# Manage MPC quorums

MPC quorums distribute wallet private key shards across multiple devices so that no single device holds the complete key. As an owner or administrator, you create quorums, manage their membership, restructure eligible quorums, and coordinate key resharing when needed. This guide covers the full quorum lifecycle.

## Create an MPC quorum

1. Go to **Controls** in the console sidebar and select the **MPC Quorums** tab.
2. Select **Create quorum**.
3. Select the **quorum type**:


| Type | Description |
|  --- | --- |
| **Mobile** | Uses mobile devices only. Each signing request requires manual approval on the device. |
| **Cloud** | Uses CloudSign instances only. Signs transactions automatically when quorum conditions are met. |
| **Mixed** | Combines mobile and CloudSign devices for flexibility. |


1. Enter a **name** and optional **description** for the quorum.
2. Select the **key shard holders** — choose the devices that hold key shards. You must select at least 2 devices.
3. Set the **required signatures** — the minimum number of devices that must participate to sign a transaction. This must be at least 2 and no more than the total number of shard holders.
4. Select a **backup and recovery kit** (for Cloud and Mobile quorums). If you don't have a kit yet, select **Create backup kit** to create one first.
5. Select **Create**, review the confirmation summary, and then select **Create quorum**.


Each quorum member receives a notification asking for their approval. The quorum becomes available after all members accept. The acceptance window is 60 minutes.

Use a majority threshold
Set the number of required signatures to a majority of the total shard holders. For example, in a quorum of 3 devices, use at least 2 signatures. This helps prevent a minority of compromised devices from signing transactions.

Design considerations
Choose your quorum size and threshold based on your security and availability needs:

| Configuration | Security | Availability | Use case |
|  --- | --- | --- | --- |
| 2-of-3 | Moderate | High | Small teams, sandbox testing |
| 3-of-5 | High | High | Production operations |
| 4-of-7 | Very high | Moderate | High-value wallets |


## View quorum details

1. Go to **Controls** > **MPC Quorums**.
2. Select a quorum to view its details: name, ID, threshold, creation date, backup kit, and the list of key shard holders with their device types and owners.


## Key resharing

Key resharing rotates the key shards held by each device without changing the underlying wallet private key. The wallet address and blockchain identity remain the same.

Wallet-as-a-Service doesn't currently expose a customer-initiated reshare action in the console, and it doesn't reshare keys automatically on a schedule. If your security program requires key resharing, contact Ripple support or your account team to coordinate it.

### When to consider resharing

- **Security policy or compliance requirement** - coordinate key-share rotation when your internal policy requires it.
- **Personnel changes** - consider resharing after a team member with device access leaves the organization.
- **Security incident** - contact Ripple immediately if you suspect key shard exposure.


### Coordinate a reshare

1. Contact Ripple support or your account team.
2. Identify the quorum and wallets that require resharing.
3. Schedule a maintenance window and confirm the expected signing availability for affected wallets.
4. Make sure the required quorum devices are online if Wallet-as-a-Service requires device participation.
5. After Wallet-as-a-Service confirms completion, take fresh backups of each CloudSign node's database. Don't restore any node snapshot that you took before the reshare.


After a successful reshare, previous key shards no longer participate in signing. Treat devices that held previous key shards as containing obsolete sensitive material until you decommission them through your device lifecycle process.

Resharing invalidates node snapshots, not key shard backups
Resharing and restructuring replace the key shards without changing the wallet's underlying key, so the encrypted key shard backups that Wallet-as-a-Service writes to S3 stay valid. Wallet-as-a-Service binds each backup file to the wallet's key ID and quorum ID, and neither of them changes. The backup file doesn't store the quorum ID, so keep it in your [offline wallet inventory](/pt-br/products/wallet/admin-guide/configure-backup-and-recovery#prepare-for-disaster-recovery). You don't need to do anything to them, and Wallet-as-a-Service can't regenerate a key shard backup for an existing key in any case.

What does change is that the backup still holds the key shares of the devices that were in the quorum when you created the wallet. That doesn't affect recovery, because the recovery CLI reconstructs the private key from the backup itself rather than restoring shards to devices. It does mean that a backup isn't a record of your current quorum membership.

