Overview
RGB Lightning Node (RLN) can run in external-signer mode. In this mode the node holds no seed and no private keys. Every signing operation it needs — channel signing, node cryptography (ECDH, inbound payments, peer storage, offers), and RGB PSBT signing — is answered by a signer built on Validating Lightning Signer (VLS). VLS does not sign blindly: it checks every request for protocol correctness and against its policy before producing a signature, and rejects anything that fails. External-signer mode is part of the Utexo RLN (#27, #95) and is used by the Utexo WDK today. Like the rest of RLN it is in beta: on mainnet, RLN supports on-chain RGB operations only.Deployment modes
Both modes share one signer contract (
rln-external-signer) and a VLS core patched for RGB channels.
Validation flow
- Reduced attack surface: a compromised node cannot read signing keys.
- Policy enforcement: the signer refuses requests that break protocol rules or its policy.
- Self-custody: keys stay in the environment you control.
What changes in external-signer mode
Run the remote signer daemon
The daemon and the node’s remote-signer support are behind theremote-signer cargo feature. It is not enabled in the default build or the Docker image, so build from source:
1
Start the daemon
0600) if --seed-file does not exist. The daemon keeps its VLS state in --data-dir (default: a signer-db directory next to the seed file). Persist this directory — it is what lets a restarted daemon keep signing for existing channels.--network accepts bitcoin, testnet, signet, or regtest.2
Print the signer identity
3
Start the node pointing at the daemon
4
Initialise external-signer mode
Send the bootstrap JSON from step 2 to the locked node:The node probes the daemon at
--remote-signer-addr and rejects the request if the submitted identity does not match the live daemon.5
Unlock
Call
POST /unlock as usual. In external-signer mode the password field is not checked; the Biscuit token is the credential that protects the node.