Grafana Signing Keys API

The signing_keys API from Grafana — 1 operation(s) for signing_keys.

Operations 1

GET /signing-keys/keys Get JSON Web Key Set (JWKS) with all the keys that can be used to verify tokens… #

Documentation

📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/
📖
Authentication
https://grafana.com/docs/grafana/latest/developers/http_api/authentication/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/dashboard/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/dashboard_versions/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/dashboard_permissions/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/dashboard_public/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/folder/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/folder_dashboard_search/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/folder_permissions/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/data_source/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/datasource_permissions/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/datasource_lbac_rules/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/alerting_provisioning/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/annotations/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/org/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/user/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/team/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/team_sync/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/preferences/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/access_control/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/serviceaccount/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/sso-settings/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/admin/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/licensing/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/reporting/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/query_and_resource_caching/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/library_element/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/correlations/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/snapshot/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/short_url/
📖
Documentation
https://grafana.com/docs/grafana/latest/developers/http_api/query_history/

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/grafana-com-signing-keys-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

grafana-com-signing-keys-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: 'The Grafana backend exposes an HTTP API, the same API is used by the frontend to do

    everything from saving dashboards, creating users and updating data sources.'
  title: Grafana HTTP API. Signing Keys API
  contact:
    name: Grafana Labs
    url: https://grafana.com
    email: hello@grafana.com
  version: 0.0.1
servers:
- url: /api
security:
- basic: []
- api_key: []
tags:
- name: signing_keys
paths:
  /signing-keys/keys:
    get:
      description: 'Required permissions

        None'
      tags:
      - signing_keys
      summary: Get JSON Web Key Set (JWKS) with all the keys that can be used to verify tokens…
      operationId: retrieveJWKS
      responses:
        '200':
          $ref: '#/components/responses/jwksResponse'
        '500':
          $ref: '#/components/responses/internalServerError'
components:
  schemas:
    AttributeTypeAndValue:
      description: 'When parsed as part of a pkix.Name structure in a crypto/x509 type,

        the Value will be


        - a string if the ASN.1 type is PrintableString, IA5String,

        NumericString, BMPString, T61String, or UTF8String;

        - an int64 if the ASN.1 type is INTEGER;

        - an asn1.BitString if the ASN.1 type is BIT STRING;

        - a []byte if the ASN.1 type is OCTET STRING;

        - an asn1.ObjectIdentifier if the ASN.1 type is OBJECT IDENTIFIER;

        - a time.Time if the ASN.1 type is UTCTIME or GENERALIZEDTIME;

        - a bool if the ASN.1 type is BOOLEAN;

        - nil if the ASN.1 type is NULL;

        - an asn1.RawValue otherwise.'
      type: object
      title: 'AttributeTypeAndValue mirrors the ASN.1 structure of the same name in

        RFC 5280, Section 4.1.2.4.'
      properties:
        Type:
          $ref: '#/components/schemas/ObjectIdentifier'
        Value: {}
    Extension:
      description: 'Extension represents the ASN.1 structure of the same name. See RFC

        5280, section 4.2.'
      type: object
      properties:
        Critical:
          type: boolean
        Id:
          $ref: '#/components/schemas/ObjectIdentifier'
        Value:
          type: array
          items:
            type: integer
            format: uint8
    JSONWebKey:
      description: 'JSONWebKey represents a public or private key in JWK format. It can be

        marshaled into JSON and unmarshaled from JSON.'
      type: object
      properties:
        Algorithm:
          description: Key algorithm, parsed from `alg` header.
          type: string
        CertificateThumbprintSHA1:
          description: X.509 certificate thumbprint (SHA-1), parsed from `x5t` header.
          type: array
          items:
            type: integer
            format: uint8
        CertificateThumbprintSHA256:
          description: X.509 certificate thumbprint (SHA-256), parsed from `x5t#S256` header.
          type: array
          items:
            type: integer
            format: uint8
        Certificates:
          description: X.509 certificate chain, parsed from `x5c` header.
          type: array
          items:
            $ref: '#/components/schemas/Certificate'
        CertificatesURL:
          $ref: '#/components/schemas/URL'
        Key:
          description: 'Key is the Go in-memory representation of this key. It must have one

            of these types:

            - ed25519.PublicKey

            - ed25519.PrivateKey

            - *ecdsa.PublicKey

            - *ecdsa.PrivateKey

            - *rsa.PublicKey

            - *rsa.PrivateKey

            - []byte (a symmetric key)


