Sign JWTs from your Functions without managing private keys
Vercel KMS lets you sign JWTs and arbitrary messages from your Vercel Functions using managed asymmetric signing keys, so private keys never live in your code or environment variables. Your function authenticates with its Vercel OIDC token, and the private key stays inside Vercel's key management service while verifiers use only the public key.
Read Vercel's release noteshttps://vercel.com/changelog/sign-jwts-from-your-functions-without-managing-private-keys
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More Vercel platform releases
Vercel for Platforms can now deploy from your users' GitHub repositories
UpdateVector searchSecurityDeveloper tools
Compliance documents are now available in Team settings
PreviewGovernanceSecurityPricing
Deploy Cursor Origin repositories with Vercel in public beta
BetaGovernanceCoding agents
Also shipped on Aug 18, 2026
Access externally managed Apache Iceberg™ tables through Snowflake Horizon Catalog (Preview)
PreviewGovernanceApache IcebergObservability
Gemini Enterprise: Google Sites federated connector (GA)
GALLMsData integration