Skip to content

[API Shield] Document default JWK algorithm#32271

Open
janrueth wants to merge 1 commit into
cloudflare:productionfrom
janrueth:APISHI-5671-jwk-alg-docs
Open

[API Shield] Document default JWK algorithm#32271
janrueth wants to merge 1 commit into
cloudflare:productionfrom
janrueth:APISHI-5671-jwk-alg-docs

Conversation

@janrueth

Copy link
Copy Markdown
Contributor

Summary

Documents API Shield JWT validation behavior when an RSA JSON Web Key omits alg:

  • Defaults the effective algorithm to RS256 for compatibility.
  • Recommends always providing alg explicitly.
  • Documents response normalization and informational message 110003.
  • Clarifies that the effective algorithm must match the JWT header.

Screenshots (optional)

Documentation checklist

@cloudflare-docs-bot

cloudflare-docs-bot Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Review

✅ No issues found in commit ec3f8cc.

Code Review

This code review is in beta and may not always be helpful — use your judgment.

No code review issues found.

Conventions

No convention issues found.

Style Guide Review

No style-guide issues found.

Commands

Only codeowners can run commands. Post a comment with the command to trigger it.

Command Description
/review Runs a review now. Incremental if a prior review exists, full if not.
/full-review Re-reviews the entire PR diff from scratch, ignoring incremental history. Useful after a rebase, when you want a fresh review, or if the bot gets out of sync and reports issues that no longer exist.
/ignore-review-limit Permanently lifts the 2-review automatic limit for this PR. Future pushes will trigger reviews as normal.
/disable-auto-review Stops automatic reviews from triggering on future pushes to this PR. Codeowners can still run /review or /full-review manually.
/rebase Rebases the PR branch against production. On conflict, attempts to resolve automatically using AI. Stops with an explanation if confidence is not high enough.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants