---
title: "POST /api/v1/kms/keys/{keyId}/verify"
method: POST
path: "/api/v1/kms/keys/{keyId}/verify"
tags: ["KMS Signing"]
---

# POST /api/v1/kms/keys/{keyId}/verify

`POST /api/v1/kms/keys/{keyId}/verify`

Verify data signatures with a KMS key.

## Path parameters

- `keyId` string, uuid, required

## Request body

- object
  - `isDigest` boolean — Whether the data is already digested or not.
  - `data` string, required — The data in string format to be verified (base64 encoded). For data larger than 1MB you must first create a digest of the data and then pass the digest in the data parameter.
  - `signature` string, required — The signature to be verified (base64 encoded).
  - `signingAlgorithm` 'RSASSA_PSS_SHA_512' | 'RSASSA_PSS_SHA_384' | 'RSASSA_PSS_SHA_256' | 'RSASSA_PKCS1_V1_5_SHA_512' | 'RSASSA_PKCS1_V1_5_SHA_384' | 'RSASSA_PKCS1_V1_5_SHA_256' | 'ECDSA_SHA_512' | 'ECDSA_SHA_384' | 'ECDSA_SHA_256' | 'ML_DSA_44' | 'ML_DSA_65' | 'ML_DSA_87', required

## Response `200`

Default Response

- object
  - `signatureValid` boolean, required
  - `keyId` string, uuid, required
  - `signingAlgorithm` 'RSASSA_PSS_SHA_512' | 'RSASSA_PSS_SHA_384' | 'RSASSA_PSS_SHA_256' | 'RSASSA_PKCS1_V1_5_SHA_512' | 'RSASSA_PKCS1_V1_5_SHA_384' | 'RSASSA_PKCS1_V1_5_SHA_256' | 'ECDSA_SHA_512' | 'ECDSA_SHA_384' | 'ECDSA_SHA_256' | 'ML_DSA_44' | 'ML_DSA_65' | 'ML_DSA_87', required

## Other responses

- `400` — Default Response
- `401` — Default Response
- `403` — Default Response
- `404` — Default Response
- `422` — Default Response
- `500` — Default Response

---

[API](https://skmtc.net/infisical/apis/infisical-api.md) · [All operations](https://skmtc.net/infisical/apis/infisical-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/infisical/infisical-api/versions/885aef3e6c11/schema)
