One root, 256 signatures

Your wallet signs one sentence. That signature is hashed into two 32-byte seeds, and those build 256 one-time keys under a single Merkle root. Only the root and the public seed are ever sent anywhere.

Each key signs exactly once. Two signatures under one key leak enough to forge a third. The identity has 256 keys and the page prints how many are left.

01 · wallet

No Solana wallet announced itself to this page. Install one, or open this in a browser that has one. Nothing else here needs it: the verify page works with no wallet at all.

02 · derive

Your wallet signs one sentence. That signature is hashed into two seeds here, in this tab, and 256 one-time keys are built from them. The secret seed is never stored and never sent.