POST /v1/quotes carry an EIP-712 signature. Verify it against quoteSigner from the source chain’s entry in GET /v1/chains. With options.allQuotes, each entry in quotes[] carries its own signature.
Signed fields
The typed-data definition is
Quote(string id, bytes32[] intentHashes, uint64 expiresAt).
Verify the signature
This function checks the signed fields and expiry. Supply the chain’s currentquoteSigner; the discovery request requires an API key, but signature recovery itself needs no network call.
What verification proves
A matching signer authenticates the quote ID, intent hash set, source-chain domain, and expiry. It does not independently authenticate the other JSON fields or the bytes ofexecution.transaction.
Intent hashes commit to encoded routes and rewards, but signature recovery alone does not recompute those hashes. Before funding, decode the funding transaction, recompute the relevant intent hashes, and verify that the route pays the requested token and amount to the requested recipient. Changing a JSON recipient while leaving its reported hash unchanged will not, by itself, fail signature recovery.
The reference implementation performs these additional checks for supported route shapes and reports when it cannot prove the recipient. Signature verification does not establish that a quote offers the best price or that an intent will be fulfilled.
