> ## Documentation Index
> Fetch the complete documentation index at: https://docs.replicas.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Workspace Identity Signing Keys

> Public RSA keys currently trusted to verify workspace identity tokens, including staged rotation keys. Match the token `kid` to a key. No authentication.



## OpenAPI

````yaml /openapi.json get /.well-known/jwks.json
openapi: 3.1.0
info:
  title: Replica API
  version: 2.0.0
  description: >-
    The Replica API allows you to programmatically manage cloud workspaces for
    AI agents. Use this API to manage environments (the org-scoped primitive
    workspaces are created from — including variables, files, skills, MCPs, warm
    hooks, start hooks, and warm pools), create and manage replicas, send
    messages, manage chats, stream events, read connected repositories and
    repository sets, and configure automations.
servers:
  - url: https://api.replicas.dev
    description: Production API
security:
  - apiKey: []
tags:
  - name: Workspace Identity
    description: >-
      Public OpenID Connect discovery and signing keys for verifying short-lived
      workspace identity tokens. Audiences are managed per environment under the
      Environments tag.
  - name: Environments
    description: >-
      Manage environments — the primitive that workspaces are created from.
      Variables, files, skills, MCPs, warm-hooks, and warm-pools are all scoped
      to an environment. Every organization has a singleton Global environment
      whose values apply to every workspace. Personal environments are scoped to
      the authenticated user and can be standalone or source-backed by a team
      environment.
  - name: Repository
    description: >-
      Read repositories and repository sets connected to your organization.
      Repositories are the underlying GitHub-connection layer; bind them to an
      environment to use them in workspaces.
  - name: Replica
    description: >-
      Manage replicas (workspaces) for AI agents. Workspace creation with `POST
      /v1/replica` accepts API keys and workspace engine-secret authentication.
      Other Replica operations also accept logged-in user JWTs from first-party
      clients.
  - name: Slack
    description: Attach Slack threads to Replicas workspaces
  - name: Automation
    description: >-
      Create and manage automations that trigger replicas on a schedule or in
      response to events
  - name: Media
    description: >-
      Read workspace media and obtain short-lived download or inline preview
      URLs
paths:
  /.well-known/jwks.json:
    get:
      tags:
        - Workspace Identity
      summary: Get Workspace Identity Signing Keys
      description: >-
        Public RSA keys currently trusted to verify workspace identity tokens,
        including staged rotation keys. Match the token `kid` to a key. No
        authentication.
      operationId: getWorkspaceIdentityJwks
      responses:
        '200':
          description: JSON Web Key Set
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WorkspaceIdentityJwks'
        '404':
          description: Workspace identity is not configured on this installation
      security: []
components:
  schemas:
    WorkspaceIdentityJwks:
      type: object
      properties:
        keys:
          type: array
          items:
            type: object
            properties:
              kty:
                type: string
                enum:
                  - RSA
              kid:
                type: string
                description: RFC 7638 thumbprint of the key
              use:
                type: string
                enum:
                  - sig
              alg:
                type: string
                enum:
                  - RS256
              'n':
                type: string
              e:
                type: string
            required:
              - kty
              - kid
              - 'n'
              - e
      required:
        - keys
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: >-
        API key authentication. Obtain your API key from the Replicas dashboard
        under Organization → Settings → API Keys.

````