WalletD developers
Tokens and login

Fetch the public signing keys

Serves the JSON Web Key Set for every ACTIVE signing key, so that any token this service has issued and not yet expired can be verified even across a rotation.

GET/.well-known/jwks.json

Serves the JSON Web Key Set for every ACTIVE signing key, so that any token this service has issued and not yet expired can be verified even across a rotation. Keys are RSA-2048 and every entry is kty=RSA, use=sig, alg=RS256.

More than one key is normal and expected: all active keys are served, the newest one signs. Cache the set and refresh it when you meet a kid you do not know, rather than on a timer — that is what makes a rotation invisible to you. Rate-limit that refresh: an unknown kid is also what a forged token looks like.

This endpoint is public and unauthenticated.

Response Body

application/json

application/problem+json

application/problem+json

curl -X GET "https://example.com/.well-known/jwks.json"
{  "keys": [    {      "kty": "RSA",      "use": "sig",      "alg": "RS256",      "kid": "1d23b0c4-6d2a-4f0e-9f1c-8a7b6c5d4e3f",      "n": "xGOr-H7A-PWG...",      "e": "AQAB"    }  ]}