# GET /.well-known/paze/{environment}/jwks.json

Paze: public JWKS for an environment.

Anonymous and unthrottled: Paze fetches it to verify/encrypt.

404 when the environment's key ids are unset or its certificate has not been generated yet.

**Operation ID:** `pazeJwksGetWellKnown`

## Authorization

No permission required.

## Parameters

| Name | In | Required | Type | Description |
| --- | --- | --- | --- | --- |
| environment | path | yes | PazeCertificateEnvironment | Paze environment a certificate belongs to. Sandbox self-signs; Production is CA-issued (CSR + merge). |
| suppressNulls | query | no | boolean | If true, omit properties with null values. |

## Responses

### 200

OK

### default

The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

## Example request

Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.

### cURL

```bash
curl -X GET "{{BASE_URL}}/.well-known/paze/{environment}/jwks.json" \
  -H "api-key: {{API_KEY}}"
```

### PowerShell

```powershell
$headers = @{
    'api-key' = '{{API_KEY}}'
}

$response = Invoke-RestMethod -Method GET -Uri '{{BASE_URL}}/.well-known/paze/{environment}/jwks.json' `
    -Headers $headers
```

### TypeScript (SDK)

```bash
npm install @winkpg/winkpg-api
```

```typescript
import { Configuration, WalletsApi } from '@winkpg/winkpg-api';

const api = new WalletsApi(new Configuration({
  basePath: '{{BASE_URL}}',
  apiKey: '{{API_KEY}}',
}));

const { data } = await api.pazeJwksGetWellKnown("ENVIRONMENT");
```

### TypeScript (raw HTTP)

```typescript
const response = await fetch('{{BASE_URL}}/.well-known/paze/{environment}/jwks.json', {
  method: 'GET',
  headers: {
    "api-key": "{{API_KEY}}",
  },
});

const data = await response.json();
```

### C# (SDK)

```bash
dotnet add package WinkPg.Api.Client
```

```csharp
using WinkPg.Api.Client.Api;
using WinkPg.Api.Client.Client;

var config = new Configuration { BasePath = "{{BASE_URL}}" };
config.AddApiKey("api-key", "{{API_KEY}}");

var api = new WalletsApi(config);
var result = await api.PazeJwksGetWellKnownAsync("ENVIRONMENT");
```

### C# (raw HTTP)

```csharp
using var http = new HttpClient { BaseAddress = new Uri("{{BASE_URL}}") };

var request = new HttpRequestMessage(new HttpMethod("GET"), "/.well-known/paze/{environment}/jwks.json");
request.Headers.Add("api-key", "{{API_KEY}}");

var response = await http.SendAsync(request);
response.EnsureSuccessStatusCode();
var json = await response.Content.ReadAsStringAsync();
```

### Python (SDK)

```bash
pip install winkpg-api
```

```python
import winkpg_api

configuration = winkpg_api.Configuration(host="{{BASE_URL}}")
configuration.api_key["ApiKey"] = "{{API_KEY}}"

with winkpg_api.ApiClient(configuration) as client:
    api = winkpg_api.WalletsApi(client)
    result = api.paze_jwks_get_well_known("ENVIRONMENT")
```

### Python (raw HTTP)

```bash
pip install requests
```

```python
import requests

headers = {
    "api-key": "{{API_KEY}}",
}

response = requests.request(
    "GET",
    "{{BASE_URL}}/.well-known/paze/{environment}/jwks.json",
    headers=headers,
)
response.raise_for_status()
data = response.json()
```

## See also

- [All documentation](https://devportal-simpay-sbx.winkpg.io/llms.txt): the machine-readable index of every public page on this site.
