{"templateId":"markdown","versions":[{"version":"v1.40","label":"v1.40 STS","link":"/products/custody/identity-and-access/vault-management/manage-vaults","default":true,"active":true,"folderId":"c15a2701"},{"version":"v1.39","label":"v1.39 STS","link":"/products/custody/v1.39/identity-and-access/vault-management/manage-vaults","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.38","label":"v1.38 STS","link":"/products/custody/v1.38/identity-and-access/vault-management/manage-vaults","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.34","label":"v1.34 LTS","link":"/products/custody/v1.34/identity-and-access/vault-management/manage-vaults","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.26","label":"v1.26 LTS","link":"/products/custody/v1.26/identity-and-access/vault-management/manage-vaults","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.19","label":"v1.19 LTS","link":"/products/custody/v1.19/identity-and-access/vault-management/manage-vaults","default":false,"active":false,"folderId":"c15a2701"},{"version":"v1.15","label":"v1.15 LTS","link":"/products/custody/v1.15/identity-and-access/vault-management/manage-vaults","default":false,"active":false,"folderId":"c15a2701"}],"sharedDataIds":{"sidebar":"sidebar-products/custody/@v1.15/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Manage vaults","description":"User guides, API reference, and support resources.","siteUrl":"https://docs.ripple.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"manage-vaults","__idx":0},"children":["Manage vaults"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use this page for post-installation vault operations. For the conceptual model, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/identity-and-access/vault-management"},"children":["Vaults"]},". A vault is an external component that securely manages blockchain transaction signing. All external vaults must be registered in ","Ripple Custody"," before accounts can use them."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A vault is not tied to a domain, so accounts in different domains can use the same vault. Vault registration and vault updates are performed from the root domain."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For the trust model, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/overview/security/data-integrity-and-audit-trail#trusted-vs-untrusted-components"},"children":["Trusted vs untrusted components"]},". For key strategy and backup implications, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/identity-and-access/vault-management#key-strategies-and-backup-implications"},"children":["Vaults"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"vault-actions","__idx":1},"children":["Vault actions"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Action"},"children":["Action"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"UI procedure"},"children":["UI procedure"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"API procedure"},"children":["API procedure"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Register a vault"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#register-a-vault-in-the-ui"},"children":["Register a vault in the UI"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#register-a-vault-with-the-api"},"children":["Register a vault with the API"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["View vault details"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#view-vault-details"},"children":["View vault details"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#view-vault-details"},"children":["View vault details"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Update a vault"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#update-a-vault"},"children":["Update a vault"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#update-a-vault"},"children":["Update a vault"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Lock or unlock a vault"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Use the API procedure."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#lock-or-unlock-a-vault"},"children":["Lock or unlock a vault"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Process cold vault operations"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/identity-and-access/vault-management/cold-vault-setup-ui"},"children":["Process cold vault operations in the UI"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/identity-and-access/vault-management/cold-vault-setup-api"},"children":["Process cold vault operations with the API"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"api-reference-and-shared-process","__idx":2},"children":["API reference and shared process"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Task"},"children":["Task"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"API reference"},"children":["API reference"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Propose a vault intent"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/intents/createintent"},"children":["Propose an intent"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Dry run a vault intent"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/intents/intentdryrun"},"children":["Perform a dry run"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["List vaults"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/vaults/getvaults"},"children":["List vaults"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Get vault details"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/vaults/getvault"},"children":["Get vault details"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Export prepared cold vault operations"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/vaults/paths/~1v1~1vaults~1{vaultid}~1operations~1prepared/get"},"children":["Export prepared operations"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Import signed cold vault operations"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/vaults/paths/~1v1~1vaults~1operations~1signed/post"},"children":["Import signed operations"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Vault changes use the standard intent flow. For signing, approval, and status checks, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/intents/manage-intents-and-approvals"},"children":["Manage intents and approvals"]},", ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/identity-and-access/authentication/authenticate-api-requests#signing-intents-state-mutation-operations"},"children":["Sign intents"]},", and ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/intents/manage-intents-and-approvals#check-state"},"children":["Check updates"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"common-operations","__idx":3},"children":["Common operations"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Operation"},"children":["Operation"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Intent type"},"children":["Intent type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Use when"},"children":["Use when"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Create vault"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_CreateVault"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Register a deployed vault component."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Update vault"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UpdateVault"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Change mutable vault details such as alias, description, custom properties, or parameters."