# Webhook signing keys

> The public half of the key our webhooks are signed with, as a JWKS.

`GET https://api.refabric.com/.well-known/jwks.json`

**Authentication.** No key: a webhook receiver verifies our signature without holding a key of ours.

**Key features**

- A delivery's timestamp is accepted within 300 seconds of now.

**Common use cases**

- Verify that a webhook delivery came from us.

**See also**

- `GET /v1/meta`

Authentication: none — this operation needs no key.

## Header parameters

- `Refabric-Version` (string, _optional_, format: date) — The contract version you wrote against (a date). Absent: the current version.
- `X-Request-ID` (string, _optional_, max length 128) — Your own id for this request; we answer it back under X-Client-Request-ID.

## Response 200

Done: the answer is in the body.

- `keys` (array<object>, _required_) — The keys; empty when webhooks are not signed.
  - `kty` (string, _required_) — The key type.
    Example: `OKP`
  - `crv` (string, _required_) — The curve.
    Example: `Ed25519`
  - `use` (string, _required_) — What the key is for: signatures.
    Example: `sig`
  - `alg` (string, _required_) — The signature algorithm.
    Example: `EdDSA`
  - `kid` (string, _required_) — The key's id.
    Example: `3f2a9c1d0e8b7a65`
  - `x` (string, _required_) — The public key, base64url.
    Example: `11qYAYKxCrfVS_7TyWQHOg`

```json
{
  "keys": []
}
```

## Response 401

No valid API key was sent.

```json
{
  "error": {
    "code": "string",
    "type": "invalid_request",
    "message": "string",
    "field": "string",
    "retryable": true,
    "docs": "string",
    "request_id": "string",
    "ctx": {
      "required": 0,
      "balance": 0,
      "retry_after": 0
    },
    "input": null,
    "job_id": "string",
    "required": 0,
    "balance": 0
  }
}
```

## Response 403

Your key or your plan does not allow this.

```json
{
  "error": {
    "code": "string",
    "type": "invalid_request",
    "message": "string",
    "field": "string",
    "retryable": true,
    "docs": "string",
    "request_id": "string",
    "ctx": {
      "required": 0,
      "balance": 0,
      "retry_after": 0
    },
    "input": null,
    "job_id": "string",
    "required": 0,
    "balance": 0
  }
}
```

## Response 429

Too many requests: wait for the number of seconds in the Retry-After header.

```json
{
  "error": {
    "code": "string",
    "type": "invalid_request",
    "message": "string",
    "field": "string",
    "retryable": true,
    "docs": "string",
    "request_id": "string",
    "ctx": {
      "required": 0,
      "balance": 0,
      "retry_after": 0
    },
    "input": null,
    "job_id": "string",
    "required": 0,
    "balance": 0
  }
}
```

## Response 500

Something went wrong on our side; retry, and quote the request id if it keeps happening.

```json
{
  "error": {
    "code": "string",
    "type": "invalid_request",
    "message": "string",
    "field": "string",
    "retryable": true,
    "docs": "string",
    "request_id": "string",
    "ctx": {
      "required": 0,
      "balance": 0,
      "retry_after": 0
    },
    "input": null,
    "job_id": "string",
    "required": 0,
    "balance": 0
  }
}
```

## Request

```python
import requests

url = "https://api.refabric.com/.well-known/jwks.json"

response = requests.get(url)

print(response.json())
```

```javascript
const url = 'https://api.refabric.com/.well-known/jwks.json';
const options = {method: 'GET'};

try {
    const response = await fetch(url, options);
    const data = await response.json();
    console.log(data);
} catch (error) {
    console.error(error);
}
```

```bash
curl --request GET \
    --url https://api.refabric.com/.well-known/jwks.json
```
