Client Authentication Keys
A signed client assertion is the recommended way for a client to authenticate to the OpenID provider. It is a JSON Web Token (JWT) signed with a private key that only you hold, and verified with a public key you register ahead of time. No shared secret is transmitted, which reduces the risk of one being intercepted and an attacker impersonating your application.
A shared client secret is also supported, and for some integrations it is the only option.
This page covers that registered key pair — how to generate it, how to handle it, and which signing algorithms are supported.
A registered key pair is used by integrations authenticating through Jack Henry Identity — those acting on behalf of a financial institution, either for its back-office staff signing in or for service-to-service calls where no person is present. Whether one is required depends on the flow:
- Client Credentials (service accounts): required. A signed client assertion is the only client authentication method supported for this flow.
- Authorization Code: optional. A client secret is also supported, but a signed client assertion is recommended.
Integrations acting on behalf of an account holder authenticate with a client secret; a registered key pair is not currently supported for them. The standard security schemes are the source of truth for which flows and client authentication methods each supports.
jwk header of each proof, and it supports a different set of algorithms. Do not reuse the registered key described on this page as your DPoP key.Private key
The private key remains solely in your possession and must be kept secret. You use it to sign the client assertion JWT when authenticating.
You’ll know you’re viewing a private key if the content looks like:
-----BEGIN PRIVATE KEY-----
[content omitted]
-----END PRIVATE KEY-----
Security considerations
Public key
The public key is registered with the product you are integrating with, and is used to verify that the signed assertion was created by your application. For Jack Henry Identity, it is configured as part of an External Application — see Configuration.
You’ll know you’re viewing a public key if the content looks like:
-----BEGIN PUBLIC KEY-----
[content omitted]
-----END PUBLIC KEY-----
Supported algorithms
The client assertion may be signed with the following algorithms, listed in order of preference. Choose the first algorithm your platform supports.
| Algorithm | Description |
|---|---|
| ES256 | ECDSA using P-256 and SHA-256 (recommended) |
| PS256 | RSASSA-PSS using SHA-256 with MGF1 and SHA-256 |
| RS256 | RSASSA-PKCS1-v1_5 using SHA-256 |
These apply to the client assertion only. A DPoP proof is a different JWT and supports a different set.
Generating a key pair
You can generate a key pair using various tools depending on your platform. The examples below use OpenSSL, but other options include cloud provider key management services or language-specific cryptography libraries.
ECDSA keys (for ES256 — recommended)
ES256 uses the P-256 curve.
Step 1: Create the private key
openssl ecparam -name prime256v1 -genkey -noout -out private.pem
Step 2: Extract the public key
openssl ec -in private.pem -pubout -out public.pem
RSA keys (for PS256 or RS256)
If your platform doesn’t support ES256, prefer PS256 over RS256.
RSA keys must be at least 2048 bits.
Step 1: Create the private key
openssl genpkey -algorithm RSA -out private.pem -pkeyopt rsa_keygen_bits:2048
Step 2: Extract the public key
openssl rsa -in private.pem -outform PEM -pubout -out public.pem
External resources: openssl-genpkey manual, openssl-ecparam manual
.pem file is a text file and can be viewed with any text editor.JWKS URL (alternative)
Instead of providing your public key in PEM format, you can host a JSON Web Key Set (JWKS) and provide its URL. A key set holds an array of keys rather than a single one, so you can publish a new key alongside the current one and rotate between them.
Requirements:
- The URL must be publicly accessible (no VPN or private network)
- The URL must use HTTPS
A JWKS URL is recommended if you intend to rotate keys, as it allows rotation without downtime or operational involvement from Jack Henry. If you publish more than one key, each JWT and each JWK must carry a kid (key ID); otherwise the JWT is validated against the first JWK matching its alg.
Create a key pair in your browser
You can generate a keypair in your browser. The keypair is never transmitted to any other system.
- Have a how-to question? Seeing a weird error? Get help on StackOverflow.
- Register for the Developer Office Hours where we answer technical Q&A from the audience.