Add missing identifiers to your published JWKS💡Feature RequestsIntegrationsOIDCAug 18Please add the x5t#S256 and/or x5c values to the key published in your JWKS.ProblemI cannot use the Spacelift OIDC token to authenticate with my app because some identifiers are missing from your JWKS. The Spacelift OIDC token is issued with a thumbprint header that represents a hash of the certificate trust chain. Neither this thumbprint, nor the corresponding trust chain are included with any of the keys in your published JWKS. My app uses the Nimbus JOSE + JWT library (https://connect2id.com/products/nimbus-jose-jwt) to validate JWTs. It strictly requires that every header in a token must match in a published JWKS key before it will use that key to validate the token, even though the "kid" and signing algorithm otherwise match.Status: ❌ Rejected1 comment2
Log in to comment and vote
Comments1
Jonah Kowall
Aug 18
Please contact our technical support team on this one. This is a bug and not a feature request.