Skip to main content
Every signature names the key that made it, in its keyId. Verification needs the public half of each named key. Parmana serves them without authentication.

Fetch a key

Response
Pass the pem field to the verifiers, keyed by keyId:
GET /.well-known/jwks.json lists every key the server holds, as JWKs.

Which keys a record needs

Collect every keyId the record names:
A hybrid record typically names default (Ed25519) and default-secondary (ML-DSA-65).

Keys in production use

  • Fetch once, then pin. Store the keys you trust and pass them in from storage. Fetching a key from the same server at verification time only proves the record matches that server’s current key.
  • Rotated keys stay valid. Rotation signs new records under a new keyId. The server keeps serving the old key while it holds it, and older records still name the old keyId, so they remain verifiable. Keep every key you have pinned.
  • Sandbox and production are separate. Each has its own keys; a record verifies only against the environment that signed it.
  • A KeyObject works too. publicKeys values may be node:crypto KeyObjects instead of PEM strings.