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Lock vault"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_LockVault"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Prevent transaction orders related to the vault from executing."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Unlock vault"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UnlockVault"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Re-enable a locked vault."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"register-a-vault-in-the-ui","__idx":4},"children":["Register a vault in the UI"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Whenever you deploy a new vault, register it by creating a corresponding vault entity. You can only register vaults in the root domain. You can then use the vault to execute transactions in any domain."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before you register the vault, collect the vault's public key and ID from the vault logs, as described in ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/install/first-time-installation"},"children":["First-time installation"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["At registration, set the key management system (KMS) type to either ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["HSM"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["MPC"]}," so the system can use the correct vault behavior. For more information about MPC key management, contact your Ripple liaison."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To register a vault:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select the root domain from the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Domain"]}," drop-down menu."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Administration > Vaults"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create a vault"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter the vault name, vault ID in UUID format, and KMS type."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter or upload the vault public key."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter any required custom properties."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Submit for Approval"]}," and ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/identity-and-access/authentication/ui-authentication#sign-ui-operations"},"children":["sign the operation with the app"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The vault is created after the intent is approved and executed."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"register-a-vault-with-the-api","__idx":5},"children":["Register a vault with the API"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Create a vault by submitting a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_CreateVault"]}," intent."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before you register a vault, prepare:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Prerequisite"},"children":["Prerequisite"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Additional information"},"children":["Additional information"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Vault public key and ID"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Retrieve these values from the vault logs. See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/deployment/install/first-time-installation"},"children":["First-time installation"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Root domain context"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Vaults are created from the root domain. To find domains you belong to, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/governance/users/manage-users-and-roles#view-users-and-roles-with-the-api"},"children":["View users and roles"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["New intent ID"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Prepare an intent ID in standard UUID format."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["KMS type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Use ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["HSM"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["MPC"]},". If ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["parameters.type"]}," is not provided, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["HSM"]}," is used."]}]}]}]}]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","header":{"controls":{"copy":{}}},"source":"{\n  \"payload\": {\n    \"id\": \"92f6c08d-10c9-4cbb-8e86-ec8275eda0ee\",\n    \"alias\": \"vault-hot\",\n    \"parameters\": {\n      \"type\": \"HSM\"\n    },\n    \"publicKey\": \"MCowBQYDK2VwAyEAIX4sz/23SbbAPWBn03zpd634Xj2uwT8Y/F7iH4XY4Ig=\",\n    \"lock\": \"Unlocked\",\n    \"description\": \"Hot vault\",\n    \"customProperties\": {},\n    \"type\": \"v0_CreateVault\"\n  }\n}\n","lang":"json"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Field notes:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Notes"},"children":["Notes"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["id"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["UUID of the vault, from the vault logs."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["alias"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["User-facing vault name."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["parameters.type"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["KMS type: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["HSM"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["MPC"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["parameters.backupEncryptionKey"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["For an ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["MPC"]}," vault, an encryption key used by the MPC backup workflow. See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/operations-and-maintenance/backup-and-restore#mpc-backed-vaults"},"children":["MPC-backed vaults"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["publicKey"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Public key of the vault, from the vault logs."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["lock"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Use ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Locked"]}," to create an inactive vault and unlock it later with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UnlockVault"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["customProperties"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Optional string metadata."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["type"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_CreateVault"]},"."