Local controller custody

Controller key custody

Generate a controller key or sign an exact Server challenge on this device. This page makes no network requests and stores nothing in the browser.

1. Generate a controller key

Do this once on a controller-controlled device. Download both files, move the private file into a protected password-manager or offline store, and delete the downloaded copy.

The private file is not passphrase-encrypted. Never upload it to a Server or evidence repository. Store it in protected custody and delete transient downloads.

No key generated

Complete the form to create a private key file and a separate public package.

2. Sign an exact controller document

Download or copy the exact JSON challenge from the Server. This tool signs only the deployment-bound controller registration or rotation format that matches the selected key.

Inspect the Server document before selecting it. The resulting signed package contains the public document and signature only; it does not contain the private key.

No document signed

Select a controller private key and the exact JSON document supplied by the Server.

Next step

Return only the signed package to the Server’s Trust & keys page. Root passkey approval remains a separate Server-side action.