@Gargron @evan I see. So both need to be verified?Or, to put it another way, the location of the key should be taken from the actor, not the signature header?