Manav signed the canonical JSON below with its server secret. Hash the JSON with HMAC-SHA256 using the MANAV_SERVER_SIGNING_SECRET and compare - if it matches, this proof is authentic.
Canonical proof JSON
{"actionPayloadHash":"235bb0cb547426121418a2d9e9815fe583527f993f0d61132b787d9b9dba3d9d","actionTitle":"Face verification · arivu","actionType":"verify_identity","actorHandle":"arivu","externalReference":null,"organizationSlug":null,"signatureSlug":"mnav_sig_KCHKz41hX6aO","signedAt":"2026-06-06 02:03:58"}
Action payload hash · SHA-256 of the canonical action payload
235bb0cb547426121418a2d9e9815fe583527f993f0d61132b787d9b9dba3d9d
Server signature · HMAC-SHA256 over canonical JSON above
772f1af41843306071819fbfb36e90e8b13596d277a20d4aacb53d2121d01f59
Recompute it yourself
$ printf '%s' '{"actionPayloadHash":"235bb0cb547426121418a2d9e9815fe583527f993f0d61132b787d9b9dba3d9d","actionTitle":"Face verification · arivu","actionType":"verify_identity","actorHandle":"arivu","externalReference":null,"organizationSlug":null,"signatureSlug":"mnav_sig_KCHKz41hX6aO","signedAt":"2026-06-06 02:03:58"}' \
| openssl dgst -sha256 -hmac "$MANAV_SERVER_SIGNING_SECRET" -hex
$ # expected: 772f1af41843306071819fbfb36e90e8b13596d277a20d4aacb53d2121d01f59