Replay-protection hook for verification.
The package does not store nonces. Implement this behaviour over caller-owned
storage and pass it as :nonce_checker to MessageSignatures.verify/2. The
callback runs after cryptographic authentication and receives the signature's
nonce, or nil when none is present.