Zum Inhalt springen
Diese Seite wurde noch nicht übersetzt.

IAuthServiceKeysProvider Interface

Provides the keys of the OpenID Connect service to encrypt and sign the JWT tokens it issues, and to publish their public halves at the JWKS endpoint.

C#
public interface IAuthServiceKeysProvider

Derived
↳ ExternalKeysProvider

Remarks

The set has two distinct roles. PUBLISHING: the whole set is published at the JWKS endpoint, so a client can verify a signature made with ANY of these keys (including one the service no longer signs with) and encrypt an inbound JWE to ANY of them (the service decrypts with whichever key the client chose by kid). This holds even for a static multi-key configuration, independent of rotation. PRODUCING: the service itself signs a token, and encrypts an outbound service token, with a SINGLE key per algorithm - by convention the FIRST one returned for that algorithm. Only the produce role depends on order; a consumer selects by kid, not by position. The split is also what lets a single flat set carry a zero-downtime rotation: return a new key AFTER the active one to announce it (published and immediately verifiable / encryptable, but not yet produced with), move it to first to activate it once client JWKS caches have caught up, and keep a retired key trailing (still published so its tokens keep verifying) until they expire. Do NOT order the set so that a retired or not-yet-active key comes first for its algorithm, or the service would produce with it.

Methods

IAuthServiceKeysProvider.GetEncryptionKeys(bool) Method

Gets the encryption keys used by the service. The first key per algorithm is the one it encrypts outbound tokens with; the rest are published so inbound JWE can be decrypted and to overlap a rotation. See the ordering note in the interface remarks.

C#
System.Collections.Generic.IAsyncEnumerable<Abblix.Jwt.JsonWebKey> GetEncryptionKeys(bool includePrivateKeys=false);

Parameters

includePrivateKeys System.Boolean

Whether to include private keys in the result.

Returns

System.Collections.Generic.IAsyncEnumerable<JsonWebKey>

IAuthServiceKeysProvider.GetSigningKeys(bool) Method

Gets the signing keys used by the service. The first key per algorithm is the one it signs with; the rest are published for verification and to overlap a rotation. See the ordering note in the interface remarks.

C#
System.Collections.Generic.IAsyncEnumerable<Abblix.Jwt.JsonWebKey> GetSigningKeys(bool includePrivateKeys=false);

Parameters

includePrivateKeys System.Boolean

Whether to include private keys in the result.

Returns

System.Collections.Generic.IAsyncEnumerable<JsonWebKey>