Signing algorithm to use. This will default to RS256.
Comma separated string or array of role client ids allowed to use this key for signing. If empty no roles are allowed. If "*" all roles are allowed.
How often to generate a new keypair.
Controls how long the public portion of a key will be available for verification after being rotated.
OK