IAuthServiceKeysProvider Interface
Provides the keys of the OpenID Connect service to encrypt and sign the JWT tokens it issues, and to publish their public halves at the JWKS endpoint.
public interface IAuthServiceKeysProviderDerived
↳ ExternalKeysProvider
Remarks
The set has two distinct roles. PUBLISHING: the whole set is published at the JWKS endpoint, so a client can
verify a signature made with ANY of these keys (including one the service no longer signs with) and encrypt
an inbound JWE to ANY of them (the service decrypts with whichever key the client chose by kid). This
holds even for a static multi-key configuration, independent of rotation. PRODUCING: the service itself signs
a token, and encrypts an outbound service token, with a SINGLE key per algorithm - by convention the FIRST one
returned for that algorithm. Only the produce role depends on order; a consumer selects by kid, not by
position. The split is also what lets a single flat set carry a zero-downtime rotation: return a new key AFTER
the active one to announce it (published and immediately verifiable / encryptable, but not yet produced with),
move it to first to activate it once client JWKS caches have caught up, and keep a retired key trailing (still
published so its tokens keep verifying) until they expire. Do NOT order the set so that a retired or
not-yet-active key comes first for its algorithm, or the service would produce with it.
Methods
IAuthServiceKeysProvider.GetEncryptionKeys(bool) Method
Gets the encryption keys used by the service. The first key per algorithm is the one it encrypts outbound tokens with; the rest are published so inbound JWE can be decrypted and to overlap a rotation. See the ordering note in the interface remarks.
System.Collections.Generic.IAsyncEnumerable<Abblix.Jwt.JsonWebKey> GetEncryptionKeys(bool includePrivateKeys=false);Parameters
includePrivateKeys System.Boolean
Whether to include private keys in the result.
Returns
System.Collections.Generic.IAsyncEnumerable<JsonWebKey>
IAuthServiceKeysProvider.GetSigningKeys(bool) Method
Gets the signing keys used by the service. The first key per algorithm is the one it signs with; the rest are published for verification and to overlap a rotation. See the ordering note in the interface remarks.
System.Collections.Generic.IAsyncEnumerable<Abblix.Jwt.JsonWebKey> GetSigningKeys(bool includePrivateKeys=false);Parameters
includePrivateKeys System.Boolean
Whether to include private keys in the result.