Generate this backend's classical (non-custodial) Ed25519 key pair, get it countersigned by
HashPay, and install the result — without touching a command line. Replaces the
generate-apps-server-identity.cjs / install-apps-server-certificate.cjs
CLI scripts with three buttons.
Generates a genuinely random Ed25519 key pair locally, in this merchant-apps-server
process — the private key is written straight to
generated-identities/<ruid>.PRIVATE-KEY-do-not-upload.pem on this machine and is
never included in any response this page receives. Only the public self-signed certificate
below ever leaves this process.
Open merchant.html, sign in as this merchant, and paste the self-signed
certificate above into Section 8 — "Merchant Apps Server Key & Certificate". Once
HashPay verifies and countersigns it, merchant.html automatically deposits the resulting
chain back into this backend's generated-identities/ folder, and it will show up
below without you having to copy anything.
If merchant.html could reach this backend directly, the chain below was deposited
automatically. Otherwise (a real, separately-operated merchant backend merchant.html cannot
reach over the network), paste the caChainPem merchant.html displayed and save
it here first.
Installs the deposited chain into this merchant's local identity. Verified before anything is written: the certificate's public key must match this RUID's own local private key, and it must genuinely chain to the Root supplied alongside it. Takes effect immediately — no restart of merchant-apps-server is needed; the very next outbound tunnel connection presents it.