            When marshaling this JSONWebKey into JSON, the "kty" header parameter

            will be automatically set based on the type of this field.'
        KeyID:
          description: Key identifier, parsed from `kid` header.
          type: string
        Use:
          description: Key use, parsed from `use` header.
          type: string
    ObjectIdentifier:
      type: array
      title: An ObjectIdentifier represents an ASN.1 OBJECT IDENTIFIER.
      items:
        type: integer
        format: int64
    URL:
      type: string
      format: url
    SignatureAlgorithm:
      type: integer
      format: int64
    ExtKeyUsage:
      description: Each of the ExtKeyUsage* constants define a unique action.
      type: integer
      format: int64
      title: ExtKeyUsage represents an extended set of actions that are valid for a given key.
    Name:
      description: 'Name represents an X.509 distinguished name. This only includes the common

        elements of a DN. Note that Name is only an approximation of the X.509

        structure. If an accurate representation is needed, asn1.Unmarshal the raw

        subject or issuer as an [RDNSequence].'
      type: object
      properties:
        CommonName:
          type: string
        Country:
          type: array
          items:
            type: string
        ExtraNames:
          description: 'ExtraNames contains attributes to be copied, raw, into any marshaled

            distinguished names. Values override any attributes with the same OID.

            The ExtraNames field is not populated when parsing, see Names.'
          type: array
          items:
            $ref: '#/components/schemas/AttributeTypeAndValue'
        Locality:
          type: array
          items:
            type: string
        Names:
          description: 'Names contains all parsed attributes. When parsing distinguished names,

            this can be used to extract non-standard attributes that are not parsed

            by this package. When marshaling to RDNSequences, the Names field is

            ignored, see ExtraNames.'
          type: array
          items:
            $ref: '#/components/schemas/AttributeTypeAndValue'
        Organization:
          type: array
          items:
            type: string
        OrganizationalUnit:
          type: array
          items:
            type: string
        PostalCode:
          type: array
          items:
            type: string
        Province:
          type: array
          items:
            type: string
        SerialNumber:
          type: string
        StreetAddress:
          type: array
          items:
            type: string
    KeyUsage:
      description: 'KeyUsage represents the set of actions that are valid for a given key. It''s

        a bitmap of the KeyUsage* constants.'
      type: integer
      format: int64
    PolicyMapping:
      type: object
      title: PolicyMapping represents a policy mapping entry in the policyMappings extension.
      properties:
        IssuerDomainPolicy:
          description: 'IssuerDomainPolicy contains a policy OID the issuing certificate considers

            equivalent to SubjectDomainPolicy in the subject certificate.'
          type: string
        SubjectDomainPolicy:
          description: 'SubjectDomainPolicy contains a OID the issuing certificate considers

            equivalent to IssuerDomainPolicy in the subject certificate.'
          type: string
    ErrorResponseBody:
      type: object
      required:
      - message
      properties:
        error:
          description: Error An optional detailed description of the actual error. Only included if running in developer mode.
          type: string
        message:
          description: a human readable version of the error
          type: string
        status:
          description: 'Status An optional status to denote the cause of the error.


            For example, a 412 Precondition Failed error may include additional information of why that error happened.'
          type: string
    Certificate:
      type: object
      title: A Certificate represents an X.509 certificate.
      properties:
        AuthorityKeyId:
          type: array
          items:
            type: integer
            format: uint8
        BasicConstraintsValid:
          description: 'BasicConstraintsValid indicates whether IsCA, MaxPathLen,

            and MaxPathLenZero are valid.'
          type: boolean
        CRLDistributionPoints:
          description: CRL Distribution Points
          type: array
          items:
            type: string
        DNSNames:
          description: 'Subject Alternate Name values. (Note that these values may not be valid

            if invalid values were contained within a parsed certificate. For

            example, an element of DNSNames may not be a valid DNS domain name.)'
          type: array
          items:
            type: string
        EmailAddresses:
          type: array
          items:
            type: string
        ExcludedDNSDomains:
          type: array
          items:
            type: string
        ExcludedEmailAddresses:
          type: array
          items:
            type: string
        ExcludedIPRanges:
          type: array
          items:
            $ref: '#/components/schemas/IPNet'
        ExcludedURIDomains:
          type: array
          items:
            type: string
        ExtKeyUsage:
          type: array
          items:
            $ref: '#/components/schemas/ExtKeyUsage'
        Extensions:
          description: 'Extensions contains raw X.509 extensions. When parsing certificates,

