Signed definitions
When enabled, the Ruby SDK fetches definitions from the signed endpoint instead of the unsigned one:
GET https://definitions.toggly.io/definitions-signed/{appKey}/{environment}
The client parses the defs payload from the signed response and applies it locally.
The Ruby SDK does not verify the response signature locally. It does not
fetch JWKS or validate ES256 signatures. Enabling use_signed_definitions
only switches the HTTP endpoint; integrity verification is not performed in
this SDK.
Enable signed definitions
client = Toggly::Client.new(
app_key: ENV['TOGGLY_APP_KEY'],
defaults: { 'ExpressCheckout' => false },
environment: 'Production',
use_signed_definitions: true
)
Use this as your single client construction and close it at process shutdown. With no app key, the nonempty defaults select offline mode and no endpoint is fetched.
allowed_key_ids is accepted on the core and Rails configurations but is unused: there is no local JWKS/ES256 verification path that consults it.
Rails
Merge this into your one Rails initializer:
Toggly::Rails.configure do |config|
config.app_key = Rails.application.credentials.dig(:toggly, :app_key)
config.environment = Rails.env.production? ? 'Production' : 'Staging'
config.use_signed_definitions = true
config.defaults = { 'ExpressCheckout' => false }
end
Shared reliability contract
Prefer clearing persisted snapshots after key rotation or suspected corruption. General server-SDK reliability guidance is in Server-side reliability.
See also Live updates and Caching.