zkLogin FAQ
Which providers work?
Google, Apple, Twitch, and Facebook. A JWT from another issuer gets 400 UNSUPPORTED_ISSUER.
Is it custodial?
No. The ephemeral key is made in your app and stays there. Inodra never sees it and cannot sign for a user. Inodra supplies the salt and the proof only. See Security.
What if Inodra is down?
- Sessions that have a proof keep signing. Signing and execution do not call the zkLogin service.
- New logins need the service. They fail until it is back.
- Funds are never at risk. The address is on Sui, not at Inodra.
Can I use my own prover?
Yes. The address response includes the salt. Send the JWT, the salt, and the ephemeral key data to your prover. The proof is valid for the same address.
Why did my user get a different address?
There are two causes:
- A different client ID. Google and Apple issue a client ID for each platform. Use one shared client ID on web, iOS, and Android. See The client ID rule.
- A different organization. Each Inodra organization has its own tenant seed. The same user gets a different address under each organization.
A different provider also gives a different address. A Google login and an Apple login are two identities.
Can I use it in an iOS or Android app?
Yes. Use one Web application client on every platform, return from Google through a small HTTPS relay page, and keep the API key on your server. See Native iOS and Android.
Why do I get MAX_EPOCH_OUT_OF_RANGE?
Your epoch comes from a different network than your API key. A new organization's default project is on mainnet. Read the epoch from the key's network, then sign in again, because maxEpoch is part of the nonce.
How long does a proof take?
About 3 seconds. Get one proof for each session and use it for every transaction until maxEpoch passes. If all prover slots are in use, you get 503 PROVER_BUSY with a Retry-After header.
How many proofs can I get?
zkLogin needs a paid plan. Each paid plan has a cap on proofs per minute, from 20 on Team to 300 on Business. Enterprise has no cap. See Proof rate caps.
Does it work with the Fuel Station?
Yes. Send the zkLogin signature as userSignature to POST /v1/gas/submit. The key needs the zkLogin and Sponsor scopes. See Make it gasless.
Does it work on devnet?
No. Mainnet and testnet only. A devnet key gets 400 NETWORK_NOT_SUPPORTED.
What happens if I remove a client ID?
Logins with that client ID stop with 403 AUDIENCE_NOT_ALLOWED. Addresses never change. Add the client ID again and the same users get the same addresses.
Am I charged for failed requests?
A failed request costs at most 2 credits, never 50. Responses with status 5xx and 429 are not charged. See Billing.
How do I leave Inodra?
- Store the salt from each address response as users log in.
- Run your own salt service and prover, or use another one, with those salts.
Every address stays the same. Tenant seed export is planned. It will cover users who have not logged in since you started to store salts. See No lock-in.