Azure JWT令牌公钥是否轮换及轮换频率咨询
Great question! Let’s break this down clearly for you:
Yes, the public keys do rotate
Azure Active Directory (Azure AD) regularly rotates the RSA keys used to sign JWT tokens. This is a core security best practice—rotating keys limits the window of risk if a key were ever compromised.Rotation frequency isn’t fixed, but here’s what to expect
Microsoft doesn’t publish a rigid, exact schedule, but based on real-world observations and official guidance, keys typically rotate every 6–12 months. That said, rotations can happen sooner in edge cases—like if a key is suspected to be compromised, or for unplanned operational reasons.Critical implementation note
Never hardcode these public keys in your app. Instead, always fetch the latest keys from the discovery endpoint at runtime. Most popular JWT libraries (likeSystem.IdentityModel.Tokens.Jwtfor .NET,jwt-decodefor JavaScript) can handle this automatically by pointing to the discovery endpoint, so you don’t have to manage key updates manually.
Pro tip: Add caching for the keys (with a reasonable TTL, like 24 hours) to avoid hitting the endpoint on every request, but ensure your cache invalidates properly so you pick up new keys as soon as they’re rotated.
内容的提问来源于stack exchange,提问作者ilooner

