jwks
module wittgenstein_oidc_backend.jwks
Keycloak JWKS fetching with an in-memory TTL cache.
Same shape as the pattern already used (and duplicated) in several services' auth modules — extracted here so every service shares one implementation instead of reimplementing it.
Classes
-
JwksClient — Fetches and caches a Keycloak realm's JWKS document.
wittgenstein_oidc_backend.jwks.JwksClient
class JwksClient(jwks_url: str, *, cache_ttl: int = _DEFAULT_CACHE_TTL)
Fetches and caches a Keycloak realm's JWKS document.
One instance per realm/issuer is expected to be shared across requests (it is not a per-request object) — construct it once at app startup.
Methods
wittgenstein_oidc_backend.jwks.JwksClient.get_keys
async method JwksClient.get_keys(self) → list[dict[str, Any]]
wittgenstein_oidc_backend.jwks.JwksClient.get_key
async method JwksClient.get_key(self, kid: str) → dict[str, Any] | None