Who Cobo is
Cobo is a digital asset custody company founded in 2017 and headquartered in Singapore. Through one wallet-as-a-service API, WaaS 2.0, it offers custodial wallets secured by hardware security modules (HSMs) and Intel SGX, MPC wallets, smart contract wallets and exchange wallets.
Exchanges, funds, fintechs and payment companies use it to run deposits, withdrawals and treasury across many chains and tokens, and Cobo is SOC 2 Type II certified. Several wallet types behind a single API is why it is one of the custody providers our module connects to.
What it does in your platform
Custody & wallets
Runs your wallets on the Cobo wallet type you choose, custodial or MPC, with an address for each customer on each chain. Before Cobo completes a withdrawal it calls the module back, so nothing leaves without your limits, screening and approvals.
How the connection works
One connector in the Custody & wallets module talks to Cobo's WaaS 2.0 API with an API key kept in your platform's secrets. Cobo signs its webhooks and callbacks with Ed25519, so the module can prove every message came from Cobo.
An address per customer
The module creates an address in your Cobo wallet for the customer and chain, and your app shows it.
Cobo reports the deposit
A signed webhook tells the module about the incoming transaction, and further webhooks follow its status.
Screened and credited
Once the transaction succeeds, the module screens it and credits the customer, and your operations team sees it in the backoffice.
A withdrawal request
After your limits, screening and approvals, the module asks Cobo to transfer the funds.
Cobo calls back
Before processing, Cobo sends a callback to the module, which answers ok for a withdrawal it created and approved, and deny for anything else.
Signed and reconciled
The transaction is signed and broadcast under the transaction policies set in Cobo Portal, and the module reconciles the movement with the chain.
Next to other providers
Cobo is one of the custody providers the module runs on, next to the others in its group and your own MPC or HSM setup. The module's limits, screening, approvals and reconciliation stay the same whichever provider signs, and Cobo's transaction policies and callback add checks of their own.
Moving from Cobo to another provider later, or to your own keys, means moving the funds and giving customers new deposit addresses. Your apps and approval rules stay as they are, and the ledger keeps the history.
When Cobo fits best
A strong fit when
- You want custodial and MPC wallets from one provider, behind a single API.
- You support many chains and tokens and want them through the same integration.
- You want your platform to confirm every withdrawal again, by callback, before the provider processes it.
Also worth a look
- A custodian with a US national trust bank or an EU MiCA licence, such as BitGo, if your regulator expects one.
- Your own HSMs or MPC cluster, when the keys must stay in your infrastructure.
How we get you live
The contract
We help you get your Cobo account and contract in place, with the wallet types and chains you need.
Wallets and policies
We set up the wallets with you in Cobo Portal, with transaction policies and roles that sit alongside the module's approvals.
The keys
The API key goes into your platform's secrets, and the callback is tied to that key, so only withdrawals the module approved can complete.
A full test run
The whole flow runs in Cobo's development environment on testnets, from a deposit to a withdrawal approved by callback, before real funds move.
