What's interesting is that ActivityPub requires signing the data twice, first on a HTTP request level, then the JSON-LD itself. It seems like the designers tried to make it simple (let's use JSON-LD and HTTP) but after several edge cases the standard got out of control.
[0]: "Linked Data Notifications also supports a number of RDF serializations which are not required for ActivityPub implementations. However, ActivityPub implementations which wish to be more broadly compatible with Linked Data Notifications implementations may wish to support other RDF representations." source: https://www.w3.org/TR/activitypub/