Expand description
The public half of a signing_key as a JSON Web Key Set (Phase 24.5).
A service that signs tokens publishes its public keys at a jwks_uri, and a
rotation needs the old and the new key listed together for as long as tokens
signed by the old one are still in flight - which is why the entry has a
first-class “previous key” slot. This turns what the vault holds (a PEM or a
JWK) into the document a verifier fetches.
Only public material is ever produced. A JWK that arrives with private
members (d, p, q, dp, dq, qi, k) has them stripped, and a PEM that
is a private key is refused rather than derived from: publishing the wrong
half is the one mistake a key set cannot take back. Nothing is verified or
generated here; keys are re-encoded, never operated on.
PEM PUBLIC KEY (SPKI) is read for RSA, EC (P-256, P-384, P-521), Ed25519 and
X25519; RSA PUBLIC KEY (PKCS#1) for RSA. A key without a kid gets its RFC
7638 thumbprint, which is what a verifier would compute for it anyway.
Functions§
- entry_
jwk - One entry of the key set: the key with its
kid,alganduse. - key_set
- The key set for a
signing_keyentry: the current key and, while a rotation is open, the previous one.Nonefor a part that is empty. - public_
jwk - A public JWK from either spelling the vault might hold, with no private members.
- thumbprint
- The RFC 7638 thumbprint of a public JWK, which is the
kida verifier would derive and the one used when the entry names none.