Skip to main content

Ethereum with an external CL

You can use Prysm, Lighthouse, or any other Consensus Layer client with Erigon by including the --externalcl flag. This integration enables direct access to the Ethereum blockchain, allowing you to manage your keys for staking ETH and block production.

warning

The Engine API drives block processing, so anything that can reach it and holds your JWT secret controls the node. The steps below widen it past localhost only so a CL on another machine can connect — when you do that, protect it:

  • prefer the specific interface — --authrpc.addr <this-host-LAN-IP> — over 0.0.0.0, which listens on every interface including any public one;
  • restrict port 8551 at the firewall to the CL host's address, and never expose it to the internet;
  • treat --authrpc.vhosts as a Host-header check, not a network control: it is not a substitute for a firewall rule;
  • keep jwt.hex readable only by the accounts that need it, and copy it to the CL host over a private channel.

If both clients run on the same machine, leave the Engine API on its default localhost address and skip those flags entirely.

tip

Keep your consensus client current, the same way you would Erigon. Beyond fixes and performance work, a CL carries the fork schedule it was built with: a version released before an upcoming hard fork may not follow the chain through it, which stalls your execution layer too. Watch your client's releases (Prysm, Lighthouse) and upgrade before scheduled forks, not after.

Erigon with Prysm as the external CL

  1. Start Erigon adding the --externalcl flag:

    erigon --externalcl

    If your Consensus Layer (CL) client is on a different device, add the following flags:

    • --authrpc.addr <this-host-LAN-IP> — the Engine API listens on localhost by default, so it has to be widened for a remote CL. Read the warning below before reaching for 0.0.0.0;
    • --authrpc.vhosts <CL_host> where <CL_host> is the source host or the appropriate hostname that your CL client is using.
  2. Install and run Prysm by following the official guide: https://docs.prylabs.network/docs/install/install-with-script.

    Prysm must fully synchronize before Erigon can start syncing, since Erigon requires an existing target head to sync to. The quickest way to get Prysm synced is to use a public checkpoint synchronization endpoint from the list at https://eth-clients.github.io/checkpoint-sync-endpoints.

  3. To communicate with Erigon, the --execution-endpoint must be specified as <erigon address>:8551, where <erigon address> is either http://localhost or the IP address of the device running Erigon.

  4. Prysm must point to the JWT secret automatically created by Erigon in the --datadir directory.

    ./prysm.sh beacon-chain \
    --execution-endpoint http://localhost:8551 \
    --mainnet --jwt-secret=<your-datadir>/jwt.hex \
    --checkpoint-sync-url=https://mainnet.checkpoint.sigp.io \
    --genesis-beacon-api-url=https://mainnet.checkpoint.sigp.io

Check Erigon and your chosen CL logs to make sure that the Execution Layer (EL) and CL are communicating and that your node is syncing correctly.