Machine-speed approvals, human-set rules
High-volume operations cannot wait for a tap per transfer. Your automated co-signer authenticates with HMAC-signed requests, joins signing sessions automatically, and signs exactly what your policies allow — everything above threshold still waits for a human.
Share the Trust, Guard the Keys
High-volume flows cannot wait for a tap, and giving a service unlimited signing authority is how a compromised key becomes a company-ending incident. API signing runs the flows you predefine, authenticated per request and bounded by the same policy engine your people answer to.
Every request is HMAC-SHA256 signed and timestamped against replay. The signer holds one share of three — compromising the machine yields a share that cannot sign alone, and policies bound what it could ever have signed.
Everything your integration engineer will ask in the first hour.
Get answers to commonly asked questions.
No — one MPC share of three, policy-bound. There is no key on the server to steal.
You do, and rule changes are approval-gated — automation cannot widen its own mandate.
Standard, Business and Enterprise.
