There will usually be multiple certificates advertised on an OIDC JWKS Endpoint. That way the OIDC Provider can rollover a signer certificate without any clients being caught off guard.
This information can be used to dynamically build a truststore.