Signed definitions
For stronger integrity guarantees, Toggly can return signed feature definitions.
When enabled, the SDK:
- fetches signed definitions from
GET https://definitions.toggly.io/definitions-signed/{appKey}/{environment} - fetches the JSON Web Key Set (JWKS) from
GET https://definitions.toggly.io/.well-known/jwks - verifies the signature using ES256
- only then applies definitions locally
Enable signed definitions
client, err := toggly.NewClient(toggly.Config{
AppKey: "YOUR_APP_KEY",
Environment: "Production",
UseSignedDefinitions: true,
})
Restrict allowed signing keys (recommended)
If you want to pin the accepted key IDs (KIDs), provide AllowedKeyIDs:
client, err := toggly.NewClient(toggly.Config{
AppKey: "YOUR_APP_KEY",
Environment: "Production",
UseSignedDefinitions: true,
AllowedKeyIDs: map[string]struct{}{
"ABCDEF...ES256": {},
},
})
How verification works (high level)
The server signs the payload using the exact JSON bytes of defs plus a timestamp:
- payload:
<raw defs json>|<timestamp> - hash: SHA-256
- signature: ES256 (ECDSA P-256), DER-encoded
The SDK preserves raw JSON for the defs field to ensure the signature matches what the server produced.