Zum Inhalt

jwks

module wittgenstein_oidc_backend.jwks

Keycloak JWKS fetching with an in-memory TTL cache.

Same shape as the pattern already used (and duplicated) in several services' auth modules — extracted here so every service shares one implementation instead of reimplementing it.

Classes

  • JwksClient — Fetches and caches a Keycloak realm's JWKS document.

wittgenstein_oidc_backend.jwks.JwksClient

class JwksClient(jwks_url: str, *, cache_ttl: int = _DEFAULT_CACHE_TTL)

Fetches and caches a Keycloak realm's JWKS document.

One instance per realm/issuer is expected to be shared across requests (it is not a per-request object) — construct it once at app startup.

Methods

wittgenstein_oidc_backend.jwks.JwksClient.get_keys

async method JwksClient.get_keys(self) → list[dict[str, Any]]

wittgenstein_oidc_backend.jwks.JwksClient.get_key

async method JwksClient.get_key(self, kid: str) → dict[str, Any] | None