[{"data":1,"prerenderedAt":808},["ShallowReactive",2],{"header:help":3,"footer:default":67,"story:navigation\u002Fsearch:help":250,"story:help\u002Fcategories":288,"story:help\u002Farticles\u002Fproduct-security-overview":314,"no-guide:product-security-overview":59,"article:\u002Fhelp\u002Farticles\u002Fproduct-security-overview":549,"story:contact":565,"help:tree:10982047-b16a-4880-b28b-9d116e2720aa":753,"_apollo:default":807},{"name":4,"created_at":5,"published_at":6,"updated_at":7,"id":8,"uuid":9,"content":10,"slug":57,"full_slug":58,"sort_by_date":59,"position":60,"tag_list":61,"is_startpage":24,"parent_id":62,"meta_data":59,"group_id":63,"first_published_at":64,"release_id":59,"lang":65,"path":59,"alternates":66,"default_full_slug":59,"translated_slugs":59},"Help Center Header","2024-08-09T18:06:34.939Z","2024-10-21T21:58:39.217Z","2024-10-21T21:58:39.232Z",10082752,"3e9b88f7-c163-4657-a2f2-62532d600fad",{"_uid":11,"link":12,"badge":16,"items":17,"title":13,"buttons":50,"new_tab":24,"submenu":51,"alignment":13,"component":52,"badge_link":53,"top_menu_items":56},"e5645a1a-f991-40e8-8d67-e40ebc082b5a",{"id":13,"url":13,"linktype":14,"fieldtype":15,"cached_url":13},"","story","multilink","Help Center",[18,27,34,39,44],{"_uid":19,"link":20,"title":23,"new_tab":24,"submenu":25,"component":26},"5cbe2861-1f49-4166-97da-a4dddd8105e3",{"id":21,"url":13,"linktype":14,"fieldtype":15,"cached_url":22},"4c0a2d99-ec30-4579-8ef1-6bf5564d4839","help\u002Fcategories\u002F","Articles",false,[],"header___item",{"_uid":28,"link":29,"title":32,"new_tab":33,"component":26},"1c8edeb5-b9e9-4cb8-b1c6-c1f292f7d7cd",{"id":13,"url":30,"linktype":31,"fieldtype":15,"cached_url":30},"https:\u002F\u002Fwiki.foxycart.com\u002F","url","Documentation",true,{"_uid":35,"link":36,"title":38,"new_tab":33,"component":26},"8d7df70e-f087-4da0-b616-6f0e9a5af35c",{"id":13,"url":37,"linktype":31,"fieldtype":15,"cached_url":37},"https:\u002F\u002Fapi.foxycart.com\u002F","API Documentation",{"_uid":40,"link":41,"title":43,"new_tab":33,"component":26},"f76e7944-23d5-4652-87e4-cdae79272762",{"id":13,"url":42,"linktype":31,"fieldtype":15,"cached_url":42},"https:\u002F\u002Fstatus.foxy.io\u002F","System Status",{"_uid":45,"link":46,"title":49,"new_tab":24,"component":26},"0de16771-4c84-466c-a1da-d8568113c71f",{"id":47,"url":13,"linktype":14,"fieldtype":15,"cached_url":48},"01e4e370-f9b9-45af-8fa9-f15540699b0d","contact","Contact Us",[],[],"header",{"id":54,"url":13,"linktype":14,"fieldtype":15,"cached_url":55},"4a679eb7-662d-4ea4-a976-5a2acbf0b663","help\u002F",[],"help-header","navigation\u002Fhelp-header",null,20,[],10082747,"71b81c2e-5e09-48a1-a397-a3c72fcd344a","2022-09-21T14:50:25.655Z","default",[],{"name":68,"created_at":69,"published_at":70,"updated_at":71,"id":72,"uuid":73,"content":74,"slug":243,"full_slug":244,"sort_by_date":59,"position":245,"tag_list":246,"is_startpage":24,"parent_id":62,"meta_data":59,"group_id":247,"first_published_at":248,"release_id":59,"lang":65,"path":59,"alternates":249,"default_full_slug":59,"translated_slugs":59},"Default