pub fn verify(token: &[u8], public_key: &[u8; 32]) -> Result<Payload, UcanError>Expand description
Checks a UCAN token’s signature against public_key (the claimed
issuer’s 32-byte Ed25519 public key) and its exp/nbf claims against
the current time, returning the decoded payload only on full success.
Mirrors macula_ucan_nif:verify/2 exactly, including its check ORDER —
public key shape, then token shape, then exp, then nbf, then
signature — matching both the Erlang fallback and the Rust NIF, which
check claims before the signature; this module preserves that order for
parity even though it means an invalid-but-well-formed token’s expiry
is observable before its signature is checked.