Skip to main content

Token Verification


Verify the transient token signature using the one-time-use public key issued with the session, to confirm that issued the token and that its data has not been tampered with.

Retrieve the Public Key

Retrieve the public key the same way you retrieved it to validate the session JWT: parse the key ID (kid) from the JWT header, then send a GET request to /flex/v2/public-keys/{kid}. See Session Validation.

Verify the Signature

Use the returned key to verify the transient token JWT signature (RS256).

Verify the JWT Claims

Verify the standard JWT claims: exp (not expired) and iss (matches the expected issuer).

For a Java implementation example, see the Unified Checkout Java Sample.

Last published: September 29, 2026