# Deploy a vault

Learn how you can deploy a vault to connect an IBM Cloud HSM by using the  available from the IBM Cloud marketplace.

Note:
Contact your Ripple liaison for an invitation to the private Ripple Custody Cloud catalog on IBM Cloud marketplace

## 1. Install 

Before you can deploy the vault, you need to install the  which you can get from the Ripple Custody Cloud catalog on IBM Cloud marketplace. To get access:

1. Accept Ripple's e-mail invitation to the private IBM Cloud catalog.
2. Navigate to the ****.
3. Complete all required fields and select **Install**.
4. In your IBM Cloud account, navigate to the **Resource list** and identify the new app ID (Identity provider).
  1. Navigate to **Manage Authentication** > **Cloud Directory** > **Users**.
  2. Select **Create User** and assign access to users who will use the .
5. In your IBM Cloud account, navigate to **Containers** > **Serverless** > **Projects**.
  1. Select **Applications**.
  2. Identify the new code engine application and then select **Open URL**.


## 2. Deploy the vault

From the  you just opened, you (or any assigned user) can now deploy the vault:

1. Enter your username and password.
2. Check your e-mail for the multi-factor authentication code, enter the code, and then select **Continue**.
![Custody onboarding](../../../../../images/custody-ibm-onboarding.png)
*This screen shows the  with the Getting started widget from where you can start to deploy the vault.*
3. On the **Getting started** widget, select **Start** and complete all sections to deploy a vault:
  - Create a new vault
  - Configure key management system
  - Configure cloud logs
  - Configure telemetry (optional)
  - Connect a Docker container registry
  - Installation
The  provides step-by-step instructions to guide you through the onboarding experience.
Once you **submit** for installation, it takes from three to five minutes to create the resources on IBM Cloud. A summary page will be displayed once the process is complete.
![Custody onboarding summary](../../../../../images/custody-ibm-onboarding-summary.png)
*This screen shows the  with the summary of the settings you selected for deploying the vault. Review the summary before you select Submit.*


## 3. Connect the vault

After the installation is complete, you must connect your vault to your Ripple Custody instance.

1. In the , select **Open Ripple Custody instance**.
2. Log in to your Ripple Custody instance.
3. Select **Administration** > **Vaults** > **Create a vault**.
4. In the **Vault name** field, enter a unique name for the vault.
5. From the , copy the **ID** and paste it into the **ID** field in your Ripple Custody instance.
6. From the , copy the **Public key** and paste it into the **Vault public key** field in your Ripple Custody instance.
![Copy ID and public key](../../../../../images/custody-onboarding-ID-key.png)
*This screen shows the  with the ID and the public key that you must copy and then paste into your Ripple Custody instance to connect the vault.*
7. Select **Submit for approval** and follow your respective approval process.