Open Connect → Identity
/websites/:id/identity— copy JWKS URL, issuer, and website id. Macro generates RS256 keys automatically (private key never leaves Macro).Configure your backend
Env: JWKS URL, expected
iss,websiteId, and your API’saudience. Verify signature, expiry, aud, and websiteId on every request.Mint from the SDK
const { token } = await macro.getIdentityAssertion({ audience: 'https://api.example.com', }) await fetch('https://api.example.com/admin/books', { method: 'POST', headers: { Authorization: `Bearer ${token}` }, body: JSON.stringify({ title: 'New book' }), })
Rotate keys
Dashboard Rotate keys (or POST /management/identity/rotate with identity:write). The previous key stays in JWKS for 24 hours so verifiers can catch up; new assertions use the active key only.
Proxy vs Identity
Need Macro to call a third-party API with a vault secret? API Proxy. Already have your own backend and only need “who is the editor”? Identity Assertion.
Management API
GET /management/identity—identity:readPATCH /management/identity— enable/disable (identity:write)POST /management/identity/rotate— rotate keys (identity:write)
Public JWKS (no auth): GET /identity/v1/websites/:websiteId/jwks.json