createEd25519DecisionVerifier
Purpose and behavior
Section titled “Purpose and behavior”Create a WorkflowDecisionVerifier that loads the trusted keys on every call, then checks the proof’s key, its actor binding, the Ed25519 signature and the expiry. Returns keyId and verifiedAt; throws on an unknown, duplicated or wrongly bound key, an invalid signature or an expired proof.
Complete example and detailed rules.
Parameters and properties
Section titled “Parameters and properties”optionsRequiredWorkflowDecisionVerifierOptionsLive trusted public-key source owned by the application.options.keysRequired() => readonly WorkflowApproverKey[] | Promise<readonly WorkflowApproverKey[]>Resolve trusted actor/public-key bindings on every verification. Remove a key to revoke new proofs; source errors reject the decision.