curl https://connect.hopae.com/jwks
{
"keys": [
{
"kty": "RSA",
"kid": "rs256-1759391683564",
"use": "sig",
"alg": "RS256",
"n": "oahUI3nmdQ1...",
"e": "AQAB"
}
]
}
OIDC
JWKS
Public keys for verifying Hopae-issued ID tokens. Served at the root of the OIDC host, not under /v2.
GET
/
jwks
curl https://connect.hopae.com/jwks
{
"keys": [
{
"kty": "RSA",
"kid": "rs256-1759391683564",
"use": "sig",
"alg": "RS256",
"n": "oahUI3nmdQ1...",
"e": "AQAB"
}
]
}
Download the JSON Web Key Set (JWKS) to validate ID token signatures. It lives at
https://connect.hopae.com/jwks, shared by v1 and v2 and by sandbox and production apps. Prefer resolving it from the discovery document (jwks_uri).
Response
object[]
Array of JWK objects containing public keys (
kty, kid, use, alg, and the key material).curl https://connect.hopae.com/jwks
{
"keys": [
{
"kty": "RSA",
"kid": "rs256-1759391683564",
"use": "sig",
"alg": "RS256",
"n": "oahUI3nmdQ1...",
"e": "AQAB"
}
]
}
The set holds more than one key (for example an ES256 and an RS256 key). Pick the key whose
kid matches the kid header of the ID token. When Hopae rotates signing keys, the JWKS is updated with the new key before tokens start referencing it. The same keys also sign integrator evidence.Related Resources
Discovery Document
Full issuer metadata via
/.well-known/openid-configurationToken
Exchange codes for ID and access tokens

