> ## Documentation Index
> Fetch the complete documentation index at: https://apidocs.finrock.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Finrock: Institutional Digital Asset Custody Platform

> Finrock is an MPC-powered platform for secure digital asset custody and transactions. Learn how threshold cryptography keeps your keys safe.

Finrock is an institutional digital asset custody and API platform built for businesses that need to store, receive, and send digital assets without ever exposing a complete private key. By combining Multi-Party Computation (MPC) wallet architecture with a developer-friendly REST API, Finrock gives treasury teams and engineering teams a single, secure foundation for managing crypto at scale.

## Who Finrock Is For

Finrock is designed for businesses that require enterprise-grade security controls alongside programmatic access to blockchain networks. Whether you are running a crypto exchange, a payment processor, a fintech product, or an institutional trading desk, Finrock handles the complexity of key management and transaction signing so your team can focus on your product.

## MPC Wallet Architecture

Traditional cryptocurrency wallets generate and store a single private key. If that key is compromised, all funds are at risk. Finrock eliminates that single point of failure through **threshold cryptography**.

Instead of creating one private key, Finrock's Distributed Key Generation (DKG) protocol splits the key mathematically into multiple independent shares. These shares are distributed across separate signing nodes. At no point during key generation or during transaction signing is the full private key ever assembled in one place — not on Finrock's servers and not on your infrastructure.

<Note>
  The full private key is never reconstructed at any point. Each signing node holds only a cryptographic share, and shares are combined through the MPC protocol to produce a valid blockchain signature without any single node knowing the whole key.
</Note>

### Supported Signing Algorithms

Finrock MPC wallets support the cryptographic algorithms required by the major blockchain ecosystems:

| Algorithm | Curve     | Used By                                          |
| --------- | --------- | ------------------------------------------------ |
| ECDSA     | secp256k1 | Bitcoin, Ethereum, and all EVM-compatible chains |
| EdDSA     | Ed25519   | Solana and other Ed25519-based networks          |

### Common MPC Threshold Configurations

The threshold defines how many of the total key shares must participate to produce a valid signature. Common configurations include:

* **2-of-3 MPC** — any two of three nodes must co-sign; one node can be offline or unavailable
* **3-of-5 MPC** — three of five nodes must co-sign; provides stronger fault tolerance
* **Custom enterprise thresholds** — Finrock supports custom configurations to match your security policy and operational requirements

Only the required number of participating nodes can jointly produce a valid digital signature. A compromised or unavailable minority of nodes cannot sign anything on their own.

## MPC Node Architecture

Each wallet's key shares are distributed across independent signing nodes deployed in separate infrastructure environments. A typical three-node deployment looks like this:

| Node       | Environment                              | Description                                                         |
| ---------- | ---------------------------------------- | ------------------------------------------------------------------- |
| **Node A** | AWS or Azure VM                          | Application server node; co-located with your backend services      |
| **Node B** | Finrock Mobile App                       | User-controlled node; requires explicit mobile approval for signing |
| **Node C** | Separate cloud or on-premise environment | Backup or disaster recovery node                                    |

Nodes communicate with each other exclusively through secure, encrypted peer-to-peer channels during signing operations. Your server-side KMS (Key Management Server) node is deployed as a Docker container on your own infrastructure — Finrock's backend servers have no access to your key shares at any time.

<Info>
  The Finrock Cloud Signer (KMS) runs as a Docker container on your infrastructure with **egress-only** networking. All inbound traffic must be blocked. The container is available at [hub.docker.com/r/finrock/signer](https://hub.docker.com/r/finrock/signer).
</Info>

## Transaction Signing Workflow

When your application submits a transaction request to the Finrock API, the platform orchestrates the MPC signing ceremony across the required threshold of nodes. Each participating node contributes its key share to compute a partial signature. The partial signatures are combined cryptographically to produce a complete, valid blockchain signature — again, without any node ever holding the full private key.

The signed transaction is then broadcast to the appropriate blockchain network by Finrock on your behalf. You receive a transaction ID and status updates through the API or via webhooks.

## Navigate the Documentation

<CardGroup cols={2}>
  <Card title="Quickstart" icon="bolt" href="/quickstart">
    Generate credentials, create your first MPC wallet, and send a transaction in minutes.
  </Card>

  <Card title="Authentication" icon="key" href="/authentication">
    Learn how to generate RSA-4096 key pairs, build JWT tokens, and authenticate every API request.
  </Card>

  <Card title="Core Concepts" icon="cubes" href="/concepts/mpc-wallets">
    Understand wallets, addresses, gas tanks, AML controls, and the full Finrock data model.
  </Card>

  <Card title="API Reference" icon="code" href="https://api.finrock.io">
    Explore the full REST API with live request examples and schema documentation.
  </Card>
</CardGroup>
