Offline Validation of Access Tokens
Space access tokens conform to JSON Web Token (JWT) standard. To reduce the number of requests, access tokens can be validated in a third-party service without making requests to Space per token. You can cache the service public key and validate access tokens offline using JSON Web Key Set (JWKS).
Space API has a dedicated endpoint that returns JSON Web Key Set. It can be accessed at: <Space service URL>/oauth/jwks.json
Here is an example of a JWKS returned from the endpoint:
data:image/s3,"s3://crabby-images/a96a3/a96a3890ecb15d5f3470db8ebbb8a87a2e4e59a0" alt="JWKSet.png JWKSet.png"
For details, refer to JSON Web Key Set Properties.
Thanks for your feedback!
Was this page helpful?