            this can be used to extract non-critical extensions that are not

            parsed by this package. When marshaling certificates, the Extensions

            field is ignored, see ExtraExtensions.'
          type: array
          items:
            $ref: '#/components/schemas/Extension'
        ExtraExtensions:
          description: 'ExtraExtensions contains extensions to be copied, raw, into any

            marshaled certificates. Values override any extensions that would

            otherwise be produced based on the other fields. The ExtraExtensions

            field is not populated when parsing certificates, see Extensions.'
          type: array
          items:
            $ref: '#/components/schemas/Extension'
        IPAddresses:
          type: array
          items:
            type: string
        InhibitAnyPolicy:
          description: 'InhibitAnyPolicy and InhibitAnyPolicyZero indicate the presence and value

            of the inhibitAnyPolicy extension.


            The value of InhibitAnyPolicy indicates the number of additional

            certificates in the path after this certificate that may use the

            anyPolicy policy OID to indicate a match with any other policy.


            When parsing a certificate, a positive non-zero InhibitAnyPolicy means

            that the field was specified, -1 means it was unset, and

            InhibitAnyPolicyZero being true mean that the field was explicitly set to

            zero. The case of InhibitAnyPolicy==0 with InhibitAnyPolicyZero==false

            should be treated equivalent to -1 (unset).'
          type: integer
          format: int64
        InhibitAnyPolicyZero:
          description: 'InhibitAnyPolicyZero indicates that InhibitAnyPolicy==0 should be

            interpreted as an actual maximum path length of zero. Otherwise, that

            combination is interpreted as InhibitAnyPolicy not being set.'
          type: boolean
        InhibitPolicyMapping:
          description: 'InhibitPolicyMapping and InhibitPolicyMappingZero indicate the presence

            and value of the inhibitPolicyMapping field of the policyConstraints

            extension.


            The value of InhibitPolicyMapping indicates the number of additional

            certificates in the path after this certificate that may use policy

            mapping.


            When parsing a certificate, a positive non-zero InhibitPolicyMapping

            means that the field was specified, -1 means it was unset, and

            InhibitPolicyMappingZero being true mean that the field was explicitly

            set to zero. The case of InhibitPolicyMapping==0 with

            InhibitPolicyMappingZero==false should be treated equivalent to -1

            (unset).'
          type: integer
          format: int64
        InhibitPolicyMappingZero:
          description: 'InhibitPolicyMappingZero indicates that InhibitPolicyMapping==0 should be

            interpreted as an actual maximum path length of zero. Otherwise, that

            combination is interpreted as InhibitAnyPolicy not being set.'
          type: boolean
        IsCA:
          type: boolean
        Issuer:
          $ref: '#/components/schemas/Name'
        IssuingCertificateURL:
          type: array
          items:
            type: string
        KeyUsage:
          $ref: '#/components/schemas/KeyUsage'
        MaxPathLen:
          description: 'MaxPathLen and MaxPathLenZero indicate the presence and

            value of the BasicConstraints'' "pathLenConstraint".


            When parsing a certificate, a positive non-zero MaxPathLen

            means that the field was specified, -1 means it was unset,

            and MaxPathLenZero being true mean that the field was

            explicitly set to zero. The case of MaxPathLen==0 with MaxPathLenZero==false

            should be treated equivalent to -1 (unset).


            When generating a certificate, an unset pathLenConstraint

            can be requested with either MaxPathLen == -1 or using the

            zero value for both MaxPathLen and MaxPathLenZero.'
          type: integer
          format: int64
        MaxPathLenZero:
          description: 'MaxPathLenZero indicates that BasicConstraintsValid==true

            and MaxPathLen==0 should be interpreted as an actual

            maximum path length of zero. Otherwise, that combination is

            interpreted as MaxPathLen not being set.'
          type: boolean
        NotAfter:
          type: string
          format: date-time
        NotBefore:
          type: string
          format: date-time
        OCSPServer:
          description: RFC 5280, 4.2.2.1 (Authority Information Access)
          type: array
          items:
            type: string
        PermittedDNSDomains:
          type: array
          items:
            type: string
        PermittedDNSDomainsCritical:
          description: Name constraints
          type: boolean
        PermittedEmailAddresses:
          type: array
          items:
            type: string
        PermittedIPRanges:
          type: array
          items:
            $ref: '#/components/schemas/IPNet'
        PermittedURIDomains:
          type: array
          items:
            type: string
        Policies:
          description: 'Policies contains all policy identifiers included in the certificate.

            See CreateCertificate for context about how this field and the PolicyIdentifiers field

            interact.