CloudSign node database snapshots are the opposite case. A snapshot taken **before** the reshare or restructure contains obsolete shards that mismatch the rest of the quorum. Never restore it. Take fresh node backups after every reshare or restructure. See [Configure backup and recovery](/pt-br/products/wallet/admin-guide/configure-backup-and-recovery#maintain-your-backups) and the [restore constraints](/pt-br/products/wallet/admin-guide/disaster-recovery#restore-a-cloudsign-node-database).

See [Key resharing](/pt-br/products/wallet/user-interface/security-controls/key-resharing) for the resharing concept. Where that page says to create new backups after a reshare, it means CloudSign node snapshots. Key shard backups in S3 need no action, and none is possible.

## Key restructuring

Key restructuring changes the quorum's membership and size. Unlike resharing, restructuring can add new devices and replace existing ones. It can't change the number of required signatures, and it can't only remove devices: the new device set must include at least one device that isn't in the current quorum. To use a different threshold, create a new quorum.

### When to restructure

| Scenario | What changes |
|  --- | --- |
| A team member leaves | Replace their device with another device |
| A new team member joins | Add their device to the quorum |
| You need more resilience | Add devices to increase the quorum size (the number of required signatures stays the same) |
| A device is lost or compromised | Replace the device with a new one |


### Perform a restructure

CloudSign quorums only
Restructuring is currently available for Cloud quorums running CloudSign version 1.10.0 or later.

1. Go to **Controls** and select the **MPC Quorums** tab.
2. Select the quorum you want to restructure to open its detail page.
3. Open the **Actions** menu (three dots next to the status badge) and select **Restructure quorum**.
4. Review the current membership and make changes:
  - Add new devices to the quorum.
  - Remove existing devices (you must retain at least as many original members as the current required signatures threshold). Removing devices only works together with adding at least one new device. Wallet-as-a-Service rejects a restructure that only removes devices.
5. Review the proposed changes in the confirmation dialog.
6. Type the quorum name to confirm.
7. Select **Confirm**.


Restructuring puts the quorum in maintenance mode
During restructuring, the quorum and all wallets that use it can't sign. Plan restructuring during a maintenance window. You can't reverse the process after it starts.

When restructuring removes a device, the removed device no longer participates in the active quorum. Treat any key material on that device as obsolete sensitive material until you block, delete, or decommission the device through your device lifecycle process.

See [Key restructuring](/pt-br/products/wallet/user-interface/security-controls/key-restructuring) for the full technical reference, including detailed examples.

## Best practices

- **Separate key shard holders**: Distribute devices across different team members to enforce separation of duties. Make sure no single person controls enough devices to meet the signing threshold alone.
- **Document your quorum design**: Record which devices belong to each quorum, who controls them, and the reasoning behind your threshold choices.
- **Review resharing requirements**: If your security policy requires key-share rotation, coordinate resharing with Ripple. The console doesn't reshare keys automatically.
- **Take fresh node backups after every reshare or restructure**: CloudSign node snapshots from before the change contain obsolete shards, so don't restore them. Key shard backups in S3 stay valid and need no action.
- **Test recovery procedures**: Verify in sandbox that you can recover from a lost device by restructuring the quorum.
- **Plan restructuring carefully**: Because restructuring puts wallets in maintenance mode, schedule it during low-activity periods and communicate the maintenance window to your team.


## Related guides

- [MPC quorums](/pt-br/products/wallet/user-interface/security-controls/mpc-quorums): Reference documentation
- [Key resharing](/pt-br/products/wallet/user-interface/security-controls/key-resharing): Resharing concept. Its backup guidance refers to CloudSign node snapshots, not to key shard backups in S3
- [Key restructuring](/pt-br/products/wallet/user-interface/security-controls/key-restructuring): Full restructuring reference
- [Manage devices](/pt-br/products/wallet/admin-guide/manage-devices): Approve and manage devices before adding them to quorums
- [Configure backup and recovery](/pt-br/products/wallet/admin-guide/configure-backup-and-recovery): Key shard backup model and maintenance