Skip to main content

Signed definitions

For stronger integrity guarantees, Toggly can return signed feature definitions.

When enabled, the SDK:

  • fetches signed definitions from GET https://definitions.toggly.io/definitions-signed/{appKey}/{environment}
  • fetches the JSON Web Key Set (JWKS) from GET https://definitions.toggly.io/.well-known/jwks
  • verifies the signature using ES256
  • only then applies definitions locally

Enable signed definitions​

client, err := toggly.NewClient(toggly.Config{
AppKey: "YOUR_APP_KEY",
Environment: "Production",
UseSignedDefinitions: true,
})

If you want to pin the accepted key IDs (KIDs), provide AllowedKeyIDs:

client, err := toggly.NewClient(toggly.Config{
AppKey: "YOUR_APP_KEY",
Environment: "Production",
UseSignedDefinitions: true,
AllowedKeyIDs: map[string]struct{}{
"ABCDEF...ES256": {},
},
})

How verification works (high level)​

The server signs the payload using the exact JSON bytes of defs plus a timestamp:

  • payload: <raw defs json>|<timestamp>
  • hash: SHA-256
  • signature: ES256 (ECDSA P-256), DER-encoded

The SDK preserves raw JSON for the defs field to ensure the signature matches what the server produced.