GET/.well-known/jwks.json

Read active public token verification keys

The approved contract does not provide a longer purpose statement for this operation.

App
Vision Core
Contract
Platform API 1.0.0-preview.2
Lifecycle
preview
Runtime
acceptance-gated
Operation ID
getVerificationKeys
Canonical origin
https://vision.ivisionstudios.com

Purpose and use cases

Read active public token verification keys

The owning App is Vision Core. Vision owns machine identity and common API policy. Source Apps retain their resource and business authority.

Business use cases and out-of-scope behavior are not yet declared in the approved OpenAPI description.

Request

GET https://vision.ivisionstudios.com/.well-known/jwks.json

Authentication and authorization

No authentication requirement is declared for this operation.

Headers

  • Accept: application/json — recommended where a JSON response is declared.

Undeclared tracing, idempotency, conditional-request, and version headers are not assumed on this page.

Path and query parameters

This operation declares no path or query parameters.

Request body

This operation declares no request body.

Runnable examples

cURL
curl 'https://vision.ivisionstudios.com/.well-known/jwks.json' \
  --request GET \
  --header 'accept: application/json'
JavaScript (server-side)
const response = await fetch('https://vision.ivisionstudios.com/.well-known/jwks.json', {
  method: 'GET',
  headers: {
    accept: 'application/json',
  },
}

if (!response.ok) throw new Error(`Vision API ${response.status}`)
const result = await response.json()
Python 3 standard library
import json
import urllib.parse
import urllib.request

request = urllib.request.Request(
    'https://vision.ivisionstudios.com/.well-known/jwks.json',
    data=None,
    headers={
    "Accept": "application/json"
},
    method='GET',
)
with urllib.request.urlopen(request, timeout=30) as response:
    result = json.load(response)

The current TypeScript reference client covers Platform token exchange and core reads. No native SDK helper is declared for this operation; use the HTTP contract directly and follow the SDK guidance.

Responses

StatusMeaningSchema
200JSON Web Key Setnot specified

Success response schema

No schema is declared.

Errors and troubleshooting

Error bodies and codes are shown only where the approved contract declares them. Use status, the declared error schema, and any correlation identifier returned by the App; do not infer that two Apps share one envelope.

    Collection behavior

    Pagination: not declared. Filtering/search: not declared. Sorting: not declared.

    Cursor lifetime, cursor binding, stable ordering, maximum traversal, and unknown-filter behavior are not assumed unless stated by a parameter description or schema constraint above.

    Operational behavior

    • Rate limit: No operation-specific limit or 429 response is declared.
    • Retry: Retry only when the documented error model or response headers authorize it. Timeout and backoff values are not declared by this operation.
    • Idempotency: No idempotency header or replay window is declared.
    • Concurrency: No ETag, If-Match, or optimistic-version header is declared.

    Security and privacy

    • Keep client credentials and bearer tokens on trusted servers.
    • Send only to the exact approved HTTPS origin and audience.
    • Treat response data according to the owning App's classification and retention policy; the OpenAPI contract does not itself grant data access.
    • Do not log credentials, tokens, complete private payloads, or secrets.

    Edge cases and known documentation gaps

    • No detailed operation description.
    • No machine-readable success schema.
    • Business roles, timeout, retry budget, rate value, idempotency window, and concurrency behavior are absent unless explicitly stated above.

    No related operation is identified by the contract tags.

    Contract history and evidence

    • Contract version: 1.0.0-preview.2
    • Approved snapshot SHA-256: 24a5c91187ba12199acfa8aeafdbd2f9c6cbe6e0c72d03f3eeb1850d4f67efac
    • Approval: Anthony, 2026-08-20T14:18:46.997Z (contract-unification-20260820)
    • Download the authoritative OpenAPI 3.1 snapshot