Retrieve JSON Web Key Set (JWKS)
Fetches the public keys that can be used to verify JWTs signed by Prolific. Clients should cache these keys and update them at least daily.
To verify the signature of a JWT you must verify the following:
- The JWT signature is authentic by verifying it with the public key from Prolific that correlates with the KID.
- The JWT hasn’t expired, by checking the
expclaim. - The
audclaim is the correct domain for your tool. - The
prolificclaim matches your expected payload as set in theexternal_study_urlproperty. It always includesPROLIFIC_PID,STUDY_ID,SESSION_ID, andworkspace_id. When the workspace is linked to an organisation, it also includesorganisation_id.
Response
Successful response with the JWKS.
keys