# Thetanuts Wallet > A user-managed, passkey-protected EOA keyring plus hosted WebAuthn authentication and encrypted storage for registered Thetanuts application origins. Decryption, WebAuthn PRF evaluation and transaction signing stay in the browser. - [My wallets](https://wallet.thetanuts.finance/): Create a central vault, import or create EOAs, switch wallets, add a passkey, lock the keyring and view recovery keys. - [Developer overview](https://wallet.thetanuts.finance/developers): Current integration modes, Ranger pilot status and the central connector boundary. - [Integration notes](https://wallet.thetanuts.finance/integration-notes): Exact origin/RP registration, client requirements, rollout and testing. - [API v1](https://wallet.thetanuts.finance/api): Authentication, encrypted records, revisions, errors and idempotency. - [OpenAPI](https://wallet.thetanuts.finance/openapi.json): Machine-readable API contract. - [Security and recovery](https://wallet.thetanuts.finance/security): Threat model, recovery paths, unsupported capabilities and reporting guidance. ## Current capability The central dashboard is a separate `wallet.thetanuts.finance` tenant and WebAuthn RP. Ranger is an embedded pilot with its own `ranger.thetanuts.finance` tenant and RP. Passkeys and encrypted vaults do not cross those origins automatically. A separate-origin popup connector for reusing the central keyring across subDAOs is in design review and is not a production API. Do not send private keys, recovery keys, PRF outputs or authorization tokens to documentation or support endpoints. The service cannot decrypt saved wallets and does not provide administrator or email recovery.