Mode A — Orka-managed
Easy- Sign-in
- Email / Google (Supabase JWT)
- Chain key
- ORKA-provisioned Stellar key, encrypted in KMS
- Who signs
- Rust backend, after verifying JWT + session
- Gas
- ORKA operator-sponsored — zero for the user
- Recovery
- Reset password → re-grant KMS access
- Custody
- Custodial (ORKA is custodian)
Mode B — Self-custody
Expert- Sign-in
- Freighter wallet connect
- Chain key
- The user's own Freighter key
- Who signs
- Freighter, in-browser
- Gas
- ORKA operator-sponsored — zero for the user
- Recovery
- The user's own seed phrase
- Custody
- Non-custodial