The 2-of-3 MPC architecture
When an operational agent is provisioned, its cryptographic identity is generated inside SohoPayβs MPC signing infrastructure as a 2-of-3 threshold key. The three shares are distributed as follows:- Agent Workload Share: Held locally by the agent runtime or MPC escrow to sign payment requests with Proof-of-Possession (PoP).
- Policy Service Share: Held by SohoPayβs Policy Service. It co-signs only after validating spend limits, available credit, merchant allowlists, and sanctions screening.
- Cold Backup Share: Stored offline in secure escrow for disaster recovery.
Key security properties
- Zero raw private key exposure: The full private key is never assembled in any single memory space, database, or API response. There is no raw private key to leak or commit to version control.
- Fail-closed security: Neither share can sign a transaction alone. If the Policy Service detects a policy violation or becomes unreachable, payment authorization fails closed.
- Persistent wallet address: The agentβs Base
wallet_addressandagent_idremain identical across key rotations.
How to rotate agent keys
Key rotation generates a fresh key share pair and retires the previous shares. In-flight orders and merchant allowlists are completely unaffected. Rotate agent keys:- Whenever an engineer or operator with access leaves your organization.
- If you suspect any environment or runtime vulnerability.
- As part of your regular compliance schedule (e.g. quarterly).
Method A: Via the Borrower Portal (Recommended)
- Sign in to the SohoPay Borrower Portal.
- Navigate to My Agents and select the agent.
- Click Rotate Key and confirm the prompt with your connected wallet signature.
Method B: Programmatic rotation via Gateway API
For autonomous platform operators, SohoPay provides a multi-step off-chain rotation protocol:Step 1: Initiate key rotation (PoP)
The agent runtime submits its new public key (JWK) along with a Proof-of-Possession (pop_signature):
Step 2: Check rotation status & fetch challenge
Poll the rotation status to retrieve the EIP-712 challenge:Step 3: Reauthorize with operator wallet signature
The operator signs the EIP-712 challenge with their external wallet:Webhook notification: agent.key_rotated
Upon successful rotation, SohoPay delivers an agent.key_rotated event to your registered webhook endpoint:
Sohopay-Signature header as documented in Webhook Verification.
Emergency agent revocation (Kill Switch)
Understanding the distinction between pausing and revoking is critical for incident response:Revoking an agent programmatically
Revocation requires cryptographic proof to prevent malicious internal tampering:- Request a revocation challenge:
- Submit signed revocation:
You can also permanently revoke an agent with a single confirmation prompt in the Borrower Portal.
Disaster recovery & cold storage
If an active signing share is corrupted, SohoPay initiates a disaster recovery ceremony using the escrowed Cold Backup Share:- SohoPayβs monitoring detects quorum interruption and automatically pauses the agent to safeguard funds.
- The cold share is brought online under multi-party custody controls.
- Fresh shares are generated and re-established (forced rotation).
- The system delivers an
agent.key_rotatedwebhook event and unpauses the agent.
Operational best practices
- Enforce velocity controls: Set tight
daily_limitthresholds on every agent. Even during an incident, total exposure is bounded by daily limits. - Monitor rotation events: Set up automated alerts for unexpected
agent.key_rotatedwebhook deliveries. - Drain before rotation: Pause the agent briefly before scheduled maintenance rotations to ensure zero in-flight authorization conflicts.
Next steps
MPC Signing Protocol
Read the cryptographic specifications of our threshold signatures.
Webhooks Guide
Handle real-time
agent.key_rotated and payment lifecycle events.Vault & Funding
Manage your USDC collateral backing and revolving capacity.

