What is a JWKS?
A JWK Set (RFC 7517 §5) is a JSON object with a keys array. Each entry is a JSON Web Key describing one public key. Identity providers publish their JWKS at a stable URL (the jwks_uri in the OpenID Connect discovery document) so APIs can verify tokens without sharing secrets.
{
"keys": [
{
"kty": "RSA",
"kid": "2026-09-a",
"use": "sig",
"alg": "RS256",
"n": "sXch…",
"e": "AQAB"
}
]
}Key members
| Member | Meaning |
|---|---|
| kty | Key type: RSA, EC, OKP or oct (symmetric). |
| kid | Key ID. Matched against the token header's kid to pick the verification key. |
| use | Intended use: sig (signatures) or enc (encryption). |
| alg | Algorithm the key is intended for. If present, verifiers should only use the key with that algorithm. |
| n, e | RSA modulus and exponent (Base64URL). |
| crv, x, y | EC curve and public point coordinates. |
| d, p, q, dp, dq, qi | Private key material. These must never appear in a published JWKS — the inspector warns if they do. |
Key rotation
To rotate keys safely, publish the new key in the JWKS before signing with it, keep the old key until every token it signed has expired, and give each key a unique kid. A kid that isn't in the set usually means the verifier's cached JWKS is stale or the token comes from another environment.
JWK thumbprints
RFC 7638 defines a canonical SHA-256 thumbprint over a key's required public members. It is a stable, standards-based way to derive a kid, and it lets you confirm that two JWKs describe the same key even when their optional members differ.
Ready to verify? Paste the token and JWKS into the JWT verifier. Need a key pair and JWKS for testing? Use the JWT key generator.