
[A]RGUS
Trustless JWKS Registry on Starknet.
Permissionless RSA key registration via zkTLS.
scroll
Trustless · Permissionless · On-chain
How It Works
01
JWKS Endpoint
Google, Apple, and Firebase publish their RSA public keys at standard HTTPS endpoints. These rotate regularly.
02
zkTLS Proof via Reclaim
Reclaim Protocol generates a cryptographic proof that the HTTP response is authentic — without trusting any intermediary server.
03
On-chain RSA Verification
Argus verifies the Reclaim proof on-chain, checks the RSA modulus and kid against the proof context, then writes the key to the JWKS Registry. Anyone can submit.
Supported Providers
Contract Addresses
| Network | Contract | Address |
|---|---|---|
| Sepolia | Argus | 0x00fad0b6…48d62c1e |
| Sepolia | JWKSRegistry | 0x059e9f82…d6cfd021 |
| Mainnet | Argus | 0x00cef99b…f7d109c0 |
| Mainnet | JWKSRegistry | 0x0012117d…c71e89b4 |