Skip to navigation

Webhook verification keys

View as Markdown

Serves the public keys you verify webhook delivery signatures against.

Every delivery carries an x-rk1-signature header: a compact ES256 JWT whose claims bind the run id, eventId, event type and a bodySha256 of the payload, inside a 5-minute exp window. Verify the signature with these keys and compare bodySha256 to the body you received.

This route needs no authentication — key material is public by definition. It is the stable alias, serving the same keys as the older /process/jwks.json.

Learn more: Webhooks guide

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Response

JSON Web Key Set (public keys only).

keyslist of objects