Skip to main content

Validating the Capture Context


The capture context that you generate is a JSON Web Token (JWT) data object. The JWT is digitally signed using a public key and confirms the validity of the JWT and that it comes from . When you do not have a key in the JWT header, recommends that you follow cryptography best practices and validate the capture context signature.

To validate a JWT, you must obtain its public key. This public RSA key is in JSON Web Key (JWK) format. The public key is associated with the capture context on the domain.

To get the public key of a capture context from the header of the capture context itself, you must retrieve the key ID associated with the public key and then pass the key ID to the /flex/v2/public-keys endpoint:

Get the key ID from the header of the capture context

From the header of the capture context, get the key ID (kid):

{    "kid": "3g",    "alg": "RS256"}

Send a GET request to the /flex/v2/public-keys endpoint and include the key ID

GET /flex/v2/public-keys/{3g}

GET /flex/v2/public-keys/{3g}

GET /flex/v2/public-keys/{3g}

GET /flex/v2/public-keys/{3g}

Depending on the cryptographic method you use to validate the public key, you might need to convert the key to privacy-enhanced mail (PEM) format.

Use the returned public key to validate the capture context

The resource returns the public key. Use this public RSA key to validate the capture context. For example:

{    "kty":"RSA",    "use":"enc",    "kid":"3g",    "n":"ir7Nl1Bj8G9rxr3co5v_JLkP3o9UxXZRX1LIZFZeckguEf7Gdt5kGFFfTsymKBesm3Pe8o1hwfkq7KmJZEZSuDbiJSZvFBZycK2pEeBjycahw9CqOweM7aKG2F_bhwVHrY4YdKsp_cSJe_ZMXFUqYmjk7D0p7clX6CmR1QgMl41Ajb7NHI23uOWL7PyfJQwP1X8HdunE6ZwKDNcavqxOW5VuW6nfsGvtygKQxjeHrI-gpyMXF0e_PeVpUIG0KVjmb5-em_Vd2SbyPNmenADGJGCmECYMgL5hEvnTuyAybwgVwuM9amyfFqIbRcrAIzclT4jQBeZFwkzZfQF7MgA6QQ",    "e":"AQAB"}

Session Validation

The session JWT is digitally signed using RS256. You must confirm that it was issued by and has not been tampered with. Follow these steps to validate the signature:

Parse the session JWT header to extract the key ID (kid)

{  "kid": "3g",  "alg": "RS256"}

Retrieve the public key by sending a request to the /flex/v2/public-keys/{kid} endpoint

GET /flex/v2/public-keys/{kid}

GET /flex/v2/public-keys/{kid}

Use the returned RSA public key in JSON Web Key format to verify the JWT signature

Depending on the cryptographic library that you use, you might need to convert the key to Privacy-Enhanced Mail (PEM) format.

Last published: September 29, 2026