> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.cloudraker.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.cloudraker.com/_mcp/server.

# Webhook verification keys

GET https://api.cloudraker.com/v1/webhooks/jwks.json

Serves the public keys you verify webhook delivery signatures against.

Every delivery carries an `x-rk1-signature` header: a compact ES256 JWT whose claims bind the run id, `eventId`, event `type` and a `bodySha256` of the payload, inside a 5-minute `exp` window. Verify the signature with these keys and compare `bodySha256` to the body you received.

This route needs no authentication — key material is public by definition. It is the stable alias, serving the same keys as the older `/process/jwks.json`.

**Learn more:** [Webhooks guide](https://docs.cloudraker.com/developers/webhooks)

Reference: https://docs.cloudraker.com/paperwork/api/webhooks/webhook-jwks

## Authentication

- `Authorization` header (bearer token, required)

## Response

### 200

JSON Web Key Set (public keys only).

- `keys` (list of object, required)
  - `kty` (string, required)
  - `crv` (string, required)
  - `x` (string, required)
  - `y` (string, required)
  - `kid` (string, required)
  - `alg` (string, required)
  - `use` (string, optional)

## Examples

**Response**

```json
{
  "keys": [
    {
      "kty": "EC",
      "crv": "P-256",
      "x": "string",
      "y": "string",
      "kid": "string",
      "alg": "ES256",
      "use": "sig"
    }
  ]
}
```

**SDK Code**

```typescript
import { CloudRakerClient } from "@cloudraker/api";

async function main() {
    const client = new CloudRakerClient({
        token: "YOUR_TOKEN_HERE",
    });
    await client.webhooks.webhookJwks();
}
main();

```

```python
from cloudraker import CloudRaker

client = CloudRaker(
    token="YOUR_TOKEN_HERE",
)

client.webhooks.webhook_jwks()

```

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.cloudraker.com/v1/webhooks/jwks.json"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.cloudraker.com/v1/webhooks/jwks.json")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api.cloudraker.com/v1/webhooks/jwks.json")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.cloudraker.com/v1/webhooks/jwks.json', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.cloudraker.com/v1/webhooks/jwks.json");
var request = new RestRequest(Method.GET);
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = ["Authorization": "Bearer <token>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://api.cloudraker.com/v1/webhooks/jwks.json")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```