Skip to main content
Install an API Co-signer in three stages: prepare the platform, register the Co-signer in the workspace and copy the pairing token, then run that platform’s installation script.

Prepare the platform

Set up the resources the Co-signer needs, including network access to the domains required for installation and operation. Follow the Install page in your platform’s group for those steps.

Get the pairing token

Create a new API user for the Co-signer. The first pairing needs admin access to the Fireblocks Console, and the workspace Owner must be available to approve the configuration change. During installation you will use two items from the Console. Copy both before you start:
  • The API user’s pairing token
  • The download link for the installation script that matches your Co-signer type: Intel SGX, AWS Nitro, or Google Cloud Confidential Space

Add an API user

Add an API user in the API users tab of the Console’s Developer Center, or with the create API user API. This API user is how the Co-signer connects to the workspace.
The Co-signer does not use the CSR to connect to the workspace. You still provide one, because the same API user can make API calls.

Add the Co-signer entry

Add the Co-signer in the Co-signers tab of the Console’s Developer Center, or with the Co-signer APIs. Select Add co-signer, then:
  • Enter the Co-signer’s name
  • Select Install a new co-signer on the local machine, then select Continue
  • Choose an API user that is not already paired with a Co-signer
  • Select Add
The Co-signer appears in the Co-signers tab as offline. It connects to the workspace only after you finish installation.

Copy the pairing token and the installation script

Select Pair API user on the new Co-signer, then:
  • Copy the API user’s pairing token. In a Mainnet workspace the token is valid for one hour.
  • Copy the download link for your Co-signer type’s installation package, under Settings > General > API co-signer. The link is valid for seven days.
If you cannot find the installation script download link in the Console, contact Fireblocks Support.

Install and connect

On the Co-signer machine, download the installation package from the link you copied and run the installation script. The Install page for your platform has the commands and the resources that script expects. You will enter the pairing token during installation.

Designate the signer in a Policy rule

After the Co-signer is connected, designate the paired API user as the signer or an approver on a Policy rule. When a transaction or configuration change matches that rule, the Co-signer paired with that API user signs or approves it. See how roles and Policy rules work with a Co-signer.