Skip to content
/.well-known/jwks.json

AS public signing keys (JWKS)

The AS's RS256 public keys. The MCP server verifies access tokens against these (it holds no signing secret). Access tokens are RS256 JWTs with `iss`, `aud` (the canonical resource), `sub` (user uuid), `scope: mcp`, `token_use: mcp_access`, short `exp` (≤15 min), and `kid`.

free

Response schema

FieldTypeNullableDescription
keysarraynoThe JSON Web Key Set — an array of the AS's public signing keys (JWK objects). A verifier picks the key whose `kid` matches the token header.
keys[].ktystringnoKey type. Always `RSA`.
keys[].nstringnoRSA modulus, base64url-encoded (the public-key material).
keys[].estringnoRSA public exponent, base64url-encoded.
keys[].usestringnoPublic-key use. Always `sig` (signature verification).
keys[].algstringnoSigning algorithm. Always `RS256`.
keys[].kidstringnoKey ID. Matched against the access-token header's `kid` to select the verifying key.

Errors

StatusLabelDescription
200OKRequest succeeded.
400Bad RequestInvalid query, body, or path parameter.
401UnauthorizedMissing or invalid Authorization header / api_Token.
402Payment RequiredInsufficient token balance for this call. Top up
429Too Many RequestsRate limit exceeded for your tier (see /pricing for tier limits). Tier limits
500Server ErrorUnexpected server-side failure. Retry with backoff; report if persistent.

Code samples

curl "https://api.finradar.ai/.well-known/jwks.json" \
  -H "Authorization: Bearer YOUR_JWT_TOKEN"

Generate an API key in /account/credentials to run live queries (literal YOUR_API_KEY placeholder shown until then).