Skip to main content

Signed definitions

When enabled, the Ruby SDK fetches definitions from the signed endpoint instead of the unsigned one:

GET https://definitions.toggly.io/definitions-signed/{appKey}/{environment}

The client parses the defs payload from the signed response and applies it locally.

No local signature verification

The Ruby SDK does not verify the response signature locally. It does not fetch JWKS or validate ES256 signatures. Enabling use_signed_definitions only switches the HTTP endpoint; integrity verification is not performed in this SDK.

Enable signed definitions​

client = Toggly::Client.new(
app_key: ENV['TOGGLY_APP_KEY'],
defaults: { 'ExpressCheckout' => false },
environment: 'Production',
use_signed_definitions: true
)

Use this as your single client construction and close it at process shutdown. With no app key, the nonempty defaults select offline mode and no endpoint is fetched.

allowed_key_ids is accepted on the core and Rails configurations but is unused: there is no local JWKS/ES256 verification path that consults it.

Rails​

Merge this into your one Rails initializer:

config/initializers/toggly.rb
Toggly::Rails.configure do |config|
config.app_key = Rails.application.credentials.dig(:toggly, :app_key)
config.environment = Rails.env.production? ? 'Production' : 'Staging'
config.use_signed_definitions = true
config.defaults = { 'ExpressCheckout' => false }
end

Shared reliability contract​

Prefer clearing persisted snapshots after key rotation or suspected corruption. General server-SDK reliability guidance is in Server-side reliability.

See also Live updates and Caching.