Skip to main content

Validate the Capture Context


Overview

The capture context that you generate is a JSON Web Token (JWT) data object. The JWT is digitally signed using a public key and confirms its validity and that it comes from . When you do not have a key in the JWT header, recommends that you follow cryptography best practices and validate the capture context signature.

To validate a JWT, you must obtain its public key. This public RSA key is in JSON Web Key (JWK) format. The public key is associated with the capture context on the domain.

Endpoint

To get the public key of a capture context from the header of the capture context itself, you must retrieve the key ID associated with the public key and then pass it to the /flex/v2/public-keys endpoint:

Get the Key ID

From the header of the capture context, get the key ID (kid):

{    "kid": "3g",    "alg": "RS256"}

Request the Public Key

Send a GET request to the /flex/v2/public-keys endpoint and include the key ID.

GET /flex/v2/public-keys/3g

GET /flex/v2/public-keys/3g

GET /flex/v2/public-keys/3g

GET /flex/v2/public-keys/3g

Depending on the cryptographic method you use to validate the public key, you might need to convert the key to privacy-enhanced mail (PEM) format.

Example: Public Key

The /flex/v2/public-keys endpoint returns the public key in JWK format:

{    "kty": "RSA",    "use": "enc",    "kid": "3g",    "n": "ir7Nl1Bj8G9rxr3co5v_JLkP3o9UxXZRX1LIZFZeckguEf7Gdt5kGFFfTsymKBesm3Pe8o1hwfkq7KmJZEZSuDbiJSZvFBZycK2pEeBjycahw9CqOweM7aKG2F_bhwVHrY4YdKsp_cSJe_ZMXFUqYmjk7D0p7clX6CmR1QgMl41Ajb7NHI23uOWL7PyfJQwP1X8HdunE6ZwKDNcavqxOW5VuW6nfsGvtygKQxjeHrI-gpyMXF0e_PeVpUIG0KVjmb5-em_Vd2SbyPNmenADGJGCmECYMgL5hEvnTuyAybwgVwuM9amyfFqIbRcrAIzclT4jQBeZFwkzZfQF7MgA6QQ",    "e": "AQAB"}

Use this public RSA key to validate the capture context.

Last published: September 29, 2026