# Connect your validator

Before your accounts can use Canton, connect Ripple Custody to your validator, register the Canton network as a ledger, and register the assets that you want to hold as tickers. Repeat these steps for each Canton network that you use: DevNet, TestNet, or MainNet.

## Validator prerequisites

| Prerequisite | Details |
|  --- | --- |
| Unified Indexer Service v2 | Your Ripple Custody environment runs UISv2. You can't register a Canton ledger without it. For more information, see [Unified Indexer Service](/pt-br/products/custody/overview/architecture/unified-indexer-service). |
| Ledger accounting refactor phase 2 | Phase 2 is active in your environment. Without it, new Canton accounts stay in the `Activating` status. For more information, see [Ledger accounting refactor phase 2](/pt-br/products/custody/support/change-history/v140#ledger-accounting-refactor-phase-2). |
| A Canton validator | Operated by you or your node provider, running the latest Splice Validator App release. |
| Token DARs | Your validator operator has installed the DARs for each CIP-56 token that you want to hold. |
| Ledger API endpoint | gRPC, over TLS 1.2 or later. |
| Validator API endpoint | REST, over TLS 1.2 or later. |
| DA Registry API endpoint | REST, over TLS 1.2 or later. |
| Ledger API user rights | A Ledger API user with the rights listed in [Ledger API user rights](#ledger-api-user-rights). |
| Credentials for each endpoint | None, a static JWT, or an OAuth2 client-credentials grant. Each endpoint uses its own setting. |
| Canton Coin on the validator operator party | Enough to cover network fees. |
| Firewall access (hybrid) | Your validator firewall allows the Ripple indexer IP addresses. Ask your Ripple liaison for the list. |


Ripple Custody rejects plaintext (`http`) endpoints. The Ledger API client connects directly to the validator and doesn't use `HTTP_PROXY` or `HTTPS_PROXY`, so the Ledger API endpoint must be reachable without a forward proxy.

### Ledger API user rights

Grant the Ledger API user that Ripple Custody authenticates as the following rights:

| Right | When it's needed |
|  --- | --- |
| `CanReadAsAnyParty` | Always. It covers contract queries, transaction streams, and transaction preparation. |
| `CanExecuteAsAnyParty` | Always. It covers transaction execution on behalf of your parties. |
| `ParticipantAdmin` | During onboarding only, to allocate parties and grant the other two rights. No later operation, including transfers and pre-approvals, needs it. |


## Connect the validator

How you connect the validator depends on your deployment model. For more information, see [Deployment models](/pt-br/products/custody/accounts-and-assets/blockchains/canton/architecture-and-responsibilities#deployment-models).

### Hybrid

SaaS customers use this model. Send the following details to your Ripple liaison for each Canton network:

- The Ledger API, Validator API, and DA Registry API addresses.
- The authentication method and credentials for each endpoint.
- The synchronizer ID and the DSO party ID of the network.


Then allow the Ripple indexer IP addresses through your validator firewall. Ripple provisions a dedicated indexer instance that connects to your validator, and confirms when the network is ready for you to register.

### On-premises

Configure the Canton network, its three endpoints, and their credentials in your Helm values, and then deploy the updated values. For the values and the Secret naming pattern, see [Canton configuration](/pt-br/products/custody/deployment/reference/canton).

## Register the Canton ledger

Register each Canton network as a ledger with a `v0_CreateLedger` intent. You can submit this intent only in the root domain, and your ledger policies apply to it like any other intent.

To register the ledger:

1. Prepare the intent payload, as shown in the [payload example](#ledger-payload-example).
2. Call the [Perform a dry run for an intent](/pt-br/products/custody/reference/api/openapi/intents/intentdryrun) operation, with the `request` field excluded. For more information, see [Dry run intents](/pt-br/products/custody/governance/intents/manage-intents-and-approvals#dry-run-an-intent-with-the-api).
3. Sign the request body and call the [Propose an intent](/pt-br/products/custody/reference/api/openapi/intents/createintent) operation. For more information, see [Submit an intent with the API](/pt-br/products/custody/governance/intents/manage-intents-and-approvals#submit-an-intent-with-the-api).
4. Check the intent status. For more information, see [Check state with the API](/pt-br/products/custody/governance/intents/manage-intents-and-approvals#check-state-with-the-api).


### Ledger payload example

This example registers Canton MainNet:

```json
{
  "payload": {
    "id": "canton-mainnet",
    "alias": "Canton MainNet",
    "parameters": {
      "type": "Canton",
      "synchronizerId": "global-domain::1220b1431ef217342db44d516bb9befde802be7d8899637d290895fa58880f19accc",
      "operatorId": "acme-validator-1::1220f3c6d9a2b5e8f1c4a7d0b3e6f9c2a5d8b1e4f7a0c3d6b9e2f5a8c1d4b7e0a3f6",
      "dsoPartyId": "DSO::1220b1431ef217342db44d516bb9befde802be7d8899637d290895fa58880f19accc",
      "daRegistryOperator": "DigitalAsset-UtilityOperator::12202679f2bbe57d8cba9ef3cee847ac8239df0877105ab1f01a77d47477fdce1204"
    },
    "description": "Canton MainNet through the ACME validator",
    "customProperties": {},
    "type": "v0_CreateLedger"
  }
}
```

| Field | Description |
|  --- | --- |
| `id` | The ledger ID that you choose. You use it in accounts, tickers, and orders. Ripple Custody rejects a duplicate ID. |
| `parameters.type` | `Canton` |
| `parameters.synchronizerId` | The synchronizer ID of the network. Get it from your validator operator. |
| `parameters.operatorId` | Your validator's own primary party ID. Get it from your validator operator. |
| `parameters.dsoPartyId` | The DSO party ID of the network. Ripple Custody uses it as the Canton Coin instrument administrator. |
| `parameters.daRegistryOperator` | The DA Registry operator party ID. |


For the DSO party and DA Registry operator values on each network, see [Network identifiers](/pt-br/products/custody/accounts-and-assets/blockchains/canton/reference#network-identifiers).