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Dry run before submitting:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"sh","header":{"controls":{"copy":{}}},"source":"curl -X POST \"${CUSTODY_API_URL}/v1/intents/dry-run\" \\\n  -H \"Authorization: Bearer ${JWT_TOKEN}\" \\\n  -H \"Content-Type: application/json\" \\\n  -d @create-vault-intent.json\n","lang":"sh"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["After the vault creation intent is approved and executed, ","Ripple Custody"," returns a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["supportedDerivations"]}," list in the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["data"]}," object. Use this information when you ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/accounts-and-assets/accounts/manage-accounts-api#create-an-account-with-the-api"},"children":["create an account"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"view-vault-details","__idx":6},"children":["View vault details"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["View vault details before creating accounts, confirming cold vault processing status, or checking the supported derivations exposed by the vault."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the UI:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Administration > Vaults"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click the vault to view its details."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The UI shows general vault details, such as the vault ID, public key, and key derivations. For cold vaults, the UI also shows pending operations. For more information, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/identity-and-access/vault-management/cold-vault-setup-ui"},"children":["Process cold vault operations in the UI"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["With the API, call ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/vaults/getvaults"},"children":["List vaults"]}," to find vaults or ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/reference/api/openapi/vaults/getvault"},"children":["Get vault details"]}," to retrieve a specific vault:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"http","header":{"controls":{"copy":{}}},"source":"GET /v1/vaults/{vaultId}\nAuthorization: Bearer <your_jwt_token>\n","lang":"http"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"update-a-vault","__idx":7},"children":["Update a vault"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UpdateVault"]}," to change mutable vault details. You can only update a vault from the root domain."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the UI:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select the root domain from the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Domain"]}," drop-down menu."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Go to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Administration > Vaults"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["At the end of the vault row, click the contextual menu and select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Edit"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Update the vault name, description, or custom properties."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Submit for Approval"]}," and ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/custody/identity-and-access/authentication/ui-authentication#sign-ui-operations"},"children":["sign the operation with the app"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["With the API, submit an update intent with the current vault reference:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","header":{"controls":{"copy":{}}},"source":"{\n  \"payload\": {\n    \"reference\": {\n      \"id\": \"92f6c08d-10c9-4cbb-8e86-ec8275eda0ee\",\n      \"revision\": 2\n    },\n    \"alias\": \"vault-hot\",\n    \"parameters\": {\n      \"type\": \"HSM\"\n    },\n    \"description\": \"Updated hot vault description\",\n    \"customProperties\": {},\n    \"type\": \"v0_UpdateVault\"\n  }\n}\n","lang":"json"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Field notes:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Notes"},"children":["Notes"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["reference"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Current vault ID and revision."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["alias"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Updated user-facing vault name."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["parameters"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["KMS parameters for the vault."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["description"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Optional updated description."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["customProperties"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Optional string metadata."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["type"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UpdateVault"]},"."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The vault is updated after the intent is approved and executed."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"lock-or-unlock-a-vault","__idx":8},"children":["Lock or unlock a vault"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Lock a vault when transaction orders related to that vault should not execute. Unlock the vault only after the operational reason for the lock is resolved."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Submit a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_LockVault"]}," intent with the current vault reference:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"json","header":{"controls":{"copy":{}}},"source":"{\n  \"payload\": {\n    \"reference\": {\n      \"id\": \"92f6c08d-10c9-4cbb-8e86-ec8275eda0ee\",\n      \"revision\": 2\n    },\n    \"type\": \"v0_LockVault\"\n  }\n}\n","lang":"json"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v0_UnlockVault"]}," with the same reference shape to re-enable the vault."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"operational-checklist","__idx":9},"children":["Operational checklist"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Before submitting a vault-management intent:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm the vault ID and public key from the deployed vault logs."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm the KMS type and any backup or wrapping-key-rotation requirements."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm that the intent is submitted from the root domain."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm the policy that will govern the vault intent."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Dry run the payload."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Verify the executed change by viewing the vault details."]}]}]},"headings":[{"value":"Manage vaults","id":"manage-vaults","depth":1},{"value":"Vault actions","id":"vault-actions","depth":2},{"value":"API reference and shared process","id":"api-reference-and-shared-process","depth":2},{"value":"Common operations","id":"common-operations","depth":2},{"value":"Register a vault in the UI","id":"register-a-vault-in-the-ui","depth":2},{"value":"Register a vault with the API","id":"register-a-vault-with-the-api","depth":2},{"value":"View vault details","id":"view-vault-details","depth":2},{"value":"Update a vault","id":"update-a-vault","depth":2},{"value":"Lock or unlock a vault","id":"lock-or-unlock-a-vault","depth":2},{"value":"Operational checklist","id":"operational-checklist","depth":2}],"frontmatter":{"seo":{"title":"Manage vaults"}},"lastModified":"2026-08-05T09:55:07.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/custody/identity-and-access/vault-management/manage-vaults","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}