How AIR uses your JWKS
If AIR cannot fetch your JWKS, or no key in it matches the JWT’skid, the request fails with 401.
Step 1: Implement the route
This Next.js route is the one used by every issuer and verifier app inair-examples. It converts your public key from PEM to JWK with jose and sets kid to your Partner ID.
app/api/.well-known/jwks/route.ts
PARTNER_PRIVATE_KEY):
Generate the key pair as described in SDK authentication.
Step 2: Register the URL in the Dashboard
- Open the Developer Dashboard.
- Go to Account → General Settings.
- Paste the full HTTPS URL into JWKS URL, for example
https://app.example.com/api/.well-known/jwks, and save.
/api/.well-known/jwks for the route above, or whatever route you defined yourself.
Each Partner ID has one JWKS URL. If your issuer and verifier apps share a Partner ID, register one JWKS and sign all Partner JWTs with a kid it contains. If you need separate JWKS per service, request a second Partner ID.
Step 3: Match the kid
The kid in each Partner JWT header must appear as a keys[].kid in your JWKS. The examples use your Partner ID for both. If you use another convention, such as key-rotation IDs, the rule is the same.
Check the endpoint before you call the SDK:
Local development (HTTPS tunnel)
AIR servers cannot reachlocalhost. Expose your dev server over public HTTPS and register the tunnel URL:
- ngrok
- cloudflared
https://abc123.ngrok.app/api/.well-known/jwks in the dashboard.Troubleshooting
If AIR still rejects your Partner JWT, see Common issues:- JWKS endpoint unreachable — AIR cannot fetch your URL.
- Invalid signature — JWKS reachable but signature does not validate.
- kid not found — JWT header
kidis not present inkeys[].