Manav signed the canonical JSON below with its server secret. Hash the JSON with HMAC-SHA256 using the MANAV_SERVER_SIGNING_SECRET and compare - if it matches, this proof is authentic.
Canonical proof JSON
{"actionPayloadHash":"908ebaa02eaf5841d194e764ccbb259cb4d84c2375cae52dd54aa28ff9aba699","actionTitle":"FIFA 2026 ticket purchase · USA vs Brazil · Cat 1 · Verified Fan","actionType":"ticket_purchase","actorHandle":"demo","externalReference":null,"organizationSlug":null,"signatureSlug":"mnav_sig_M5DRBgssWlC8","signedAt":"2026-07-31 08:37:45"}
Action payload hash · SHA-256 of the canonical action payload
908ebaa02eaf5841d194e764ccbb259cb4d84c2375cae52dd54aa28ff9aba699
Server signature · HMAC-SHA256 over canonical JSON above
0679eb40dcb4662cb8be69e83b2b8808d96bd4dcb9d77f2ba75c9732eae4c09b
Recompute it yourself
$ printf '%s' '{"actionPayloadHash":"908ebaa02eaf5841d194e764ccbb259cb4d84c2375cae52dd54aa28ff9aba699","actionTitle":"FIFA 2026 ticket purchase · USA vs Brazil · Cat 1 · Verified Fan","actionType":"ticket_purchase","actorHandle":"demo","externalReference":null,"organizationSlug":null,"signatureSlug":"mnav_sig_M5DRBgssWlC8","signedAt":"2026-07-31 08:37:45"}' \
| openssl dgst -sha256 -hmac "$MANAV_SERVER_SIGNING_SECRET" -hex
$ # expected: 0679eb40dcb4662cb8be69e83b2b8808d96bd4dcb9d77f2ba75c9732eae4c09b