> ## Documentation Index
> Fetch the complete documentation index at: https://developers.circle.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Before reading these docs, install the relevant Circle Skill to get pre-loaded context — skills are LLM-optimized and cover architecture decisions, correct flows, and common pitfalls. In Claude Code: run /plugin marketplace add circlefin/skills then /plugin install circle-skills@circle. With Vercel Skills CLI: run npx skills add circlefin/skills. Available skills: use-usdc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-usdc/SKILL.md (balances, transfers, approvals on EVM and Solana); EURC has no skill — see https://developers.circle.com/stablecoins/what-is-eurc.md; bridge-stablecoin https://github.com/circlefin/skills/blob/master/plugins/circle/skills/bridge-stablecoin/SKILL.md (crosschain transfers via CCTP, USDC, EURC, and third-party assets); use-arc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-arc/SKILL.md (Arc chain config, contract deployment, USDC bridging — Arc docs: https://docs.arc.io/llms.txt); use-circle-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-circle-wallets/SKILL.md (choose wallet type); use-developer-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-developer-controlled-wallets/SKILL.md (custodial wallets for payouts and treasury); use-user-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-user-controlled-wallets/SKILL.md (embedded wallets with Web2 login); use-modular-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-modular-wallets/SKILL.md (smart contract wallets with passkeys and ERC-4337); use-gateway https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-gateway/SKILL.md (unified USDC balance, nanopayments); use-smart-contract-platform https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-smart-contract-platform/SKILL.md (deploy, interact, monitor contracts). Pair any skill with the Circle MCP server for live SDK signatures, contract addresses, and chain IDs: {"mcpServers":{"circle":{"url":"https://api.circle.com/v1/codegen/mcp"}}}.
> Read the product overview first. Each product has an overview explaining when and why to use it. Read it before quickstarts.
> Pick the right wallet type. Developer-controlled (you hold keys), user-controlled (end user holds keys via PIN/social login), or modular (smart contract wallets with passkeys). See https://developers.circle.com/wallets.md.
> Use CCTP V2 for crosschain transfers. CCTP natively transfers USDC and EURC via burn-and-mint, and supports permissionless wrapping of third-party assets via lock-and-mint. V1 is legacy; always use V2 unless V1 is specified or the chain requires it (Noble, Sui, and Aptos still require V1). Migration guide: https://developers.circle.com/cctp/migration-from-v1-to-v2.md.
> Use Bridge Kit for frontend bridging. Wraps CCTP with a simpler SDK for user-facing apps. Use CCTP directly for backend transfers.
> Gas Station vs Paymaster. Gas Station sponsors gas for Circle Wallet transactions. Paymaster lets users pay gas in USDC. Different use cases — read both overviews.
> Gateway Nanopayments for sub-cent payments. Gasless USDC micropayments down to $0.000001 via x402 and batched settlement. For pay-per-request APIs, AI agent payments, streaming.
> Look up USDC addresses per chain. Never hardcode — use https://developers.circle.com/stablecoins/usdc-contract-addresses.md.
> Prefer SDKs over raw API calls. Node.js and Python SDKs handle auth, retries, and errors.
> API key required. Bearer token in Authorization header. Testnet and mainnet use separate keys and may use different base URLs depending on the product.
> Set up webhooks when available. Most operations are async. Webhooks deliver transaction confirmations and state changes.
> When calling list endpoints, paginate using pageSize and pageAfter until no nextPageAfter cursor is returned—stopping at the first page silently misses records.
> Building an AI agent? Start with the Agent Stack—Circle CLI, agent wallets, and nanopayments built for autonomous use cases: https://developers.circle.com/agent-stack.md.

# Attestation verification

> Technical reference for verifying CCTP attestation signatures

When you retrieve an attestation from Circle's Attestation Service, you can
optionally verify the attestation signature before using it to mint USDC on the
destination blockchain. This page explains how the verification process works
and when you might want to use it.

## How verification works

The verification process uses cryptographic signature recovery to confirm that
Circle's Attestation Service signed the message. It involves the following
steps:

<Steps>
  <Step title="Retrieve the public key">
    Fetch Circle's current public key from the
    [`GET /v2/publicKeys`](/api-reference/cctp/all/get-public-keys-v2) endpoint.
  </Step>

  <Step title="Hash the message">
    Create a `keccak256` hash of the message bytes.
  </Step>

  <Step title="Parse the attestation">
    Split the 65-byte attestation into its `r`, `s`, and `v` components (ECDSA
    signature format).
  </Step>

  <Step title="Recover the signer">
    Use the signature and message hash to recover the public key that signed the
    message.
  </Step>

  <Step title="Compare addresses">
    Convert both the recovered public key and Circle's public key to Ethereum
    addresses and compare them.
  </Step>
</Steps>

If the addresses match, the attestation was signed by Circle's Attestation
Service and is valid.

## When to verify attestations

Attestation verification is optional because the CCTP contracts on the
destination blockchain perform their own verification when you call
`receiveMessage`. However, you might want to verify attestations before
submitting the mint transaction if:

* **Your application requires an additional layer of security**: Verifying
  before minting provides defense-in-depth by catching invalid attestations at
  the application layer.

* **You want to detect invalid attestations before paying gas fees**: If an
  attestation is invalid, the mint transaction fails and you lose the gas fees.
  Pre-verification lets you catch this before submitting the transaction.

* **You're building a relayer service that batches multiple attestations**:
  Relayers can verify each attestation in a batch before submitting, preventing
  a single invalid attestation from affecting the entire batch.

