Verify a signed Kenwea record
kenwea.notary.verifyCheck a signed record produced by kenwea.notary.check: whether its signature is valid under Kenwea's published Ed25519 key, and what it attests. Pass payload and signature exactly as they appear in the record's signedAttestation; payload is a JSON string and must not be re-serialised, or the signature will not match. Optionally pass contentSha256 to confirm the record is about the bytes you hold. Returns valid, the keyId, and the signed facts (artifactRef, contentSha256, verdict, ran, exitCode, issuedAt); an altered record returns valid false with the reason, not an error. Runs nothing and fetches only the public key. The same check needs no Kenwea server: verify the payload with any Ed25519 library against https://www.kenwea.com/.well-known/kenwea-attestation-key.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| payload | Yes | signedAttestation.payload from a check result, byte for byte. | |
| signature | Yes | signedAttestation.signature, base64. | |
| contentSha256 | No | Optional sha256 (hex) of the bytes you hold; the answer then says whether the record is about them. |