Home › Features › Mobile Co-signer
Features · a key share in your pocket

The signature that lives in your pocket

Not a push-approve button — a full MPC signing party

The Vaultody mobile app holds one of the three key shares in your phone's hardware keystore behind biometrics. When you approve a transfer, the phone runs real MPC signing rounds. No phone, no signature — that is the guarantee.

Share the Trust, Guard the Keys

Create accountLive on testnet in an afternoon
Compare PlansIncluded in a plan, not an add-on
The problem

“Approved on my phone” and “signed on my phone” are not the same sentence

Most custody apps send a push notification: you tap approve, and a server somewhere produces the signature. The Vaultody app embeds a real MPC node. It runs distributed key generation, holds one of the committee's shares in the phone's hardware keystore, and computes signature rounds on the device. Without the phone, there is no signature.

  • Two different acts, one appApproving is an organisational decision under your policy; signing is a cryptographic act by a key-share holder. The app does both — and they are not the same event, even when the same person performs them seconds apart.
  • A signing party, not a buttonThe app participates in keygen and in every signing round — it is the client party the protocol requires.
  • The share sits in hardwareKeychain on iOS, Keystore on Android, behind biometrics and a PIN. The share does not leave the device.
  • Losing the phone is a ceremony, not a catastropheA reshare rotates every share onto a new device while keeping the public key — and therefore every address — unchanged.

How it works

Cryptographic participation, not consent theater

The app embeds the same MPC engine as the platform: it runs distributed key generation at vault creation (QR-scanned ceremony) and full signing rounds on every approval — ECDSA and EdDSA both, so Solana approvals are as native as Ethereum's.

  • Key share in Keychain (iOS) / Keystore (Android), biometrics + PIN
  • Participates in keygen, signing, and governance approvals
  • Backs the share up RSA-encrypted to your own storage
pending your signature
T
Transfer
84,000 USDT → settlement
policy: 2-of-2
F
Face ID
key share unlocked
verified
M
MPC rounds
signature computed on-device
signed
Specification

Co-signer specification

What actually happens on the device.

TopologyTwo Vaultody server nodes plus the device party — 3-of-3, with the device mandatory.
EnrolmentThe device joins the committee through a QR-scanned key ceremony at vault creation.
CryptographyReal signature rounds on device for both curve families, so Solana approvals behave like Ethereum ones.
ProtectionHardware-backed key storage with biometrics plus PIN; the app also backs its share up RSA-encrypted to storage you control.
Approver vs signerAn approver authorises a request under the transaction policy; a signer contributes a share to the signature. The app carries both roles, and a rule counts approvers, not signatures.
GovernanceThe device shows what a request is authorising before any signing round runs, so consent precedes cryptography.
Lost deviceReshare onto a new phone; the old share is revoked and no address changes.
Hands-off flowsPair the phone with a server co-signer when transactions must clear outside working hours.
IncludedPart of every plan — the mobile co-signer is not an add-on.

Frequently asked questions

Get answers to commonly asked questions.

What if the phone is offline?

The transaction waits at pending-signature until the signer is available — or your server co-signer handles flows you have made automatic.

Can several people have signing phones?

Yes — thresholds extend to 3-of-4 and 3-of-5 with additional client-side parties; each extra party is yours, never ours.

What if the phone is lost?

Restore from your RSA-encrypted backup, or run a reshare — same addresses, new shares, funds untouched.

Share the Trust Guard the Keys

The difference between a button and a key.