Skip to main content
A Partner JWT proves that a request comes from your app. Your backend signs it with your private key, your app passes it to AIR Kit, and AIR checks the signature against the public key in your registered JWKS endpoint. You need a Partner JWT for:
  • issueCredential and verifyCredential in the SDK
  • Direct issuance through the AIR API
  • login on Flutter, and login with Custom Auth on Web
On Web, standard AIR login works without a Partner JWT, but passing one is recommended. Always sign Partner JWTs on your server, never in the browser.

JWT requirements

To learn more about JWTs, see jwt.io.

Next.js Partner JWT endpoint

Install jose:
Create a server-only endpoint that returns a five-minute token. This example signs an issuance token; use scope: "verify" for verification.
app/api/partner-jwt/route.ts
Keep PARTNER_PRIVATE_KEY server-only. This example uses the Partner ID as the kid, matching the JWKS route.

Generating an RS256 key pair

Generate a private key and extract its public key with OpenSSL:
Sign Partner JWTs with private.key and keep it secret. Publish public.key through your JWKS endpoint.

Examples

Sign a Partner JWT in other backend languages. Each example signs an issuance token with RS256; change scope for verification.
Replace your-partner-id, your-key-id, and the key paths with your own values. For ES256, use the matching signing method and an EC key.