Rather than forcing users to save a seed phrase or download MetaMask, you give them login via Google, Apple, or email. This isn't just convenience—it's conversion. Your dApp's potential audience is ten times wider when you remove the barrier of installing an extension. We use Web3Auth to solve this without security compromises. By our estimates, Web3Auth increases onboarding conversion by 3–5 times compared to manual seed phrase entry.
Under the hood, it's threshold cryptography (MPC/TSS). On registration, a key pair is generated, and the private key is split into three shares: one stored on Web3Auth nodes (tKey), one locally in the browser (deviceShare), and one optional backup (e.g., password). Signing a transaction requires any two of the three shares. Web3Auth never holds the full key. Even if an attacker compromises their infrastructure, they can't access user funds.
How does threshold cryptography protect users?
Unlike a seed phrase stored in one place and prone to theft, MPC distributes trust. Each share is isolated, and the threshold (2 of 3) means compromising one node doesn't grant access to the key. This is a security standard used in banking systems. As noted in the Web3Auth documentation, threshold cryptography eliminates the single point of failure.
How does access recovery work?
User lost their device? No problem. They log in again through the same OAuth provider, and the system restores the backup share (if configured) or generates a new deviceShare upon confirmation via a second factor (backup password). This is a hybrid of self-custody and managed wallet: you retain control over keys, but the user doesn't need to remember anything.
Why choose Web3Auth for your dApp?
Web3Auth returns a standard EIP-1193 provider, meaning your existing code using ethers.js, viem, or wagmi works unchanged. You simply replace window.ethereum with the provider from Web3Auth. The entire stack (signTypedData, sending ETH, interacting with contracts) remains the same. No vendor lock-in: you can switch to a different key abstraction at any time.
Comparison of Modal and NoModal SDK
| Criterion | Modal SDK | NoModal SDK |
|---|---|---|
| Integration time | 1-2 days | 1-2 weeks |
| UI customization | Limited (branding) | Full (any interface) |
| Provider flexibility | Preset buttons | Any OAuth adapters of your choice |
| Suitable for | MVPs, prototypes | Production dApps with unique UX |
Integration Process
1. Analysis
We define the target audience, list of OAuth providers, white-label requirements, and UI customization needs. We select the SDK version: Modal (ready UI) or NoModal (logic only).
2. Design
We design the authentication flow: registration, login, recovery, session revocation. We determine backup mechanisms (password, social backup). We integrate with your backend authorization (JWT tokens, sessions).
3. Implementation
We configure the Web3Auth Dashboard, obtain a clientId. We connect the SDK and implement login/logout calls. Example code below shows a basic modal integration:
import { Web3Auth } from '@web3auth/modal' import { CHAIN_NAMESPACES } from '@web3auth/base' const web3auth = new Web3Auth({ clientId: 'YOUR_CLIENT_ID', chainConfig: { chainNamespace: CHAIN_NAMESPACES.EIP155, chainId: '0x1', rpcTarget: 'https://rpc.ankr.com/eth' } }) await web3auth.initModal() // Login — modal with Google/Twitter/Email/Apple const provider = await web3auth.connect() // Then use as a standard EIP-1193 provider const ethersProvider = new ethers.BrowserProvider(provider) const signer = await ethersProvider.getSigner() 4. White-label and Customization
For production, you'll typically want your own branding. We use NoModal SDK:
import { Web3AuthNoModal } from '@web3auth/no-modal' import { OpenloginAdapter } from '@web3auth/openlogin-adapter' const web3auth = new Web3AuthNoModal({ clientId, chainConfig }) const openloginAdapter = new OpenloginAdapter({ adapterSettings: { uxMode: 'redirect', whiteLabel: { appName: 'My App', logoLight: 'https://example.com/logo.png', defaultLanguage: 'ru' } } }) web3auth.configureAdapter(openloginAdapter) await web3auth.init() // Call specific provider await web3auth.connectTo('openlogin', { loginProvider: 'google' }) 5. Testing
We verify all scenarios: first login, repeat, device loss, access revocation. We use testnets (Goerli, Sepolia). We check transaction signing latency — MPC adds ~100-300 ms, imperceptible to the user.
6. Mainnet Deployment
We change the RPC, update the clientId for production, enable backup mechanisms. We set up monitoring via Tenderly.
More about backup mechanisms
The backup share can be stored as a password-encrypted file or via a social factor (the same OAuth). In case all devices are lost, the user authenticates via the provider and confirms the backup password — this restores access. Our engineers help configure the optimal backup strategy for your audience.
What's included in the work
- Selection of Web3Auth configuration (number of shares, threshold, backup)
- Setup of OAuth providers (Google, Apple, Twitter, Discord, GitHub)
- UI implementation: ready modal or fully custom interface
- Integration with existing authorization system (JWT, sessions)
- Code in TypeScript/React/Vue with ethers.js, viem, wagmi support
- Admin documentation for Web3Auth Dashboard
- Testing of secure scenarios (recovery, key revocation)
- Guarantee: we support the code for 3 months after integration
Timelines and Cost
| Stage | Time |
|---|---|
| Basic integration (Modal) | 1-2 days |
| White-label (NoModal) | 1-2 weeks |
| Full cycle + backend | 2-4 weeks |
Cost is calculated individually — depends on UI complexity, number of providers, and security requirements. We produce a project estimate within 1 day: send your dApp description and target audience. Get a consultation from an engineer who has implemented Web3Auth in 12+ dApps, including DeFi platforms and NFT marketplaces. Our experience — 5 years in Web3, 30+ successful integrations. We guarantee stable mainnet operation and support for new standards (ERC-4337, EIP-3074).
Want to remove the barrier to entry for your users? Contact us — we'll evaluate your project and propose a turnkey architecture.







