Skip to main content
An active session combines a selected wallet with an unexpired OMS credential. The SDK persists completed session metadata and restores it when you create OMSWallet again.

Read restored session state

OMSWalletSessionState contains completed-session metadata: walletAddress, expiresAt, and authentication metadata in auth. For OIDC, the metadata identifies .idToken or .redirect, the issuer, optional provider details, and an email when OMS returns one. The request-signing credential is separate. Its non-extractable P-256 private key remains Keychain-managed and is not serialized into OMSWalletSessionState. Restoration succeeds only when the completed metadata is unexpired and its Keychain credential can be restored.
A manual PendingWalletSelection is not completed session metadata. It remains in memory only until your app activates a wallet.

Observe expiration

Expired sessions are not activated. Keep the returned observation alive while you need notifications. The callback runs on MainActor.
The event retains the expired session snapshot so you can choose the appropriate reauthentication UI.

List, switch, and create wallets

These operations require the authenticated credential. listWallets() follows all server cursors and returns the complete list.
Create and activate another wallet for the same credential when your product requires one.
Both useWallet and createWallet replace the active wallet while preserving the current session expiry and authentication metadata. Pass walletType: .solana to create a Solana wallet:

Import and activate a wallet

Ethereum imports accept 32 raw bytes or 64 hexadecimal digits with an optional 0x prefix. Solana imports accept a 32-byte seed or 64-byte keypair as raw bytes, or the base58 encoding of either. The SDK encrypts the key locally for the attested import transport and does not persist the plaintext key. The current WaaS key origins are .enclave and .imported; Swift preserves an unrecognized future value as .unknown(String). Attestation failures throw OMSWalletError with code .attestationVerificationFailed.
Development uses Nitro debug-mode attestation. Use only disposable test keys in Development. Staging and Production verify against SDK-pinned enclave measurements.

Understand access objects

Keep these three objects distinct: The OIDC provider ID token used during authentication is a fourth object: it is app-owned identity proof consumed as auth input, not an OMS wallet token.

Request a wallet ID token

Call getIdToken() only after a wallet is active. Send the returned string to a backend that verifies it using the OMS issuer and JWKS flow described in backend wallet verification.
Custom claims originate in the client. Your backend should not treat them as trusted authorization state unless it controls how they are assigned.

List and revoke access grants

Use listAccess() to load all access-grant pages for account-management UI.
Use the async sequence when your UI should process one server page at a time.
You can also request one page with listAccessPage(pageSize:cursor:type:). Revoke only a grant whose credential has isCaller == false:
For a remote grant, sessionId is required and revokes exactly that session. Revocation cannot be undone. Revoking the caller invalidates the credential making the current request and prevents subsequent protected operations from that session. Keep caller revocation out of the normal access-management UI.

Authorize remote access

Remote access grants are bounded EVM smart sessions. Inspect the remote credential and show its returned metadata to the wallet owner before requesting approval: This example uses Polygon Amoy. Grant limits are raw EVM base-unit amounts. A native-transfer limit is cumulative, so 1000000000000000 wei authorizes up to 0.001 POL across the session.
WaaS caps the requested session expiry at the remote credential’s expiry. Backend credential registration and remote execution are outside the Swift SDK; implement them with the TypeScript SDK’s backend smart sessions guide.

Sign out

Signing out clears the completed session, Keychain credential, pending redirect state, and pending wallet selection for this SDK scope. It does not revoke other access credentials on the wallet.