Skip to main content

Why transactions need signatures

Every transaction on the Hive blockchain must be cryptographically signed to prove that it’s authorized by the account(s) performing the operations. Signatures ensure:

Authentication

Proves the transaction creator has access to the private keys

Authorization

Verifies the account holder approves the operations

Integrity

Ensures the transaction hasn’t been modified after signing

Non-repudiation

Creates an immutable proof of the transaction’s origin

How signing works

Signature digest

Before signing, WAX calculates a signature digest (hash) of the transaction:
The signature digest is deterministic - the same transaction always produces the same digest, making signatures verifiable.

Signature providers

WAX supports multiple signature providers through a pluggable interface. You choose the provider based on your application’s needs:

Available providers

Beekeeper

Server-side wallet manager for automated signing

Hive Keychain

Browser extension for secure key management

PeakVault

Mobile-friendly wallet integration

MetaMask

Ethereum wallet adapter for Hive

Provider interface

All signature providers implement a common interface:
ts/wasm/lib/detailed/extensions/signatures/index.ts

Signing with Beekeeper

Beekeeper is the recommended signature provider for server-side applications and automation:

Signing with browser extensions

For web applications, browser extensions like Hive Keychain provide secure signing without exposing private keys:
Browser extension providers handle user interaction (prompts, confirmations) automatically.

Authority levels

Hive accounts have multiple authority levels, each with different permissions:
Used for social interactions:
  • Voting on content
  • Creating posts and comments
  • Following/unfollowing
  • Custom JSON operations (most apps)
Lowest security level - Safe to use with third-party apps
Used for financial operations:
  • Transfers
  • Market orders
  • Power ups/downs
  • Account updates
Medium security level - Use with trusted apps only
Used for account recovery:
  • Changing owner key
  • Account recovery
  • Changing other authorities
Highest security level - Keep offline, use rarely
Used for encrypting memos:
  • Encrypting transfer memos
  • Private messages
Special purpose - Separate key for privacy

Required authorities

You can check which authorities a transaction requires:

Multiple signatures

Some operations require signatures from multiple accounts or multiple keys from the same account:

Manual signature handling

For advanced use cases, you can manage signatures manually:

Signature verification

You can verify that a transaction’s signatures are valid:

Encryption and decryption

Signature providers also handle encryption for private memos:
Encrypted memos must start with # to be recognized as encrypted. WAX handles this automatically when you use encryption.

Key management

WAX provides utilities for working with cryptographic keys:

Generate keys

Brain keys

Best practices

Always use signature providers that keep private keys secure. Never log or transmit private keys.
Only request the minimum authority level needed for your operations. Use posting authority for social operations.
Always call tx.validate() before signing to catch errors early and avoid wasting signatures.
Use tx.requiredAuthorities to inform users which keys they need to sign with.
Users may reject signing requests. Always handle errors and provide clear feedback.

Next steps

Broadcasting

Learn how to broadcast signed transactions

Signature Providers

Explore all signature provider options

Transactions

Review transaction concepts

Security

Best practices for secure signing