Glossary · Protocols and standards
JSON Web Key Set (JWKS)
A JWKS is a JSON document that lists public keys as JSON Web Keys (RFC 7517), so a verifier can find the key that matches a signature's kid.
A JSON Web Key Set (JWKS) is a JSON object whose keys member is an array of JSON Web Keys, the format RFC 7517 defines for representing cryptographic keys.
How it works. Each JWK describes one key. kty gives the key type, such as EC or RSA, and type-specific members carry the key material, such as crv, x and y for an elliptic-curve key. Optional members include kid (key ID), use (signature or encryption) and alg. A publisher serves its public keys as a JWKS at a stable HTTPS URL, with the media type application/jwk-set+json. A verifier reads the kid from a signature’s header and picks the key with the same kid. Keys in one set should have distinct kid values, which makes rotation possible: publish the new key next to the old one, start signing with the new key, then remove the old one.
Illustrative JWKS with one P-256 signing key (the coordinates are the example key from RFC 7517):
{
"keys": [
{
"kty": "EC",
"crv": "P-256",
"x": "MKBCTNIcKUSDii11ySs3526iDZ8AiTo7Tu6KPAqv7D4",
"y": "4Etl6SRW2YiLUrN5vfvVHuhp7x8PxltmWWlbbM4IFyM",
"use": "sig",
"alg": "ES256",
"kid": "key-1"
}
]
}
In A2A. The protected header of an Agent Card signature may include jku, a URL that points to a JWKS holding the signing key. To verify, a client gets the public key through kid and jku, or from its own trusted key store, and checks the signature over the canonical card. The A2A specification says keys should be fetched over HTTPS and that expired or revoked keys must not be used. A card may carry several signatures during key rotation.
Do not trust jku blindly. A key fetched from the signer’s own jku URL only shows that whoever controls that URL signed the card. Check that the URL belongs to the provider you expect, or pin known keys in a trusted key store. RFC 8725 adds that following arbitrary jku URLs can expose a verifier to server-side request forgery, and recommends matching them against an allowlist.
Neighbouring terms. JWS is the signature format that refers to these keys. JCS produces the exact payload they verify.