TAPSIGNER: setup and NFC signing
A bitcoin key in a credit card, signing by tap. Initialising it, the backup that must happen before you fund it, and the one number printed on the card that you have to copy down before it goes anywhere.
A TAPSIGNER is a bitcoin key inside a credit card. There is no screen, no battery, and no buttons — you build a transaction in a wallet app on your phone, hold the card against the back of it, and the card signs. The key itself never leaves the chip.
It is the least intrusive hardware wallet available: it lives in a wallet next to your bank cards and costs about as much as a nice dinner. That convenience is bought with one specific compromise, which this page will not bury — and there is a number printed on the card that you must copy down before the card ever leaves your desk.
A TAPSIGNER card held against the back of a phone showing a wallet app mid-signature, shot close, the card's printed back not legible.
Image to come
Before you start
- A TAPSIGNER card, bought from Coinkite or an authorised reseller.
- A phone with NFC and one of the supported wallet apps — Nunchuk, Cove, Bitcoin Keeper, or Sparrow on desktop.
- Somewhere to store an encrypted backup file that is not only your phone.
- A pen. Genuinely — see step 3.
- No bitcoin yet. Do not fund this card until the backup exists and the check at the end passes.
1What it is, and the one thing it cannot do
The card holds a single BIP-32 master key in a secure element and signs with it on request. Your wallet app does everything else: watching balances, choosing coins, building transactions, and broadcasting them.
The compromise is the missing screen. Every other hardware wallet shows you the amount and the destination on its own display, precisely so that a compromised computer cannot show you one transaction while asking you to sign another. A TAPSIGNER has no display, so it signs what it is given and cannot tell you what that is.
What that actually means for you
Your phone becomes the thing you are trusting to tell the truth about a payment. That is a real step down from a device with its own screen, and it is the reason to think of a TAPSIGNER as an excellent everyday key rather than the place to keep your life savings.
2Pair it with a wallet
Setup happens through the wallet app rather than on the card, and takes a couple of minutes.
- Open your wallet app and add a TAPSIGNER as a new key or signer.
- Let it verify the factory certificate. The card proves it is genuine Coinkite hardware and not a substitute. Do not skip past a failure here.
- Create the key on the card. It generates its own BIP-32 master key internally; nothing is imported and nothing is typed.
- Find the CVC. A six-digit code is printed on the back of the card — the spend code, sometimes called the starting PIN. You will need it for every signature, and you can change it later.
3The backup, and the number on the card
This is the most important section on this page, and the step people skip because the card works fine without it.
A TAPSIGNER has no recovery words. Instead, it gives you an encrypted backup file containing your master key. That file is encrypted with a 128-bit AES key, and that key is printed on the back of the card.
Read that again, because two conclusions follow and they point in opposite directions.
- Lose the card and you lose the decryption key with it — unless you copied it down first. The backup file alone is inert. Copy the printed key onto paper, now, before the card goes into a wallet or a drawer or a pocket.
- Anyone holding both the file and that printed key has your wallet. They do not need the card, and they do not need the CVC. A photograph of the back of your card plus a copy of your backup file is a complete theft.
- So store them apart. The printed key and the backup file in the same place is the same mistake as a seed phrase photographed next to its hardware wallet.
There is also no restoring back onto the card. Recovery decrypts the master key so you can load it into other software — the original card is not part of the picture. That is fine, and worth knowing before the day you need it.
The card is the convenience. The backup file and the number printed on its back are the wallet. Treat those two the way you would treat twenty-four words.
4Signing a transaction
Day to day, this is the whole workflow and it is genuinely pleasant:
- Build the payment in your wallet app as usual.
- Check the amount and the destination address on the phone screen. This is your only opportunity — the card will not show you anything.
- Enter the CVC when prompted.
- Hold the card flat against the back of the phone until the app confirms. Finding the NFC sweet spot takes a couple of tries the first time.
- The wallet broadcasts the signed transaction.
5Before you fund it
- Confirm the backup file exists and is stored somewhere that is not just your phone.
- Confirm you have written the printed decryption key down, separately from that file.
- Change the CVC from the printed default if your wallet app supports it, and record the new one.
- Send a small test amount, confirm it arrives, then sign a transaction sending it back out.
- Consider where this card fits: excellent as an everyday spending key, or as one key of a multisig where the other signers have screens.
The short version
A TAPSIGNER is a key in a card that signs by tap and never reveals itself. It has no screen, so your phone is what you are trusting about each payment. Its backup is an encrypted file whose decryption key is printed on the card — copy that number down before the card leaves your desk, and never store the copy beside the file.
If you take one thing from this page
Copy the decryption key off the back of the card today. Everything else here can be fixed later; that number cannot be recovered once the card is gone, and without it the backup file is a permanently locked box.