Token Verification
Verify the transient token signature using the one-time-use public key issued with the session, to confirm that issued the token and that its data has not been tampered with.
Retrieve the Public Key
Retrieve the public key the same way you retrieved it to validate the session JWT: parse the key ID (kid) from the JWT header, then send a GET request to /flex/v2/public-keys/{kid}. See Session Validation.
Verify the Signature
Use the returned key to verify the transient token JWT signature (RS256).
Verify the JWT Claims
Verify the standard JWT claims: exp (not expired) and iss (matches the expected issuer).
For a Java implementation example, see the Unified Checkout Java Sample.
Thanks for your feedback!
Last published: September 29, 2026