Authlete JWK Set Endpoint API

API endpoints for to generate JSON Web Key Set (JWKS) for a service.

Operations 1

GET /api/{serviceId}/service/jwks/get Get JWK Set #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/authlete-jwk-set-endpoint-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

authlete-jwk-set-endpoint-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Authlete JWK Set Endpoint API
  description: Welcome to the **Authlete API documentation**.
  version: 3.0.16
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
servers:
- description: 🇺🇸 US Cluster
  url: https://us.authlete.com
- description: 🇯🇵 Japan Cluster
  url: https://jp.authlete.com
- description: 🇪🇺 Europe Cluster
  url: https://eu.authlete.com
- description: 🇧🇷 Brazil Cluster
  url: https://br.authlete.com
security:
- bearer: []
tags:
- name: JWK Set Endpoint
  description: API endpoints for to generate JSON Web Key Set (JWKS) for a service.
  x-tag-expanded: false
paths:
  /api/{serviceId}/service/jwks/get:
    get:
      summary: Get JWK Set
      description: 'This API gathers JWK Set information for a service so that its client applications can verify

        signatures by the service and encrypt their requests to the service.


        This API is supposed to be called from within the implementation of the jwk set endpoint of the

        service where the service that supports OpenID Connect must expose its JWK Set information so that

        client applications can verify signatures by the service and encrypt their requests to the service.

        The URI of the endpoint can be found as the value of `jwks_uri` in OpenID Provider Metadata

        if the service supports OpenID Connect Discovery 1.0.'
      parameters:
      - in: path
        name: serviceId
        description: A service ID.
        required: true
        schema:
          type: string
      - in: query
        name: includePrivateKeys
        schema:
          type: boolean
        required: false
        description: The boolean value that indicates whether the response should include the private keys associated with the service or not. If `true`, the private keys are included in the response. The default value is `false`.
      - in: query
        name: pretty
        schema:
          type: boolean
        required: false
        description: This boolean value indicates whether the JSON in the response should be formatted or not. If `true`, the JSON in the response is pretty-formatted. The default value is `false`.
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/service_jwks_get_response'
              example:
                keys:
                - e: AQAB
                  n: kVXi0XB8LGYZfFPXymaszWjBQsO22tasQH3PEiPeLSymBHbp7PtqM8O8xblqhbxV-24lKNs2zDugQaBiVt4zpalyYxL5kqnfY247priZRfmeUatdECh81T-i3VcLpz_M5yfljfVp3sFdaURUQNA3ow9VtUfvPIxN_9YIxXN1zP2nLP5amC2XA8xMt5iubRwbbPbrLyg69zTOzosDVhRTSs5adHK5HNwVn8wCCZPbU7u1cQD8hFNn8xlQcmOmJjSXUQ9slBpLc7G-dUEOI59RxiPd4R44GtSe8gA1WFXvOAdtGjivSm8BAbxuNO8HFtDJmpVl9YsDr9FsxirFl9ZPKs
                  kty: RSA
                  use: sig
                  kid: rsa-sig-001
                - e: AQAB
                  n: lQui3_DlrkLs_dyaOQBOclphIIRTTMo0gNlnAgfEM9xjbYQJQzi0CLtO6eseecE3HtvDBWVTw-rMM_NMJTlPTO0_ODWvmJRjXy9DZGEm05LFd_qr6jZ7cdOvjD7zUC3GI9TIokPbjGzueBPJjtAvv_tAazRFCQQfiFy7sQR3u-J4tM8fNo9szo9H09R_eA29llZ3hU39JDKs9nzG60I1mVZtJYPx0_bnO8eYeVDHqoj4SZ4jeru3iX9iDeccH_cDm3M87UomUh-Ri4LlAxXgewDvOaPxAef9ADkDvBVmRo5t60_PJxQ3Tug2EKK-xF1_T7I4TxgS7ga8entMmCxLca
                  kty: RSA
                  use: enc
                  kid: rsa-enc-001
                - crv: P-256
                  kty: EC
                  use: sig
                  y: 824At71mYpbGK2oOCKAL1Z2scLPrbVwhM882v3a9gBq
                  x: ZXE3h9BxCyyb_Z9ZJ5qH4Vx650y09qwI1EpZO4o4OmL
                  kid: ec256-sig-001
                - crv: P-256
                  kty: EC
                  use: enc
                  y: j80Y3leZHHnxC_gN-Ols_l_VfEBQkfGDFFDG5LNJKMl
                  x: xAdEkaExYWGGAC1xYjwxzvqcaCyDloylZk04yiE9_OF
                  kid: ec256-enc-001
        '204':
          description: No JWK Set available for this service
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '403':
          $ref: '#/components/responses/403'
        '500':
          $ref: '#/components/responses/500'
      operationId: service_jwks_get_api
      x-code-samples:
      - lang: shell
        label: curl
        source: 'curl -v https://us.authlete.com/api/21653835348762/service/jwks/get?pretty=true \

          -H ''Authorization: Bearer V5a40R6dWvw2gMkCOBFdZcM95q4HC0Z-T0YKD9-nR6F''

          '
      - lang: java
        label: java
        source: 'AuthleteConfiguration conf = ...;

          AuthleteApi api = AuthleteApiFactory.create(conf);


          boolean pretty = true;

          boolean includePrivateKey = false;


          api.getServiceJwks(pretty, includePrivateKey);

          '
      - lang: python
        source: 'conf = ...

          api = AuthleteApiImpl(conf)


          pretty = True

          includePrivateKey = False


          api.getServiceJwks(pretty, includePrivateKey)

          '
      tags:
      - JWK Set Endpoint
components:
  responses:
    '403':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001215
            resultMessage: '[A001215] /auth/authorization, The client (ID = 26837717140341) is locked.'
    '500':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001101
            resultMessage: '[A001101] /auth/authorization, Authlete Server error.'
    '400':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001201
            resultMessage: '[A001201] /auth/authorization, TLS must be used.'
    '401':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001202
            resultMessage: '[A001202] /auth/authorization, Authorization header is missing.'
  schemas:
    service_jwks_get_response:
      type: object
      properties:
        keys:
          type: array
          items:
            type: object
            additionalProperties: true
            description: 'An object representing JWK. See [RFC 7517](https://datatracker.ietf.org/doc/html/rfc7517) for more details.

              '
          description: An array of [JWK](https://datatracker.ietf.org/doc/html/rfc7517)s.
    result:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'Authenticate every request with a **Service Access Token** or **Organization Token**.

        Set the token value in the `Authorization: Bearer <token>` header.


        **Service Access Token**: Scoped to a single service. Use when automating service-level configuration or runtime flows.


        **Organization Token**: Scoped to the organization; inherits permissions across services. Use for org-wide automation or when managing multiple services programmatically.


        Both token types are issued by the Authlete console or provisioning APIs.

        '