Skip to main content

Generate a key pair

The curve is EC P-256 (prime256v1). Pick one of the paths below. In all of them the private key never leaves your infrastructure. Do not send it to us or to anyone. No field of our API accepts a private key, and no one from our support will ever ask for one.

Generate the pair​

# privada (guarde em cofre)
openssl ecparam -name prime256v1 -genkey -noout | openssl pkcs8 -topk8 -nocrypt -out privateKey.pem

# pública (é esta que você registra no portal)
openssl ec -in privateKey.pem -pubout -out publicKey.pem

# confira antes de registrar
openssl ec -in privateKey.pem -text -noout | head -3
# Private-Key: (256 bit) ... NIST CURVE: P-256
Sanity check

If the file you are about to upload contains BEGIN PRIVATE KEY or BEGIN EC PRIVATE KEY, it is the wrong file. The one you register starts with BEGIN PUBLIC KEY.

Every tab above is executed and checked before it ships: the private key must parse as P-256 and the stored public key must match it byte for byte. Prefer OpenSSL or your language's standard library on a controlled machine: a key that went through a browser went through extensions, cache and download history.

In the browser, on the "New API credential" screen​

Click Generate keys. The pair is created in your browser, the private key is downloaded as privateKey.pem, and the public key is filled into the form for you. The private key never travels. It never reaches our servers.

It is the fastest way to get started, and fine for sandbox.

Keys in KMS or HSM​

Fully supported and encouraged. Create an ECC P-256, sign/verify key, export the public key and register it. Your Sign calls return DER-encoded signatures. Send them as they are: we accept both DER and raw R‖S. See signing requests.

What to do with the private key​

Keep it in a vault. Never in a repository, never in a log, never in an environment variable shared across teams.

If it leaks, revoke the credential in the portal and create another one. There is no "replace the key" while keeping the credential, and that is deliberate: a credential is a signed binding between one key, one account and one profile. Changing the key means a new binding, that is, a new credential.