Prepare the platform
Set up the resources the Co-signer needs, including network access to the domains required for installation and operation. Follow the Install page in your platform’s group for those steps.Get the pairing token
Create a new API user for the Co-signer. The first pairing needs admin access to the Fireblocks Console, and the workspace Owner must be available to approve the configuration change. During installation you will use two items from the Console. Copy both before you start:- The API user’s pairing token
- The download link for the installation script that matches your Co-signer type: Intel SGX, AWS Nitro, or Google Cloud Confidential Space
Add an API user
Add an API user in the API users tab of the Console’s Developer Center, or with the create API user API. This API user is how the Co-signer connects to the workspace.- Enter a name of up to 30 characters
- Select the API user’s role
- Attach a certificate signing request (CSR) file
The Co-signer does not use the CSR to connect to the workspace. You still provide one, because the same API user can make API calls.
Add the Co-signer entry
Add the Co-signer in the Co-signers tab of the Console’s Developer Center, or with the Co-signer APIs. Select Add co-signer, then:- Enter the Co-signer’s name
- Select Install a new co-signer on the local machine, then select Continue
- Choose an API user that is not already paired with a Co-signer
- Select Add
Copy the pairing token and the installation script
Select Pair API user on the new Co-signer, then:- Copy the API user’s pairing token. In a Mainnet workspace the token is valid for one hour.
- Copy the download link for your Co-signer type’s installation package, under Settings > General > API co-signer. The link is valid for seven days.
If you cannot find the installation script download link in the Console, contact Fireblocks Support.