Skip to main content
KYI verifies an asset by tying it to the organization that controls it. After KYB proves who the organization is, wallet verification proves the organization controls the token. A member signs once for each wallet that holds on-chain authority over the token.

Key concepts

How it works

  1. Bluprynt reads the token’s contract and lists the authority wallets.
  2. The member picks a wallet and a signing method.
  3. Bluprynt issues a challenge that expires: five minutes for a browser wallet, 30 minutes for a manual signature. An expired challenge is refreshed automatically.
  4. The member signs. Most methods sign off-chain: no funds move and no gas is paid.
  5. Bluprynt verifies the signature against the wallet address. Off-chain signatures are confirmed instantly; HSM memo transactions are reviewed by Bluprynt.
  6. When every token has an attested authority, the member can file the asset for decision.
Select Signing Method dialog listing extension wallet, manual signature and HSM options.

Signing methods for an Ethereum authority wallet (Bluprynt Passport; the widget shows the same dialog).

Methods by chain

WalletConnect and transaction verification are switched on per integration. Ask your Bluprynt contact which methods your members get.

Extension wallet

Sign with Extension Wallet with Connect Wallet, the message and Sign Message.
  1. Connect Wallet, and switch to the authority account if the wallet opens another one.
  2. Check the message being signed. It names the purpose, the organization it’s issued to, and the address with a nonce.
  3. The message expires after five minutes and is refreshed automatically.
  4. Sign Message. The wallet shows a personal_sign request (EVM), a message-signing request (Solana), or a GemWallet / Crossmark prompt (XRPL).
The connected account must be the authority wallet. Otherwise, the signature doesn’t verify for that address.

Manual signature (CLI)

Use this for keys in a keystore, a hardware wallet over USB, or any machine without a browser wallet.
Manual Signature screen with challenge, cast command and signature field.
  1. Copy the signature challenge whole, including line breaks.
  2. Run the command the widget shows. It already contains the challenge.
  3. Paste the signature and press Submit.
cast prints a 0x-prefixed 65-byte signature. Paste only that line. For XRPL, the widget shows a short script for xrpl or ripple-keypairs with the challenge filled in.

HSM or custody

Use this when the key can’t sign arbitrary messages, for example an HSM policy or a qualified custodian.
HSM screen with the memo text and email instructions.
  1. From the authority wallet, submit a no-op transaction carrying exactly this memo:
  2. Email the transaction link (block explorer URL) to product@bluprynt.com.
  3. Bluprynt reviews the transaction and replies. The wallet stays unverified until then.
No assets move. The transaction pays normal network fees.

Multisig

If a token’s authority is a multisig, such as a Safe, the queue offers two ways to sign:

Worked example: USD Coin on Ethereum

The queue for an asset with one authority, an upgrade admin:
Verify your wallets dialog with one upgrade admin wallet.
  1. The member clicks Sign next to 0x80…95d2 · Upgrade admin.
  2. They choose Manual Signature (CLI) and copy the challenge.
  3. They run cast wallet sign --ledger "<challenge>" with the admin key on a Ledger.
  4. They paste the signature and press Submit. The authority becomes ATTESTED and the queue reads “Nothing left to sign for.”

Errors and limits

FAQ

No, for extension wallet, WalletConnect and manual signatures: they sign off-chain. HSM memo transactions and transaction verification are on-chain and pay network fees, but move no assets beyond the micro-transfer.
Only that the signer controls the address. It doesn’t attest to the asset’s name, reserves or any other field.
Once per wallet. One signature covers every token that wallet controls.
Related: Verification flow · Supported chains · KYI