xKey is a local, offline-first Web3 wallet vault built to manage wallet records, private keys, seed phrases, folders, tags, encrypted backups, Shamir QR recovery, local audit history, manual balances, privacy masking, and offline vanity wallet generation.
The architecture prioritizes local control, explicit secret handling, privacy-preserving UI flows, and a release pipeline that can build Android artifacts from signed git tags.
- UI: React 19 with TypeScript
- Build tool: Vite
- Styling: Tailwind CSS v4 plus project CSS utilities
- Native bridge: Capacitor 8
- Android package:
com.haivcon.xkey - Storage: Capacitor Preferences plus application-level encryption wrappers
- Cryptography: Web Crypto API, CryptoJS utilities, and Android Keystore integrations where available
- Workers: Web Workers for CPU-heavy vanity wallet generation
- Interaction libraries:
@dnd-kit/core,@dnd-kit/sortable,@tanstack/react-virtual,lucide-react - Testing and verification: TypeScript, focused wallet/security tests, Playwright smoke tests, Vite build, and Capacitor Android sync
flowchart TD
UI[React UI] --> Contexts[Vault State and Contexts]
Contexts --> Crypto[Crypto and Vault Utilities]
Contexts --> Storage[Encrypted Local Storage]
UI --> Workers[Web Workers]
Workers --> Vanity[Vanity Wallet Scanner]
UI --> Bridge[Capacitor Bridge]
Bridge --> Android[Android Device Credential and Keystore]
Crypto --> Backup[Encrypted .xkey Backups]
Crypto --> Shamir[Shamir QR Recovery]
The UI does not depend on a custody server. User data remains local unless the user manually exports it.
src/
ββ App.tsx Top-level vault shell, route orchestration, home layout
ββ app/ Constants, app contracts, shared app utilities
ββ components/
β ββ auth/ Unlock, onboarding, and auth error screens
β ββ backup/ Backup export/import UI
β ββ create-wallet/ Create/import/vanity wallet feature module
β ββ entropy/ Advanced entropy and derivation panels
β ββ qr/ QR display, scan, receive, and transfer modals
β ββ settings/ Settings tabs and security/data/info panels
β ββ shamir/ Shamir backup/restore components
β ββ shared/ Shared UI helpers and secure text inputs
β ββ vanity/ Vanity score UI
β ββ wallet/ Wallet card/list/sort/swipe/drop UX
ββ contexts/ Language, theme, toast, confirm, secure display, vault contexts
ββ hooks/ App, backup, security, folder, vanity, and wallet hooks
ββ locales/ Localized string trees
ββ utils/ Storage, crypto, backup, audit, wallet, amount, vanity utilities
ββ types.ts Core wallet and app data models
Top-level folders:
android/ Capacitor Android app, Gradle config, native plugins, release metadata
assets/ Project asset sources
icons/ Icon resources
public/ Static web assets
scripts/ Maintenance and audit scripts
tests/ Unit, focused, and smoke/regression tests
1/ Local scratch/instruction folder; ignored and never pushed
- A vault key is generated or restored locally.
- On Android, the vault key can be protected by Android Device Credential and Android Keystore capabilities.
- Web fallback builds depend on browser storage and the local device environment.
- Sensitive fields such as private keys and seed phrases are hidden by default and revealed only through explicit UI actions.
- Privacy Mode masks wallet names, addresses, balances, dashboard totals, and the Total Assets card where supported.
- Hold-to-reveal allows temporary secret viewing without changing persistent reveal state.
- Vault data is encrypted before persistence.
.xkeybackups are encrypted portable containers controlled by the user.- Backup metadata and tamper-aware structures support safer restore workflows.
- Shamir Secret Sharing QR recovery can split recovery material into shares for offline storage.
- Reed-Solomon resilience is used in backup/storage flows where corruption recovery is supported.
- xKey cannot recover user data without the required key, backup password, or recovery shares.
v6.0.1 keeps the custody/security model unchanged and updates the mobile interaction layer:
HomeHeaderis focused on brand, slogan, donate, and settings actions.- Key Health opens from the Tools menu with badge support.
ActionBaruses a two-column mobile grid: search/add-wallet on the left and camera/filter/tools on the right.- Sorting is part of the filter panel so the mobile toolbar has fewer standalone buttons.
- The Total Assets card owns the compact privacy eye toggle.
- Settings toggle rows reserve more space for icon, title, description, and switch alignment.
The vanity generator runs as an offline CPU-bound workflow. Generated secrets must remain local, hidden until explicit reveal, and bounded by pause/stop and reserve limits.
For v6.0.35:
package.jsonversion:6.0.35package-lock.jsonversion:6.0.35- Android
versionName:6.0.35 - Android
versionCode:133 - Android application ID/package:
com.haivcon.xkey
Release builds are intended to be triggered by git tags matching v*.
Recommended release verification:
npm run type-check
npm run build
npx cap sync androidRelease flow:
- Update app version metadata and documentation.
- Run verification commands.
- Commit only intended source and documentation files.
- Ensure local-only folders such as
1/and build artifacts are ignored. - Create an annotated tag such as
v6.0.35. - Push
mainand the tag to GitHub. - Let GitHub Actions build Android artifacts from the clean tag.
The repository should exclude dependencies, build outputs, APK/AAB/release artifacts, local secrets, Playwright/test outputs, and local instruction or scratch folders such as 1/.