4 ms·
Well true, public keys would be better wording wise. One thing I just wanted to append to this here: > Not necessarily in real-time, but at least on a frequen
by ffo 4y ago
Well true, public keys would be better wording wise.
One thing I just wanted to append to this here:
> Not necessarily in real-time, but at least on a frequent periodic basis.
Periodically fetching the keys is not really a best practice on its own. The consumer (RP) must be able to handle newly published keys at runtime. Since a JWT includes a KID it is recommended to lookup a local cache pre-filled from a scheduler while fetching new KIDs on demand.