Connector · Custody and wallet-as-a-service

Cobo, running your wallets.

How our Custody & wallets module uses Cobo's wallet-as-a-service API: which wallet types fit, how a callback gives your platform the last word on withdrawals, and how we get you live.

CoboCustody and wallet-as-a-service
Website
cobo.com
Modules
Custody & wallets
Contract
We help you get it

Who Cobo is

Cobo is a digital asset custody company founded in 2017 and headquartered in Singapore. Through one wallet-as-a-service API, WaaS 2.0, it offers custodial wallets secured by hardware security modules (HSMs) and Intel SGX, MPC wallets, smart contract wallets and exchange wallets.

Exchanges, funds, fintechs and payment companies use it to run deposits, withdrawals and treasury across many chains and tokens, and Cobo is SOC 2 Type II certified. Several wallet types behind a single API is why it is one of the custody providers our module connects to.

What it does in your platform

  • Custody & wallets

    Runs your wallets on the Cobo wallet type you choose, custodial or MPC, with an address for each customer on each chain. Before Cobo completes a withdrawal it calls the module back, so nothing leaves without your limits, screening and approvals.

How the connection works

One connector in the Custody & wallets module talks to Cobo's WaaS 2.0 API with an API key kept in your platform's secrets. Cobo signs its webhooks and callbacks with Ed25519, so the module can prove every message came from Cobo.

  1. An address per customer

    The module creates an address in your Cobo wallet for the customer and chain, and your app shows it.

  2. Cobo reports the deposit

    A signed webhook tells the module about the incoming transaction, and further webhooks follow its status.

  3. Screened and credited

    Once the transaction succeeds, the module screens it and credits the customer, and your operations team sees it in the backoffice.

  4. A withdrawal request

    After your limits, screening and approvals, the module asks Cobo to transfer the funds.

  5. Cobo calls back

    Before processing, Cobo sends a callback to the module, which answers ok for a withdrawal it created and approved, and deny for anything else.

  6. Signed and reconciled

    The transaction is signed and broadcast under the transaction policies set in Cobo Portal, and the module reconciles the movement with the chain.

Next to other providers

Cobo is one of the custody providers the module runs on, next to the others in its group and your own MPC or HSM setup. The module's limits, screening, approvals and reconciliation stay the same whichever provider signs, and Cobo's transaction policies and callback add checks of their own.

Moving from Cobo to another provider later, or to your own keys, means moving the funds and giving customers new deposit addresses. Your apps and approval rules stay as they are, and the ledger keeps the history.

When Cobo fits best

A strong fit when

  • You want custodial and MPC wallets from one provider, behind a single API.
  • You support many chains and tokens and want them through the same integration.
  • You want your platform to confirm every withdrawal again, by callback, before the provider processes it.

Also worth a look

  • A custodian with a US national trust bank or an EU MiCA licence, such as BitGo, if your regulator expects one.
  • Your own HSMs or MPC cluster, when the keys must stay in your infrastructure.

How we get you live

  • The contract

    We help you get your Cobo account and contract in place, with the wallet types and chains you need.

  • Wallets and policies

    We set up the wallets with you in Cobo Portal, with transaction policies and roles that sit alongside the module's approvals.

  • The keys

    The API key goes into your platform's secrets, and the callback is tied to that key, so only withdrawals the module approved can complete.

  • A full test run

    The whole flow runs in Cobo's development environment on testnets, from a deposit to a withdrawal approved by callback, before real funds move.

Questions

Asked about this connector.

How do we get started with Cobo?

Talk to us. We help you get the Cobo contract in place, choose the wallet types with you, connect them to your platform and run the whole flow in Cobo's development environment.

Custodial or MPC wallets?

Custodial wallets leave the keys to Cobo, protected by HSMs and Intel SGX. MPC wallets split each key into shares held by different parties, such as a TSS node you run on your own server and Cobo's own node. The module works the same way on both.

What does the callback add?

A last gate inside Cobo. Even with a valid API key, a withdrawal completes only if the module answers ok, so a transfer the module did not create and approve is denied.

What if we want to leave Cobo later?

You move the funds and customers get new deposit addresses on the new provider or on your own keys. Your apps, your approval rules and your records do not change.

Start your project

Tell us the idea. We'll show you the platform.

One call is enough to map your product to the modules that already exist.

  • Response in under one business day
  • NDA on request
  • No obligation
What are you building?