altinn-jwks 3.0.0

dotnet tool install --global altinn-jwks --version 3.0.0
                    
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
                    
if you are setting up this repo
dotnet tool install --local altinn-jwks --version 3.0.0
                    
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=altinn-jwks&version=3.0.0
                    
nuke :add-package altinn-jwks --version 3.0.0
                    

Altinn.Cli Console App

The Altinn.Cli.Jwks console application provides a convenient and secure way to generate Json Web Keys.

Installation

Install using dotnet tool install -g altinn-jwks.

Usage

After installation, the altinn-jwks tool is available to use in your favorite terminal. You can execute altinn-jwks --help to get started:

> altinn-jwks --help

  Description:
    Console app for creating Json Web Keys

  Usage:
    altinn-jwks [command] [options] [[--] <additional arguments>...]]

  Options:
    -?, -h, --help  Show help and usage information
    --version       Show version information

  Commands:
    create <name>  Create a new key and add it to a keyset
    export         Export key sets
    list           List all keys sets

  Additional Arguments:
    Arguments passed to the application that is being run.

  Sample usage:
    altinn-jwks create my-app

Key store location

By default, the tool will create and use JWKs in the current directory. You can specify a different store location using the --store option, which is available for all commands. The environment variable ALTINN_JWK_STORE can also be used to set a default store location.

A store location can point to a local directory or a remote Azure Key Vault. In order to use a Key Vault location, you must have the Azure CLI installed and be logged in to your Azure account. The Key Vault location should be specified in the format https://<key-vault-name>.vault.azure.net/.

The structure of the JWK store is an undocumented implementation detail, and should not be relied uppon. It can be changed arbitrarily, without this being considered a breaking change. Use the CLI to get keys/key-sets in the different formats.

Example

The following example shows how to create a key in a local subdirectory called keys:

> altinn-jwks create my-app --store keys/
  Generating key my-app-TEST.AAAA
  Generating key my-app-PROD.AAAA

> altinn-jwks export key my-app --store keys/ | jq
  {
    "alg": "RS256",
    "e": "AQAB",
    ...
  }

The following example shows how to create a key in a remote Key Vault:

> altinn-jwks create my-app --store https://example.vault.azure.net/
  Generating key my-app-TEST.AAAA
  Generating key my-app-PROD.AAAA

> altinn-jwks export key my-app --store https://example.vault.azure.net/ | jq
  {
    "alg": "RS256",
    "e": "AQAB",
    ...
  }

Listing key-sets

The list command will list all key-sets available in the current store:

> altinn-jwks list

  app1 (TEST, PROD)
  app2 (TEST, PROD)

Creating keys

The create command lets you create new JWKs, using a range of available options.

> altinn-jwks create --help

  Description:
    Create a new key and add it to a keyset

  Usage:
    altinn-jwks create <name> [options] [[--] <additional arguments>...]]

  Arguments:
    <name>  Name of the integration to generate a new key for

  Options:
    -e, --env, --environment <None|Prod|Test>  Comma-separated list of Json Web Key Set environments to use [default:
                                              Test, Prod]
    -s, --size                                 Key size in bits []
    -a, --alg, --algorithm                     The algorithm to use for the key [default: RS256]
    <ES256|ES384|ES512|RS256|RS384|RS512>
    -u, --use <enc|sig>                        Use for the JWK [default: sig]
    --suffix                                   Optional suffix to append to the key ID [default: BKBQ]
    -?, -h, --help                             Show help and usage information
    -s, --store                                The JWKs store to use. Either a directory or an Azure Key Vault URI
                                              [default: .]

Exporting keys

The export key command allows you to export a specific key in your required format.

> altinn-jwks export key --help

  Description:
    Export the current private or public key

  Usage:
    altinn-jwks export key <name> [options] [[--] <additional arguments>...]]

