Fetch the public signing keys
Serves the JSON Web Key Set for every ACTIVE signing key, so that any token this service has issued and not yet expired can be verified even across a rotation.
/.well-known/jwks.jsonServes the JSON Web Key Set for every ACTIVE signing key, so that any
token this service has issued and not yet expired can be verified even
across a rotation. Keys are RSA-2048 and every entry is
kty=RSA, use=sig, alg=RS256.
More than one key is normal and expected: all active keys are served,
the newest one signs. Cache the set and refresh it when you meet a
kid you do not know, rather than on a timer — that is what makes a
rotation invisible to you. Rate-limit that refresh: an unknown kid is
also what a forged token looks like.
This endpoint is public and unauthenticated.
Response Body
application/json
application/problem+json
application/problem+json
curl -X GET "https://example.com/.well-known/jwks.json"{ "keys": [ { "kty": "RSA", "use": "sig", "alg": "RS256", "kid": "1d23b0c4-6d2a-4f0e-9f1c-8a7b6c5d4e3f", "n": "xGOr-H7A-PWG...", "e": "AQAB" } ]}Sign a portal staff member in
Authenticates a portal staff member against their Argon2id password hash and returns a staff session JWT.
List a tenant's API keys
Lists every key that can act in the tenant, active and revoked, oldest first, and never their secrets — incident response needs to see what exists before deciding what dies.