Skip to main content
Checks a signed Execution Trust Record offline: the hash, the Ed25519 signature, and, when present, the hybrid signatures array.

Parameters

ExecutionTrustRecord
required
The record, as returned by GET /trust-records/{businessTransactionId} or parsed from exported JSON. Timestamps may be Date objects or ISO 8601 strings; both verify the same.
Record<string, string | KeyObject>
required
Maps each keyId the record names to its public key, as a PEM string (the pem field of GET /keys/{keyId}) or a node:crypto KeyObject. A plain record names one key, in signature.keyId. A hybrid record also names one per signatures entry. See Public keys.

Returns

A promise for an OfflineVerificationResult. It never rejects for bad input: a malformed record, a missing key or an unknown algorithm comes back as valid: false with a reason in errors.
boolean
true only when hashValid and legacySignatureValid are true, and hybridSignaturesValid is true or absent.
boolean
trustRecordHash equals the SHA-256 of the record’s signed fields.
boolean
The signature field verifies against its key.
boolean | undefined
Present only when the record has a signatures array. true when it has at least two entries, no two with the same algorithm, and every entry verifies. Absent means the record is not hybrid signed, not that a check failed.
string[]
Every algorithm actually checked, in order. A hybrid record gives ["ed25519", "ed25519", "dilithium3"].
string[]
One readable reason per failed or skipped check. Empty when valid is true. See Results and errors.

Example: a hybrid record

Valid record
The same record with one amount changed
These are real outputs from @parmana/sign 0.2.0, on a sample record signed by the server’s own signing code (key ids are from that sample).

Requiring hybrid signatures

The function reports what the record carries; it does not decide what a record must carry. If your policy requires the post-quantum signature, check for it yourself:
This catches a hybrid record whose signatures array was removed, which otherwise still passes on its Ed25519 signature alone.

What it does not check

  • That the key belongs to Parmana. Get keys from a source you trust, such as the server you used, and pin them.
  • Anything about the business outcome. A valid record proves what was recorded and that it has not changed since signing.