Who Finrock Is For
Finrock is designed for businesses that require enterprise-grade security controls alongside programmatic access to blockchain networks. Whether you are running a crypto exchange, a payment processor, a fintech product, or an institutional trading desk, Finrock handles the complexity of key management and transaction signing so your team can focus on your product.MPC Wallet Architecture
Traditional cryptocurrency wallets generate and store a single private key. If that key is compromised, all funds are at risk. Finrock eliminates that single point of failure through threshold cryptography. Instead of creating one private key, Finrock’s Distributed Key Generation (DKG) protocol splits the key mathematically into multiple independent shares. These shares are distributed across separate signing nodes. At no point during key generation or during transaction signing is the full private key ever assembled in one place — not on Finrock’s servers and not on your infrastructure.The full private key is never reconstructed at any point. Each signing node holds only a cryptographic share, and shares are combined through the MPC protocol to produce a valid blockchain signature without any single node knowing the whole key.
Supported Signing Algorithms
Finrock MPC wallets support the cryptographic algorithms required by the major blockchain ecosystems:Common MPC Threshold Configurations
The threshold defines how many of the total key shares must participate to produce a valid signature. Common configurations include:- 2-of-3 MPC — any two of three nodes must co-sign; one node can be offline or unavailable
- 3-of-5 MPC — three of five nodes must co-sign; provides stronger fault tolerance
- Custom enterprise thresholds — Finrock supports custom configurations to match your security policy and operational requirements
MPC Node Architecture
Each wallet’s key shares are distributed across independent signing nodes deployed in separate infrastructure environments. A typical three-node deployment looks like this:
Nodes communicate with each other exclusively through secure, encrypted peer-to-peer channels during signing operations. Your server-side KMS (Key Management Server) node is deployed as a Docker container on your own infrastructure — Finrock’s backend servers have no access to your key shares at any time.
The Finrock Cloud Signer (KMS) runs as a Docker container on your infrastructure with egress-only networking. All inbound traffic must be blocked. The container is available at hub.docker.com/r/finrock/signer.
Transaction Signing Workflow
When your application submits a transaction request to the Finrock API, the platform orchestrates the MPC signing ceremony across the required threshold of nodes. Each participating node contributes its key share to compute a partial signature. The partial signatures are combined cryptographically to produce a complete, valid blockchain signature — again, without any node ever holding the full private key. The signed transaction is then broadcast to the appropriate blockchain network by Finrock on your behalf. You receive a transaction ID and status updates through the API or via webhooks.Navigate the Documentation
Quickstart
Generate credentials, create your first MPC wallet, and send a transaction in minutes.
Authentication
Learn how to generate RSA-4096 key pairs, build JWT tokens, and authenticate every API request.
Core Concepts
Understand wallets, addresses, gas tanks, AML controls, and the full Finrock data model.
API Reference
Explore the full REST API with live request examples and schema documentation.