trustRecordHash mismatch: expected …, got …. (or intentHash) | A signed field changed after signing. | Treat the record as tampered. |
signature verification failed for keyId "…" (…) | The signature does not match this content and key. | Check you used the right environment’s key. Otherwise treat the record as tampered. |
no public key supplied for keyId "…". | publicKeys has no entry for a key the record names. | Fetch that key; see Public keys. |
unsupported algorithm: …. | The record names an algorithm other than ed25519 or dilithium3. | Upgrade @parmana/sign if a newer version supports it. Never treat it as valid. |
signatures array has 1 entry, need at least 2 for a hybrid record. | A hybrid record lost an entry. | Treat as tampered. |
duplicate algorithm in signatures array: …. | Two hybrid entries use the same algorithm. | Treat as tampered. |
signatures is present but is not an array. | The record is malformed. | Check how the record was stored or parsed. |
signature is missing or malformed. | The record has no usable signature field. | Check how the record was stored or parsed. |
error verifying keyId "…" (…): … | The key could not be used, for example a PEM that does not parse, or a key of the wrong type. | Check the key material for that keyId. |