Just a heads up – in the next drop of IdentityServer we will be switching to Microsoft’s JWT token handler. This adds support for X.509 based signatures and JWT over WS*.
On github there’s a branch called “Microsoft-JWT”, if you want to test ahead of time you can use the new code base already.