Verify signature
verify_signatureOffline EIP-191 verify of a signed nsgoods response. Identifies the service from the
manifest (or the optional service arg), strips exactly that service's post-sign fields,
canonicalises (JCS, both ASCII modes), recovers the signer and checks it against the
published manifest signers. Reproduction-attestation (JCS/byte-length) and envelope
(signer/signature, components) shapes are reported as unsupported_shape, not verified here.
Refusals carry a distinct status: malformed_signature (signature is not a 65-byte 0x-prefixed
hex string), schema_rejected (the body carries a signed_by/signature pair but fails the required
field shape for every service the claimed signer covers; recovery was not attempted, checked is
false, reasons lists the failed candidates), signature_mismatch (well-formed but recovers a
different address than signed_by under every candidate service recipe of this signer),
no_flat_recipe (signed_by is a manifest signer but every service it covers uses an envelope shape,
so there is no flat recipe to check; recovery was not attempted, checked is false),
unknown_signer (signed_by is not a manifest signer; recovery was not attempted, checked is false),
unsupported_shape, or the no-signed_by/signature-pair case.
checked is true only when EIP-191 recovery actually ran; every other refusal reports checked false.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| service | No | ||
| response_json | Yes |