Keysets

The keys this bench signs and decrypts with

A keyset is a named key pair. The private half stays here; the public half is published at a stable JWKS URL, so a verifier can point at it with one configuration change.

Shared

Demo keysets

These are the shared demo keys, the same ones the bench signs with when nobody is signed in. Look at how a keyset is put together, then make your own: Cryptobench keeps the private half and publishes the public half at a fixed URL, so your app can check the tokens it signs.

Everyone uses these keys. A signature made with them proves nothing about who made it, and anything encrypted to them can be read by anybody. Never use them for real traffic.

Reference

URL or embedded key?

Your app needs the public key to check a token. It can fetch it from a URL at runtime, or carry it as a file. Both are normal. The trade is always the same one: who controls rotation.

Fetch from the URLEmbed the key
RotationAutomatic on next fetchNeeds a redeploy
NetworkDepends on the URLNone
TrustWhatever the endpoint servesPinned to one key
SuitsA signer that rotates keysOffline, air-gapped, or pinned

Use the URL when the signer rotates its keys, which is what every identity provider does. That is why it became the norm, and it is usually a one-line config change.

Embed the key when you cannot make a network call while checking a token, or when you want your app pinned to one key so a compromised endpoint could not introduce another. Export the PEM from the Keysets tab.

One catch worth knowing: Spring Boot's public-key-location only loads RSA keys. An ES256 or EdDSA key needs a custom decoder, or the URL.