You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure JWT令牌公钥是否轮换及轮换频率咨询

Azure AD JWT Public Key Rotation: What You Need to Know

Great question! Let’s break this down clearly for you:

  • Yes, the public keys do rotate
    Azure Active Directory (Azure AD) regularly rotates the RSA keys used to sign JWT tokens. This is a core security best practice—rotating keys limits the window of risk if a key were ever compromised.

  • Rotation frequency isn’t fixed, but here’s what to expect
    Microsoft doesn’t publish a rigid, exact schedule, but based on real-world observations and official guidance, keys typically rotate every 6–12 months. That said, rotations can happen sooner in edge cases—like if a key is suspected to be compromised, or for unplanned operational reasons.

  • Critical implementation note
    Never hardcode these public keys in your app. Instead, always fetch the latest keys from the discovery endpoint at runtime. Most popular JWT libraries (like System.IdentityModel.Tokens.Jwt for .NET, jwt-decode for JavaScript) can handle this automatically by pointing to the discovery endpoint, so you don’t have to manage key updates manually.

Pro tip: Add caching for the keys (with a reasonable TTL, like 24 hours) to avoid hitting the endpoint on every request, but ensure your cache invalidates properly so you pick up new keys as soon as they’re rotated.

内容的提问来源于stack exchange,提问作者ilooner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 04:12:29