Sign from a hardware enclave
Cosigner is an independent signer that Fystack never controls. It holds its own key share, decodes every transaction locally, and shows you exactly what you are about to sign — before a signature exists.

/WHAT YOU SEE IS WHAT YOU SIGN/
Validate the transaction locally, before it is signed
The cosigner does not trust the request it receives. It decodes the raw payload itself, checks it against your policies, and asks you to confirm the result — so what appears on screen is provably what gets signed.
- Chain
- Base
- Contract
- USDC · 0x8335…2913Verified
- Method
- transfer(address,uint256)
- Recipient
- 0x510e94…e56370Whitelisted
- Amount
- 10.00 USDC ≈ $10.01
- Network fee
- 0.00021 ETH ≈ $0.68
Blind signing
No opaque hex to approve. The cosigner renders the human-readable intent of the payload, and refuses anything it cannot decode.
Tampered payloads
If a compromised backend or middleware alters the recipient or amount after a request is created, the decoded view no longer matches — and signing stops.
Address poisoning
Look-alike addresses from clipboard swaps or dusting attacks are caught against your address book before the signature is produced.
Malicious approvals
Unlimited token approvals and unexpected contract calls are surfaced explicitly instead of hidden inside calldata.
/HOW IT WORKS/
A key share you hold, in hardware you control
Pair with a scoped token
Enroll a device or a server with a one-time pairing token bound to a single workspace. Pairing can be revoked at any time without touching the wallet.
Generate a share in the enclave
The key share is created inside Secure Enclave, StrongBox, or a server TEE, and never leaves it. Fystack never sees it and cannot reconstruct it.
Decode and verify locally
Every sign request is decoded on the cosigner itself, checked against your policies, and displayed in full before anything is approved.
Contribute a partial signature
On confirmation the enclave produces its part of the MPC signature. Without it the threshold is never met and the transaction cannot settle.
/TWO FORM FACTORS/
A phone in your pocket, or a daemon in your infrastructure

Mobile cosigner
Approve from a device only your team can unlock
Server cosigner
A headless signer running in your own infrastructure
/INSIDE THE APP/
Every approval, on the record
The mobile cosigner is not just an approve button. It keeps the full context of what was requested, what was signed, and what this device has authorized.

Approvals and timeline
The raw signing input, who still has to approve, and every stage from request to settlement.

Transaction history
Everything you signed, with live confirmation status and the destination address.

Activity log
An audit trail of every wallet setup and signing event this device approved.
/USE CASES/
Where a second signer changes the risk profile
Treasury with human approval
Finance operators hold the mobile cosigner. Large withdrawals cannot leave the treasury until a named person reviews the decoded transaction and signs.
Automated payouts with a guardrail
The server cosigner signs high-volume payouts around the clock, but only when the decoded transaction satisfies your policy — amount, destination, and chain.
Provable separation of duties
Fystack orchestrates, your cosigner authorizes. Neither side can move funds alone, which is exactly what auditors and regulators want to see.
Cosigner is rolling out soon
Tell us how your team approves transactions today and we will bring you into the early access group for both the mobile and server cosigner.
Join the waitlist