altinn-jwks
3.0.0
dotnet tool install --global altinn-jwks --version 3.0.0
dotnet new tool-manifest
dotnet tool install --local altinn-jwks --version 3.0.0
#tool dotnet:?package=altinn-jwks&version=3.0.0
nuke :add-package altinn-jwks --version 3.0.0
Altinn.Cli Console App
The Altinn.Cli.Jwks console application provides a convenient and secure way to generate Json Web Keys.
Installation
Install using dotnet tool install -g altinn-jwks.
Usage
After installation, the altinn-jwks tool is available to use in your favorite terminal. You can execute altinn-jwks --help to get started:
> altinn-jwks --help
Description:
Console app for creating Json Web Keys
Usage:
altinn-jwks [command] [options] [[--] <additional arguments>...]]
Options:
-?, -h, --help Show help and usage information
--version Show version information
Commands:
create <name> Create a new key and add it to a keyset
export Export key sets
list List all keys sets
Additional Arguments:
Arguments passed to the application that is being run.
Sample usage:
altinn-jwks create my-app
Key store location
By default, the tool will create and use JWKs in the current directory. You can specify a different store location using the --store option,
which is available for all commands. The environment variable ALTINN_JWK_STORE can also be used to set a default store location.
A store location can point to a local directory or a remote Azure Key Vault. In order to use a Key Vault location,
you must have the Azure CLI installed and be
logged in to your Azure account.
The Key Vault location should be specified in the format https://<key-vault-name>.vault.azure.net/.
The structure of the JWK store is an undocumented implementation detail, and should not be relied uppon. It can be changed arbitrarily, without this being considered a breaking change. Use the CLI to get keys/key-sets in the different formats.
Example
The following example shows how to create a key in a local subdirectory called keys:
> altinn-jwks create my-app --store keys/
Generating key my-app-TEST.AAAA
Generating key my-app-PROD.AAAA
> altinn-jwks export key my-app --store keys/ | jq
{
"alg": "RS256",
"e": "AQAB",
...
}
The following example shows how to create a key in a remote Key Vault:
> altinn-jwks create my-app --store https://example.vault.azure.net/
Generating key my-app-TEST.AAAA
Generating key my-app-PROD.AAAA
> altinn-jwks export key my-app --store https://example.vault.azure.net/ | jq
{
"alg": "RS256",
"e": "AQAB",
...
}
Listing key-sets
The list command will list all key-sets available in the current store:
> altinn-jwks list
app1 (TEST, PROD)
app2 (TEST, PROD)
Creating keys
The create command lets you create new JWKs, using a range of available options.
> altinn-jwks create --help
Description:
Create a new key and add it to a keyset
Usage:
altinn-jwks create <name> [options] [[--] <additional arguments>...]]
Arguments:
<name> Name of the integration to generate a new key for
Options:
-e, --env, --environment <None|Prod|Test> Comma-separated list of Json Web Key Set environments to use [default:
Test, Prod]
-s, --size Key size in bits []
-a, --alg, --algorithm The algorithm to use for the key [default: RS256]
<ES256|ES384|ES512|RS256|RS384|RS512>
-u, --use <enc|sig> Use for the JWK [default: sig]
--suffix Optional suffix to append to the key ID [default: BKBQ]
-?, -h, --help Show help and usage information
-s, --store The JWKs store to use. Either a directory or an Azure Key Vault URI
[default: .]
Exporting keys
The export key command allows you to export a specific key in your required format.
> altinn-jwks export key --help
Description:
Export the current private or public key
Usage:
altinn-jwks export key <name> [options] [[--] <additional arguments>...]]
Arguments:
<name> Name of the key to export
Options:
-e, --env, --environment <Prod|Test> Json Web Key Set environment to use [default: Test]
-r, --variant <Private|Public> Decides whether to export the private or the public key [default: Private]
-b, --base64 Outputs the base64 version of the key [default: False]
-?, -h, --help Show help and usage information
-s, --store The JWKs store to use. Either a directory or an Azure Key Vault URI [default: .]
Example Maskinporten key
Create the key
> altinn-jwks create maskinportclientkey
Export public key. Default matches format for maskinporten
> altinn-jwks export key maskinportclientkey -r Public
Export private key as base64 (depends on format used in your app)
> altinn-jwks export key maskinportclientkey -b
Contributing
Contributions are welcome! If you find any issues or have suggestions for improvements, please feel free to open an issue or submit a pull request on GitHub.
License
This library is licensed under the MIT License.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
This package has no dependencies.
# Changelog
## [3.0.0](https://github.com/Altinn/altinn-authorization-utils/compare/Altinn.Cli-v2.0.0...Altinn.Cli-v3.0.0) (2026-08-25)
### ⚠ BREAKING CHANGES
* removes net9 support
### Miscellaneous Chores
* drop net9 support ([#628](https://github.com/Altinn/altinn-authorization-utils/issues/628)) ([843ad55](https://github.com/Altinn/altinn-authorization-utils/commit/843ad55d842eaeea662f4b7b370949a3b8ca69ab))
## [2.0.0](https://github.com/Altinn/altinn-authorization-utils/compare/Altinn.Cli-v1.3.0...Altinn.Cli-v2.0.0) (2025-07-31)
### ⚠ BREAKING CHANGES
* Modifies arguments to the CLI. Uses a new file structure for storing the JWKS. Old JWKS will not be recognized without manual intervention (rename the file from `.json` to `.jwks.json` or the key from `--priv` to `--jwks`).
### Features
* update jwks cli ([#321](https://github.com/Altinn/altinn-authorization-utils/issues/321)) ([b9d4a45](https://github.com/Altinn/altinn-authorization-utils/commit/b9d4a455822d7cc1c4d671525188a11ad71341bd))
## [1.3.0](https://github.com/Altinn/altinn-authorization-utils/compare/Altinn.Cli-v1.2.0...Altinn.Cli-v1.3.0) (2025-03-06)
### Features
* npgsql export/import ([#187](https://github.com/Altinn/altinn-authorization-utils/issues/187)) ([e73450e](https://github.com/Altinn/altinn-authorization-utils/commit/e73450e291326ee38cc3bdb7463a434ddc236869))
### Bug Fixes
* cli --help text bug ([#206](https://github.com/Altinn/altinn-authorization-utils/issues/206)) ([86318e8](https://github.com/Altinn/altinn-authorization-utils/commit/86318e82007e7dc21b60ba2e4fd75457389449a5))
## [1.2.0](https://github.com/Altinn/altinn-authorization-utils/compare/Altinn.Cli-v1.1.0...Altinn.Cli-v1.2.0) (2024-12-06)
### Features
* upgrade to .NET 9 ([#166](https://github.com/Altinn/altinn-authorization-utils/issues/166)) ([867c940](https://github.com/Altinn/altinn-authorization-utils/commit/867c9400ac8fd9a37c71d0af6386fbb414523267))
## [1.1.0](https://github.com/Altinn/altinn-authorization-utils/compare/Altinn.Cli-v1.0.0...Altinn.Cli-v1.1.0) (2024-07-25)
### Features
* add keyvault as valid jwks store ([58346b7](https://github.com/Altinn/altinn-authorization-utils/commit/58346b739fc1a7ffaea72bfeb825e9b794827f9e))
## 1.0.0 (2024-06-28)
### Features
* Create altinn-jwks Console App ([#72](https://github.com/Altinn/altinn-authorization-utils/issues/72)) ([b5d1dc0](https://github.com/Altinn/altinn-authorization-utils/commit/b5d1dc0cc55eedc1c6ff3fe97f6cd76ec9704b56))