---
search:
  tags:
    - Discovery
    - GET
seo:
  description: >-
    Used to verify ACS voucher JWTs offline. In live mode returns 503… Reference
    for the GET /.well-known/jwks.json endpoint in the agentsub Gateway API.
sidebar:
  label: Voucher signing JWKS (ES256)
  badge: GET
title: Voucher signing JWKS (ES256)
type: openapi-operation
---
Used to verify ACS voucher JWTs offline. In live mode returns `503 signing_configuration_required` when signing keys are not configured.

`GET /.well-known/jwks.json`

**Responses**

- `200` — JWKS key set
- `503` — Runtime or provider configuration unavailable (\`runtime\_configuration\_required\`, \`signing\_configuration\_required\`, \`runtime\_unavailable\`, \`workspace\_unavailable\`, \`provider\_configuration\_required\`)

Response example, 200:

```json
{
  "keys": [
    {}
  ]
}
```
