---
title: ApplicationSignatureStatus enum | Wartiva GraphQL API
description: Verification outcome for an application's code signature, normalized across the platform verifiers. Wartiva GraphQL API reference with examples.
url: https://wartiva.com/api-docs/types/application-signature-status.html
updated: 2026-10-07
---

Applications and updates · GraphQL enum

# `ApplicationSignatureStatus` enum

Verification outcome for an application's code signature, normalized across the platform verifiers: Code Signing Services (SecStaticCodeCheckValidityWithErrors) on macOS, Authenticode (WinVerifyTrust) on Windows, and snap store publisher attribution on Linux. INVALID indicates tampering or corruption of signed code; UNTRUSTED and REVOKED indicate the signature is cryptographically intact but the signing identity must not be trusted. Reference: [Code Signing Services](https://developer.apple.com/documentation/security/code-signing-services) Reference: [WinVerifyTrust function (wintrust.h)](https://learn.microsoft.com/en-us/windows/win32/api/wintrust/nf-wintrust-winverifytrust)

## Values

| Enum Value | Description |
|---|---|
| `UNKNOWN` | The verifier produced no usable result; the signing state could not be determined. |
| `UNSIGNED` | No code signature is present. On Linux this includes snap packages not delivered by the snap store. |
| `VALID` | The signature is cryptographically valid and its certificate chain is trusted by the operating system. |
| `AD_HOC` | macOS only: the code is ad-hoc signed (codesign identity "-"). The code directory is sealed but carries no signing certificate chain, so no signer identity can be attributed or trusted. |
| `INVALID` | The signature does not verify: the code or the signature itself was modified or is corrupt. |
| `UNTRUSTED` | The signature is intact but its certificate chain is not trusted by the operating system, for example an untrusted or expired root. |
| `REVOKED` | The signing certificate has been revoked. Treat the application as compromised. |

## Used by

- [`ApplicationSignature`](https://wartiva.com/api-docs/types/application-signature.html) type: Code-signing verification state of an ApplicationInstall, evaluated on the endpoint by the platform's native verifier.

## Example

### Example

```json
"UNKNOWN"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
