> For a complete page index, fetch https://docs.conduit.xyz/llms.txt

# JSON Web Token authentication

> Require signed JSON Web Tokens for requests that use a Conduit Nodes API key.

JSON Web Token (JWT) authentication adds a signed credential to a Conduit Nodes API key. You sign each token with an asymmetric key pair that you control, and Conduit verifies it with the public key registered to your organization.

JWT authentication is opt-in per API key. An API key without a bound public key continues to work as before. After you bind a public key, every request that uses that API key must include both:

* The Nodes API key in the RPC endpoint URL.
* A signed JWT in the `Authorization: Bearer <JWT>` header.

## How authentication works

A JWT has three Base64URL-encoded parts: `header.payload.signature`. The header identifies the signing algorithm and public key, the payload contains time claims, and the signature lets Conduit detect changes and verify the signer.

1. You generate an asymmetric public and private key pair.
2. You register the public key with Conduit. Conduit derives a Key ID (`kid`) from it.
3. You bind the public key to one or more Nodes API keys.
4. You sign a JWT with the private key and include the Key ID in its header.
5. Conduit selects the bound public key identified by `kid`, then verifies the algorithm, signature, and expiration.

Conduit supports these asymmetric signing algorithms:

* `RS256` with an RSA key.
* `ES256` with an elliptic curve P-256 key.
* `EdDSA` with an Ed25519 key.

Conduit doesn't support symmetric algorithms such as `HS256`. The algorithm selected for the registered public key must match its key type and the JWT signing algorithm.

> **Warning**
>
> Keep private keys in a secrets manager or another protected backend
> environment. Never upload a private key to Conduit, commit it to source
> control, or expose it in browser code. Conduit only needs the public key.

## Get started

#### Create a Nodes API key

[Create a Nodes API key](/rpc-nodes/getting-started/get-api-key) if you
don't already have one.

#### Open your organization's JWT public keys

In the [Conduit app](https://app.conduit.xyz/), open your organization
settings and find **JWT public keys**.

![JWT public keys section](/_fern-img/9948dc8d0e566fd3b43d43d69323e9f34e395b9a44b996d80a0837200789296a.webp)

#### Register your public key

Add your public key in Privacy-Enhanced Mail (PEM) format.

![Adding public key](/_fern-img/268f54af66de5fc4f32e7e4b5603a937b7d1821e50d2572574f1f5d78e0ca75a.webp)

Copy the generated Key ID.

![The derived Key ID](/_fern-img/e9f9296fda56862095fac69d6d0427150974d396f6f17c4587b6d102b2e8ebd2.webp)

#### Open your API key's authentication settings

In **Nodes**, select your API key and open **Authentication**.

![Select public key](/_fern-img/53a5bfc1db90633ed47fa6d802e2821ac1048f4f49057b2bc711809fd4c503f5.webp)

#### Bind the public key

Click **Select a public key**, select the registered public key, then click
**Bind**.

![Public key selected](/_fern-img/548b35a1181db9f61a75d82e94ac5b2748bde499d2c979dfbffa93f3560ca25a.webp)

The Authentication section displays the bound public key.

![Public key bound to the Nodes API key](/_fern-img/5475f452dadf51a0bad67ac1b202bda7af3a1a8f606c3cb8837c6ed30cc1d586.webp)

Changes may take a moment to apply. Admin and Read-Write members can manage public keys and bindings. Read-Only members can view them.

#### [Generate JWTs](/rpc-nodes/guides/jwt-authentication/generate-jwts)

Create an RS256 key pair with Node.js or Bash, then sign short-lived tokens with TypeScript or Go.

#### [Make authenticated requests](/rpc-nodes/guides/jwt-authentication/make-requests)

Send both your Nodes API key and bearer token to a Conduit RPC endpoint.

To rotate credentials without interrupting requests, register a new public key and bind it before you stop signing with the old private key. Update your services to use the new Key ID, then unbind or delete the old public key.