Generate a key pair for use with the SLTS CA third-party integration programme.
Both keys are created entirely inside your browser — the private key is never transmitted.
After registration, Static Labs will countersign your public keys under SLTS CA Issuing G1, creating an intermediate certificate that other services in the ecosystem can verify without contacting you directly. Your service signs tokens with its private key; verifiers check the signature against the countersigned public key retrieved from the registry.
For outbound request signing, use RSA-PSS 4096-bit — this matches the
X-Net-Certificate-SLTS header scheme. For mutual TLS or attestation flows,
ECDSA P-256 is recommended for its compact signature size.
Full technical details: staticlabs.app/pki/slts · Public key registry: kubian.staticlabs.app/ca/slts/3rd-party