Skip to content

Comment on Self-Signed JWTsparent

Comments

Even better: Imagine a world where you could just host your public keys on e.g. mydomain.com/.well-known/jwks.json, you register with a service provider with me@mydomain.com, then the service automatically pulls public keys from that. Then, all you have to do is sign new keys with an appropriate audience like aud:"serviceprovider.com".

And for the public email providers, a service like Gravatar could exist to host them for you.

Wouldn't that be nice.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.