Posted by scarlin90
Sep 28, 2026/11:14 UTC
The recent updates to the Signing Room and the stateless PSBT coordination BIP draft have introduced significant enhancements, particularly in security and access control management. The release of version 3.4.0 of the coordinator and version 1.2.0 of the SDK marks a shift towards Role-Based Access Control (RBAC). This new feature is designed to maintain privacy and security by avoiding accounts or database states, and by ensuring participant identities are not exposed through the relay process.
In these updates, the protocol has moved beyond the simple binary access model that categorized users as either Coordinator or Guest. This change is crucial for environments where transaction processes require high-security measures, such as institutional settings or legal frameworks involving multisignature configurations. Now, transactions can involve off-chain witnesses, compliance officers, or observers who have the capability to verify outputs and signatures in real-time without the ability to directly submit signatures or alter the state machine.
A key innovation involves the generation of role-scoped capability tokens by the room initiator, derived from the root session entropy and embedded directly within the browser's URL fragment. Importantly, this key material does not traverse over HTTP. These tokens define signed policy scopes like can_propose, can_sign, or witness_only, which are enforced ephemerally in RAM by the relay. This means if an unauthenticated socket or an observer without signing privileges tries to send a signature payload, it is promptly rejected by the relay.
Further technical details and implementation guidelines can be found in the release notes at https://github.com/scarlin90/signingroom/releases/tag/v3.4.0. Additionally, the BIP draft has been updated to reflect the revised URL fragment schema, capability token message formats, and test vectors, which are available at BIP Draft Update.
Looking ahead, there is ongoing work to incorporate Tapscript and BIP 371 support to enhance capabilities beyond native SegWit multisig setups and to accommodate Miniscript spending trees. Feedback on these developments, especially concerning token derivation and message format, is actively encouraged to refine and optimize the framework further.
TLDR
We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.
We'd love to hear your feedback on this project.
Give Feedback