Note: This feature is currently in Early Access. If you are interested in joining the Early Access phase, contact your Fireblocks Customer Success Manager.
Overview
Setting an MPC Key Provisioner allows workspaces to designate an Admin user as the MPC key provisioner rather than relying solely on the workspace Owner. This feature helps organizations maintain operational continuity and meet compliance requirements by eliminating single-person dependencies for critical MPC key provisioning tasks.
When configured, all MPC key provisioning requests for new Signers and Admins will be routed to the designated Admin instead of the Owner.
Key benefits
- Operational resilience: Avoid delays when the Owner is unavailable.
- Compliance: Meet internal policies and regulatory requirements that prohibit single-person dependencies.
- Business continuity: Ensure critical key provisioning operations can continue without bottlenecks.
Before you begin
- You must have Admin permissions in the workspace to configure an MPC Key Provisioner.
Configuring an MPC Key Provisioner
- In the Fireblocks Console, go to Settings > MPC keys > Key provisioner.
- On the Key provisioner page, select Change provisioner.
- On the Change key provisioner dialog, select an Admin user from the list.
- Select Change provisioner.
After you're done, a "Pending changes" badge will appear next to the page heading to indicate an active change request. The Admin Quorum must then review and approve the request using the Fireblocks mobile app.
Once approved, the designated Admin becomes the provisioner for all future MPC key provisioning requests.
FAQ
What happens if the designated MPC Key Provisioner is unavailable?
If the designated provisioner is deleted or loses Admin permissions, Fireblocks automatically reverts to provisioning MPC keys via the Owner.
Can I designate multiple MPC Key Provisioners?
No. Only one Admin can be designated as the MPC Key Provisioner at this time.
Who can request to change the MPC Key Provisioner?
Any Admin in the workspace may request to change the MPC Key Provisioner.
What happens if I don't configure an MPC Key Provisioner?
The workspace Owner will continue to serve as the default MPC key provisioner.