WBA Signature Validator
Verify an HTTP Message Signature against RFC 9421 — the mechanism behind WebBot Auth
Parsed and, if you choose to verify, checked entirely in your browser using the Web Crypto API — the request is never sent to any server. Fetching a signer's key directory makes a direct browser fetch to that URL (not through our server). If the request has a Signature-Agent header (WBA's agent identity), it's detected and shown, including a check that it's actually covered by the signature. Currently supports the ed25519 algorithm only, and covered components that are plain header fields (optionally with a ;key dictionary-member selector), or the @method/@path/@query/@authority/@scheme/@target-uri/@request-target derived components — not structured-field (;sf), binary-wrapped (;bs), trailer (;tr), or @query-param component parameters, and not Inner-List-valued dictionary members.
Verify Signature
Provide the key material this signature claims to be from. Nothing here leaves your browser except an optional direct fetch to a directory URL you specify.
Matches the signature's "keyid" against keys in the fetched set. If there's no keyid and the set has exactly one key, that key is used. Most third-party directories won't allow a cross-origin browser read (CORS) — if the fetch fails, paste the JWK directly instead.