Skip to content


Once a smart contract wallet has integrated Keyspace support, the client software needs to add support as well.

Sending Transactions

Transactions for Keyspace wallets are authorized by the user's signature alongside a proof of the wallet's current configuration in Keyspace. Keyspace's mksr_proof RPC call retrieves the needed proof from a Keyspace node.

export async function signAndWrap(
  { hash, privateKey, keyspaceKey }: { hash: Hex; privateKey: Hex; keyspaceKey: Hex }
): Promise<Hex> {
  const signature = await sign({ hash, privateKey });
  const publicKey = secp256k1.getPublicKey(privateKey.slice(2), false);
  const pk256 = serializePublicKeyFromBytes(publicKey);
  const dataHash = getDataHash(pk256);
  const configProof = await getKeyspaceConfigProof(keyspaceClient, keyspaceKey, vkHashEcdsaAccount, dataHash);
  return encodeSignature({
    configProof: configProof.proof,

Changing Keys

Changes to owner keys are written to Keyspace instead of the smart contract itself. The smart contract picks up key changes through the configuration proofs that are provided with each transaction and are verified against the latest Keyspace state root.

To change the configuration stored in Keyspace, the user needs to sign the new configuration, then generate a zero-knowledge proof with the appropriate Account circuit for their wallet to demonstrate to Keyspace that they're authorized to make the change.

Sign the New Configuration

Account proofs require a signature of the newKey. This isn't a "new key," it's a commitment to the new configuration to be stored in the Keyspace record, and this commitment is constructed in the same manner as the original key for the wallet.

  const dataHash = getDataHashSecp256k1(newPrivateKey);
  const newKey = getKeyspaceKey(vkHashEcdsaAccount, dataHash);
  const newKey254 = toHex(fromHex(newKey, "bigint") >> BigInt(2), { size: 32 });
  const signature = await sign({ hash: newKey254, privateKey: currentPrivateKey });
  const signatureData = encodePackedSignature(signature);

Generate an Account Circuit Proof

With a signature of the newKey, anyone can generate the Account proof needed to change the key. The proving key for these circuits can be quite large: our EcdsaAccount circuit has a 96MB proving key:

-rw-r--r--  1     65M Mar 13 14:57 51baa0cc62607033629f491a79cca59244f2d3b4d122d5dabb4f5c3d18a35155.ccs
-rw-r--r--  1     96M Mar 13 14:57
-rw-r--r--  1     48K Mar 13 14:57 51baa0cc62607033629f491a79cca59244f2d3b4d122d5dabb4f5c3d18a35155.vk

Other than the size, the other obstacle to letting users generate their own proofs is that it isn't straightforward to compile gnark circuits into the WebAssembly we need for JavaScript clients.

Instead, we expect wallet vendors to run their own wallet support services that includes an mksr_recover RPC call for their users to use.

With that service available, the client can fetch the zero-knowledge proof they need to change their key:

  const recoverResult = await recoveryClient.getSignatureProof({
    signature: signatureData,

mksr_recover returns the proof, current verification key, and the current data in the wallet's Keyspace record.

Set the New Configuration

With those values, you have everything you need for an mksr_set call, which sends your proof to the sequencer and updates the Keyspace state on your behalf.

  await keyspaceClient.setConfig({

Keyspace RPC API

mksr_proof: generate a state proof for a given key


  • key: keystore key
  • vkHash: keccak256(verification key) >> 8
  • dataHash: keccak256(account data) >> 8


curl -H "Content-Type: application/json" \
  -d '{"id":0,"jsonrpc":"2.0","method":"mksr_proof","params":["0x41f3582833f849b9cbe51c7eb3e86effde1cebf94af99fc752fab6481fb0cfc","0x7d36e133ab7f897fb8f97dec38a69fb083f5cd282717da9a0bc51986cc19b7","0x96b36c7046c67e8165814c3bd34ea0f13e5e731228b362e1efae54980b3107"]}'

mksr_get: get the current value for a given key


  • key: keystore key


curl -H "Content-Type: application/json" \
  -d '{"id":0,"jsonrpc":"2.0","method":"mksr_get","params":["0x48245f681e532926c9435f6aed714e368cea1070ccf9c77352fbb1dc42fe232"]}'

mksr_set: change the current value for a given key


  • key: keystore key
  • newKey: new keystore key
  • currentVk: verification key
  • currentData: account data
  • proof: state proof


curl -H "Content-Type: application/json" \
  -d '{"id":0,"jsonrpc":"2.0","method":"mksr_set","params":["0x48245f681e532926c9435f6aed714e368cea1070ccf9c77352fbb1dc42fe232","0x1c882cabbc2303d8a1eb20e62a35b40d5378ecdbc1ed71ed41f659da1d0d4c31","0x...","0x...","0x..."]}'