Verifies a JWK proof: a compact JWS with typ device-key-proof+jwt, the public key in its header's jwk, over { nonce, aud, iat }.
typ
device-key-proof+jwt
jwk
{ nonce, aud, iat }
An x5c in the header is an Android Key Attestation, verified by android(); without one the key is self-asserted.
x5c
android()
self-asserted
token, nonce (the enrolment challenge) and audience
token
nonce
audience
{ ok, jwk, alg, attestation }, or a refusal
{ ok, jwk, alg, attestation }
Verifies a JWK proof: a compact JWS with
typdevice-key-proof+jwt, the public key in its header'sjwk, over{ nonce, aud, iat }.An
x5cin the header is an Android Key Attestation, verified byandroid(); without one the key isself-asserted.