CCIP v2.0.0 CommitteeVerifier API Reference

CommitteeVerifier is a CCIP Cross-Chain Verifier that validates messages using a signature quorum model.

On the source chain, it produces verifier output containing signatures over the message hash.
On the destination chain, it verifies that a quorum of authorized signers has attested to the message before allowing execution.

This verifier combines source-side and destination-side responsibilities behind a single proxy address per chain.

  • A single verifier instance per chain handles both source and destination responsibilities.

Applications do not call this contract directly.

Usage Boundary

You do not call this contract directly.

  • OffRamp components invoke this verifier during message validation.
  • Verifier implementations use this contract to enforce quorum-based validation rules.
  • The owner configures quorum parameters and chain-specific behavior.
  • You are responsible for ensuring signer sets and configuration remain correct.

Contract

ccvs/CommitteeVerifier.sol

Import

import {CommitteeVerifier} from "chainlink-ccip/ccvs/CommitteeVerifier.sol";

Inheritance

  • Ownable2StepMsgSender
  • ICrossChainVerifierV1
  • SignatureQuorumValidator
  • BaseVerifier

Constructor

constructor(
  DynamicConfig memory dynamicConfig,
  string[] memory storageLocations,
  address rmn,
  bytes4 versionTag
) BaseVerifier(
  storageLocations,
  rmn,
  versionTag
)
ParameterTypeDescription
dynamicConfigDynamicConfig memoryConfiguration for quorum validation and runtime behavior.
storageLocationsstring[] memoryOff-chain storage locations used by verifier infrastructure.
rmnaddressRMN contract used to enforce network-wide safety conditions.
versionTagbytes4Identifier for the verifier implementation version.

External API

forwardToVerifier

function forwardToVerifier(
  MessageV1Codec.MessageV1 calldata message,
  bytes32 messageId,
  address feeToken,
  uint256 feeTokenAmount,
  bytes calldata verifierArgs
) external view returns (bytes memory verifierReturnData)

Produces verifier output containing signature data for the message.

  • Produces deterministic verifier output based on the message hash.
  • Output is consumed by verifyMessage on the destination chain.

verifyMessage

function verifyMessage(
  MessageV1Codec.MessageV1 calldata message,
  bytes32 messageHash,
  bytes calldata verifierResults
) external view

Verifies that a sufficient quorum of signatures attests to the message before allowing execution.

  • Requires that signatures match the message hash and configured signer set.
  • verifierResults must match the output produced during verification forwarding.

getDynamicConfig

function getDynamicConfig() external view returns (DynamicConfig memory dynamicConfig)

Returns runtime configuration.


setDynamicConfig

function setDynamicConfig(DynamicConfig memory dynamicConfig) external onlyOwner

Updates runtime configuration.


applyRemoteChainConfigUpdates

function applyRemoteChainConfigUpdates(
  RemoteChainConfigArgs[] calldata remoteChainConfigArgs
) external onlyOwner

Updates remote chain configuration.


applyAllowlistUpdates

function applyAllowlistUpdates(AllowlistConfigArgs[] calldata allowlistConfigArgsItems) external

Updates allowlist configuration.

Callable by the owner or the allowlistAdmin set in the dynamic config. Any other caller reverts with OnlyCallableByOwnerOrAllowlistAdmin.


setAllowedFinalityConfig

function setAllowedFinalityConfig(bytes4 allowedFinality) external onlyOwner

Sets allowed finality configuration.


getStorageLocationsAdmin

function getStorageLocationsAdmin() external view returns (address storageLocationsAdmin)

Returns storage locations administrator.


getPendingStorageLocationsAdmin

function getPendingStorageLocationsAdmin() external view returns (address pendingStorageLocationsAdmin)

Returns pending storage locations administrator.


transferStorageLocationsAdmin

function transferStorageLocationsAdmin(address to) external

Proposes a new storage locations administrator.


acceptStorageLocationsAdmin

function acceptStorageLocationsAdmin() external

Accepts storage locations administrator role.


updateStorageLocations

function updateStorageLocations(string[] memory newLocations) external

Updates storage locations.


withdrawFeeTokens

function withdrawFeeTokens(address[] calldata feeTokens) external

Withdraws accumulated fee token balances to the feeAggregator in the dynamic config.

