# How to generate Device JWT token for hosted mender virtual device

**URL:** <https://hub.mender.io/t/how-to-generate-device-jwt-token-for-hosted-mender-virtual-device/5324>\
**Category:** General Discussions\
**Created:** [October 17, 2022, 5:49pm UTC](https://hub.mender.io/t/how-to-generate-device-jwt-token-for-hosted-mender-virtual-device/5324 "2022-10-17T17:49:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mender111](https://avatars.discourse-cdn.com/v4/letter/m/cab0a1/32.png) [@mender111](https://hub.mender.io/u/mender111)\
**Post date:** [October 17, 2022, 5:49pm UTC](https://hub.mender.io/t/how-to-generate-device-jwt-token-for-hosted-mender-virtual-device/5324/1 "2022-10-17T17:49:18Z")

</div>

I am trying to generate device jwt token from **[https://hosted.mender.io/api/devices/v1/authentication/auth\_requests](https://hosted.mender.io/api/devices/v1/authentication/auth_requests)** this api but everytime is says **signature verification failed**. Can someone please guide on this?

---

<div class="post-metadata">

**Author:** ![TheYoctoJester](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/theyoctojester/32/1444_2.png) [@TheYoctoJester](https://hub.mender.io/u/TheYoctoJester)\
**Post date:** [October 17, 2022, 8:13pm UTC](https://hub.mender.io/t/how-to-generate-device-jwt-token-for-hosted-mender-virtual-device/5324/2 "2022-10-17T20:13:25Z")

</div>

Hi @mender111 ,

First and foremost, which kind of public key are you using? Are you setting the `X-MEN-Signature` field in the header accordingly? If in doubt, you could for example drop your public key generation command here to cross check.

Greetz,  
Josef

---

<div class="post-metadata">

**Author:** ![mender111](https://avatars.discourse-cdn.com/v4/letter/m/cab0a1/32.png) [@mender111](https://hub.mender.io/u/mender111)\
**Post date:** [October 18, 2022, 10:52am UTC](https://hub.mender.io/t/how-to-generate-device-jwt-token-for-hosted-mender-virtual-device/5324/3 "2022-10-18T10:52:14Z")

</div>

Hi @TheYoctoJester, I am using hosted mender as of now. Also I have created one virtual device there. So the public key I have received from there that I am using now. How can I get a X-MEN-Signature for that?

Thx,  
Vinay

---

<div class="post-metadata">

**Author:** ![TheYoctoJester](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/theyoctojester/32/1444_2.png) [@TheYoctoJester](https://hub.mender.io/u/TheYoctoJester)\
**Post date:** [October 18, 2022, 1:36pm UTC](https://hub.mender.io/t/how-to-generate-device-jwt-token-for-hosted-mender-virtual-device/5324/4 "2022-10-18T13:36:59Z")

</div>

Hi @mender111,

It sounds like there are some misunderstandings on which key is involved in which way here. So, the public key which is mandatory in the request body is a per-device unique key. So you have to create it yourself, and you can choose the algorithm amongst `RSA`, `ECDSA` and `ED25519`. The algorithm you chose goes into the `X-MEN-Signature` field of the header.

The tenant token you can obtain from the web interface goes into the `tenant_token` field of the request body (see also [the body format documentation](https://docs.mender.io/api/#device-api-device-authentication-schemas-authrequest)). If you are using the Hosted Mender instance, then it is mandatory because it will be used to map the device to your account.

Greetz,  
Josef
