SDK — add a signer to a wallet in a business account
Adds a signer to a business-account wallet by running a same-parties
2/2 -> 2/2 MPC reshare ceremony. The caller must hold an active share on
the wallet (only existing share-holders can reshare). The target user
is resolved the same way as addMember and, if absent, is created and
added to the account. The response is text/event-stream (NOT JSON):
clients consume it via EventSource and receive room_created and
ceremony_complete events; the new signer share is delivered to the
initiating client (iframe) via Sodot’s relay and backed up to the
client-keyshare service on the target’s behalf.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
ID of the environment
36^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"95b11417-f18f-457f-8804-68e361f9164f"
ID of the business account
36^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"95b11417-f18f-457f-8804-68e361f9164f"
36^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$"95b11417-f18f-457f-8804-68e361f9164f"
Body
SDK addSigner body. Same user resolution shape as addMember (userId OR identifier + type), plus signerType for the signer-role enum (endUser/server). type here is the user-resolution type, NOT the signer type — signerType lives on a dedicated field. smsCountryCode is required when type is phoneNumber; socialProvider is required when type is socialUsername or socialAccountId.
The remaining fields parameterise the MPC reshare ceremony that runs during the SSE response. clientKeygenIds come from the caller's local MPC state (the JS SDK obtains them internally by calling exportID() on the existing client share); the threshold scheme fields describe the source share set (old) and the destination share set (new) that the ceremony produces.
Type of a business account signer
endUser, server Caller's MPC keygen IDs participating in the reshare.
TWO_OF_TWO, TWO_OF_THREE, THREE_OF_FIVE TWO_OF_TWO, TWO_OF_THREE, THREE_OF_FIVE email, id, externalUserId, phoneNumber, socialUsername, socialAccountId The 'turnkey' value is deprecated and will be removed in a future version.
emailOnly, magicLink, apple, bitbucket, coinbasesocial, discord, epicgames, facebook, farcaster, github, gitlab, google, instagram, linkedin, microsoft, twitch, twitter, blocto, banxa, coinbaseOnramp, cryptoDotCom, moonPay, dynamic, alchemy, zerodev, telegram, turnkey, coinbaseWaas, sms, spotify, tiktok, line, steam, shopify, zksync, kraken, blockaid, passkey, okta, sendgrid, resend, trmWalletScreening, chainalysisAddressScreening Optional Rules to seed the new signer's signer-Layer with at add-signer time, so the signer is restricted from its first sign. Only valid when policy composition is enabled and the wallet is a composition wallet (env/wallet Layers exist); if supplied otherwise the request is rejected with 422 rather than creating an unrestricted signer. Rule shape mirrors the signer self-service policy-layer schema.
Response
SSE stream for the add-signer reshare ceremony. The response is
text/event-stream (NOT JSON): clients consume it via EventSource
and receive room_created and ceremony_complete events.
The response is of type string.