Context
The first build generated vault keys locally and moved money through wallets Corridor controlled. For a licensed payment company that is a dealbreaker: funds in flight would sit with an unlicensed intermediary, and due diligence stops at “who holds our money?”. In most jurisdictions it would also make Corridor a money transmitter or crypto-asset service provider.Decision
All signing goes through one interface, implemented by the customer’s signer.@corridor/signer defines secp256k1 (Tempo, Base) and Ed25519 (Solana) signers; adapters turn them into chain accounts. Corridor runs self-hosted or as a dedicated managed instance and calls the customer’s KMS or MPC provider with digests only.
Consequences
- Corridor is software, not a custodian: the licence, the funds and the keys stay with the customer.
- AWS KMS is supported now; each further provider is one adapter.
- Local keys remain for development and testnet only.
- The shielded lane keeps FROST 2-of-3 (ADR 0006).
Alternatives rejected
- Corridor-run custody with a licence: slow to obtain, and it puts Corridor in competition with the providers it should route through.
- Partner custody (Corridor picks a custodian): still a third party between the customer and its money, and it locks the customer to that custodian.