Skip to main content

Keys

Tokens are signed with RS256 keys, and cookies with secrets, and both live in the database and look after themselves.

Rotation

Every FG_ID_KEY_ROTATION_DAYS (30) a new key is made. It is published in the JWKS a day before it signs anything, so services that cache the JWKS have it before they meet a token signed with it, and it is kept for two rotations after it stops signing, so tokens it signed still verify. Three are kept.

Running instances check at most once a minute, so a new key reaches all of them without a redeploy. When several notice at once, a lock makes sure only one key is made.

After a leak

pnpm keys rotate            # sign with a new key now; the old one still verifies
pnpm keys rotate --retire   # and stop publishing the old ones
pnpm keys list

Keys in a secret store instead

FG_ID_JWKS (a JWK Set, as JSON or base64url JSON) and FG_ID_COOKIE_SECRETS take over from the database. The first key or secret signs; all of them verify.

pnpm keys generate          # a JWK Set to start with
pnpm keys rotate --env      # the next value: a new key first, the last two after it