Skip to main content
Privy integration hero

Overview

Privy provides secure, server-side key management for Starknet wallets. With Privy, you can:
  • Create and manage Starknet wallets for users
  • Sign transactions server-side without exposing private keys
  • Support social login and email-based authentication
  • Integrate with existing Privy authentication flows
Privy supports Starknet as a Tier 2 chain, allowing you to use Privy’s raw sign functionality for transaction signing.

Why Use Privy?

  • ✅ Security: Private keys never leave Privy’s secure infrastructure
  • ✅ User Experience: Social login and email-based authentication
  • ✅ Server-Side Signing: Sign transactions on your backend
  • ✅ Multi-Chain: Same infrastructure for multiple blockchains
  • ✅ Gasless Transactions: Configure AVNU Paymaster for sponsored transactions (see AVNU Paymaster Integration)

Wallet ownership model

Privy supports two ways to use wallets. Choosing the wrong one can lead to JWT or auth errors, so use this as a guide:
  • Server-managed: Create wallets without an owner (omit owner). Your backend signs with PrivyClient (app credentials) and no end-user JWT is required. Create with just { chain_type: "starknet" }. Best for custodial / backend-only flows.
  • User-owned: Create wallets with owner: { user_id } (the user’s DID) so the wallet is tied to a Privy user; access and signing then require that user’s JWT. This is the model the examples below use — the client authenticates with a Privy client SDK, and the backend verifies the token before creating/using the wallet.
Note: owner: { user_id } takes the user’s DID (did:privy:...). The separate owner_id field expects a cuid2 key-quorum id, not a user DID — passing a DID there fails with an Invalid cuid2 error.

Setup

1. Install Privy

2. Initialize Privy Client

3. Create a Starknet Wallet

Integration with Starkzap

Server-Side Signing Endpoint

Create an endpoint that signs transaction hashes using Privy:

Client-Side Integration

The access token comes from a Privy client SDK — @privy-io/js-sdk-core (vanilla JS/Svelte/Vue), @privy-io/react-auth (React), or @privy-io/expo (React Native) — after the user logs in. The @privy-io/node PrivyClient shown above is server-only and has no getAccessToken(). Below, privy refers to the initialized client SDK instance.
Use Privy with Starkzap:

Complete Example

Backend (Express.js)

Frontend

React Native Integration

For React Native applications, use @privy-io/expo:

Resources

Best Practices

  1. Never expose private keys - Always use server-side signing
  2. Authenticate requests - Verify user identity before signing
  3. Use HTTPS - Always use secure connections for signing endpoints
  4. Handle errors gracefully - Provide user-friendly error messages
  5. Monitor usage - Track wallet creation and signing operations