> ## Documentation Index
> Fetch the complete documentation index at: https://docs.parmanasystems.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List every public signing key this deployment can currently produce

> Same unauthenticated, third-party-verification purpose as GET /keys/{keyId} — this is the enumeration form. Not a standards-pure RFC 7517 JWK Set (not every entry necessarily has a `jwk` field), but a superset any consumer that only wants `.jwk` per entry can filter down to.




## OpenAPI

````yaml /openapi.bundled.yaml get /.well-known/jwks.json
openapi: 3.1.0
info:
  title: Parmana API
  version: 1.0.0
  description: >
    Parmana is an Execution Trust Infrastructure that ensures there is no gap
    between what humans decide and what AI systems do. The API enables creation,
    execution, verification, replay, and auditing of Business Transactions
    through cryptographically verifiable Execution Trust Records.


    **Every route requires a caller bearer key, except GET /health.** Send
    `Authorization: Bearer <key>` on every other request. Keys are issued by
    `scripts/generate-api-key.ts` and configured server-side via
    `PARMANA_API_KEYS`; only a hash of each key is ever held by the server,
    verified in constant time. A missing or invalid credential returns 401
    before a Business Transaction is even constructed, independent of Policy
    evaluation and gateway attestation, see
    `packages/api/src/middleware/caller-auth.ts` and
    [Authentication](/api-reference/authentication). Local development may set
    `PARMANA_AUTH_DISABLED=true` to skip this middleware entirely; that flag
    must never be set in a real deployment.
  contact:
    name: Parmana
    email: support@parmana.ai
  license:
    name: Apache-2.0
    identifier: Apache-2.0
servers:
  - url: http://localhost:3000
    description: Local (packages/api, PORT env var, default 3000)
security:
  - bearerAuth: []
tags:
  - name: Execution
    description: >-
      Executes a Business Transaction through the complete Execution Trust
      pipeline
  - name: Transactions
    description: Business Transaction creation and retrieval
  - name: Verification
    description: Deterministic verification of an Execution Trust Record
  - name: Receipts
    description: Cryptographically signed Execution Trust Receipts
  - name: Trust Records
    description: Execution Trust Record retrieval
  - name: Replay
    description: Deterministic replay of a recorded Execution Trust Record
  - name: Policies
    description: Policy existence/readability check
  - name: System
    description: Operational endpoints
paths:
  /.well-known/jwks.json:
    get:
      tags:
        - System
      summary: List every public signing key this deployment can currently produce
      description: >
        Same unauthenticated, third-party-verification purpose as GET
        /keys/{keyId} — this is the enumeration form. Not a standards-pure RFC
        7517 JWK Set (not every entry necessarily has a `jwk` field), but a
        superset any consumer that only wants `.jwk` per entry can filter down
        to.
      operationId: getJwks
      responses:
        '200':
          description: Every key this deployment can currently produce a public key for.
          content:
            application/json:
              schema:
                type: object
                required:
                  - keys
                properties:
                  keys:
                    type: array
                    items:
                      type: object
                      required:
                        - keyId
                        - algorithm
                        - use
                        - pem
                      properties:
                        keyId:
                          type: string
                        algorithm:
                          type: string
                        use:
                          type: string
                          enum:
                            - sig
                        pem:
                          type: string
                        jwk:
                          type: object
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >
        Caller API key issued by scripts/generate-api-key.ts. Sent as
        Authorization: Bearer <key>. Verified against a stored SHA-256 hash in
        constant time by packages/api/src/auth/StaticKeyAuthenticator.ts.
        Required on every route except GET /health. See
        /api-reference/authentication.

````