> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hopae.com/llms.txt
> Use this file to discover all available pages before exploring further.

# JWKS

> Public keys for verifying Hopae-issued ID tokens. Served at the root of the OIDC host, not under /v2.

Download the JSON Web Key Set (JWKS) to validate ID token signatures. It lives at `https://connect.hopae.com/jwks`, shared by v1 and v2 and by sandbox and production apps. Prefer resolving it from the [discovery document](/v2/api-reference/oidc/well-known) (`jwks_uri`).

## Response

<ResponseField name="keys" type="object[]">
  Array of JWK objects containing public keys (`kty`, `kid`, `use`, `alg`, and the key material).
</ResponseField>

<RequestExample>
  ```bash theme={null}
  curl https://connect.hopae.com/jwks
  ```
</RequestExample>

<ResponseExample>
  ```json Response theme={null}
  {
    "keys": [
      {
        "kty": "RSA",
        "kid": "rs256-1759391683564",
        "use": "sig",
        "alg": "RS256",
        "n": "oahUI3nmdQ1...",
        "e": "AQAB"
      }
    ]
  }
  ```
</ResponseExample>

<Info>
  The set holds more than one key (for example an ES256 and an RS256 key). Pick the key whose `kid` matches the `kid` header of the ID token. When Hopae rotates signing keys, the JWKS is updated with the new key before tokens start referencing it. The same keys also sign integrator [evidence](/v2/guides/verifications/evidence).
</Info>

## Related Resources

<CardGroup cols={2}>
  <Card title="Discovery Document" icon="magnifying-glass" href="/v2/api-reference/oidc/well-known">
    Full issuer metadata via `/.well-known/openid-configuration`
  </Card>

  <Card title="Token" icon="key" href="/v2/api-reference/oidc/token">
    Exchange codes for ID and access tokens
  </Card>
</CardGroup>


## OpenAPI

````yaml GET /jwks
openapi: 3.1.0
info:
  title: Hopae Connect OpenID Provider
  version: 2.0.0
servers:
  - url: https://connect.hopae.com/v2
    description: Hopae Connect
security: []
tags:
  - name: OIDC
paths:
  /jwks:
    servers:
      - url: https://connect.hopae.com
        description: Hopae Connect (discovery and keys live at the root)
    get:
      tags:
        - OIDC
      summary: JWKS
      operationId: jwks
      parameters: []
      responses:
        '200':
          description: Key set.
          content:
            application/json:
              schema:
                type: object
                properties:
                  keys:
                    type: array
                    items:
                      type: object
                    description: JWK public keys.
      security: []

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.