘              └──────────┘
       │
       ▼ build tx / finalize
┌─────────────┐   relay via    ┌─────────┐
│   SDK       │─── paymaster ─▶│ Solana  │
└─────────────┘                └─────────┘

The WebAuthn ceremony runs in the LazorKit portal (portalUrl, default https://portal.lazor.sh), opened in a dialog iframe on your page, with a popup window as the fallback where an iframe cannot be used. Passkeys are registered under the portal's relying party (its domain), not your app's. Closing the dialog or popup rejects the pending call with PortalCancelledError. Once signed, transactions are relayed by the paymaster and confirmed by the SDK.

Explore