Skip to content

Sign and Verify

sucks less edited this page Sep 10, 2026 · 1 revision

Sign and Verify

mnp can sign arbitrary data with the wallet view key and verify Monero message signatures.

This is useful for proving control over a wallet address without creating a transaction.

Typical use cases include:

  • signing payment requests
  • authorizing refund addresses
  • proving that a message originated from a specific wallet
  • signing identifiers or machine-generated metadata

Sign a Message

Sign a message directly:

mnp sign "hello"

Example output:

SigV2CPE7uMnbN7pKsjSob2AWLXVpsiUZ9GXZtUR6hNcEExUtTQxY87wedCpRcuvfZNMqQndch2h5a5tvuLEfgaWdrZff

mnp sign uses the wallet view key by default.

Sign from stdin

If no message argument is supplied, mnp sign reads the data from stdin:

echo "hello" | mnp sign

Exactly one trailing line feed is removed from stdin.

This means:

mnp sign "hello"

and:

echo "hello" | mnp sign

sign the same data.

Other whitespace is preserved.

Sign using a subaddress

A specific subaddress can be selected:

mnp sign --subaddr 3 "hello"

The configured wallet account is used.

Verify a Signature

Verify a signed message with:

mnp verify ADDRESS SIGNATURE "hello"

A valid signature returns:

true

with exit status 0.

An invalid signature returns:

false

with a non-zero exit status.

This makes mnp verify suitable for shell scripts.

Verify from stdin

The message can also be supplied through stdin:

echo "hello" | mnp verify "$ADDRESS" "$SIGNATURE"

Sign a Payment Request

mnp sign works well together with mnp payment.

For example:

URI="$(mnp payment new --amount 60060065)"
SIGNATURE="$(printf '%s\n' "$URI" | mnp sign)"

The generated payment URI can later be verified:

printf '%s\n' "$URI" |
    mnp verify "$ADDRESS" "$SIGNATURE"

Expected output:

true

This allows payment requests to be authenticated independently of the transport used to send them.

Refund Address Authorization

Message signatures can also be used when a buyer requests a refund to a different Monero address.

Instead of accepting an unsigned address, the buyer can sign the requested refund address:

printf '%s' "$REFUND_ADDRESS" | mnp sign

The merchant can then verify the authorization:

printf '%s' "$REFUND_ADDRESS" |
    mnp verify "$BUYER_ADDRESS" "$SIGNATURE"

For stronger binding, include the original transaction ID in the signed message:

mnp-refund:v1
original_txid=<TXID>
refund_address=<ADDRESS>

This prevents the same signed refund address from being reused for an unrelated transaction.

Input Validation

mnp verify performs lightweight offline validation before contacting monero-wallet-rpc.

It rejects obviously malformed:

  • Monero addresses
  • message signatures

The local checks validate basic syntax and expected encoding only.

Cryptographic signature verification is still performed by monero-wallet-rpc.

Examples

Sign:

SIG="$(mnp sign "invoice #4711")"

Verify:

mnp verify "$ADDRESS" "$SIG" "invoice #4711"

Pipe usage:

printf '%s\n' "invoice #4711" |
    mnp sign

Invalid message:

mnp verify "$ADDRESS" "$SIG" "invoice #4712"

Output:

false

Clone this wiki locally