connect/keys
) 是一种安全措施,可用于验证从 Canva Connect 收到的 webhook 的真实性。Keys API 返回 JSON Web Key (JWK),您可以使用它来解密 webhook 签名并验证它来自 Canva 而不是潜在的恶意行为者。这有助于保护您的系统免受 重放攻击。curl --location --request GET 'http://dev-cn.your-api-server.com/rest/v1/connect/keys'
{
"keys": [
{
"kid": "a418dc7d-ecc5-5c4b-85ce-e1104a8addbe",
"kty": "OKP",
"crv": "Ed25519",
"x": "aIQtqd0nDfB-ug0DrzZbwTum-1ITdXvKxGFak_1VB2j"
},
{
"kid": "c8de5bec1-1b88-4ddaae04acc-ce415-5d7",
"kty": "OKP",
"crv": "Ed25519",
"x": "m2d1FT-gfBXxIzKwdQVTra0D-aBq_ubZ1jI0GuvkDtn"
}
]
}