  Arguments:
    <name>  Name of the key to export

  Options:
    -e, --env, --environment <Prod|Test>  Json Web Key Set environment to use [default: Test]
    -r, --variant <Private|Public>        Decides whether to export the private or the public key [default: Private]
    -b, --base64                          Outputs the base64 version of the key [default: False]
    -?, -h, --help                        Show help and usage information
    -s, --store                           The JWKs store to use. Either a directory or an Azure Key Vault URI [default: .]
Example Maskinporten key
Create the key
> altinn-jwks create maskinportclientkey

Export public key. Default matches format for maskinporten
> altinn-jwks export key maskinportclientkey -r Public

Export private key as base64 (depends on format used in your app)
> altinn-jwks export key maskinportclientkey -b

Contributing

Contributions are welcome! If you find any issues or have suggestions for improvements, please feel free to open an issue or submit a pull request on GitHub.

License

This library is licensed under the MIT License.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

Version Downloads Last Updated
3.0.0 120 8/25/2026
2.0.0 403 7/31/2025
1.3.0 360 3/6/2025
1.2.0 241 12/6/2024
1.1.0 253 7/25/2024
1.0.0 226 6/28/2024

# Changelog

## [3.0.0](https://github.com/Altinn/altinn-authorization-utils/compare/Altinn.Cli-v2.0.0...Altinn.Cli-v3.0.0) (2026-08-25)


### ⚠ BREAKING CHANGES

* removes net9 support

### Miscellaneous Chores

* drop net9 support ([#628](https://github.com/Altinn/altinn-authorization-utils/issues/628)) ([843ad55](https://github.com/Altinn/altinn-authorization-utils/commit/843ad55d842eaeea662f4b7b370949a3b8ca69ab))

## [2.0.0](https://github.com/Altinn/altinn-authorization-utils/compare/Altinn.Cli-v1.3.0...Altinn.Cli-v2.0.0) (2025-07-31)


### ⚠ BREAKING CHANGES

* Modifies arguments to the CLI. Uses a new file structure for storing the JWKS. Old JWKS will not be recognized without manual intervention (rename the file from `.json` to `.jwks.json` or the key from `--priv` to `--jwks`).

### Features

* update jwks cli ([#321](https://github.com/Altinn/altinn-authorization-utils/issues/321)) ([b9d4a45](https://github.com/Altinn/altinn-authorization-utils/commit/b9d4a455822d7cc1c4d671525188a11ad71341bd))

## [1.3.0](https://github.com/Altinn/altinn-authorization-utils/compare/Altinn.Cli-v1.2.0...Altinn.Cli-v1.3.0) (2025-03-06)


### Features

* npgsql export/import ([#187](https://github.com/Altinn/altinn-authorization-utils/issues/187)) ([e73450e](https://github.com/Altinn/altinn-authorization-utils/commit/e73450e291326ee38cc3bdb7463a434ddc236869))


### Bug Fixes

* cli --help text bug ([#206](https://github.com/Altinn/altinn-authorization-utils/issues/206)) ([86318e8](https://github.com/Altinn/altinn-authorization-utils/commit/86318e82007e7dc21b60ba2e4fd75457389449a5))

## [1.2.0](https://github.com/Altinn/altinn-authorization-utils/compare/Altinn.Cli-v1.1.0...Altinn.Cli-v1.2.0) (2024-12-06)


### Features

* upgrade to .NET 9 ([#166](https://github.com/Altinn/altinn-authorization-utils/issues/166)) ([867c940](https://github.com/Altinn/altinn-authorization-utils/commit/867c9400ac8fd9a37c71d0af6386fbb414523267))

## [1.1.0](https://github.com/Altinn/altinn-authorization-utils/compare/Altinn.Cli-v1.0.0...Altinn.Cli-v1.1.0) (2024-07-25)


### Features

* add keyvault as valid jwks store ([58346b7](https://github.com/Altinn/altinn-authorization-utils/commit/58346b739fc1a7ffaea72bfeb825e9b794827f9e))

## 1.0.0 (2024-06-28)


### Features

* Create altinn-jwks Console App ([#72](https://github.com/Altinn/altinn-authorization-utils/issues/72)) ([b5d1dc0](https://github.com/Altinn/altinn-authorization-utils/commit/b5d1dc0cc55eedc1c6ff3fe97f6cd76ec9704b56))