Well Known | API & MCP Reference | Archera

/.well-known/jwks.json

get/.well-known/jwks.json

Returns the JSON Web Key Set (JWKS) containing public keys used to verify JWT tokens issued by Archera. This endpoint follows the RFC 7517 standard for JWK and is used by clients to validate JWT signatures. No authentication is required as this endpoint provides public cryptographic keys.

Responses

200

OK

application/json

keys object · JWK[] Required

Array of JSON Web Keys

400

Bad request

application/json

401

Unauthorized

application/json

403

Forbidden

application/json

404

Not found

application/json

405

Method not allowed

application/json

409

Conflict

application/json

500

Failed to load keys

default

Default error response

application/json

HTTP

GET /.well-known/jwks.json HTTP/1.1
Accept: */*

200

OK

{
  "keys": [
    {
      "kty": "text",
      "use": "text",
      "kid": "text",
      "alg": "text",
      "n": "text",
      "e": "text"
    }
  ]
}

/.well-known/oauth-authorization-server

get/.well-known/oauth-authorization-server

Returns OAuth 2.0 Authorization Server Metadata as specified in RFC 8414. This endpoint provides automatic discovery of the authorization server's configuration, including supported endpoints, grant types, response types, PKCE methods, and available scopes. OAuth client libraries can use this endpoint to automatically configure themselves without manual endpoint configuration. No authentication is required as this is a public discovery endpoint.

Responses

200

OK

application/json

issuer string Required

The authorization server's issuer identifier URL

authorization_endpoint string Required

URL of the OAuth 2.0 authorization endpoint

token_endpoint string Required

URL of the OAuth 2.0 token endpoint

revocation_endpoint string Required

URL of the OAuth 2.0 token revocation endpoint (RFC 7009)

registration_endpoint string Required

URL of the OAuth 2.0 dynamic client registration endpoint (RFC 7591)

jwks_uri string Required

URL of the JSON Web Key Set document

response_types_supported string[] Required

OAuth 2.0 response_type values supported

grant_types_supported string[] Required

OAuth 2.0 grant type values supported

code_challenge_methods_supported string[] Required

PKCE code challenge methods supported

token_endpoint_auth_methods_supported string[] Required

Client authentication methods supported at token endpoint

scopes_supported string Required

OAuth 2.0 scope values supported

service_documentation string Optional

URL of service documentation for developers

400

Bad request

application/json

401

Unauthorized

application/json

403

Forbidden

application/json

404

Not found

application/json

405

Method not allowed

application/json

409

Conflict

application/json

500

Internal server error

application/json

HTTP

GET /.well-known/oauth-authorization-server HTTP/1.1
Accept: */*

200

OK

{
  "issuer": "text",
  "authorization_endpoint": "text",
  "token_endpoint": "text",
  "revocation_endpoint": "text",
  "registration_endpoint": "text",
  "jwks_uri": "text",
  "response_types_supported": [
    "text"
  ],
  "grant_types_supported": [
    "text"
  ],
  "code_challenge_methods_supported": [
    "text"
  ],
  "token_endpoint_auth_methods_supported": [
    "text"
  ],
  "scopes_supported": [
    "text"
  ],
  "service_documentation": "text"
}