Manav signed the canonical JSON below with its server secret. Hash the JSON with HMAC-SHA256 using the MANAV_SERVER_SIGNING_SECRET and compare - if it matches, this proof is authentic.
Canonical proof JSON
{"actionPayloadHash":"1ad39c1b1b73bb8847091bdc38971505c7bfba165ab4de5faaa24fd3bb7cbda9","actionTitle":"MSA: Acme AI Labs ↔ GreenLeaf Designs LLC","actionType":"contract_sign","actorHandle":null,"externalReference":null,"organizationSlug":null,"signatureSlug":"mnav_sig_ksiijL2BmwVo","signedAt":"2026-06-02 10:49:09"}
Action payload hash · SHA-256 of the canonical action payload
1ad39c1b1b73bb8847091bdc38971505c7bfba165ab4de5faaa24fd3bb7cbda9
Server signature · HMAC-SHA256 over canonical JSON above
7bdda2593528d2843c66ea86b3154459ec92979707f869b69eb4ace628fca800
Recompute it yourself
$ printf '%s' '{"actionPayloadHash":"1ad39c1b1b73bb8847091bdc38971505c7bfba165ab4de5faaa24fd3bb7cbda9","actionTitle":"MSA: Acme AI Labs ↔ GreenLeaf Designs LLC","actionType":"contract_sign","actorHandle":null,"externalReference":null,"organizationSlug":null,"signatureSlug":"mnav_sig_ksiijL2BmwVo","signedAt":"2026-06-02 10:49:09"}' \
| openssl dgst -sha256 -hmac "$MANAV_SERVER_SIGNING_SECRET" -hex
$ # expected: 7bdda2593528d2843c66ea86b3154459ec92979707f869b69eb4ace628fca800