Security & abuse

Signed responses — do I have to check the signature?

1 reply · 306 views · started Aug 31, 2026
DH
Derek H
Aug 31, 2026
Question

The verify response has a signature field. Is checking it actually necessary if I'm already on HTTPS?

PS
Priya S
Aug 31, 2026

HTTPS proves you talked to us. The signature proves the answer you're holding is the one we gave, and the nonce proves it isn't one we gave an hour ago being replayed at you.

If the answer never leaves the request that fetched it, HTTPS alone is close enough. The moment you cache it — and you should — check the signature, because a cached answer is exactly what's worth tampering with.