Atomically return the existing key or create-and-store one — the WHOLE get→create→put cycle under the keystore's lock (issue #8). Two concurrent callers must end up with the SAME key: a lost generated key means every field sealed to it is unrecoverable (the server holds no copy; that is the design), so the factory must run at most once per stored key.
Staticdefault
JSON file keystore for server-side/CLI use. The file is chmod 0600 and holds the ONLY copy of the private keys — losing it means losing the ability to open fields sealed to those keys (the DeFarm server cannot recover them; that is the whole point).