Signer keys
Your signer key signs every trade and transfer from a user's wallet. Where it lives decides what you can build, and you choose it before you create the user. How requests and signing work covers the other key, the one that signs you in.
What the signer key controls
A signer key is a P-256 key pair whose public half you register on a user when you create them. Every trade or transfer from that user's wallet needs two approvals: a signature from the signer key, and an approval from True Markets. Neither side can move funds on its own.
The wallet itself runs on Turnkey. Its private key is generated inside a secure enclave, a sealed environment that no person can read from, and it never leaves. Nobody holds that key: not Turnkey, not True Markets, not you. What you hold is signing authority.
Where the signer key lives shapes the product you build. There are two common setups.
One key for your organization
Generate one key pair, register the same public key on every user, and sign on your servers. Orders go through without prompting the user, which suits one-tap buying and automated strategies.
That key can sign for any of your users, so guard it the way you guard a production database credential.
One key per user
Each user gets their own key pair, and you register its public key. Every order is signed with that user's key, so nothing moves without them, and you never hold a key that can spend their funds.
You and your user decide how the key is created, stored and recovered. The trade-off is a signing step in your product, and a recovery flow you design.
Register the signer key
You choose per user, when you create them, by sending signer_public_key: a 33-byte compressed P-256 public key as 66 hex characters.
There's no way to rotate a signer key yet. If you lose it, that user's wallet can never sign again, and we can't recover it. Keep the key in an HSM or a secrets manager, with a backup, and decide where it lives before you create real users.
How the signer key signs
How requests and signing work shows the signature format, a version with no dependencies, and the Turnkey libraries that build it for you.
Next: User accounts