Skip to main content
Version: 2.0-beta

Web key Service

This API is intended to manage web keys for a ZITADEL instance, used to sign and validate OIDC tokens. This service is in beta state. It can AND will continue breaking until a stable version is released.

The public key endpoint (outside of this service) is used to retrieve the public keys of the active and inactive keys.

Please make sure to enable the web_key feature flag on your instance to use this service.

Authentication​

Security Scheme Type:

oauth2

OAuth Flow (authorizationCode):

Token URL: $CUSTOM-DOMAIN/oauth/v2/token

Authorization URL: $CUSTOM-DOMAIN/oauth/v2/authorize

Scopes:

  • openid: openid

  • urn:zitadel:iam:org:project🆔zitadel:aud: urn:zitadel:iam:org:project🆔zitadel:aud

License

Apache 2.0