{"repo":"ecadlabs/signatory","free":true,"listed":false,"github":"https://github.com/ecadlabs/signatory","clone":"git clone https://github.com/ecadlabs/signatory.git","description":"Tezos remote signer with policies, Prometheus metrics, and HSM/KMS + TEE backends (YubiHSM, CloudHSM, Nitro Enclaves, Confidential Space).","language":"Go","stars":75,"topics":["tezos","tezos-baking","hsm","kms","cryptography","yubihsm","aws-kms","gcp-kms","ledger-wallet","blockchain"],"license":"Apache-2.0","category":"blockchain-web3","readme_excerpt":"A Tezos Remote Signer What is Signatory? Signatory is a remote signing daemon that allows Tezos bakers and Tezos Application teams to protect their private keys. The goal of the Signatory service is to make key management as secure as possible in a Cloud and on-premise HSM context. Why Use Signatory? Security and convenience are typically at odds with each other. Signatory makes it easier for Tezos teams to manage their keys securely by offering several well-tested & supported signing options for cloud-based or hardware-based HSMs, as well as Trusted Execution Environments (TEEs). BLS (tz4) Support Tezos consensus supports BLS12-381 via tz4 keys, introduced in the Seoul protocol. Signatory signs tz4 consensus and DAL companion keys from AWS Nitro Enclaves and Google Confidential Space, the only production-grade cloud backends that handle BLS12-381 today. See Signatory for Tezos BLS for the migration story, deployment patterns, and backend support. Quick Start See docs --- GitHub Docs Explore detailed documentation for various components of Signatory: Introduction - Getting Started - Authorized Keys - Command-Line Interface (CLI) - Bakers - DAL & BLS Attestations Vault Backends - Azure KMS - AWS KMS - AWS Nitro Enclave - Google Cloud KMS - Google Confidential Space - Hashicorp Vault - Ledger Integration - Local Secret Storage - PKCS#11 (AWS CloudHSM compatible) - YubiHSM Watermark / Signing Tracking - Memory - File - AWS DynamoDB - Google Cloud Firestore Other - JWT Authentica","default_branch":null,"files":null,"tree":[],"storefront":"/r/ecadlabs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ecadlabs/signatory/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}