Validate the Capture Context
Overview
The capture context that you generate is a JSON Web Token (JWT) data object. The JWT is digitally signed using a public key and confirms its validity and that it comes from . When you do not have a key in the JWT header, recommends that you follow cryptography best practices and validate the capture context signature.
To validate a JWT, you must obtain its public key. This public RSA key is in JSON Web Key (JWK) format. The public key is associated with the capture context on the domain.
Endpoint
To get the public key of a capture context from the header of the capture context itself, you must retrieve the key ID associated with the public key and then pass it to the /flex/v2/public-keys endpoint:
Get the Key ID
From the header of the capture context, get the key ID (kid):
{ "kid": "3g", "alg": "RS256"}Request the Public Key
Send a GET request to the /flex/v2/public-keys endpoint and include the key ID.
GET /flex/v2/public-keys/3g
GET /flex/v2/public-keys/3g
GET /flex/v2/public-keys/3g
GET /flex/v2/public-keys/3g
Depending on the cryptographic method you use to validate the public key, you might need to convert the key to privacy-enhanced mail (PEM) format.
Example: Public Key
The /flex/v2/public-keys endpoint returns the public key in JWK format:
{ "kty": "RSA", "use": "enc", "kid": "3g", "n": "ir7Nl1Bj8G9rxr3co5v_JLkP3o9UxXZRX1LIZFZeckguEf7Gdt5kGFFfTsymKBesm3Pe8o1hwfkq7KmJZEZSuDbiJSZvFBZycK2pEeBjycahw9CqOweM7aKG2F_bhwVHrY4YdKsp_cSJe_ZMXFUqYmjk7D0p7clX6CmR1QgMl41Ajb7NHI23uOWL7PyfJQwP1X8HdunE6ZwKDNcavqxOW5VuW6nfsGvtygKQxjeHrI-gpyMXF0e_PeVpUIG0KVjmb5-em_Vd2SbyPNmenADGJGCmECYMgL5hEvnTuyAybwgVwuM9amyfFqIbRcrAIzclT4jQBeZFwkzZfQF7MgA6QQ", "e": "AQAB"}Use this public RSA key to validate the capture context.
Thanks for your feedback!
Last published: September 29, 2026