Permissionless: it only transfers tokens to the configured fee aggregator. Reverts if feeAggregator is address(0).


getSignatureConfig

function getSignatureConfig(
  uint64 sourceChainSelector
) external view returns (address[] memory signers, uint8 threshold)

Returns the signer set and threshold for a source chain. Inherited from SignatureQuorumValidator.


getAllSignatureConfigs

function getAllSignatureConfigs() external view returns (SignatureConfig[] memory configs)

Returns every configured signature configuration, one per source chain selector. Inherited from SignatureQuorumValidator.


applySignatureConfigs

function applySignatureConfigs(
  uint64[] calldata sourceChainSelectorsToRemove,
  SignatureConfig[] calldata signatureConfigs
) external onlyOwner

Removes the signer configuration for the listed source chains, then applies the updates. Last update per selector wins. Inherited from SignatureQuorumValidator.

Reverts InvalidSignatureConfig() if a threshold is zero or exceeds its signer list length.


getFee

function getFee(
  uint64 destChainSelector,
  Client.EVM2AnyMessage memory message,
  bytes memory extraArgs,
  bytes4 requestedFinality
) external view returns (uint16 feeUSDCents, uint32 gasForVerification, uint32 payloadSizeBytes)

Returns the fee in USD cents, verification gas, and payload size for messages to a remote chain. Inherited from BaseVerifier.

Reverts RemoteChainNotSupported(destChainSelector) if the chain has no configuration, and reverts if requestedFinality is outside getAllowedFinalityConfig().


versionTag

function versionTag() public view returns (bytes4 tag)

Returns the immutable version tag set at construction. Used by operational tooling and as a domain separator for signatures. Inherited from BaseVerifier.


getAllowedFinalityConfig

function getAllowedFinalityConfig() public view returns (bytes4 allowedFinality)

Returns the allowed finality encoding for fast finality transfers. Inherited from BaseVerifier.


getStorageLocations

function getStorageLocations() public view returns (string[] memory)

Returns the off-chain storage locations for verifier infrastructure to read from. Inherited from BaseVerifier.


getRemoteChainConfig

function getRemoteChainConfig(
  uint64 remoteChainSelector
) external view returns (RemoteChainConfig memory)

Returns the router, fee, verification gas, payload size, and allowlist state for a remote chain. Inherited from BaseVerifier.


supportsInterface

function supportsInterface(bytes4 interfaceId) external pure returns (bool)

Returns true for ICrossChainVerifierV1 and IERC165. Inherited from BaseVerifier.


Structs

DynamicConfig

struct DynamicConfig {
  address feeAggregator;
  address allowlistAdmin;
}
  • feeAggregator: the entity receiving withdrawn fees. address(0) is valid and makes withdrawFeeTokens revert.
  • allowlistAdmin: the entity that may call applyAllowlistUpdates besides the owner.

SignatureConfig

struct SignatureConfig {
  uint64 sourceChainSelector;
  uint8 threshold;
  address[] signers;
}

The signer set for a source chain. threshold must be nonzero and no greater than signers.length.

Events

  • event ConfigSet(DynamicConfig dynamicConfig)
  • event StorageLocationsAdminTransferRequested(address indexed from, address indexed to)
  • event StorageLocationsAdminTransferred(address indexed from, address indexed to)

For a cross-contract event index, see Events.

Errors

  • error InvalidVerifierResults()
  • error InvalidCCVVersion(bytes4 verifierVersion)
  • error OnlyCallableByOwnerOrAllowlistAdmin()
  • error MustBeProposedStorageLocationsAdmin()
  • error OnlyCallableByStorageLocationsAdmin()

For a cross-contract error index, see Errors.

Notes

  • Verification is based on a quorum of signatures over the message hash.
  • Signatures are produced by a configured set of off-chain committee members.
  • A message is valid only if the number of valid signatures meets or exceeds the configured quorum threshold.
  • The message hash and signature set must match exactly between source and destination phases.
  • Each message is identified by its hash, preventing reuse of signatures for different messages.
  • Verifier output is generated on the source chain and consumed during destination validation.
  • Messages are executed only if both signature quorum validation and BaseVerifier checks succeed.
  • Messages will revert if signatures are invalid, insufficient, or from unauthorized signers.
  • Relies on BaseVerifier for router validation, RMN checks, and optional sender allowlisting.
  • Storage location configuration is controlled by a dedicated two-step admin role separate from the owner.

Security model

  • Relies on SignatureQuorumValidator to enforce quorum-based validation.
  • Relies on BaseVerifier for RMN checks, router validation, and sender allowlisting.
  • Owner controls dynamic configuration and remote chain settings.
  • Correct operation depends on integrity of signer set and quorum configuration.
  • Misconfiguration or compromised signer sets may allow invalid message execution or block valid messages.

Get the latest Chainlink content straight to your inbox.