CCIP v2.0.0 CommitteeVerifier API Reference
CommitteeVerifier is a CCIP Cross-Chain Verifier that validates messages using a signature quorum model.
On the source chain, it produces verifier output containing signatures over the message hash.
On the destination chain, it verifies that a quorum of authorized signers has attested to the message before allowing execution.
This verifier combines source-side and destination-side responsibilities behind a single proxy address per chain.
- A single verifier instance per chain handles both source and destination responsibilities.
Applications do not call this contract directly.
Usage Boundary
You do not call this contract directly.
- OffRamp components invoke this verifier during message validation.
- Verifier implementations use this contract to enforce quorum-based validation rules.
- The owner configures quorum parameters and chain-specific behavior.
- You are responsible for ensuring signer sets and configuration remain correct.
Contract
ccvs/CommitteeVerifier.sol
Import
import {CommitteeVerifier} from "chainlink-ccip/ccvs/CommitteeVerifier.sol";
Inheritance
Ownable2StepMsgSenderICrossChainVerifierV1SignatureQuorumValidatorBaseVerifier
Constructor
constructor(
DynamicConfig memory dynamicConfig,
string[] memory storageLocations,
address rmn,
bytes4 versionTag
) BaseVerifier(
storageLocations,
rmn,
versionTag
)
| Parameter | Type | Description |
|---|---|---|
dynamicConfig | DynamicConfig memory | Configuration for quorum validation and runtime behavior. |
storageLocations | string[] memory | Off-chain storage locations used by verifier infrastructure. |
rmn | address | RMN contract used to enforce network-wide safety conditions. |
versionTag | bytes4 | Identifier for the verifier implementation version. |
External API
forwardToVerifier
function forwardToVerifier(
MessageV1Codec.MessageV1 calldata message,
bytes32 messageId,
address feeToken,
uint256 feeTokenAmount,
bytes calldata verifierArgs
) external view returns (bytes memory verifierReturnData)
Produces verifier output containing signature data for the message.
- Produces deterministic verifier output based on the message hash.
- Output is consumed by
verifyMessageon the destination chain.
verifyMessage
function verifyMessage(
MessageV1Codec.MessageV1 calldata message,
bytes32 messageHash,
bytes calldata verifierResults
) external view
Verifies that a sufficient quorum of signatures attests to the message before allowing execution.
- Requires that signatures match the message hash and configured signer set.
verifierResultsmust match the output produced during verification forwarding.
getDynamicConfig
function getDynamicConfig() external view returns (DynamicConfig memory dynamicConfig)
Returns runtime configuration.
setDynamicConfig
function setDynamicConfig(DynamicConfig memory dynamicConfig) external onlyOwner
Updates runtime configuration.
applyRemoteChainConfigUpdates
function applyRemoteChainConfigUpdates(
RemoteChainConfigArgs[] calldata remoteChainConfigArgs
) external onlyOwner
Updates remote chain configuration.
applyAllowlistUpdates
function applyAllowlistUpdates(AllowlistConfigArgs[] calldata allowlistConfigArgsItems) external
Updates allowlist configuration.
Callable by the owner or the allowlistAdmin set in the dynamic config. Any other caller reverts with OnlyCallableByOwnerOrAllowlistAdmin.
setAllowedFinalityConfig
function setAllowedFinalityConfig(bytes4 allowedFinality) external onlyOwner
Sets allowed finality configuration.
getStorageLocationsAdmin
function getStorageLocationsAdmin() external view returns (address storageLocationsAdmin)
Returns storage locations administrator.
getPendingStorageLocationsAdmin
function getPendingStorageLocationsAdmin() external view returns (address pendingStorageLocationsAdmin)
Returns pending storage locations administrator.
transferStorageLocationsAdmin
function transferStorageLocationsAdmin(address to) external
Proposes a new storage locations administrator.
acceptStorageLocationsAdmin
function acceptStorageLocationsAdmin() external
Accepts storage locations administrator role.
updateStorageLocations
function updateStorageLocations(string[] memory newLocations) external
Updates storage locations.
withdrawFeeTokens
function withdrawFeeTokens(address[] calldata feeTokens) external
Withdraws accumulated fee token balances to the
feeAggregatorin the dynamic config.
