SESSION KEY
SESSION KEY / PASS 001

SESSION KEY

AN AGENT SIGNS WITH A KEY THAT EXPIRES BEFORE IT CAN DO MUCH HARM.

An experiment in borrowed authority, short deadlines, and letting software act without giving it everything.

EXPIRED
ISSUED TO: AGENT-09
PASS #8841-A
ACTIVE
DELEGATED SCOPE
SCOPE: PAY | MAX: 5.0 SOL
// SESSION KEY / PASS STATUS
master keyat home
session keyissued
scopenarrow
expiry10s remaining
*Visual illustration, not live telemetry.
01 / ARCHITECTURAL PRINCIPLE

NOBODY SHOULD HOLD THE REAL KEY ALL DAY.

Software now acts on our behalf: it pays, posts, trades, signs. The lazy way to let it is to give it the key that controls everything and hope. The careful way is older than computers: issue a pass that opens one door, for one afternoon. If it is lost or abused, the loss has an edge and an end.

WHO → WHAT → UNTIL WHEN
02 / BROWSER DEMONSTRATION

MAKE A KEY. GIVE IT SIXTY SECONDS.

Real Web Crypto API demonstration running entirely in your browser memory.

Click 'ISSUE A PASS' to generate non-extractable ECDSA P-256 keys in browser memory.
1. Master Signature on Grant UNCHECKED
2. Session Signature on Message UNCHECKED
3. Verifier Policy (Scope & Expiry) UNCHECKED
* The signature never stops being valid. The verifier stops accepting it.
* Keys are generated in this tab, held in memory, and gone when you close it. This page uses P-256 because every browser supports it; Solana itself uses Ed25519. Nothing here touches a wallet or a chain.
03 / BOUNDARIES

A KEY WITH THREE EDGES.

A session key is useful because of the statement attached to it. That statement limits three things:

01 — SCOPE

WHAT IT MAY SIGN

One kind of action, not all of them. Restricts execution capabilities to specific functions.

02 — CEILING

HOW MUCH

A cap on amount or count. Limits total potential monetary exposure or operation frequency.

03 — EXPIRY

UNTIL WHEN

After that, verifiers say no. The key's authority terminates automatically by clock reading.

MASTER SIGNS GRANT → SESSION SIGNS ACTION → VERIFIER CHECKS BOTH
* These limits are enforced by whoever verifies (a program or smart account), not by the key. A session key does not stop a compromised agent from doing everything the grant allows until it expires, does not undo actions already taken, and does not protect the master key if that is stored carelessly. It shrinks the blast radius; it does not remove it.
04 / DIALOGUE

PERMISSION DENIED, POLITELY.

$ session issue --scope pay --max 5 --ttl 10m
session: sk_7f3a...c21e
scope: pay <= 5
expires: in 10 minutes
> agent: can i have the master key?
no.
> agent: it would be faster.
it would.
> agent: sign this for me then.
your pass expired four seconds ago.
05 / RULES OF RESTRAINT

TERMS OF THE PASS.

  • 01. Authority should be lent, not given.
  • 02. Every permission needs an end time.
  • 03. Narrow is a feature.
  • 04. A limit nobody checks is a suggestion.
  • 05. Let it expire.
06 / TOKEN ARTIFACT

SESSION KEY / $SESSION

Session Key is a community-driven Solana meme coin inspired by short-lived keys and the idea that trust should come with a deadline. The token is the cultural artifact. The pass is the story.

PROJECT Session Key
SYMBOL $SESSION
NETWORK Solana
VERIFIED MINT ADDRESS
FgQRNJtqTquEzMukXu4uJPGuEQJPEYzpzwz7Hpjkpump

Disclaimer: Session Key is a meme coin and community experiment. It provides no product, wallet, key service or guarantee of future utility. The token is speculative and may lose all its value. The token itself does not expire.

07 / NARRATIVE SEQUENCE

TIMELINE OF A PASS.

T-MINUS 3
ISSUED

Someone writes the idea on a pass and signs it.

T-MINUS 2
SCOPED

People agree on what it is for and set the bounds.

T-MINUS 1
IN USE

The pass gets handed around and agents sign.

T-ZERO
EXPIRED

Whatever is issued next. Authority returns to zero.

TAKE A PASS

LEND THE KEY. KEEP THE CLOCK.

SESSION KEY / FINAL PASS ACTIVE
VALID UNTIL FURTHER NOTICE IS NOT A POLICY.

Let it expire.