---
title: ApplicationSignature type | Wartiva GraphQL API
description: Code-signing verification state of an ApplicationInstall, evaluated on the endpoint by the platform's native verifier.
url: https://wartiva.com/api-docs/types/application-signature.html
updated: 2026-10-07
---

Applications and updates · GraphQL type

# `ApplicationSignature` type

Code-signing verification state of an [ApplicationInstall](https://wartiva.com/api-docs/types/application-install.html), evaluated on the endpoint by the platform's native verifier. Reference: [Code Signing Services](https://developer.apple.com/documentation/security/code-signing-services) Reference: [WinVerifyTrust function (wintrust.h)](https://learn.microsoft.com/en-us/windows/win32/api/wintrust/nf-wintrust-winverifytrust)

## Fields

| Field Name | Description |
|---|---|
| `status` - [`ApplicationSignatureStatus!`](https://wartiva.com/api-docs/types/application-signature-status.html) | Outcome of the signature verification. See [ApplicationSignatureStatus](https://wartiva.com/api-docs/types/application-signature-status.html) for the meaning of each value. |
| `signer` - [`String!`](https://wartiva.com/api-docs/types/string.html) | Human-readable signer identity: the organization of the leaf signing certificate (macOS Developer ID / Windows Authenticode subject), or the snap store publisher on Linux. Empty when the application is unsigned, ad-hoc signed, or the signer could not be determined. |
| `thumbprint` - [`String!`](https://wartiva.com/api-docs/types/string.html) | Lowercase hex SHA-256 fingerprint of the DER-encoded leaf signing certificate. Currently reported on macOS only; empty when no certificate chain is available (unsigned or ad-hoc signed) and on other platforms. |
| `teamIdentifier` - [`String!`](https://wartiva.com/api-docs/types/string.html) | Apple Developer Program Team ID of the signing identity (macOS only). Empty on other platforms and for unsigned or ad-hoc signed applications. |
| `signedAt` - [`Time`](https://wartiva.com/api-docs/types/time.html) | Secure timestamp embedded in the signature (macOS secure timestamp / Authenticode countersignature). Null when the signature carries no timestamp or the application is unsigned. |

## Used by

- [`ApplicationInstall`](https://wartiva.com/api-docs/types/application-install.html) type: One installed copy of an application on one Endpoint.

## Example

### Example

```json
{
  "status": "UNKNOWN",
  "signer": "abc123",
  "thumbprint": "abc123",
  "teamIdentifier": "xyz789",
  "signedAt": "2021-10-07T18:23:25.829Z"
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
