The transaction record fetched from the Salt API.
The unsigned transaction shared by the ceremony host.
Optional ReadonlycauseOptional ReadonlydataOptional structured data attached to the failure (e.g. on-chain receipt).
ReadonlyexpectedThe digest the backend derives from the policy-checked params, or null
when the record's params cannot be serialized at all.
ReadonlymismatchedWhich transaction fields differ between the record and the payload.
ReadonlyreceivedThe hash of the payload that actually arrived on the wire, or null when
that payload is not a serializable transaction at all.
OptionalstackReadonlytransactionDatabase id of the transaction record the payload was checked against.
Thrown when the unsigned transaction shared in a signing ceremony does not match the transaction record the ceremony claims to be for.
The relay is a routing layer, not an authority: it forwards whatever payload a party puts on the wire. A co-signer therefore hashes the payload it is asked to sign and compares it against
unsignedTxHashon the record — the digest the backend derived from the params it ran the policy check against. A mismatch means the ceremony would produce a signature over a transaction that no policy check ever saw, so signing stops here.mismatchedFields names which fields drifted, for diagnosis; the hashes are the authority.
Example: Reacting to a tampered payload