Run SignerSet
Start with a quick single-account demo, or move directly to the production multi-account setup.
Quick demo: one account
For getting to a demo the fastest, have claude code/codex/cursor guide you through the single-user process in setup-macos.md:
Recommended setup: separate accounts
For a meaningful security boundary, use three user accounts:
- 1.Proposer account — runs the agent that proposes actions.
- 2.Approver account (MPAS Maintainer) — runs the human, agent, or software that reviews and approves actions.
- 3.Credential account — runs the Credential Adapter and holds the protected service credentials. A local demo can connect directly to the adapter at http://127.0.0.1:7544. With separate machines or accounts, the adapter and proposer can communicate through the hosted Action Relay at https://api.signerset.com: start the adapter with --verifier-relay-url https://api.signerset.com. api.signerset.com is currently in closed beta. Once your organization and participant DIDs are provisioned, use SignerSet for both the Action Relay and Coordination Service. The adapter makes an outbound connection and does not need an inbound public HTTP endpoint.
The proposer and maintainer should not be able to read each other’s signing keys. Neither agent account should be able to read the credential account.
Do not give OpenClaw, Hermes, Codex, Claude Code, or another general-purpose agent access to credentials on the credential account.
Create the accounts
Create the proposer, maintainer, and credential accounts (on separate machines, virtual machines, containers, or operating-system user accounts).
Separate machines provide the strongest boundary, but separate user accounts are an accessible place to start.
Prepare each agent account
Install an agent harness (proposer and maintainer only)
Set up the account normally with the preferred agent environment, such as:
- OpenClaw
- Hermes
- Codex
- Claude Code
- Another MCP-compatible or agentic harness
Start with no direct permissions or credentials for the protected application. The agent should reach governed operations only through the MPAS integration below.
Clone the source repositories (all accounts)
Clone:
- The MPAS repository
- The MPAS Applications repository
Continue setup in each account using agent with file system access
Contact us to get on our closed beta program for SignerSet.com. Once you are set up, use the editable prompts below for all three accounts.
Credential account
Find the mpas repository on this machine and read examples/demo/guides/credential-adapter.md inside it. Follow the guide to set up this account as the Credential Adapter operator. Ask the operator to supply the public did:jwk values collected from the proposer and maintainer accounts through an authenticated out-of-band channel; do not assume those harnesses transmitted the values automatically. Complete every step in order: create the ~/.mpas directory tree, generate the adapter key, identify and display its public DID as the Credential Adapter’s verifier DID, source the application plugin and adapter-config template from mpas-applications, fill in the deployment config with the supplied proposer and maintainer DIDs, store the upstream credential, and validate the config. Tell the operator to provide the verifier DID to the proposer for relay configuration. Start the adapter in hosted relay mode with --verifier-relay-url https://api.signerset.com; this is an outbound connection and requires no inbound public HTTP endpoint. Have the SignerSet operator confirm the organization bindings, participant roles, designated verifier, and maintainer review access are provisioned. The proposer and maintainer must both use https://api.signerset.com as coordination.url. Do not start a local Coordination Service for this hosted setup. Never expose or transfer any private key or key file. Do not proceed until the adapter health check passes.Maintainer account
Find the mpas repository on this machine and read examples/demo/guides/maintainer.md inside it. Follow the guide to set up this account as a Maintainer. Complete every step in order: create the ~/.mpas directory tree, generate your Ed25519 signing key, and display the public did:jwk value to the user. Tell the user to provide only that public DID to the Credential Adapter operator through an authenticated out-of-band channel. Do not claim you transmitted the DID unless you actually have an authorized communication channel. Never expose or transfer the private key or key file. Stop and wait for the user to confirm that the DID has been registered before continuing. Then create the signer server config and register the signer server as an MCP server in this agent harness. Set coordination.url to https://api.signerset.com, matching the proposer configuration. Confirm with the SignerSet operator that your DID has an enabled same-organization binding or an explicit signer_review grant, separately from registration in the Credential Adapter approval policy. Use the base URL exactly; the MPAS client appends /mpas/v1/coordination. Do not start a local Coordination Service. Do not add any proposer bridge to this account. Verify by listing your available MCP tools and polling for pending approvals.Proposer account
Find the mpas repository on this machine and read examples/demo/guides/proposer.md inside it, and use the relay example in mpas-applications/README.md as the authority for the bridge configuration shape. Follow the guide to set up this account as a Proposer. Complete every step in order: create the ~/.mpas directory tree, generate your Ed25519 signing key, and display the public did:jwk value to the user. Tell the user to provide only that public DID to the Credential Adapter operator through an authenticated out-of-band channel. Do not claim you transmitted the DID unless you actually have an authorized communication channel. Never expose or transfer the private key or key file. Stop and wait for the user to confirm that the DID has been registered before continuing. Then find and clone the bridge for your application from mpas-applications, build it, and register it as an MCP server in this agent harness. For relay mode, configure actionEndpoint.url = "https://api.signerset.com" and actionEndpoint.verifierDid = "<Credential Adapter verifier DID>"; do not put the relay URL in adapter.url. Also set coordination.url to https://api.signerset.com, matching the maintainer configuration. Confirm that the SignerSet operator has provisioned your proposer organization binding and role, the designated verifier, and the nominated maintainers’ review access. Use the base URL exactly; the client appends /mpas/v1/coordination. Do not configure a localhost adapter or Coordination Service for this hosted setup. Do not add any maintainer signer server to this account. Verify by listing your available MCP tools and running a pass-through action.