You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何获取带X5c字段的RFC7517格式Firebase JWKS?

Hey there! I've dealt with this exact scenario before when integrating Firebase auth with Tyk, so let me share a couple of straightforward solutions that should work for you.

Tyk actually has native support for validating Firebase JWTs, which means you don't need to fuss with manual public key format conversions at all. Here's how to set it up:

  • Head to your API's Authentication settings in the Tyk Dashboard
  • Select JSON Web Token as the authentication type
  • Set the Signing Method to RS256
  • Paste the Google JWKS endpoint (the one ending with /jwk/securetoken@system.gserviceaccount.com you mentioned) into the JWKS URL field
  • Add your Firebase project's issuer (format: https://securetoken.google.com/<your-project-id>) to the Valid Issuer field
  • Enter your Firebase project ID in the Valid Audiences field

Tyk will automatically fetch and use the correct public keys from that JWKS endpoint to validate Firebase tokens. Even though the JWKS doesn't include the x5c field, that's totally fine—x5c is an optional extension in RFC7517, and Tyk only needs the core public key data (from the n and e fields) to verify the JWT signature.

2. Manually Generate a JWKS with the x5c Field

If you absolutely need a JWKS that includes the X.509 certificate chain, you can combine data from the two endpoints you found:

  • First, pull the X.509 certificates from the x509 metadata endpoint (the one returning PEM-formatted certificates mapped by kid)
  • For each certificate, strip the PEM header (-----BEGIN CERTIFICATE-----) and footer (-----END CERTIFICATE-----), then keep the base64-encoded body
  • Merge this base64 string into the corresponding key entry from the JWKS endpoint as the first element in the x5c array

Here's an example of what the modified JWKS entry would look like:

{
  "keys": [
    {
      "kty": "RSA",
      "alg": "RS256",
      "use": "sig",
      "kid": "abc123",
      "n": "example-modulus-value",
      "e": "AQAB",
      "x5c": [
        "base64-encoded-certificate-body-without-pem-lines"
      ]
    }
  ]
}

You can whip up a simple script (Node.js, Python, whatever you prefer) to periodically fetch data from both endpoints, merge the x5c fields, and host the resulting JWKS for Tyk to use.

Just a quick reminder: RFC7517 doesn't require the x5c field for valid JWKS, so the first method is by far the most hassle-free option for most use cases.

内容的提问来源于stack exchange,提问作者Pierre Leonard

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 04:57:11