> ## Documentation Index
> Fetch the complete documentation index at: https://docs.capedigital.co.ke/llms.txt
> Use this file to discover all available pages before exploring further.

# Profile token JWKS (public keys)

> Public JWKS for offline validation of profile tokens (RS256, Keycloak-style).

Downstream services (content/recommend) fetch this, pick the key by the
token's ``kid`` header, and verify the signature without calling this service.



## OpenAPI

````yaml /openapi/user.yaml get /api/v1/auth/profiles/.well-known/jwks.json
openapi: 3.0.3
info:
  title: CapeMedia User Service API
  version: 1.0.0
  description: |2-

        **CapeMedia User Service API** - Comprehensive user service and management system.

        ## Authentication
        This API uses **JWT Bearer tokens** for authentication.

        1. Login via `/api/v1/auth/login` to obtain tokens
        2. Include the access token in the `Authorization` header: `Bearer <access_token>`
        3. Refresh expired tokens via `/api/v1/auth/refresh-token`

        ## Versioning
        The API uses URL path versioning (e.g., `/api/v1/`, `/api/v2/`).
        Current version: **v1**
        
  contact:
    name: API Support
    email: support@capemedia.co.ke
  license:
    name: Cape Media
servers:
  - url: https://api.diginacape.co.ke/acl
    description: Production
  - url: http://localhost:8000
    description: Local
security: []
paths:
  /api/v1/auth/profiles/.well-known/jwks.json:
    get:
      tags:
        - Profiles
      summary: Profile token JWKS (public keys)
      description: >-
        Public JWKS for offline validation of profile tokens (RS256,
        Keycloak-style).


        Downstream services (content/recommend) fetch this, pick the key by the

        token's ``kid`` header, and verify the signature without calling this
        service.
      operationId: profiles_jwks
      responses:
        '200':
          content:
            application/json:
              schema:
                type: object
                additionalProperties: {}
          description: JWKS document
      security:
        - bearerAuth: []
        - {}
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'Enter your JWT token in the format: Bearer <token>'

````