Developer Programs

Learn

Docs

Client Authentication Keys

Concepts > Client Authentication Keys

A signed client assertion is the recommended way for a client to authenticate to the OpenID provider. It is a JSON Web Token (JWT) signed with a private key that only you hold, and verified with a public key you register ahead of time. No shared secret is transmitted, which reduces the risk of one being intercepted and an attacker impersonating your application.

A shared client secret is also supported, and for some integrations it is the only option.

This page covers that registered key pair — how to generate it, how to handle it, and which signing algorithms are supported.

Which integrations use a registered key pair?

A registered key pair is used by integrations authenticating through Jack Henry Identity — those acting on behalf of a financial institution, either for its back-office staff signing in or for service-to-service calls where no person is present. Whether one is required depends on the flow:

  • Client Credentials (service accounts): required. A signed client assertion is the only client authentication method supported for this flow.
  • Authorization Code: optional. A client secret is also supported, but a signed client assertion is recommended.

Integrations acting on behalf of an account holder authenticate with a client secret; a registered key pair is not currently supported for them. The standard security schemes are the source of truth for which flows and client authentication methods each supports.

DPoP proofs use a different key
If you are using DPoP, the DPoP proof is signed with a separate key pair that you generate and never register. Its public half travels in the jwk header of each proof, and it supports a different set of algorithms. Do not reuse the registered key described on this page as your DPoP key.

Private key

The private key remains solely in your possession and must be kept secret. You use it to sign the client assertion JWT when authenticating.

You’ll know you’re viewing a private key if the content looks like:

-----BEGIN PRIVATE KEY-----
[content omitted]
-----END PRIVATE KEY-----

Security considerations

Don't
Do not share the private key via unsecured channels (e.g., email or instant messaging).
Don't
Do not expose the private key through frontend JavaScript or commit it to your source code repository. Store it securely on your backend server.
Do
Store private keys securely using environment variables, secrets managers, or key vaults.

Public key

The public key is registered with the product you are integrating with, and is used to verify that the signed assertion was created by your application. For Jack Henry Identity, it is configured as part of an External Application — see Configuration.

You’ll know you’re viewing a public key if the content looks like:

-----BEGIN PUBLIC KEY-----
[content omitted]
-----END PUBLIC KEY-----

Supported algorithms

The client assertion may be signed with the following algorithms, listed in order of preference. Choose the first algorithm your platform supports.

AlgorithmDescription
ES256ECDSA using P-256 and SHA-256 (recommended)
PS256RSASSA-PSS using SHA-256 with MGF1 and SHA-256
RS256RSASSA-PKCS1-v1_5 using SHA-256

These apply to the client assertion only. A DPoP proof is a different JWT and supports a different set.

Generating a key pair

You can generate a key pair using various tools depending on your platform. The examples below use OpenSSL, but other options include cloud provider key management services or language-specific cryptography libraries.

ES256 uses the P-256 curve.

Step 1: Create the private key

openssl ecparam -name prime256v1 -genkey -noout -out private.pem

Step 2: Extract the public key

openssl ec -in private.pem -pubout -out public.pem

RSA keys (for PS256 or RS256)

If your platform doesn’t support ES256, prefer PS256 over RS256.

RSA keys must be at least 2048 bits.

Step 1: Create the private key

openssl genpkey -algorithm RSA -out private.pem -pkeyopt rsa_keygen_bits:2048

Step 2: Extract the public key

openssl rsa -in private.pem -outform PEM -pubout -out public.pem

External resources: openssl-genpkey manual, openssl-ecparam manual

The public key .pem file is a text file and can be viewed with any text editor.

JWKS URL (alternative)

Instead of providing your public key in PEM format, you can host a JSON Web Key Set (JWKS) and provide its URL. A key set holds an array of keys rather than a single one, so you can publish a new key alongside the current one and rotate between them.

Requirements:

  1. The URL must be publicly accessible (no VPN or private network)
  2. The URL must use HTTPS

A JWKS URL is recommended if you intend to rotate keys, as it allows rotation without downtime or operational involvement from Jack Henry. If you publish more than one key, each JWT and each JWK must carry a kid (key ID); otherwise the JWT is validated against the first JWK matching its alg.

Create a key pair in your browser

You can generate a keypair in your browser. The keypair is never transmitted to any other system.

Key type:
Format:

Have a Question?

Did this page help you?

Last updated Mon Sep 28 2026