https://api.finrock.io.
1
Generate Your RSA Key Pair
Finrock authenticates API requests using JWT tokens signed with your RSA-4096 private key. You share the public key with Finrock; your private key never leaves your infrastructure.Run the following commands to generate a 4096-bit RSA key pair:This produces two files:
private_key.pem— your signing key; store this securely and never commit it to source controlpublic_key.pem— the key you upload to Finrock in the next step
2
Get Your API Key
Log in to the Finrock Control Panel and navigate to API Users. Create a new API User, then:
- Upload the contents of
public_key.pemwhen prompted for your RSA public key. - Copy the API Key UUID that is generated — it looks like
4466c45a-7b28-4c50-a0f7-198f8d7f34c5.
sub field in your JWT payload and as the value of the x-api-key header on every authenticated request.Each API User has its own key pair and permission scope. Create separate API Users for different environments (development, staging, production) or for different services within your organisation.
3
Build and Sign Your JWT
Every authenticated request to the Finrock API requires a JWT token signed with RS256 (RSASSA-PKCS1-v1_5 with SHA-256). The JWT payload must contain the following fields:Attach two headers to every authenticated request:See the Authentication guide for additional language examples and a full breakdown of the JWT specification.
The following Node.js example shows how to build and sign a JWT for an authenticated request:
4
Create a Wallet
With your credentials ready, create your first MPC wallet by posting an asset identifier to the create-wallet endpoint. Finrock provisions the wallet and distributes key shares across your configured MPC nodes.Replace
<JWT> with a token generated for the URI /dac/v1/create-wallet and the body {"asset":"BTC"}. Replace <your-api-key> with your API Key UUID.On success you receive a 200 response containing the wallet ID and asset details. Save the wallet ID — you will reference it when generating addresses and submitting transactions.The
asset value must match an entry from the supported assets list. Use the exact asset identifier string shown there, for example BTC, ETH, or SOL.5
Generate a Deposit Address
Generate a blockchain address under your new wallet to start receiving funds. Each address can be labelled to track its purpose and optionally configured for automatic gas refills.The
label field helps you identify the address’s purpose later. Setting omnibus: false creates an isolated address dedicated to a single wallet. Set auto_refill: true if you want Finrock to automatically fund gas from your Gas Tank when this address initiates EVM transactions.The response includes the generated blockchain address string that you can share with depositors or use in your payment flows.6
Send a Transaction
Submit an outbound transaction from your wallet using the transaction endpoint. Finrock coordinates the MPC signing ceremony across your nodes and broadcasts the signed transaction to the network.Key fields in the transaction request:
The response returns a transaction ID and initial status. Transaction signing and network broadcast happen asynchronously; use webhooks to track completion.
Next Steps
You have completed the core integration flow. Explore these topics to build out the rest of your integration:Authentication Deep Dive
Understand every JWT field, see multi-language code snippets, and review security best practices.
Gas Tanks
Learn how to fund and manage gas tanks so EVM transactions always have enough gas.
AML Controls
Integrate address screening and automatic transaction blocking for compliance.
Webhooks
Subscribe to transaction and wallet events for real-time updates in your application.