signatures array.
Parameters
ExecutionTrustRecord
required
The record, as returned by
GET /trust-records/{businessTransactionId} or
parsed from exported JSON. Timestamps may be Date objects or ISO 8601
strings; both verify the same.Record<string, string | KeyObject>
required
Maps each
keyId the record names to its public key, as a PEM string (the
pem field of GET /keys/{keyId}) or a node:crypto KeyObject. A plain
record names one key, in signature.keyId. A hybrid record also names one per
signatures entry. See Public keys.Returns
A promise for anOfflineVerificationResult. It never rejects for bad input: a malformed
record, a missing key or an unknown algorithm comes back as valid: false with a reason in
errors.
boolean
true only when hashValid and legacySignatureValid are true, and
hybridSignaturesValid is true or absent.boolean
trustRecordHash equals the SHA-256 of the record’s signed fields.boolean
The
signature field verifies against its key.boolean | undefined
Present only when the record has a
signatures array. true when it has at
least two entries, no two with the same algorithm, and every entry verifies.
Absent means the record is not hybrid signed, not that a check failed.string[]
Every algorithm actually checked, in order. A hybrid record gives
["ed25519", "ed25519", "dilithium3"].string[]
One readable reason per failed or skipped check. Empty when
valid is true.
See Results and errors.Example: a hybrid record
Valid record
The same record with one amount changed
@parmana/sign 0.2.0, on a sample record signed by the server’s
own signing code (key ids are from that sample).
Requiring hybrid signatures
The function reports what the record carries; it does not decide what a record must carry. If your policy requires the post-quantum signature, check for it yourself:signatures array was removed, which otherwise still
passes on its Ed25519 signature alone.
What it does not check
- That the key belongs to Parmana. Get keys from a source you trust, such as the server you used, and pin them.
- Anything about the business outcome. A valid record proves what was recorded and that it has not changed since signing.