Agent keys are the credentials that authorize your autonomous agents’ on-chain payments. This guide covers how agent keys operate within SohoPay’s 2-of-3 threshold infrastructure, how to perform zero-downtime key rotations, and how emergency revocations function.

The 2-of-3 MPC architecture

When an operational agent is provisioned, its cryptographic identity is generated inside SohoPay’s MPC signing infrastructure as a 2-of-3 threshold key. The three shares are distributed as follows:
  1. Agent Workload Share: Held locally by the agent runtime or MPC escrow to sign payment requests with Proof-of-Possession (PoP).
  2. Policy Service Share: Held by SohoPay’s Policy Service. It co-signs only after validating spend limits, available credit, merchant allowlists, and sanctions screening.
  3. Cold Backup Share: Stored offline in secure escrow for disaster recovery.

Key security properties

  • Zero raw private key exposure: The full private key is never assembled in any single memory space, database, or API response. There is no raw private key to leak or commit to version control.
  • Fail-closed security: Neither share can sign a transaction alone. If the Policy Service detects a policy violation or becomes unreachable, payment authorization fails closed.
  • Persistent wallet address: The agent’s Base wallet_address and agent_id remain identical across key rotations.

How to rotate agent keys

Key rotation generates a fresh key share pair and retires the previous shares. In-flight orders and merchant allowlists are completely unaffected. Rotate agent keys:
  • Whenever an engineer or operator with access leaves your organization.
  • If you suspect any environment or runtime vulnerability.
  • As part of your regular compliance schedule (e.g. quarterly).
  1. Sign in to the SohoPay Borrower Portal.
  2. Navigate to My Agents and select the agent.
  3. Click Rotate Key and confirm the prompt with your connected wallet signature.

Method B: Programmatic rotation via Gateway API

For autonomous platform operators, SohoPay provides a multi-step off-chain rotation protocol:

Step 1: Initiate key rotation (PoP)

The agent runtime submits its new public key (JWK) along with a Proof-of-Possession (pop_signature):

Step 2: Check rotation status & fetch challenge

Poll the rotation status to retrieve the EIP-712 challenge:

Step 3: Reauthorize with operator wallet signature

The operator signs the EIP-712 challenge with their external wallet:

Webhook notification: agent.key_rotated

Upon successful rotation, SohoPay delivers an agent.key_rotated event to your registered webhook endpoint:
Verify the Sohopay-Signature header as documented in Webhook Verification.

Emergency agent revocation (Kill Switch)

Understanding the distinction between pausing and revoking is critical for incident response:

Revoking an agent programmatically

Revocation requires cryptographic proof to prevent malicious internal tampering:
  1. Request a revocation challenge:
  2. Submit signed revocation:
You can also permanently revoke an agent with a single confirmation prompt in the Borrower Portal.

Disaster recovery & cold storage

If an active signing share is corrupted, SohoPay initiates a disaster recovery ceremony using the escrowed Cold Backup Share:
  1. SohoPay’s monitoring detects quorum interruption and automatically pauses the agent to safeguard funds.
  2. The cold share is brought online under multi-party custody controls.
  3. Fresh shares are generated and re-established (forced rotation).
  4. The system delivers an agent.key_rotated webhook event and unpauses the agent.
SohoPay staff will never ask you for private keys, seed phrases, or sensitive passwords. Always report suspicious requests to security@sohopay.xyz.

Operational best practices

  • Enforce velocity controls: Set tight daily_limit thresholds on every agent. Even during an incident, total exposure is bounded by daily limits.
  • Monitor rotation events: Set up automated alerts for unexpected agent.key_rotated webhook deliveries.
  • Drain before rotation: Pause the agent briefly before scheduled maintenance rotations to ensure zero in-flight authorization conflicts.

Next steps

MPC Signing Protocol

Read the cryptographic specifications of our threshold signatures.

Webhooks Guide

Handle real-time agent.key_rotated and payment lifecycle events.

Vault & Funding

Manage your USDC collateral backing and revolving capacity.