Manav signed the canonical JSON below with its server secret. Hash the JSON with HMAC-SHA256 using the MANAV_SERVER_SIGNING_SECRET and compare - if it matches, this proof is authentic.
Canonical proof JSON
{"actionPayloadHash":"b0a149ec5bf34207660fb6156b76d94916e401bdf3a80d9c7ea4cb3e6c66800a","actionTitle":"FIFA 2026 ticket purchase · USA vs Brazil · Cat 1 · Verified Fan","actionType":"ticket_purchase","actorHandle":"demo","externalReference":null,"organizationSlug":null,"signatureSlug":"mnav_sig_LCI9pH7fScvH","signedAt":"2026-08-20 10:04:30"}
Action payload hash · SHA-256 of the canonical action payload
b0a149ec5bf34207660fb6156b76d94916e401bdf3a80d9c7ea4cb3e6c66800a
Server signature · HMAC-SHA256 over canonical JSON above
10959fdedf5738aaf4b280e12558164a70f1817c134c09bd3174bf4f198876a2
Recompute it yourself
$ printf '%s' '{"actionPayloadHash":"b0a149ec5bf34207660fb6156b76d94916e401bdf3a80d9c7ea4cb3e6c66800a","actionTitle":"FIFA 2026 ticket purchase · USA vs Brazil · Cat 1 · Verified Fan","actionType":"ticket_purchase","actorHandle":"demo","externalReference":null,"organizationSlug":null,"signatureSlug":"mnav_sig_LCI9pH7fScvH","signedAt":"2026-08-20 10:04:30"}' \
| openssl dgst -sha256 -hmac "$MANAV_SERVER_SIGNING_SECRET" -hex
$ # expected: 10959fdedf5738aaf4b280e12558164a70f1817c134c09bd3174bf4f198876a2