KMS verification uses the same /v1/verify endpoint as BYOK. Pass the KMS key ARN as the public_key parameter — the server detects the ARN format and routes to KMS verification.
Verification does not require Pro plan. Any authenticated user can verify signatures.