Skip to content
COINHOST / INDEPENDENT BITCOIN CUSTODYYOUR KEYS. YOUR AUTHORITY.
coinhostGet in touch
coinhost / docs / creating a vault

Creating a vault.

A vault brings separate keys into one signing policy. In the private beta's 2-of-3 design, two keys must agree before a transaction can be authorized.

02 of 4private beta · testnetupdated · 15 September 2026

Setup checklist

Follow the setup instructions for your beta build. Before completing setup, review these four things:

  1. Network. Confirm that you are using testnet, with test coins only.
  2. Policy. Confirm a 2-of-3 threshold and the three distinct signers: your phone, your hardware device, and Coinhost recovery.
  3. Key identities. Check the displayed key fingerprints against the signer information available to you.
  4. Recovery. Save the wallet information and understand how the remaining signers would help if one key became unavailable.

Readiness is more than a label

A vault name or balance screen does not establish that you can sign. Complete hardware pairing, resolve any incomplete-setup warnings, and rehearse a transaction on testnet. If the app's status is unclear, stop and ask support before proceeding.

The descriptor

A Bitcoin output descriptor describes how a wallet's addresses are constructed. For a multisignature wallet, it includes the public key information and signing policy needed to reconstruct that wallet. See the Bitcoin multisig descriptor specification for the standard.

Keep the complete export, including all key origins, derivation information, and receive and change descriptors supplied by the app. Do not replace it with a screenshot of a single address.

Wallet map, not a spending key

A descriptor does not authorize spending. You still need two usable signing keys for a 2-of-3 vault. It is also sensitive: its public key information can reveal wallet activity, so keep it private.

Receiving on testnet

Confirm the network and receiving address before requesting test coins. Where your signer supports displaying the address for this multisig policy, compare it with the address in the app. If they differ, do not proceed.

Use fresh receiving addresses where supported. Save the wallet's complete recovery information so another compatible tool can find both receive and change outputs.

Rehearse signing

The everyday path uses your mobile key and hardware key. Before approving, review the destination, amount, and network fee. Use the hardware signer's display when available; a signer without a display cannot independently show you what you are approving.

Confirm that the test transaction appears on the intended network. Then review the recovery guide and rehearse your independent path with compatible tools. Import support and signer access must both be checked; a descriptor import alone is not a complete recovery test.