> ## Documentation Index
> Fetch the complete documentation index at: https://developers.fireblocks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Install an API Co-signer

> Register an API Co-signer in the Console, copy the pairing token and installation script, then install it on your platform.

Install an API Co-signer in three stages: prepare the platform, register the Co-signer in the workspace and copy the pairing token, then run that platform's installation script.

## Prepare the platform

Set up the resources the Co-signer needs, including network access to the domains required for installation and operation. Follow the **Install** page in your platform's group for those steps.

## Get the pairing token

Create a new API user for the Co-signer. The first pairing needs admin access to the Fireblocks Console, and the workspace Owner must be available to approve the configuration change.

During installation you will use two items from the Console. Copy both before you start:

* The API user's pairing token
* The download link for the installation script that matches your Co-signer type: Intel SGX, AWS Nitro, or Google Cloud Confidential Space

### Add an API user

Add an API user in the **API users** tab of the Console's Developer Center, or with the [create API user](https://swagger.fireblocks.com/#/Api%20User/createApiUser) API. This API user is how the Co-signer connects to the workspace.

* Enter a name of up to 30 characters
* Select the API user's role
* Attach [a certificate signing request (CSR) file](/docs/generate-a-csr-for-an-api-user)

<Note>
  The Co-signer does not use the CSR to connect to the workspace. You still provide one, because the same API user can make API calls.
</Note>

### Add the Co-signer entry

Add the Co-signer in the **Co-signers** tab of the Console's Developer Center, or with the [Co-signer APIs](https://swagger.fireblocks.com/#/Cosigners%20\(Beta\)).

Select **Add co-signer**, then:

* Enter the Co-signer's name
* Select **Install a new co-signer on the local machine**, then select **Continue**
* Choose an API user that is not already paired with a Co-signer
* Select **Add**

The Co-signer appears in the **Co-signers** tab as offline. It connects to the workspace only after you finish installation.

### Copy the pairing token and the installation script

Select **Pair API user** on the new Co-signer, then:

* Copy the API user's pairing token. In a Mainnet workspace the token is valid for one hour.
* Copy the download link for your Co-signer type's installation package, under **Settings** > **General** > **API co-signer**. The link is valid for seven days.

<Note>
  If you cannot find the installation script download link in the Console, [contact Fireblocks Support](https://support.fireblocks.io/hc/en-us/requests/new).
</Note>

## Install and connect

On the Co-signer machine, download the installation package from the link you copied and run the installation script. The **Install** page for your platform has the commands and the resources that script expects. You will enter the pairing token during installation.

## Designate the signer in a Policy rule

After the Co-signer is connected, [designate the paired API user](https://support.fireblocks.io/hc/en-us/articles/29211687914268-Policy-rule-parameters#h_01KYS72RFHKWNZVCZGAMX77KAK) as the signer or an approver on a [Policy rule](https://support.fireblocks.io/hc/en-us/articles/29184395887772-About-Policies). When a transaction or configuration change matches that rule, the Co-signer paired with that API user signs or approves it. See [how roles and Policy rules work with a Co-signer](/cosigners/overview/cosigner-architecture-overview#configuring-your-workspace-to-sign-or-approve-using-an-api-co-signer).
