Skip to content
Executive summary

Ripple Custody custodies Canton Coin and CIP-56 tokens on the Canton Network, on a validator that you or your node provider operate.

  • You hold and transfer Canton Coin (Amulet) and CIP-56 tokens issued through the Digital Asset (DA) Registry.
  • Ripple Custody holds each account's signing key in your vault's HSM or KMS backend, and checks every transaction against its approved intent before it signs.
  • You bring your own validator (BYOV). Ripple Custody connects to it and acts as the party manager for your accounts.
  • Transfer pre-approvals let your accounts receive assets without signing each incoming transfer, which makes Canton compatible with cold vaults and long approval flows.
  • Canton support is available from version 1.43, for on-premises deployments and, through the hybrid model, for SaaS.
Why this matters

Canton is the public Layer 1 network that many regulated institutions use for tokenization, settlement, and repo. With Canton support, you keep your Canton assets in the same custody platform, policy engine, and audit trail that you use for your other ledgers, instead of in a separate custodian.

For architects and operators: Canton works differently from other ledgers. Accounts are parties hosted on a validator, balances are sets of Holdings, and an account must complete a one-time setup before it can send or receive. Read Canton concepts and Architecture and responsibilities before you plan your rollout.

What you can do

CapabilityDescription
Custody Canton accountsCreate accounts whose Canton parties your validator hosts. Ripple Custody holds the party's signing key in your vault.
Hold Canton Coin and CIP-56 tokensHold Canton Coin and any CIP-56 token that the DA Registry publishes. Each account can hold several instruments.
Receive without per-transfer signingSet up transfer pre-approvals once per account, so incoming transfers settle directly into the account.
Send transfersSend Canton Coin and CIP-56 tokens to any Canton party, subject to your Ripple Custody policies.
Manage two-step transfersAccept or reject an incoming transfer offer, or withdraw an outgoing offer that the receiver hasn't acted on.
View balances and historyView real-time balances and indexed transaction history through the standard Ripple Custody API operations.
Use DevNet, TestNet, and MainNetRegister each Canton network as a separate ledger in the same Ripple Custody installation.

In this release, you manage Canton through the Ripple Custody API.

What's not supported

  • Canton-native applications. You can't sign arbitrary Daml commands or deploy contracts.
  • CIP-56 Allocation and delivery versus payment (DvP) workflows.
  • Token registries other than the Validator API registry for Canton Coin and the DA Registry for other CIP-56 tokens.
  • A validator operated by Ripple. You provide the validator yourself or through a node provider.

Frequently asked questions

Do you support CIP-56 tokens beyond Canton Coin?

Yes. Ripple Custody indexes and transfers Canton Coin and every CIP-56 token that the DA Registry publishes. You register each token as a ticker. For more information, see Register Canton tokens.

Can we bring our own validator and create accounts on it?

Yes. BYOV is the only hosting model. You or your node provider operate the validator, and you create each Ripple Custody account's party on that validator with a CreateParty transaction order. Each Canton network that you register points to one validator. For more information, see Architecture and responsibilities.

How do we activate an account on the validator?

You create the account, then submit three one-time setup orders: CreateParty allocates the party on your validator, CreateNativeTransferPreapproval enables Canton Coin receipts, and CreateTokenTransferPreapproval enables receipts of each CIP-56 token. For more information, see Set up Canton accounts with the API.

Do you support transfer offers, and can we accept or reject them?

Yes. When a sender transfers to an account that has no pre-approval for the asset, Canton creates a two-step transfer offer. You accept or reject it with an Accept or Reject order. As a sender, you can withdraw an offer that the receiver hasn't acted on. For more information, see Accept or reject an incoming transfer offer.

Do you support automatic acceptance of incoming transfers?

Yes, through transfer pre-approvals. After an account has a pre-approval for an asset, incoming transfers of that asset settle directly into the account, without a signature from you. Like incoming transfers on every other ledger, they then enter quarantine until your quarantine release policies release them. For more information, see Receive assets.

Do transfers expire?

A two-step transfer offer expires at the deadline that the sender sets in executeBefore. If the sender doesn't set a deadline, Ripple Custody applies 30 days. A transfer that settles directly through a pre-approval doesn't expire, because it completes as soon as the network commits it. For more information, see Transfer deadlines.

Is there a maximum number of Holdings (UTXOs) per account?

Ripple Custody doesn't limit how many Holdings an account holds. A single transfer can spend at most 100 Holdings. The network enforces this limit for Canton Coin, and Ripple Custody applies it to other CIP-56 tokens. Treat it as an upper bound, because the effective limit can be lower. For how the limit works, see Holdings. To merge small Holdings, see Manage Holdings.

Who receives validator rewards?

The Canton Network pays validator rewards to your validator's own service party, not to a Ripple Custody account. To move rewards into custody, transfer them from the validator party to a Ripple Custody account. For more information, see Validator rewards.

Get started

TaskPage
Learn the Canton concepts that affect custodyCanton concepts
Understand who operates whatArchitecture and responsibilities
Connect your validator and register the network and tokensConnect your validator
Create an account, its party, and its pre-approvalsSet up Canton accounts with the API
Send, receive, and manage transfers and HoldingsSend and receive Canton assets with the API
Look up payload fields, identifiers, and errorsCanton reference