Why You Shouldn't Use an Online PGP Key Generator

A PGP key protects you only while the private half is known to you alone. An online generator creates that private key on someone else's page: whoever runs the site โ€” or whoever has modified its code โ€” can keep a copy, and you have no way to check. A key that anyone else has seen can decrypt your 2FA messages and every message sent to you.

That's why this page doesn't generate keys. The free programs below do it offline, on your own device, in a few clicks.

Pick the Right Tool for Your Device

Device Program Where to get it
Windows Kleopatra Part of Gpg4win, from gpg4win.org
Tails Kleopatra Built in. Turn on the GnuPG feature of Persistent Storage, or your keys disappear at shutdown.
Linux GnuPG (gpg) Preinstalled on most distributions; Kleopatra is in the package manager
macOS GnuPG or GPG Suite brew install gnupg, or GPG Suite from gpgtools.org
Android OpenKeychain F-Droid or Google Play

RSA 4096 or ECC? RSA 4096 works with every PGP implementation, so it is the safe choice when you don't know what the other side supports. ECC keys (Ed25519/Cv25519) are shorter and faster and are supported by current GnuPG, Kleopatra and OpenKeychain. Both are secure; what matters far more is where the private key is stored.

Kleopatra (Windows and Tails)

  1. Start a new key pair.

    File โ†’ New OpenPGP Key Pair (Ctrl+N).

  2. Enter a pseudonym.

    Use your market username or another name that isn't yours. Leave the email empty or use one that isn't linked to you โ€” both are visible to anyone who has your public key.

  3. Set the algorithm and expiry.

    Open Advanced Settings: choose RSA 4096 (or ECC) and set "Valid until" one to two years ahead. Keep "Protect the generated key with a passphrase" ticked.

  4. Choose a strong passphrase.

    Several random words work well. Without it, anyone who copies the key file can use your key.

  5. Copy your public key.

    Right-click the new key โ†’ Export, save the .asc file and open it in a text editor. The whole block, from -----BEGIN PGP PUBLIC KEY BLOCK----- to the END line, is what you give the market.

  6. Back up the private key.

    Right-click โ†’ Backup Secret Keys, and store the file offline, away from the computer you use every day.

To decrypt a message later, open Kleopatra's Notepad, paste the message and press Decrypt/Verify.

GnuPG Command Line (Linux and macOS)

Create the key and answer the prompts โ€” pick RSA and 4096 bits, or the default ECC option, and an expiry such as 1y:

gpg --full-generate-key

Print your public key to copy it into the market:

gpg --armor --export yourname

Decrypt a 2FA message: save it to a file, then run

gpg --decrypt message.asc

Back up the private key to a file you keep offline:

gpg --armor --export-secret-keys yourname > private-key.asc

GnuPG 2.1 and newer save a revocation certificate automatically in ~/.gnupg/openpgp-revocs.d/. Copy it next to your backup.

OpenKeychain (Android)

  1. Create the key.

    On first launch tap "Create my key", enter a pseudonym and skip the email. Change the key configuration there if you want RSA 4096 specifically.

  2. Share the public key.

    Open the key and use Share โ†’ copy to clipboard, then paste it into the market.

  3. Decrypt messages.

    Copy the encrypted message, open Encrypt/Decrypt and choose to decrypt from the clipboard.

  4. Back it up.

    Use Backup key from the menu and write the backup code down on paper โ€” without the code the backup file can't be opened.

A phone holding your market key should have a strong screen lock and no cloud backup of app data.

Add the Key to Dark Matter and Pass Your First 2FA Check

  1. Sign in through a verified link.

    Take the address from Mirrors โ€” a key saved on a phishing site gives the attacker control of your 2FA.

  2. Paste the whole public key.

    In your account's PGP settings, paste the full block including the BEGIN and END lines. Never paste the private key anywhere.

  3. Test decryption before turning on 2FA.

    Make sure you can decrypt a message to this key on the device you'll use. With 2FA on, losing the private key or passphrase means losing access.

  4. Check the personal phrase on every sign-in.

    At registration Dark Matter asks for a personal phrase, and every 2FA message contains it. If a decrypted message doesn't show your phrase, stop โ€” you are not on the real market.

Account-side 2FA settings are covered step by step in the Dark Matter 2FA guide; key expiry and revocation in Generate Your PGP Keys; encrypting messages to vendors in PGP Message Encryption.

Mistakes That Undo a Good Key

  • Uploading it to a public keyserver. Keyservers publish the key and the name on it permanently. A market key only needs to be pasted into the market.
  • Using your real name or a personal email. They are readable by every vendor and admin who has your public key.
  • Reusing one key across markets and forums. The same key fingerprint links all those accounts to one person. Use a separate key per identity.
  • No backup, or a backup next to the key. A lost key locks you out when 2FA is on; a backup on the same laptop is lost or seized together with it.
  • A weak or reused passphrase. The passphrase is what protects the key file if someone copies it.

PGP Key FAQ

Is there a PGP key generator for Dark Matter?

Use Kleopatra, GnuPG or OpenKeychain โ€” they generate the key offline on your device. Avoid online generators: the site that creates your private key can keep a copy.

Should I choose RSA 4096 or ECC?

Both are secure. RSA 4096 is compatible with every PGP implementation; ECC keys are shorter and faster. If in doubt, choose RSA 4096.

What name and email should I put on the key?

A pseudonym, such as your market username, and no email or one not linked to you. Both are visible to anyone who has your public key.

I lost my private key and 2FA is on. What now?

Without the private key you can't decrypt the 2FA message, so restore it from your backup. That is why the backup and the test decryption come before turning 2FA on.

Can I use the same key on other markets?

You can, but the shared fingerprint links your accounts to each other. A separate key for each identity keeps them apart.

How do I check Dark Matter's own PGP key?

The market links its key from the "PGP" item in its footer. How to use it to verify signed messages is in the market verification guide.