For AI agents: this page is also available as Markdown at https://docs.refabric.com/api-reference/platform/webhooks/webhook-signing-keys.md, and the index of every page is https://docs.refabric.com/llms.txt.
Platform API › Webhooks
Webhook signing keys
The public half of the key our webhooks are signed with, as a JWKS.
https://api.refabric.com/.well-known/jwks.jsonimport requests
url = "https://api.refabric.com/.well-known/jwks.json"
response = requests.get(url)
print(response.json()){
"keys": []
}Authentication. No key: a webhook receiver verifies our signature without holding a key of ours.
Key features
- A delivery's timestamp is accepted within 300 seconds of now.
Common use cases
- Verify that a webhook delivery came from us.
See also
GET /v1/meta
Authorization
No key needed.
Parameters
Header parameters
- stringoptional
The contract version you wrote against (a date). Absent: the current version.
format: date
- stringoptional
Your own id for this request; we answer it back under X-Client-Request-ID.
max length 128
Response
200 — Done: the answer is in the body.
- array<object>required
The keys; empty when webhooks are not signed.
- stringrequired
The key type.
Example:
OKP - stringrequired
The curve.
Example:
Ed25519 - stringrequired
What the key is for: signatures.
Example:
sig - stringrequired
The signature algorithm.
Example:
EdDSA - stringrequired
The key's id.
Example:
3f2a9c1d0e8b7a65 - stringrequired
The public key, base64url.
Example:
11qYAYKxCrfVS_7TyWQHOg
- 401 — No valid API key was sent.
- 403 — Your key or your plan does not allow this.
- 429 — Too many requests: wait for the number of seconds in the Retry-After header.
- 500 — Something went wrong on our side; retry, and quote the request id if it keeps happening.