Sepior (Blockdaemon) MPC Vault
Threshold multi-party computation — key shares split across TSM nodes, reached through the DuoKey KMS API.
Overview
Sepior (now part of Blockdaemon) provides a threshold MPC / TSM (Threshold Signature Module) vault: each key is split into shares across multiple nodes, and no single node ever holds the complete key. Cryptographic operations are computed jointly across the nodes.
In Cockpit v2 this backend does not talk to the TSM nodes directly — it proxies through the DuoKey KMS API, which brokers the MPC session and operations.
| Property | Value |
|---|---|
| Vault type | sepior_mpc |
| Model | Threshold MPC (key shares across TSM nodes) |
| Integration | Via the DuoKey KMS API (not direct to TSM) |
| Post-quantum | Not supported (classical algorithms only) |
How it connects
Obtain an OAuth2 token
The adapter authenticates to the configured identity provider (Azure AD v1/v2 supported) using client credentials.
Initialize a KMS session
It calls the DuoKey KMS API to initialize a session, passing the Sepior TSM credentials as signed credentials alongside the bearer token.
Run crypto operations
Create, encrypt/decrypt, sign/verify and delete are executed through the KMS API against the MPC key shares.
Configuration
| Field | Purpose |
|---|---|
token_endpoint | OAuth2 token endpoint (Azure AD v1/v2 supported) |
client_id | OAuth2 client id |
client_secret | OAuth2 client secret (encrypted at rest, zeroized in memory) |
scope | Optional OAuth2 scope |
vault_credentials | Required Sepior TSM credentials (user id, node passwords, node URLs) |
The vault id is injected automatically so the KMS API routes to the correct key set. Secrets and cached tokens are zeroized from memory when no longer needed. If the backend's API rate-limit is exceeded, the call fails immediately with a rate-limit error rather than being retried.
What it supports
| Capability | Detail |
|---|---|
| Symmetric | AES-128 / AES-256 |
| RSA | RSA-2048 / RSA-4096 |
| ECC | EC-P256 / EC-P384 |
| MAC | HMAC |
| Operations | create, delete, encrypt, decrypt, sign, verify, public-key, key info, key count |
| Post-quantum | Not supported — use the Software Vault or Securosys for PQC |
Keys created through this backend are tracked in the Cockpit database rather than enumerated from the TSM, so remote key listing is served from Cockpit; a remote count is available for reconciliation.
Both the Sepior vault and the DuoKey MPC KMS remove the single-point-of-compromise of a monolithic key store. For the rationale behind multi-party computation, see Why MPC.