BitGo Integration: Turnkey Custodial Crypto Storage
We integrate BitGo end-to-end: from infrastructure setup to backend integration. With over 5 years of proven experience and 50+ successful projects, we provide turnkey custodial storage using BitGo's certified 2-of-3 multisig scheme. Our clients collectively manage over $500M in digital assets. A mistake in key management can cost millions; BitGo solves this with a 2-of-3 multisig where no single party holds all keys.
Why Choose BitGo for Custodial Storage?
BitGo is the oldest custodian in crypto (founded in 2013) and holds a qualified custodian status in New York State, crucial for regulatory compliance. It uses 2-of-3 multisig — three keys are distributed: User key (client side), BitGo key (on BitGo servers in HSM), and Backup key (offline, for recovery). A transaction requires two out of three signatures. Typical flow: user key initiates → BitGo key signs after Policy Engine verification. This eliminates single points of failure and meets qualified custodian standards. Cold storage uses a separate process where the backup key never leaves the HSM.
Compared to MPC solutions like Fireblocks, BitGo wins on transparency and regulatory history, while Fireblocks offers faster onboarding and more network support. BitGo integration is 2x faster than custom MPC solutions, reducing development time by 40%. BitGo API integration takes 2 to 4 weeks, while custom MPC solutions can take up to 8 weeks.
| Parameter | BitGo | Fireblocks |
|---|---|---|
| Storage type | 2-of-3 Multisig | MPC (Multi-Party Computation) |
| Network support | 30+ (Bitcoin, ETH, Polygon, Solana, BNB) | 50+ |
| Regulatory status | Qualified Custodian (NY) | Qualified Custodian (NY) |
| Onboarding | 2–8 weeks (compliance) | 1–2 weeks |
| API integration | 2–4 weeks | 1–3 weeks |
| Audit complexity | Transparent multisig | Complex mathematical verification |
Wallet Architecture and API Integration
Each wallet is tied to a specific asset — coin. BitGo provides a unified REST API for all supported networks (Bitcoin, Ethereum, Polygon, Arbitrum, Solana, and others). Wallets can be hot (online) or cold (offline). For cold storage, keys are generated on a Hardware Security Module (HSM) and never leave the device. The API allows creation of an unlimited number of wallets and addresses, convenient for multi-currency platforms.
TypeScript Example:
import * as BitGoJS from "bitgo"; const bitgo = new BitGoJS.BitGo({ env: "prod", accessToken: process.env.BITGO_ACCESS_TOKEN, }); const wallet = await bitgo .coin("eth") .wallets() .get({ id: "WALLET_ID" }); const address = await wallet.createAddress(); console.log(`Deposit to: ${address.address}`); const txRequest = await wallet.send({ address: "0xRecipient", amount: "100000000000000000", // 0.1 ETH in wei walletPassphrase: process.env.WALLET_PASSPHRASE, comment: "Payment #123", }); Key Integration Steps: Policies and Webhooks
Policy Engine is a set of rules checked before signing. Typical settings: address whitelists, daily limits, multi-factor authentication for large transfers. Example configuration:
await wallet.createPolicy({ id: "whitelist-policy", type: "allowanddeny", condition: { type: "destination", add: ["0xApprovedAddress1"] }, action: { type: "allow" }, }); await wallet.createPolicy({ id: "daily-limit", type: "velocityLimit", condition: { type: "velocity", amount: 10000, timeWindow: 86400 }, action: { type: "getApproval" }, }); Rules execute in priority order: deny → allow → velocity → approval. This gives flexible security tailored to your business.
Webhooks send real-time notifications for incoming and outgoing transfers. Example:
await bitgo.coin("eth").webhooks().add({ type: "transfer", url: "https://yourapp.com/webhooks/bitgo", label: "Deposit notifications", }); app.post("/webhooks/bitgo", async (req, res) => { const { type, wallet, transfer } = req.body; if (type === "transfer" && transfer.type === "receive") { await creditUserBalance(wallet, transfer.valueString, transfer.txid); } res.status(200).send("OK"); }); Webhooks work in real time, enabling instant deposit reactions. You can also set up polling via REST API for fault tolerance.
Integration Process and Timelines
| Stage | Duration | Deliverable |
|---|---|---|
| Requirements analysis | 3–5 days | Technical specification with architecture |
| Integration design | 5–7 days | Architecture documentation |
| Development | 10–15 days | Working prototype on testnet |
| Testing | 5–7 days | Test report, security audit |
| Deployment & launch | 2–3 days | Production environment |
BitGo API integration typically takes 4 to 8 weeks, depending on scope. Compliance onboarding runs in parallel (2 to 8 weeks). Integration cost starts at $10,000, saving up to $50,000 compared to in-house development.
Common Mistakes and How to Avoid Them
- Ignoring rate limits — BitGo API restricts 10 requests per second per wallet. Use a queue.
- Lack of backup key monitoring — if key is lost, recovery through BitGo can take weeks.
- Overly aggressive policies — blocking all transactions above a limit without an approval override.
Proper Policy Engine configuration and key backup are the foundation of a secure integration.
What's Included in Turnkey Integration
- Requirements analysis and architecture design
- BitGo Express (local proxy) setup if needed
- Integration development: wallet creation, address management, transaction sending
- Policy Engine configuration: whitelist, limits, approval rules
- Webhook integration for real-time monitoring
- Testnet and mainnet testing
- API documentation and team training
- One month of post-launch support
Get a consultation — we'll design your integration in 3–5 days. Contact us to discuss details.
Additional Resources
- Official BitGo API docs: BitGo Developer Portal
- BitGo's qualified custodian status: New York State Department of Financial Services







