ChainIT Rolls Out Organizational MPC Wallets, Bringing 'Your Face Is Your Password' to Web3
Key Takeaways
- •Every transaction signed through ChainIT's organizational wallets must first be approved by a verified organizational member whose current authorization is checked at signing time, not only at onboarding.
- •ChainIT ID removes the need for memorized passwords by combining biometric liveness detection, device verification, and cryptographic proof of identity.
- •The wallet employs two-party MPC signing, with cryptographic shares isolated in separate AWS Nitro Enclaves so an Ethereum-compatible signature is produced without ever assembling the complete private key.
- •ChainIT is offering the wallet capability at no additional charge as part of every organizational digital identity profile.
- •The current release covers only human-approved transactions, while full partner integrations and AI agent-executed transactions within set limits are still being developed and tested separately.

ChainIT Inc. announced the production availability of its organizational Multi-Party Computation (MPC) wallets, linking the company's passwordless ChainIT ID to transaction-specific authority checks carried out before any signing takes place. The release requires a verified, authorized organizational member to approve each transaction signed through the wallet. The capability is included at no additional cost in each ChainIT organizational digital identity profile.
The announcement follows ChainIT's October 6 presentation of its Agentic Web3 Complete Commerce architecture during TOKEN2049 Week. The wallet launch centers on the people and organizations behind those transactions: confirming who they are, confirming they are currently authorized to act, and requiring their approval before any funds move. The underlying distinction—authentication, or proving who a person is, versus authorization, or proving what that person may do—is one that shared logins and memorized passwords tend to blur.
"A password is not a verified identity, and logging in is not authority to move company assets," said Jeremy Blackburn, Founder and Chief Executive Officer of ChainIT. "ChainIT connects who you are, what you are authorized to do and the transaction you approve. Your face is your password. Your authority is verified before the wallet signs. That is a Web3 solution for Web3 companies."
No memorized password, no blanket permission
Passwords and passphrases can be copied, shared, phished or forgotten. ChainIT ID removes the need for a memorized account password or passphrase, combining biometric liveness, device verification and cryptographic proof of identity. One-time verification challenges remain part of applicable security workflows. For organizations holding onchain assets, the stakes are direct: whoever controls a wallet's credentials generally controls the assets it holds.
In the organizational wallet flow, the member completes biometric liveness and wallet authentication, then signs an operation-specific approval using their own wallet identity. The live-person check occurs outside the signing enclaves. The Primary enclave—the isolated environment that verifies authorization before signing—then confirms that the wallet-signed approval came from a registered member of the organization and matches the requested action.
Authority before every transaction, not just at onboarding
Before any transaction is signed through the organization's wallet, the Primary enclave runs a series of checks. It confirms the wallet approval is valid, that the person is still an active member of the organization, and that the approval matches the exact action and transaction being requested. Each approval expires after a short window and can be used only once. Logging in, or approving one transaction, does not give anyone permission to carry out a different one.
ChainIT's organizational governance model connects officer registration, assigned roles and authority, and attested wallet policy. Invitations, member additions and member removals each require their own verified authorization. The objective is to connect not only who may transact, but also who may change the permissions governing future transactions.
Distributed signing without assembling the private key
The organizational wallet uses two-party MPC signing. Its signing key is represented by two separate cryptographic shares, each protected inside an isolated AWS Nitro Enclave. Both enclaves must participate to produce a standard Ethereum-compatible signature without reconstructing the complete private key. Persisted MPC key material is encrypted. Key-sharing designs of this kind underpin much of institutional crypto custody, where the goal is that compromising any single component is not enough to move funds.
A member's personal authorization key is separate from those organizational signing shares. The member approves the specific action; the Primary enclave verifies the authorization before initiating the joint signing process. The organizational shares remain within the enclave infrastructure rather than on members' devices. Neither MPC party can produce the organizational signature alone.
A Web3 solution for Web3 companies
ChainIT ID can be used wherever ChainIT-enabled applications support it, rather than requiring a new password for each participating service. Each integration retains its applicable verification, authorization and product requirements. ChainIT invites wallet providers, exchanges, marketplaces, payment platforms and enterprise Web3 teams to explore integrations for verified access and governed organizational transactions.
"Web3 companies need more than just another way to sign a transaction," said Eric Tacl, PhD, Executive Vice President, Verified Payments and Commerce, at ChainIT. "They need to connect the verified person, the organization, the appropriate level of authority and the action. Passwordless access simplifies the experience. Verifying authority for each specific transaction gives businesses control over what happens next."
The production wallet adds a human-authorized execution component to ChainIT's broader Complete Commerce architecture, which places authority and transaction-specific compliance before execution and transaction evidence. This release covers transactions approved by people. Full integration with partners' systems and transactions carried out by AI agents within set limits are being developed and tested separately, making both the pace of partner integrations and the eventual scoping of agent-executed transactions the follow-on developments that will show how far this model extends beyond human-approved transfers.