Merchant Apps Server Identity Tool

Generate this backend's classical (non-custodial) Ed25519 key pair, get it countersigned by HashPay, and install the result — without touching a command line. Replaces the generate-apps-server-identity.cjs / install-apps-server-certificate.cjs CLI scripts with three buttons.

Current status

Loaded
not loaded yet — enter a RUID above

1. Generate Keys & Self-Signed Certificate

Generates a genuinely random Ed25519 key pair locally, in this merchant-apps-server process — the private key is written straight to generated-identities/<ruid>.PRIVATE-KEY-do-not-upload.pem on this machine and is never included in any response this page receives. Only the public self-signed certificate below ever leaves this process.

2. Get it countersigned

Open merchant.html, sign in as this merchant, and paste the self-signed certificate above into Section 8 — "Merchant Apps Server Key & Certificate". Once HashPay verifies and countersigns it, merchant.html automatically deposits the resulting chain back into this backend's generated-identities/ folder, and it will show up below without you having to copy anything.

3. Countersigned chain & Install

If merchant.html could reach this backend directly, the chain below was deposited automatically. Otherwise (a real, separately-operated merchant backend merchant.html cannot reach over the network), paste the caChainPem merchant.html displayed and save it here first.

Installs the deposited chain into this merchant's local identity. Verified before anything is written: the certificate's public key must match this RUID's own local private key, and it must genuinely chain to the Root supplied alongside it. Takes effect immediately — no restart of merchant-apps-server is needed; the very next outbound tunnel connection presents it.