Sandbox APIhttps://sandbox-api.nuvante.io

Custody & chains

Custody models

Nuvanté never creates or holds a wallet. Every participant and issuer comes with an account of their own, and we just register a reference to it.

Self-custody

You hold the private keys yourself, in a hardware wallet, an HSM or key management software you run. It's the easiest model to explain, and it puts the most operational work on you.

  • Mode 1 (delegated signing): Give Nuvanté's operator key signing authority on-chain. On Stellar, for example, you'd add our operator as a co-signer with the right weight and threshold. The mechanics vary by chain, so check the relevant chain guide.
  • Mode 2 and Mode 3: There's no on-chain delegation. You implement the instruction API and sign with your own key when we send an instruction. Mode 3 also needs the mandatory refund endpoint described in Mode 3.

Illustrative example: a Stellar account you control, with a trustline to the issued asset and, for Mode 1, Nuvanté's operator key added as a co-signer. This is an illustration of the pattern and hasn't been certified as a setup.

MPC (multi-party computation)

Your key material is split into shares, so compromising a single share doesn't expose the key. For Mode 1, delegating signing to Nuvanté means adding our operator as an approved co-signer or policy rule inside your MPC provider's policy engine. It's a configuration change on your side, and we never see any key shares.

For Mode 2 and Mode 3, your MPC provider's signing API sits behind the backend that handles our instructions. Approval times may partly depend on your MPC co-signer quorum as well as your own business process.

Illustrative example: configuring an external co-signer rule (a TAP-style policy rule, for instance) that lets Nuvanté's operator sign Mode 1 instructions. This is an illustration and doesn't mean any provider is officially supported.

Custody-as-a-Service (CaaS)

A regulated third-party custodian holds the keys for you. You approve actions through the custodian's API or console, and the custodian executes them on-chain.

  • Mode 1: Only works if your custodian lets you add an external delegate or co-signer. This varies between providers, so check with yours first.
  • Mode 2 and Mode 3: Custodians usually offer a webhook or API, and your backend relays its events to Nuvanté. That's an extra hop for you to build, because we don't connect to the custodian directly.

Illustrative example: a regulated custodian with an approval API, which your issuer backend relays for Mode 2 instruction events.

Compatibility matrix: custody vs. settlement mode

Custody modelMode 1Mode 2Mode 3
Self-custodyWorks through native multi-sig or a co-signerWorks: you sign when instructedFail-closed, not enabled
MPCWorks only if your policy engine can add an external co-signer ruleWorks: MPC signing sits behind your instruction APIFail-closed, not enabled
CaaSWorks only if your custodian supports an external delegate or co-signerWorks through a relay from the custodian's APIFail-closed, not enabled

Check this matrix before you set commitPoint or preBurnTransferRequired in your issuer capability profile.