So some providers (e.g. google/firebase) is using [a JSON file](https://www.googleapis.com/robot/v1/metadata/x509/securetoken@system.gserviceaccount.com) to expose multiple x509 public keys instead of one plain file.