# Start DKG Ceremony

Begin a 2-of-3 distributed key generation ceremony — the first step in provisioning a new MPC wallet.

## Overview

This endpoint creates a relay session and triggers Aurea's HSM-backed cosigner to join. The browser-side party then joins via `/relay/session/{id}/join` and runs the DKG message loop with the cosigner. After the ceremony completes, the browser uploads its share to encrypted backup (passkey / recovery code) and the relay returns a verified Ethereum address.

Finalise by calling **Register MPC Wallet** with the `sessionId`, `walletId`, and the recovered `address`.

Aurea runs one of two threshold-signature engines, chosen per ceremony via the `scheme` field: the audited **CGGMP** (Dfns cggmp21) engine — recommended, with instant address generation — or the legacy **GG18** (tss-lib) engine. Both produce standard secp256k1 wallets whose addresses and signatures are indistinguishable on-chain, and both use the identical relay/join message loop. When `scheme` is omitted the ceremony defaults to `gg18`; pass `scheme: "cggmp"` for the audited engine.

> ⚠️ Aurea NEVER sees the device or backup shares. If you lose both, the wallet is unrecoverable. Always verify the user has at least one backup factor (passkey or recovery code) before starting DKG.

### `POST /v1/mpc/wallets/dkg/start`

Authentication: bearer token required.

Creates a relay session, triggers the AUREA cosigner, returns the sessionId and provisional walletId.

**Request body**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `chain` | string | yes | Chain the wallet will operate on (e.g. base, ethereum, polygon, gnosis) |
| `curve` | string | no | Curve (default: secp256k1) |
| `scheme` | string | no | MPC engine: 'cggmp' (audited Dfns cggmp21 — recommended) or 'gg18' (legacy tss-lib). Default: 'gg18'. |
| `isTestnet` | boolean | no | Provision against testnet (default: false) |

**Responses**

`200` OK

```json
{
  "sessionId": "ses_01J…",
  "walletId":  "mpc-wallet-uuid"
}
```

`403` Forbidden

```json
{ "error": "MPC not enabled for this tenant" }
```

## Implementation

```javascript
// 1. Server-side: trigger the AUREA cosigner + reserve a walletId
const { sessionId, walletId } = await fetch(
  'https://api.aureahub.com/v1/mpc/wallets/dkg/start',
  {
    method: 'POST',
    headers: { Authorization: `Bearer ${hubJwt}`, 'Content-Type': 'application/json' },
    body: JSON.stringify({ chain: 'base', isTestnet: false })
  }
).then(r => r.json());

// 2. Browser-side: join the session, run the DKG message loop with the engine
//    (loadEngineBrowser drives the proven WASM party — same wire envelope on every leg)
//    → after the loop completes, the engine returns { address, deviceShare, backupShare }
// 3. Store deviceShare locally, encrypt backupShare with the user's passkey
// 4. Call POST /v1/mpc/wallets to finalise — see "Register MPC Wallet"
```

---

Web version: https://docs.aureahub.com/#mpc-dkg-start