## Verification code example

The following examples show how to verify an attestation signature using Viem or
Ethers:

<CodeGroup>
  ```ts Viem theme={null}
  import { keccak256, hexToBytes, recoverAddress, bytesToHex } from "viem";

  interface PublicKey {
    publicKey: `0x${string}`;
    cctpVersion: number;
  }

  interface AttestationData {
    message: string;
    attestation: string;
  }

  function publicKeyToAddress(publicKey: `0x${string}`): `0x${string}` {
    // Remove '0x04' prefix (uncompressed public key marker)
    const publicKeyWithoutPrefix = `0x${publicKey.slice(4)}` as `0x${string}`;
    const hash = keccak256(hexToBytes(publicKeyWithoutPrefix));
    // Take last 20 bytes (40 hex chars) as address
    return `0x${hash.slice(-40)}`;
  }

  async function getPublicKeys() {
    const response = await fetch(
      "https://iris-api-sandbox.circle.com/v2/publicKeys",
    );
    const data = await response.json();
    return data.publicKeys
      .filter((key: PublicKey) => key.cctpVersion === 2)
      .map((key: PublicKey) => key.publicKey);
  }

  async function verifyAttestation(
    attestationData: AttestationData,
    publicKeys: `0x${string}`[],
  ) {
    try {
      const messageHash = keccak256(attestationData.message as `0x${string}`);
      const attestationBytes = hexToBytes(
        attestationData.attestation as `0x${string}`,
      );
      const signatureLength = 65;
      const numSignatures = attestationBytes.length / signatureLength;

      if (attestationBytes.length % signatureLength !== 0) {
        throw new Error(`Invalid attestation length: ${attestationBytes.length}`);
      }

      let validSignatures = 0;

      for (let i = 0; i < numSignatures; i++) {
        const start = i * signatureLength;
        const signature = attestationBytes.slice(start, start + signatureLength);

        const recoveredAddress = await recoverAddress({
          hash: messageHash,
          signature: bytesToHex(signature),
        });

        const isValid = publicKeys.some(
          (publicKey) =>
            publicKeyToAddress(publicKey).toLowerCase() ===
            recoveredAddress.toLowerCase(),
        );

        if (isValid) validSignatures++;
      }

      const threshold = Math.ceil(publicKeys.length / 2);
      console.log(
        `Valid signatures: ${validSignatures}/${numSignatures}, threshold: ${threshold}`,
      );

      return validSignatures >= threshold;
    } catch (error) {
      console.error(
        "Error verifying attestation:",
        error instanceof Error ? error.message : String(error),
      );
      return false;
    }
  }

  const attestationData: AttestationData = {
    message: "0x000000010000001a00000015...", // Full message hex from API
    attestation: "0x3c5951abd82a83369d603ebaf9...", // Full attestation hex from API
  };

  // Example usage
  const publicKeys = await getPublicKeys();
  const isValid = await verifyAttestation(attestationData, publicKeys);
  ```

  ```ts Ethers.js theme={null}
  import { ethers } from "ethers";

  interface PublicKey {
    publicKey: string;
    cctpVersion: number;
  }

  interface AttestationData {
    message: string;
    attestation: string;
  }

  async function getPublicKeys() {
    const response = await fetch(
      "https://iris-api-sandbox.circle.com/v2/publicKeys",
    );
    const data = await response.json();

    // Get all public keys for CCTP V2
    const v2Keys = data.publicKeys
      .filter((key: PublicKey) => key.cctpVersion === 2)
      .map((key: PublicKey) => key.publicKey);

    if (v2Keys.length === 0) {
      throw new Error("CCTP V2 public key not found");
    }

    return v2Keys;
  }

  function verifyAttestation(
    attestationData: AttestationData,
    publicKeys: string[],
  ) {
    try {
      const messageHash = ethers.keccak256(attestationData.message);
      const attestationBytes = ethers.getBytes(attestationData.attestation);

      // V2 attestation has multiple 65-byte signatures
      const signatureLength = 65;
      const numSignatures = attestationBytes.length / signatureLength;

      if (attestationBytes.length % signatureLength !== 0) {
        throw new Error(`Invalid attestation length: ${attestationBytes.length}`);
      }

      let validSignatures = 0;

      // Verify each signature
      for (let i = 0; i < numSignatures; i++) {
        const start = i * signatureLength;
        const sigBytes = attestationBytes.slice(start, start + signatureLength);

        const r = ethers.hexlify(sigBytes.slice(0, 32));
        const s = ethers.hexlify(sigBytes.slice(32, 64));
        const v = sigBytes[64];

        const signature = { r, s, v };
        const recoveredAddress = ethers.recoverAddress(messageHash, signature);

        // Check if recovered address matches any V2 public key
        const isValid = publicKeys.some(
          (publicKey) =>
            ethers.computeAddress(publicKey).toLowerCase() ===
            recoveredAddress.toLowerCase(),
        );

        if (isValid) validSignatures++;
      }

      const threshold = Math.ceil(publicKeys.length / 2);
      console.log(
        `Valid signatures: ${validSignatures}/${numSignatures}, threshold: ${threshold}`,
      );

      return validSignatures >= threshold;
    } catch (error) {
      console.error("Error verifying attestation:", (error as Error).message);
      return false;
    }
  }

  // Use attestation data from the API
  const attestationData: AttestationData = {
    message: "0x000000010000001a00000015...", // Full message hex from API
    attestation: "0x3c5951abd82a83369d603ebaf9...", // Full attestation hex from API
  };

  // Example usage
  const publicKeys = await getPublicKeys();
  const isValid = verifyAttestation(attestationData, publicKeys);
  ```
</CodeGroup>
