Ripple Custody custodies Canton Coin and CIP-56 tokens on the Canton Network, on a validator that you or your node provider operate.
- You hold and transfer Canton Coin (Amulet) and CIP-56 tokens issued through the Digital Asset (DA) Registry.
- Ripple Custody holds each account's signing key in your vault's HSM or KMS backend, and checks every transaction against its approved intent before it signs.
- You bring your own validator (BYOV). Ripple Custody connects to it and acts as the party manager for your accounts.
- Transfer pre-approvals let your accounts receive assets without signing each incoming transfer, which makes Canton compatible with cold vaults and long approval flows.
- Canton support is available from version 1.43, for on-premises deployments and, through the hybrid model, for SaaS.
Canton is the public Layer 1 network that many regulated institutions use for tokenization, settlement, and repo. With Canton support, you keep your Canton assets in the same custody platform, policy engine, and audit trail that you use for your other ledgers, instead of in a separate custodian.
For architects and operators: Canton works differently from other ledgers. Accounts are parties hosted on a validator, balances are sets of Holdings, and an account must complete a one-time setup before it can send or receive. Read Canton concepts and Architecture and responsibilities before you plan your rollout.
| Capability | Description |
|---|---|
| Custody Canton accounts | Create accounts whose Canton parties your validator hosts. Ripple Custody holds the party's signing key in your vault. |
| Hold Canton Coin and CIP-56 tokens | Hold Canton Coin and any CIP-56 token that the DA Registry publishes. Each account can hold several instruments. |
| Receive without per-transfer signing | Set up transfer pre-approvals once per account, so incoming transfers settle directly into the account. |
| Send transfers | Send Canton Coin and CIP-56 tokens to any Canton party, subject to your Ripple Custody policies. |
| Manage two-step transfers | Accept or reject an incoming transfer offer, or withdraw an outgoing offer that the receiver hasn't acted on. |
| View balances and history | View real-time balances and indexed transaction history through the standard Ripple Custody API operations. |
| Use DevNet, TestNet, and MainNet | Register each Canton network as a separate ledger in the same Ripple Custody installation. |
In this release, you manage Canton through the Ripple Custody API.
- Canton-native applications. You can't sign arbitrary Daml commands or deploy contracts.
- CIP-56 Allocation and delivery versus payment (DvP) workflows.
- Token registries other than the Validator API registry for Canton Coin and the DA Registry for other CIP-56 tokens.
- A validator operated by Ripple. You provide the validator yourself or through a node provider.
Do you support CIP-56 tokens beyond Canton Coin?
Yes. Ripple Custody indexes and transfers Canton Coin and every CIP-56 token that the DA Registry publishes. You register each token as a ticker. For more information, see Register Canton tokens.
Can we bring our own validator and create accounts on it?
Yes. BYOV is the only hosting model. You or your node provider operate the validator, and you create each Ripple Custody account's party on that validator with a CreateParty transaction order. Each Canton network that you register points to one validator. For more information, see Architecture and responsibilities.
How do we activate an account on the validator?
You create the account, then submit three one-time setup orders: CreateParty allocates the party on your validator, CreateNativeTransferPreapproval enables Canton Coin receipts, and CreateTokenTransferPreapproval enables receipts of each CIP-56 token. For more information, see Set up Canton accounts with the API.
Do you support transfer offers, and can we accept or reject them?
Yes. When a sender transfers to an account that has no pre-approval for the asset, Canton creates a two-step transfer offer. You accept or reject it with an Accept or Reject order. As a sender, you can withdraw an offer that the receiver hasn't acted on. For more information, see Accept or reject an incoming transfer offer.
Do you support automatic acceptance of incoming transfers?
Yes, through transfer pre-approvals. After an account has a pre-approval for an asset, incoming transfers of that asset settle directly into the account, without a signature from you. Like incoming transfers on every other ledger, they then enter quarantine until your quarantine release policies release them. For more information, see Receive assets.
Do transfers expire?
A two-step transfer offer expires at the deadline that the sender sets in executeBefore. If the sender doesn't set a deadline, Ripple Custody applies 30 days. A transfer that settles directly through a pre-approval doesn't expire, because it completes as soon as the network commits it. For more information, see Transfer deadlines.
Is there a maximum number of Holdings (UTXOs) per account?
Ripple Custody doesn't limit how many Holdings an account holds. A single transfer can spend at most 100 Holdings. The network enforces this limit for Canton Coin, and Ripple Custody applies it to other CIP-56 tokens. Treat it as an upper bound, because the effective limit can be lower. For how the limit works, see Holdings. To merge small Holdings, see Manage Holdings.
Who receives validator rewards?
The Canton Network pays validator rewards to your validator's own service party, not to a Ripple Custody account. To move rewards into custody, transfer them from the validator party to a Ripple Custody account. For more information, see Validator rewards.
| Task | Page |
|---|---|
| Learn the Canton concepts that affect custody | Canton concepts |
| Understand who operates what | Architecture and responsibilities |
| Connect your validator and register the network and tokens | Connect your validator |
| Create an account, its party, and its pre-approvals | Set up Canton accounts with the API |
| Send, receive, and manage transfers and Holdings | Send and receive Canton assets with the API |
| Look up payload fields, identifiers, and errors | Canton reference |