How the desktop app works

zk.money Desktop is a locally-running version of zk.money. The zk.money website is the hosted wallet you reach in a browser at the zk.money domain.

zk.money Desktop runs the same wallet on your own computer, using the passkey you already created on the website, so your funds stay reachable while the website is down.

Nothing zk.money Desktop sets up is permanent. Launching the app starts a local web server and a dedicated Chrome profile, and closing the wallet window shuts both down. There is nothing to configure.

Why zk.money Desktop serves the wallet at wallet.zk.money

A passkey belongs to the site that created it. Yours belongs to auth.zk.money, which publishes a short list of the zk.money sites allowed to use it. The wallet at wallet.zk.money is on that list. Chrome offers your passkey only to a site on the list, which stops any other site from asking for it.

So zk.money Desktop serves the wallet at wallet.zk.money, from your own computer. Three pieces make that work:

  • the wallet is bundled inside zk.money Desktop and served from your own machine,
  • Chrome resolves https://wallet.zk.money to that local server,
  • zk.money Desktop issues an HTTPS certificate for the server, and tells Chrome to trust that one certificate.

All of this is scoped to the Chrome profile zk.money Desktop opens. Your DNS, your operating system and your everyday browser are untouched, and the zk.money website is unchanged.

Chrome still reads the list from the real auth.zk.money, over the internet.

What zk.money Desktop does at launch

  1. Issues an HTTPS certificate for wallet.zk.money. The certificate is generated in zk.money Desktop's data folder, and no public certificate authority signs it, because the certificate never leaves your computer.
  2. Tells Chrome to trust that one certificate, by its fingerprint, rather than turning certificate checking off.
  3. Starts a web server for the bundled wallet. The server accepts connections from your own computer only.
  4. Serves the wallet over that certificate, so the connection is real HTTPS rather than a warning you click through.
  5. Resolves wallet.zk.money to that server, for this Chrome profile alone, so Chrome loads your local wallet instead of the website.
  6. Opens a dedicated Chrome profile, which starts without your extensions, cached files, cookies or old service workers. Signing it in to Google can bring your extensions in; see How to run the desktop app. Your wallet data lives in this profile, separate from your normal browsing.
  7. Shuts the server down when you close the window. Nothing keeps running in the background.

What reaches the internet

Every page, script and image comes from the copy bundled inside zk.money Desktop, and no website assets are fetched from the internet.

An internet connection is still needed for the wallet to do its actual job of reading your balances and sending transactions on the network. At launch zk.money Desktop also asks the zk.money website for its configuration (which contracts to talk to), but every build ships with a copy of that configuration, and falls back to the bundled copy when the website is unreachable. Chrome also reads the passkey list from auth.zk.money, and that has no bundled copy.

zk.money Desktop never handles your passkey

Your passkey never leaves where it is kept, whether that is iCloud Keychain, Google Password Manager, 1Password or a security key. The wallet asks your authenticator for the same operation the zk.money website asks for, and your authenticator applies the same checks it always does. Like the website, the app keeps your secret key in its own browser storage until you sign out.