## Update the Canton ledger

To change a Canton ledger's alias, description, or parameters, submit a `v0_UpdateLedger` intent. It takes the same `parameters` as `v0_CreateLedger`, and it references the ledger by ID and current revision. Follow the same dry run, propose, and check steps as for registration.

Your existing parties stay hosted on the validator where you created them. Before you change `synchronizerId`, `operatorId`, `dsoPartyId`, or `daRegistryOperator` on a ledger with active accounts, contact your Ripple liaison.

```json
{
  "payload": {
    "reference": {
      "id": "canton-mainnet",
      "revision": 1
    },
    "alias": "Canton MainNet (ACME validator)",
    "parameters": {
      "type": "Canton",
      "synchronizerId": "global-domain::1220b1431ef217342db44d516bb9befde802be7d8899637d290895fa58880f19accc",
      "operatorId": "acme-validator-1::1220f3c6d9a2b5e8f1c4a7d0b3e6f9c2a5d8b1e4f7a0c3d6b9e2f5a8c1d4b7e0a3f6",
      "dsoPartyId": "DSO::1220b1431ef217342db44d516bb9befde802be7d8899637d290895fa58880f19accc",
      "daRegistryOperator": "DigitalAsset-UtilityOperator::12202679f2bbe57d8cba9ef3cee847ac8239df0877105ab1f01a77d47477fdce1204"
    },
    "description": "Canton MainNet through the ACME validator",
    "customProperties": {},
    "type": "v0_UpdateLedger"
  }
}
```

To get the current revision, call the [Get trusted ledger details](/pt-br/products/custody/reference/api/openapi/ledgers/gettrustedledger) operation.

## Register Canton Coin and CIP-56 tokens

Register Canton Coin and each CIP-56 token that you want to hold as a ticker, with a `v0_ValidateTickers` intent. Your ticker policies apply to it. Follow the same dry run, propose, and check steps as for the ledger. For more information about tickers, see [Allowlist tokens](/pt-br/products/custody/accounts-and-assets/tokenization/token-management/api/allowlist-token).

### Ticker payload example

This example registers Canton Coin and a CIP-56 token on Canton MainNet in one intent:

```json
{
  "payload": {
    "tickers": [
      {
        "id": "5a1f9c3e-7b2d-4e8a-9c6f-1d3b5e7a9c2f",
        "ledgerId": "canton-mainnet",
        "kind": "Native",
        "name": "Canton Coin",
        "symbol": "CC",
        "decimals": 10,
        "ledgerDetails": {
          "type": "Canton",
          "properties": {
            "type": "Native"
          }
        },
        "lock": "Unlocked",
        "customProperties": {}
      },
      {
        "id": "8e4b2d6f-1a3c-4f7e-b9d2-6c8a0e2f4b7d",
        "ledgerId": "canton-mainnet",
        "kind": "Token",
        "name": "Example Token",
        "symbol": "EXT",
        "decimals": 10,
        "ledgerDetails": {
          "type": "Canton",
          "properties": {
            "type": "Instrument",
            "instrumentAdmin": "token-issuer-admin::1220c7e1a4d7b0e3f6a9c2d5b8e1f4a7d0c3b6e9f2a5d8c1b4e7f0a3d6c9b2e5f8a1",
            "instrumentId": "EXT"
          }
        },
        "lock": "Unlocked",
        "customProperties": {}
      }
    ],
    "type": "v0_ValidateTickers"
  }
}
```

| Field | Description |
|  --- | --- |
| `tickers[].id` | A new ticker ID, in UUID format. You use it as `tickerId` in token orders. |
| `tickers[].ledgerId` | The ID of the Canton ledger that you registered. |
| `tickers[].kind` | `Native` for Canton Coin. `Token` for a CIP-56 token. |
| `tickers[].decimals` | `10` for every Canton asset. |
| `tickers[].ledgerDetails.type` | `Canton` |
| `tickers[].ledgerDetails.properties.type` | `Native` for Canton Coin. `Instrument` for a CIP-56 token. |
| `tickers[].ledgerDetails.properties.instrumentAdmin` | `Instrument` only. The party ID of the token's administrator. Get it from the token issuer. |
| `tickers[].ledgerDetails.properties.instrumentId` | `Instrument` only. The token's instrument ID. Get it from the token issuer. |


The `instrumentAdmin` and `instrumentId` values in the example are placeholders. Get the real values for each token from its issuer or from the DA Registry.

## Next steps

After you register the ledger and tickers, create accounts and set them up to send and receive. For more information, see [Set up Canton accounts with the API](/pt-br/products/custody/accounts-and-assets/blockchains/canton/set-up-accounts-api).