Skip to main content
POST
SDK — add a signer to a wallet in a business account

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

environmentId
string
required

ID of the environment

Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

businessAccountId
string
required

ID of the business account

Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

walletId
string
required
Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

Body

application/json

SDK addSigner body. Same user resolution shape as addMember (userId OR identifier + type), plus signerType for the signer-role enum (endUser/server). type here is the user-resolution type, NOT the signer type — signerType lives on a dedicated field. smsCountryCode is required when type is phoneNumber; socialProvider is required when type is socialUsername or socialAccountId. The remaining fields parameterise the MPC reshare ceremony that runs during the SSE response. clientKeygenIds come from the caller's local MPC state (the JS SDK obtains them internally by calling exportID() on the existing client share); the threshold scheme fields describe the source share set (old) and the destination share set (new) that the ceremony produces.

signerType
enum<string>
required

Type of a business account signer

Available options:
endUser,
server
clientKeygenIds
string[]
required

Caller's MPC keygen IDs participating in the reshare.

oldThresholdSignatureScheme
enum<string>
required
Available options:
TWO_OF_TWO,
TWO_OF_THREE,
THREE_OF_FIVE
newThresholdSignatureScheme
enum<string>
required
Available options:
TWO_OF_TWO,
TWO_OF_THREE,
THREE_OF_FIVE
userId
string<uuid> | null
identifier
string | null
type
enum<string>
Available options:
email,
id,
externalUserId,
phoneNumber,
socialUsername,
socialAccountId
smsCountryCode
object
socialProvider
enum<string>

The 'turnkey' value is deprecated and will be removed in a future version.

Available options:
emailOnly,
magicLink,
apple,
bitbucket,
coinbasesocial,
discord,
epicgames,
facebook,
farcaster,
github,
gitlab,
google,
instagram,
linkedin,
microsoft,
twitch,
twitter,
blocto,
banxa,
coinbaseOnramp,
cryptoDotCom,
moonPay,
dynamic,
alchemy,
zerodev,
telegram,
turnkey,
coinbaseWaas,
sms,
spotify,
tiktok,
line,
steam,
shopify,
zksync,
kraken,
blockaid,
passkey,
okta,
sendgrid,
resend,
trmWalletScreening,
chainalysisAddressScreening
initialSignerRules
object[]

Optional Rules to seed the new signer's signer-Layer with at add-signer time, so the signer is restricted from its first sign. Only valid when policy composition is enabled and the wallet is a composition wallet (env/wallet Layers exist); if supplied otherwise the request is rejected with 422 rather than creating an unrestricted signer. Rule shape mirrors the signer self-service policy-layer schema.

Response

SSE stream for the add-signer reshare ceremony. The response is text/event-stream (NOT JSON): clients consume it via EventSource and receive room_created and ceremony_complete events.

The response is of type string.

Last modified on August 11, 2026