Skip to main content
THRESHOLD MPC — THE KEY IS NEVER ASSEMBLED IN ONE PLACEMPC node 1share 1MPC node 2share 2MPC node 3share 3Resultsignature / plaintext, computed jointly
The key is split into shares held by separate nodes; cryptographic operations are computed jointly, so no single node ever holds the complete key.
Applies to:
Cockpit v2Software Vault (dev)DuoKey Software HSM (MPC)

DuoKey provides two distinct software backends. They are easy to confuse because both are "software", but they serve very different purposes.

Software VaultDuoKey Software HSM (MPC)
PurposeDevelopment / testProduction key management
Where keys liveIn process memorySplit across a 3+ node MPC cluster
Vault typesoftware_vaultduokey_software_hsm
CredentialsNone (local)OAuth2 client credentials
Post-quantumYesNo (classical only)

Software Vault (in-memory)​

The Software Vault performs all cryptography locally and holds keys in process memory. It is the platform's default fallback when no other vault is resolved, which makes local development and testing frictionless.

Not for production

Key material lives in process memory. The Software Vault is for development and testing only — it has no hardware protection and keys do not survive a restart unless persisted. Bind production tenants to the DuoKey MPC KMS, Securosys or another hardware/MPC backend.

What it supports​

CapabilityDetail
SymmetricAES-128 / AES-256 GCM
RSARSA-2048 / RSA-4096 — PKCS#1 v1.5 & PSS signing, OAEP-SHA256 encryption
ECCEC-P256 / EC-P384 — ECDSA SHA-256/384
MACHMAC-SHA256/384/512
Post-quantumML-KEM-512/768/1024, ML-DSA-44/65/87, SLH-DSA-128f/128s
Key exportPKCS#8 PEM export (RSA/EC) for local X.509 signing

Symmetric and private-key material is zeroized from memory when it is no longer needed. Because it is one of only two PQC-capable backends (with Securosys), the Software Vault is useful for exercising post-quantum flows in development.

DuoKey Software HSM (MPC KMS)​

The DuoKey Software HSM is the DuoKey key-management service: a multi-party-computation cluster where each key is split into shares across three or more nodes, so no single node ever holds the complete key. It is the default DuoKey KMS for production when no dedicated HSM is bound.

No single point of compromise

Keys are never reconstructed in one place; cryptographic operations are computed jointly across the cluster nodes.

Direct to the cluster

This backend connects directly to the MPC cluster (unlike the Sepior backend, which proxies through the DuoKey KMS API).

OAuth2-secured

Authenticated with client-credentials; tokens are cached and refreshed automatically, and secrets are zeroized from memory when no longer needed.

Configuration​

FieldPurpose
HostnameBase URL of the MPC cluster
client_idOAuth2 client id
client_secretOAuth2 client secret (encrypted at rest, zeroized in memory)

The backend authenticates via OAuth2 and then performs key and crypto operations against the MPC cluster.

What it supports​

CapabilityDetail
SymmetricAES-128 / AES-256
RSARSA-2048 / RSA-4096
ECCEC-P256 / EC-P384
MACHMAC
Operationscreate, delete, encrypt, decrypt, sign, verify, list, public-key
Post-quantumNot supported — use the Software Vault or Securosys for PQC
MPC threshold

The cluster is described as three or more nodes; the number of nodes is a deployment property rather than a per-vault configurable N-of-M constant.