Skip to main content
GET
Retrieves Method’s complete JSON Web Key Set (JWKS) containing all public keys used for Message Level Encryption. The key set contains encryption keys, which you use to encrypt your requests to Method, and signing keys, which you use to verify the signature on Method’s responses on the signed MLE path. This endpoint requires no authentication.
This endpoint returns Method’s public keys — encryption keys for encrypting your requests, and signing keys for verifying Method’s response signatures — not your own registered keys. To manage your own keys, use the Team JWKS API.

Caching

This endpoint includes cache control headers to optimize performance:
You should respect these cache headers and cache the response for up to 1 hour to reduce unnecessary requests.

Key Uses

Filter on use as well as status when selecting a key:
  • Encryption keys carry use: "enc" and alg: "RSA-OAEP-256". Use the active encryption key to encrypt your requests to Method.
  • Signing keys carry use: "sig" and alg: "RS256". Use them to verify the signature on Method’s responses on the signed MLE path. More than one signing key can be active during a rotation, so retain every active signing key and select the one whose kid matches the kid in the JWS protected header of the response.

Key Lifecycle

  • Active Keys: Use keys with status: "active"
  • Deprecated Keys: Keys with status: "deprecated" will be removed after 90 days
  • Key Identification: Method JWKs always have their kid equal to their id
  • Lifetime Claims: Every key carries numeric iat, nbf, and exp claims. Method keys are minted with a 365-day lifetime.
Always use keys with status: "active". Deprecated keys will be removed from the system after 90 days.

Returns

Returns a JWKS object containing an array of Method’s public keys with their current status and metadata.

Best Practices

  • Cache Responses: Respect the Cache-Control header and cache responses for up to 1 hour
  • Use Active Keys: Always filter for keys with status: "active" when selecting keys
  • Filter on Use: Select use: "enc" keys for encryption and use: "sig" keys for signature verification
  • Handle Multiple Keys: Your application should be able to handle multiple active keys
  • Monitor Webhooks: Subscribe to method_jwk.create and method_jwk.update webhooks to stay informed of key changes
  • Graceful Degradation: Implement fallback logic for when preferred keys become deprecated

Environment-Specific Endpoints

Method’s JWKS endpoints are environment-specific:
  • Production: https://production.methodfi.com/.well-known/jwks.json
  • Sandbox: https://sandbox.methodfi.com/.well-known/jwks.json
  • Development: https://dev.methodfi.com/.well-known/jwks.json