            In Go 1.22, encoding/gob cannot handle and ignores this field.'
          type: array
          items:
            type: string
        PolicyIdentifiers:
          description: 'PolicyIdentifiers contains asn1.ObjectIdentifiers, the components

            of which are limited to int32. If a certificate contains a policy which

            cannot be represented by asn1.ObjectIdentifier, it will not be included in

            PolicyIdentifiers, but will be present in Policies, which contains all parsed

            policy OIDs.

            See CreateCertificate for context about how this field and the Policies field

            interact.'
          type: array
          items:
            $ref: '#/components/schemas/ObjectIdentifier'
        PolicyMappings:
          description: PolicyMappings contains a list of policy mappings included in the certificate.
          type: array
          items:
            $ref: '#/components/schemas/PolicyMapping'
        PublicKey: {}
        PublicKeyAlgorithm:
          $ref: '#/components/schemas/PublicKeyAlgorithm'
        Raw:
          type: array
          items:
            type: integer
            format: uint8
        RawIssuer:
          type: array
          items:
            type: integer
            format: uint8
        RawSignatureAlgorithm:
          type: array
          items:
            type: integer
            format: uint8
        RawSubject:
          type: array
          items:
            type: integer
            format: uint8
        RawSubjectPublicKeyInfo:
          type: array
          items:
            type: integer
            format: uint8
        RawTBSCertificate:
          type: array
          items:
            type: integer
            format: uint8
        RequireExplicitPolicy:
          description: 'RequireExplicitPolicy and RequireExplicitPolicyZero indicate the presence

            and value of the requireExplicitPolicy field of the policyConstraints

            extension.


            The value of RequireExplicitPolicy indicates the number of additional

            certificates in the path after this certificate before an explicit policy

            is required for the rest of the path. When an explicit policy is required,

            each subsequent certificate in the path must contain a required policy OID,

            or a policy OID which has been declared as equivalent through the policy

            mapping extension.


            When parsing a certificate, a positive non-zero RequireExplicitPolicy

            means that the field was specified, -1 means it was unset, and

            RequireExplicitPolicyZero being true mean that the field was explicitly

            set to zero. The case of RequireExplicitPolicy==0 with

            RequireExplicitPolicyZero==false should be treated equivalent to -1

            (unset).'
          type: integer
          format: int64
        RequireExplicitPolicyZero:
          description: 'RequireExplicitPolicyZero indicates that RequireExplicitPolicy==0 should be

            interpreted as an actual maximum path length of zero. Otherwise, that

            combination is interpreted as InhibitAnyPolicy not being set.'
          type: boolean
        SerialNumber:
          type: integer
        Signature:
          type: array
          items:
            type: integer
            format: uint8
        SignatureAlgorithm:
          $ref: '#/components/schemas/SignatureAlgorithm'
        Subject:
          $ref: '#/components/schemas/Name'
        SubjectKeyId:
          type: array
          items:
            type: integer
            format: uint8
        URIs:
          type: array
          items:
            $ref: '#/components/schemas/URL'
        UnhandledCriticalExtensions:
          description: 'UnhandledCriticalExtensions contains a list of extension IDs that

            were not (fully) processed when parsing. Verify will fail if this

            slice is non-empty, unless verification is delegated to an OS

            library which understands all the critical extensions.


            Users can access these extensions using Extensions and can remove

            elements from this slice if they believe that they have been

            handled.'
          type: array
          items:
            $ref: '#/components/schemas/ObjectIdentifier'
        UnknownExtKeyUsage:
          type: array
          items:
            $ref: '#/components/schemas/ObjectIdentifier'
        Version:
          type: integer
          format: int64
    IPNet:
      type: object
      title: An IPNet represents an IP network.
      properties:
        IP:
          type: string
        Mask:
          $ref: '#/components/schemas/IPMask'
    IPMask:
      description: See type [IPNet] and func [ParseCIDR] for details.
      type: array
      title: 'An IPMask is a bitmask that can be used to manipulate

        IP addresses for IP addressing and routing.'
      items:
        type: integer
        format: uint8
    PublicKeyAlgorithm:
      type: integer
      format: int64
  responses:
    internalServerError:
      description: InternalServerError is a general error indicating something went wrong internally.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponseBody'
    jwksResponse:
      description: (empty)
      content:
        application/json:
          schema:
            type: object
            properties:
              keys:
                type: array
                items:
                  $ref: '#/components/schemas/JSONWebKey'
  securitySchemes:
    api_key:
      type: apiKey
      name: Authorization
      in: header
    basic:
      type: http
      scheme: basic