Permissionless: it only transfers tokens to the configured fee aggregator. Reverts if feeAggregator is address(0).
getSignatureConfig
function getSignatureConfig(
uint64 sourceChainSelector
) external view returns (address[] memory signers, uint8 threshold)
Returns the signer set and threshold for a source chain. Inherited from
SignatureQuorumValidator.
getAllSignatureConfigs
function getAllSignatureConfigs() external view returns (SignatureConfig[] memory configs)
Returns every configured signature configuration, one per source chain selector. Inherited from
SignatureQuorumValidator.
applySignatureConfigs
function applySignatureConfigs(
uint64[] calldata sourceChainSelectorsToRemove,
SignatureConfig[] calldata signatureConfigs
) external onlyOwner
Removes the signer configuration for the listed source chains, then applies the updates. Last update per selector wins. Inherited from
SignatureQuorumValidator.
Reverts InvalidSignatureConfig() if a threshold is zero or exceeds its signer list length.
getFee
function getFee(
uint64 destChainSelector,
Client.EVM2AnyMessage memory message,
bytes memory extraArgs,
bytes4 requestedFinality
) external view returns (uint16 feeUSDCents, uint32 gasForVerification, uint32 payloadSizeBytes)
Returns the fee in USD cents, verification gas, and payload size for messages to a remote chain. Inherited from
BaseVerifier.
Reverts RemoteChainNotSupported(destChainSelector) if the chain has no configuration, and reverts if requestedFinality is outside getAllowedFinalityConfig().
versionTag
function versionTag() public view returns (bytes4 tag)
Returns the immutable version tag set at construction. Used by operational tooling and as a domain separator for signatures. Inherited from
BaseVerifier.
getAllowedFinalityConfig
function getAllowedFinalityConfig() public view returns (bytes4 allowedFinality)
Returns the allowed finality encoding for fast finality transfers. Inherited from
BaseVerifier.
getStorageLocations
function getStorageLocations() public view returns (string[] memory)
Returns the off-chain storage locations for verifier infrastructure to read from. Inherited from
BaseVerifier.
getRemoteChainConfig
function getRemoteChainConfig(
uint64 remoteChainSelector
) external view returns (RemoteChainConfig memory)
Returns the router, fee, verification gas, payload size, and allowlist state for a remote chain. Inherited from
BaseVerifier.
supportsInterface
function supportsInterface(bytes4 interfaceId) external pure returns (bool)
Returns true for
ICrossChainVerifierV1andIERC165. Inherited fromBaseVerifier.
Structs
DynamicConfig
struct DynamicConfig {
address feeAggregator;
address allowlistAdmin;
}
feeAggregator: the entity receiving withdrawn fees.address(0)is valid and makeswithdrawFeeTokensrevert.allowlistAdmin: the entity that may callapplyAllowlistUpdatesbesides the owner.
SignatureConfig
struct SignatureConfig {
uint64 sourceChainSelector;
uint8 threshold;
address[] signers;
}
The signer set for a source chain. threshold must be nonzero and no greater than signers.length.
Events
event ConfigSet(DynamicConfig dynamicConfig)event StorageLocationsAdminTransferRequested(address indexed from, address indexed to)event StorageLocationsAdminTransferred(address indexed from, address indexed to)
For a cross-contract event index, see Events.
Errors
error InvalidVerifierResults()error InvalidCCVVersion(bytes4 verifierVersion)error OnlyCallableByOwnerOrAllowlistAdmin()error MustBeProposedStorageLocationsAdmin()error OnlyCallableByStorageLocationsAdmin()
For a cross-contract error index, see Errors.
Notes
- Verification is based on a quorum of signatures over the message hash.
- Signatures are produced by a configured set of off-chain committee members.
- A message is valid only if the number of valid signatures meets or exceeds the configured quorum threshold.
- The message hash and signature set must match exactly between source and destination phases.
- Each message is identified by its hash, preventing reuse of signatures for different messages.
- Verifier output is generated on the source chain and consumed during destination validation.
- Messages are executed only if both signature quorum validation and BaseVerifier checks succeed.
- Messages will revert if signatures are invalid, insufficient, or from unauthorized signers.
- Relies on
BaseVerifierfor router validation, RMN checks, and optional sender allowlisting. - Storage location configuration is controlled by a dedicated two-step admin role separate from the owner.
Security model
- Relies on
SignatureQuorumValidatorto enforce quorum-based validation. - Relies on
BaseVerifierfor RMN checks, router validation, and sender allowlisting. - Owner controls dynamic configuration and remote chain settings.
- Correct operation depends on integrity of signer set and quorum configuration.
- Misconfiguration or compromised signer sets may allow invalid message execution or block valid messages.