Skip to main content

Signer keys

Your signer key signs every trade and transfer from a user's wallet. Where it lives decides what you can build, and you choose it before you create the user. How requests and signing work covers the other key, the one that signs you in.

What the signer key controls​

A signer key is a P-256 key pair whose public half you register on a user when you create them. Every trade or transfer from that user's wallet needs two approvals: a signature from the signer key, and an approval from True Markets. Neither side can move funds on its own.

The wallet itself runs on Turnkey. Its private key is generated inside a secure enclave, a sealed environment that no person can read from, and it never leaves. Nobody holds that key: not Turnkey, not True Markets, not you. What you hold is signing authority.

Where the signer key lives shapes the product you build. There are two common setups.

One key for your organization
Your servers
one signer key
Wallets
cust_7781
cust_7782
cust_7783
Orders go through without prompting the user.
That one key can sign for every user.
One key per user
Each user's device
key A
key B
key C
Wallets
cust_7781
cust_7782
cust_7783
Nothing moves without that user.
You build a signing step and a recovery flow.

One key for your organization​

Generate one key pair, register the same public key on every user, and sign on your servers. Orders go through without prompting the user, which suits one-tap buying and automated strategies.

That key can sign for any of your users, so guard it the way you guard a production database credential.

One key per user​

Each user gets their own key pair, and you register its public key. Every order is signed with that user's key, so nothing moves without them, and you never hold a key that can spend their funds.

You and your user decide how the key is created, stored and recovered. The trade-off is a signing step in your product, and a recovery flow you design.

Register the signer key​

You choose per user, when you create them, by sending signer_public_key: a 33-byte compressed P-256 public key as 66 hex characters.

Losing the signer key loses the wallet

There's no way to rotate a signer key yet. If you lose it, that user's wallet can never sign again, and we can't recover it. Keep the key in an HSM or a secrets manager, with a backup, and decide where it lives before you create real users.

How the signer key signs​

How requests and signing work shows the signature format, a version with no dependencies, and the Turnkey libraries that build it for you.

Next: User accounts