Skip to content

MPC quorums distribute wallet private key shards across multiple devices so that no single device holds the complete key. As an owner or administrator, you create quorums, manage their membership, restructure eligible quorums, and coordinate key resharing when needed. This guide covers the full quorum lifecycle.

Create an MPC quorum

  1. Go to Controls in the console sidebar and select the MPC Quorums tab.
  2. Select Create quorum.
  3. Select the quorum type:
TypeDescription
MobileUses mobile devices only. Each signing request requires manual approval on the device.
CloudUses CloudSign instances only. Signs transactions automatically when quorum conditions are met.
MixedCombines mobile and CloudSign devices for flexibility.
  1. Enter a name and optional description for the quorum.
  2. Select the key shard holders — choose the devices that hold key shards. You must select at least 2 devices.
  3. Set the required signatures — the minimum number of devices that must participate to sign a transaction. This must be at least 2 and no more than the total number of shard holders.
  4. Select a backup and recovery kit (for Cloud and Mobile quorums). If you don't have a kit yet, select Create backup kit to create one first.
  5. Select Create, review the confirmation summary, and then select Create quorum.

Each quorum member receives a notification asking for their approval. The quorum becomes available after all members accept. The acceptance window is 60 minutes.

Use a majority threshold

Set the number of required signatures to a majority of the total shard holders. For example, in a quorum of 3 devices, use at least 2 signatures. This helps prevent a minority of compromised devices from signing transactions.

Design considerations

Choose your quorum size and threshold based on your security and availability needs:

ConfigurationSecurityAvailabilityUse case
2-of-3ModerateHighSmall teams, sandbox testing
3-of-5HighHighProduction operations
4-of-7Very highModerateHigh-value wallets

View quorum details

  1. Go to Controls > MPC Quorums.
  2. Select a quorum to view its details: name, ID, threshold, creation date, backup kit, and the list of key shard holders with their device types and owners.

Key resharing

Key resharing rotates the key shards held by each device without changing the underlying wallet private key. The wallet address and blockchain identity remain the same.

Wallet-as-a-Service doesn't currently expose a customer-initiated reshare action in the console, and it doesn't reshare keys automatically on a schedule. If your security program requires key resharing, contact Ripple support or your account team to coordinate it.

When to consider resharing

  • Security policy or compliance requirement - coordinate key-share rotation when your internal policy requires it.
  • Personnel changes - consider resharing after a team member with device access leaves the organization.
  • Security incident - contact Ripple immediately if you suspect key shard exposure.

Coordinate a reshare

  1. Contact Ripple support or your account team.
  2. Identify the quorum and wallets that require resharing.
  3. Schedule a maintenance window and confirm the expected signing availability for affected wallets.
  4. Make sure the required quorum devices are online if Wallet-as-a-Service requires device participation.
  5. After Wallet-as-a-Service confirms completion, take fresh backups of each CloudSign node's database. Don't restore any node snapshot that you took before the reshare.

After a successful reshare, previous key shards no longer participate in signing. Treat devices that held previous key shards as containing obsolete sensitive material until you decommission them through your device lifecycle process.

Resharing invalidates node snapshots, not key shard backups

Resharing and restructuring replace the key shards without changing the wallet's underlying key, so the encrypted key shard backups that Wallet-as-a-Service writes to S3 stay valid. Wallet-as-a-Service binds each backup file to the wallet's key ID and quorum ID, and neither of them changes. The backup file doesn't store the quorum ID, so keep it in your offline wallet inventory. You don't need to do anything to them, and Wallet-as-a-Service can't regenerate a key shard backup for an existing key in any case.

What does change is that the backup still holds the key shares of the devices that were in the quorum when you created the wallet. That doesn't affect recovery, because the recovery CLI reconstructs the private key from the backup itself rather than restoring shards to devices. It does mean that a backup isn't a record of your current quorum membership.

CloudSign node database snapshots are the opposite case. A snapshot taken before the reshare or restructure contains obsolete shards that mismatch the rest of the quorum. Never restore it. Take fresh node backups after every reshare or restructure. See Configure backup and recovery and the restore constraints.

See Key resharing for the resharing concept. Where that page says to create new backups after a reshare, it means CloudSign node snapshots. Key shard backups in S3 need no action, and none is possible.

Key restructuring

Key restructuring changes the quorum's membership and size. Unlike resharing, restructuring can add new devices and replace existing ones. It can't change the number of required signatures, and it can't only remove devices: the new device set must include at least one device that isn't in the current quorum. To use a different threshold, create a new quorum.

When to restructure

ScenarioWhat changes
A team member leavesReplace their device with another device
A new team member joinsAdd their device to the quorum
You need more resilienceAdd devices to increase the quorum size (the number of required signatures stays the same)
A device is lost or compromisedReplace the device with a new one

Perform a restructure

CloudSign quorums only

Restructuring is currently available for Cloud quorums running CloudSign version 1.10.0 or later.

  1. Go to Controls and select the MPC Quorums tab.
  2. Select the quorum you want to restructure to open its detail page.
  3. Open the Actions menu (three dots next to the status badge) and select Restructure quorum.
  4. Review the current membership and make changes:
    • Add new devices to the quorum.
    • Remove existing devices (you must retain at least as many original members as the current required signatures threshold). Removing devices only works together with adding at least one new device. Wallet-as-a-Service rejects a restructure that only removes devices.
  5. Review the proposed changes in the confirmation dialog.
  6. Type the quorum name to confirm.
  7. Select Confirm.
Restructuring puts the quorum in maintenance mode

During restructuring, the quorum and all wallets that use it can't sign. Plan restructuring during a maintenance window. You can't reverse the process after it starts.

When restructuring removes a device, the removed device no longer participates in the active quorum. Treat any key material on that device as obsolete sensitive material until you block, delete, or decommission the device through your device lifecycle process.

See Key restructuring for the full technical reference, including detailed examples.

Best practices

  • Separate key shard holders: Distribute devices across different team members to enforce separation of duties. Make sure no single person controls enough devices to meet the signing threshold alone.
  • Document your quorum design: Record which devices belong to each quorum, who controls them, and the reasoning behind your threshold choices.
  • Review resharing requirements: If your security policy requires key-share rotation, coordinate resharing with Ripple. The console doesn't reshare keys automatically.
  • Take fresh node backups after every reshare or restructure: CloudSign node snapshots from before the change contain obsolete shards, so don't restore them. Key shard backups in S3 stay valid and need no action.
  • Test recovery procedures: Verify in sandbox that you can recover from a lost device by restructuring the quorum.
  • Plan restructuring carefully: Because restructuring puts wallets in maintenance mode, schedule it during low-activity periods and communicate the maintenance window to your team.