Skip to main content
Signing is a critical step that proves you have authority to execute the operations in a transaction. WAX supports multiple signing providers for different use cases.

Understanding signatures

Every transaction must be signed with one or more private keys that correspond to the authorities required by the operations in the transaction.
1

Check required authorities

Before signing, determine which authorities are needed for your transaction.
Most operations require posting authority (votes, comments). Financial operations require active authority (transfers, power ups). Account recovery requires owner authority.
2

Get the signature digest

The signature digest is what you actually sign. It’s a cryptographic hash of the transaction.
3

Sign with a provider

Use your preferred signing provider to sign the transaction. See the sections below for provider-specific examples.
4

Verify signatures

After signing, you can verify which public keys signed the transaction.

Signing with Beekeeper

Beekeeper is the official wallet solution for Hive. It provides secure key management and signing.
Beekeeper runs as a separate process and manages keys securely. Never hardcode private keys in production code.

Signing with Hive Keychain

Hive Keychain is a browser extension that provides secure signing for web applications.
Hive Keychain must be installed in the user’s browser. Always check if Keychain is available before attempting to sign.

Signing with MetaMask

MetaMask Snaps enables signing Hive transactions using MetaMask.

Signing with PeakVault

PeakVault is a mobile wallet that supports signing through deep links.

Manual signing

You can also sign transactions manually if you have the private key.
Be extremely careful when handling private keys directly. Never expose them in client-side code or logs.

Multi-signature transactions

Some operations require multiple signatures from different authorities.

Best practices

Always validate your transaction before attempting to sign it. This catches errors early and prevents wasted signing attempts.
Before signing, verify that you have the correct authority level for the operations in your transaction.
Signing can fail for various reasons (user rejection, wrong key, etc.). Always handle errors appropriately.
Private keys should never be:
  • Hardcoded in source code (except for testing)
  • Logged to console or files
  • Sent over insecure connections
  • Stored in plaintext
Use secure signing providers like Beekeeper or Keychain instead.

Next steps

Broadcasting transactions

Learn how to broadcast your signed transactions

Signing providers

Explore all available signing provider extensions

Beekeeper setup

Detailed guide to using Beekeeper

Keychain integration

Integrate Hive Keychain in your web app