Skip to main content
The node’s signer backend is pluggable. A keyfile is the default; Turnkey and MPCVault keep the key in an MPC service and sign each offer through its API. In the app: Wallet → Use a wallet I already have → Connect Turnkey (or MPCVault). It tests a signature before it saves anything. On the command line, put one of the blocks below in your policy. The API key never goes in the file.
Set PANOFX_TURNKEY_API_PRIVATE_KEY_FILE to a file holding the API private key (or PANOFX_TURNKEY_API_PRIVATE_KEY to the key itself). Turnkey can also send the Permit2 approvals through panofx-node approve.When sign_with is a private key id rather than an address, set address too. base_url overrides the API host.
Run panofx-node signer test --policy policy.yaml after either change. MPC signing must stay under the 700 ms budget, or the node declines with signer_unavailable and never wins a quote.
The relay records the signer type (keyfile, turnkey or mpcvault) with each heartbeat, and shows it in the resolver directory.