1. Generate a controller key
Do this once on a controller-controlled device. Download both files, move the private file into a protected password-manager or offline store, and delete the downloaded copy.
The private file is not passphrase-encrypted. Never upload it to a Server or evidence repository. Store it in protected custody and delete transient downloads.
No key generated
Complete the form to create a private key file and a separate public package.
- Controller
- Key
- Fingerprint
2. Sign an exact controller document
Download or copy the exact JSON challenge from the Server. This tool signs only the deployment-bound controller registration or rotation format that matches the selected key.
Inspect the Server document before selecting it. The resulting signed package contains the public document and signature only; it does not contain the private key.
No document signed
Select a controller private key and the exact JSON document supplied by the Server.
- Document
- Controller
- Key
Next step
Return only the signed package to the Server’s Trust & keys page. Root passkey approval remains a separate Server-side action.