Signature verification in Azure API Management with openid-config

linacn 0 Reputation points
2024-11-14T10:54:53.0933333+00:00

I'm going through the documentation - https://zcusa.951200.xyz/en-us/azure/api-management/validate-jwt-policy to set up JWT validation for my APIs in Azure API Management.

What exactly are the steps executed when openid-config is included in the API Management Policy and an OpenID compliant configuration endpoint URL is specified? Is signature verification performed by default when openid-config is included?

Specifically, I want to understand when there would be a need to specify issuer-signing-keys and whether it is required if my OpenID compliant configuration endpoint URL provides the JWKS URI.

Azure API Management
Azure API Management
An Azure service that provides a hybrid, multi-cloud management platform for APIs.
2,184 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,209 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.