Software & DuoKey MPC KMS
Two DuoKey-operated software backends: a local in-memory vault for development, and the DuoKey MPC key-management service for production.
DuoKey provides two distinct software backends. They are easy to confuse because both are "software", but they serve very different purposes.
| Software Vault | DuoKey Software HSM (MPC) | |
|---|---|---|
| Purpose | Development / test | Production key management |
| Where keys live | In process memory | Split across a 3+ node MPC cluster |
| Vault type | software_vault | duokey_software_hsm |
| Credentials | None (local) | OAuth2 client credentials |
| Post-quantum | Yes | No (classical only) |
Software Vault (in-memory)
The Software Vault performs all cryptography locally and holds keys in process memory. It is the platform's default fallback when no other vault is resolved, which makes local development and testing frictionless.
Key material lives in process memory. The Software Vault is for development and testing only — it has no hardware protection and keys do not survive a restart unless persisted. Bind production tenants to the DuoKey MPC KMS, Securosys or another hardware/MPC backend.
What it supports
| Capability | Detail |
|---|---|
| Symmetric | AES-128 / AES-256 GCM |
| RSA | RSA-2048 / RSA-4096 — PKCS#1 v1.5 & PSS signing, OAEP-SHA256 encryption |
| ECC | EC-P256 / EC-P384 — ECDSA SHA-256/384 |
| MAC | HMAC-SHA256/384/512 |
| Post-quantum | ML-KEM-512/768/1024, ML-DSA-44/65/87, SLH-DSA-128f/128s |
| Key export | PKCS#8 PEM export (RSA/EC) for local X.509 signing |
Symmetric and private-key material is zeroized from memory when it is no longer needed. Because it is one of only two PQC-capable backends (with Securosys), the Software Vault is useful for exercising post-quantum flows in development.
DuoKey Software HSM (MPC KMS)
The DuoKey Software HSM is the DuoKey key-management service: a multi-party-computation cluster where each key is split into shares across three or more nodes, so no single node ever holds the complete key. It is the default DuoKey KMS for production when no dedicated HSM is bound.
No single point of compromise
Keys are never reconstructed in one place; cryptographic operations are computed jointly across the cluster nodes.
Direct to the cluster
This backend connects directly to the MPC cluster (unlike the Sepior backend, which proxies through the DuoKey KMS API).
OAuth2-secured
Authenticated with client-credentials; tokens are cached and refreshed automatically, and secrets are zeroized from memory when no longer needed.
Configuration
| Field | Purpose |
|---|---|
| Hostname | Base URL of the MPC cluster |
client_id | OAuth2 client id |
client_secret | OAuth2 client secret (encrypted at rest, zeroized in memory) |
The backend authenticates via OAuth2 and then performs key and crypto operations against the MPC cluster.
What it supports
| Capability | Detail |
|---|---|
| Symmetric | AES-128 / AES-256 |
| RSA | RSA-2048 / RSA-4096 |
| ECC | EC-P256 / EC-P384 |
| MAC | HMAC |
| Operations | create, delete, encrypt, decrypt, sign, verify, list, public-key |
| Post-quantum | Not supported — use the Software Vault or Securosys for PQC |
The cluster is described as three or more nodes; the number of nodes is a deployment property rather than a per-vault configurable N-of-M constant.