Manav signed the canonical JSON below with its server secret. Hash the JSON with HMAC-SHA256 using the MANAV_SERVER_SIGNING_SECRET and compare - if it matches, this proof is authentic.
Canonical proof JSON
{"actionPayloadHash":"b450a9d22269876c5de5ac2cc135e73ba200d42d95c79fa37ac62b2a4f2e17e6","actionTitle":"FIFA 2026 ticket purchase · USA vs Brazil · Cat 1 · Verified Fan","actionType":"ticket_purchase","actorHandle":"demo","externalReference":null,"organizationSlug":null,"signatureSlug":"mnav_sig_Ve4-_mnHTGW5","signedAt":"2026-06-08 05:55:22"}
Action payload hash · SHA-256 of the canonical action payload
b450a9d22269876c5de5ac2cc135e73ba200d42d95c79fa37ac62b2a4f2e17e6
Server signature · HMAC-SHA256 over canonical JSON above
75ac1482fa474b88f5977cb74704347d2b8dde7aee8a0d17d280d66f61e12dbb
Recompute it yourself
$ printf '%s' '{"actionPayloadHash":"b450a9d22269876c5de5ac2cc135e73ba200d42d95c79fa37ac62b2a4f2e17e6","actionTitle":"FIFA 2026 ticket purchase · USA vs Brazil · Cat 1 · Verified Fan","actionType":"ticket_purchase","actorHandle":"demo","externalReference":null,"organizationSlug":null,"signatureSlug":"mnav_sig_Ve4-_mnHTGW5","signedAt":"2026-06-08 05:55:22"}' \
| openssl dgst -sha256 -hmac "$MANAV_SERVER_SIGNING_SECRET" -hex
$ # expected: 75ac1482fa474b88f5977cb74704347d2b8dde7aee8a0d17d280d66f61e12dbb