openapi: 3.2.0 info: contact: email: hi@ory.sh description: Documentation for all of Ory Oathkeeper's APIs. license: name: Apache 2.0 title: Ory Oathkeeper .well Known API version: '' tags: - name: .well Known paths: /.well-known/jwks.json: get: description: This endpoint returns cryptographic keys that are required to, for example, verify signatures of ID Tokens. operationId: getWellKnownJSONWebKeys responses: '200': content: application/json: schema: $ref: '#/components/schemas/jsonWebKeySet' description: jsonWebKeySet '500': content: application/json: schema: $ref: '#/components/schemas/genericError' description: genericError summary: Lists Cryptographic Keys tags: - .well Known components: schemas: jsonWebKey: properties: alg: description: 'The "alg" (algorithm) parameter identifies the algorithm intended for use with the key. The values used should either be registered in the IANA "JSON Web Signature and Encryption Algorithms" registry established by [JWA] or be a value that contains a Collision- Resistant Name.' type: string crv: type: string d: type: string dp: type: string dq: type: string e: type: string k: type: string kid: description: 'The "kid" (key ID) parameter is used to match a specific key. This is used, for instance, to choose among a set of keys within a JWK Set during key rollover. The structure of the "kid" value is unspecified. When "kid" values are used within a JWK Set, different keys within the JWK Set SHOULD use distinct "kid" values. (One example in which different keys might use the same "kid" value is if they have different "kty" (key type) values but are considered to be equivalent alternatives by the application using them.) The "kid" value is a case-sensitive string.' type: string kty: description: 'The "kty" (key type) parameter identifies the cryptographic algorithm family used with the key, such as "RSA" or "EC". "kty" values should either be registered in the IANA "JSON Web Key Types" registry established by [JWA] or be a value that contains a Collision- Resistant Name. The "kty" value is a case-sensitive string.' type: string n: type: string p: type: string q: type: string qi: type: string use: description: 'The "use" (public key use) parameter identifies the intended use of the public key. The "use" parameter is employed to indicate whether a public key is used for encrypting data or verifying the signature on data. Values are commonly "sig" (signature) or "enc" (encryption).' type: string x: type: string x5c: description: 'The "x5c" (X.509 certificate chain) parameter contains a chain of one or more PKIX certificates [RFC5280]. The certificate chain is represented as a JSON array of certificate value strings. Each string in the array is a base64-encoded (Section 4 of [RFC4648] -- not base64url-encoded) DER [ITU.X690.1994] PKIX certificate value. The PKIX certificate containing the key value MUST be the first certificate.' items: type: string type: array y: type: string type: object jsonWebKeySet: properties: keys: description: 'The value of the "keys" parameter is an array of JWK values. By default, the order of the JWK values within the array does not imply an order of preference among them, although applications of JWK Sets can choose to assign a meaning to the order for their purposes, if desired.' items: $ref: '#/components/schemas/jsonWebKey' type: array type: object genericError: description: The standard error format properties: code: format: int64 type: integer details: items: additionalProperties: {} type: object type: array message: type: string reason: type: string request: type: string status: type: string type: object errorOAuth2: description: Error properties: error: description: Error type: string error_debug: description: 'Error Debug Information Only available in dev mode.' type: string error_description: description: Error Description type: string error_hint: description: 'Error Hint Helps the user identify the error cause.' example: The redirect URL is not allowed. type: string status_code: description: HTTP Status Code example: 401 format: int64 type: integer type: object securitySchemes: basic: scheme: basic type: http bearer: scheme: bearer type: http oauth2: flows: authorizationCode: authorizationUrl: https://hydra.demo.ory.sh/oauth2/auth scopes: offline: A scope required when requesting refresh tokens (alias for `offline_access`) offline_access: A scope required when requesting refresh tokens openid: Request an OpenID Connect ID Token tokenUrl: https://hydra.demo.ory.sh/oauth2/token type: oauth2 x-forwarded-proto: string x-request-id: string