Your keys
User key
You control this key. Use it to recover the wallet or revoke Locus’s permissioned key. It is generated in your browser and never stored on Locus servers. Save your user key securely when you create the wallet. See the quickstart for setup.Permissioned key
Locus stores this key in a hardware security module to sign agent transactions. It can rotate itself; only your user key can fully revoke it.Subwallets
Email payments use subwallets to hold funds until the recipient claims them:- Send USDC to an email address.
- Locus places the funds in a separate subwallet.
- The recipient receives an email with a one-time password.
- They claim the funds to a wallet address of their choosing.
Locus smart wallet
Locus wallets use ERC-4337 accounts based on Solady. Either the user key or active permissioned key can sign. The user key can callrevokePermissionedKey() to remove Locus’s access.
The wallet implementation is immutable: _authorizeUpgrade always reverts.
Factory
LocusFactory deploys wallets at deterministic addresses using CREATE2. The permissioned key is set during deployment.
For contract methods and subwallet limits, inspect the verified implementations:
Smart wallet contract
Signing, access revocation, transfers, and wallet deployment.
Subwallet contract
Email payment escrow, deadlines, and claims.