Relying Party (RP) signatures prove a proof request comes from your app, preventing impersonation attacks.
Your backend signs every request with the signing_key from the Developer Portal,
and World ID verifies the signature before generating a proof. World ID enforces RP signatures for World ID 4.0 requests.
Never expose your signing key to client-side code. If the key leaks, rotate it immediately in the Developer Portal.
Algorithm
Other exports
@worldcoin/idkit-server exports two more functions alongside signRequest:
computeRpSignatureMessage(...) — builds the message bytes described in compute_rp_signature_message above, if you need the raw message instead of a full signature. Also exported from @worldcoin/idkit-core/signing.
getSessionCommitment(sessionId: string): bigint — converts a session ID into the on-chain commitment value, for session-proof flows (see Session proofs). Also exported from @worldcoin/idkit-core/session and @worldcoin/idkit/session.
Test vectors
Verify your implementation against these. All vectors use deterministic inputs.
hash_to_field
compute_rp_signature_message
sign_request
Related pages