Passkeys
A passkey is a WebAuthn credential on this device. Nothing secret is uploaded. The chain stores a public authenticator; the device signs locally.
First time
- On the mint desk, choose this-device unlock (not Keplr).
- The page creates a Terp key and asks the OS for fingerprint / Face ID / PIN.
- After a paid checkout (Pedersen
cconfirmed by DREGG), HashMerchant feegrantsMsgAddAuthenticatorand 1 THIOL runway. - The page submits
MsgAddAuthenticator. The first ephemeral key is not kept as the long-term signer.
Later
Unlock with the same passkey. The dest terp1 is the smart account that already has the authenticator.
Keplr users skip this path entirely.
What the feegrant may cover
Only /terp.smartaccount.v1beta1.MsgAddAuthenticator. Not bank send, not CosmWasm mint, not IBC. HashMerchant does not buy the NFT.