Dashboard · Connect

Identity Assertion

Short-lived JWTs so your own backend can trust Macro editor logins — without vault secrets or the API Proxy.

  1. Open Connect → Identity

    /websites/:id/identity — copy JWKS URL, issuer, and website id. Macro generates RS256 keys automatically (private key never leaves Macro).

  2. Configure your backend

    Env: JWKS URL, expected iss, websiteId, and your API’s audience. Verify signature, expiry, aud, and websiteId on every request.

  3. Mint from the SDK

    identity.tstypescript
    const { token } = await macro.getIdentityAssertion({
      audience: 'https://api.example.com',
    })
    
    await fetch('https://api.example.com/admin/books', {
      method: 'POST',
      headers: { Authorization: `Bearer ${token}` },
      body: JSON.stringify({ title: 'New book' }),
    })

Rotate keys

Dashboard Rotate keys (or POST /management/identity/rotate with identity:write). The previous key stays in JWKS for 24 hours so verifiers can catch up; new assertions use the active key only.

Proxy vs Identity
Need Macro to call a third-party API with a vault secret? API Proxy. Already have your own backend and only need “who is the editor”? Identity Assertion.

Management API

  • GET /management/identity — identity:read
  • PATCH /management/identity — enable/disable (identity:write)
  • POST /management/identity/rotate — rotate keys (identity:write)

Public JWKS (no auth): GET /identity/v1/websites/:websiteId/jwks.json