Footer","2024-08-09T18:06:59.024Z","2025-09-04T06:24:46.223Z","2025-09-04T06:24:46.241Z",10082753,"e59e67ac-248a-482f-84a1-53d4f318186a",{"_uid":75,"about":76,"logos":77,"socials":82,"sections":108,"component":225,"cta_title":226,"bottom_links":227,"cta_subtitle":241,"cta_button_link":242,"cta_button_text":183},"830983f5-c4c4-43c8-b150-86a5e3fa6dc8","Foxy’s hosted cart & payment page allow you to sell anything, using your existing website or platform.",[78],{"id":79,"alt":13,"name":13,"focus":13,"title":13,"filename":80,"copyright":13,"fieldtype":81},14760,"https:\u002F\u002Fa-us.storyblok.com\u002Ff\u002F1001040\u002Fx\u002F3b030847ec\u002Fb-corp.svg","asset",[83,90,96,102],{"_uid":84,"icon":85,"link":86,"name":88,"component":89},"faf0a618-ea94-42ea-9182-03be18c43216","fa-facebook",{"id":13,"url":87,"linktype":31,"fieldtype":15,"cached_url":87},"https:\u002F\u002Fwww.facebook.com\u002Ffoxycart","Facebook","footer___social",{"_uid":91,"icon":92,"link":93,"name":95,"component":89},"14309c18-7e79-423e-b375-34555bac0811","fa-instagram",{"id":13,"url":94,"linktype":31,"fieldtype":15,"cached_url":94},"https:\u002F\u002Fwww.instagram.com\u002Ffoxy_io","Instagram",{"_uid":97,"icon":98,"link":99,"name":101,"component":89},"8f7fe7cf-0dd3-4596-8334-226ea466716a","fa-linkedin",{"id":13,"url":100,"linktype":31,"fieldtype":15,"cached_url":100},"https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Ffoxycart.com","LinkedIn",{"_uid":103,"icon":104,"link":105,"name":107,"component":89},"90a675b4-dd97-40b5-be09-00a87223d4c5","fa-youtube",{"id":13,"url":106,"linktype":31,"fieldtype":15,"cached_url":106},"https:\u002F\u002Fwww.youtube.com\u002Fuser\u002Ffoxycart","Youtube",[109,139,184,206],{"_uid":110,"name":111,"items":112,"component":138},"82849945-282f-488c-b18d-a8d2252f514a","Company",[113,120,126,132],{"_uid":114,"link":115,"title":118,"new_tab":24,"component":119},"1f699ab1-938b-4d9d-9825-aabcbe6f57fe",{"id":116,"url":13,"linktype":14,"fieldtype":15,"cached_url":117},"63634293-a749-4226-9439-9f38ee6dcda0","about-us","About Us","footer___menu_items",{"_uid":121,"link":122,"title":125,"new_tab":24,"component":119},"b26b00f1-a0e7-4be2-8ab3-428b8cc841f8",{"id":123,"url":13,"linktype":14,"fieldtype":15,"cached_url":124},"26cb7c55-faed-4a77-a291-1552d4111b3e","how-foxy-works","How Foxy Works",{"_uid":127,"link":128,"title":131,"new_tab":24,"component":119},"b40c68a0-1ceb-4226-9515-6176534f61fe",{"id":129,"url":13,"linktype":14,"fieldtype":15,"cached_url":130},"dc6657d7-7f4f-4c0d-b781-e971b038ee26","for-good","Foxy For Good",{"_uid":133,"link":134,"title":137,"new_tab":24,"component":119},"3ad0c134-bef9-4fff-b891-e09f16109036",{"id":135,"url":13,"linktype":14,"fieldtype":15,"cached_url":136},"23cae210-baf4-4588-9862-d09f4f52ccd2","brand-assets","Brand Assets","footer___section",{"_uid":140,"name":141,"items":142,"component":138},"a6805fa8-ac60-47f1-b8f0-f27aded0afbe","Product",[143,149,155,161,167,173,179],{"_uid":144,"link":145,"title":148,"new_tab":24,"component":119},"b39c8a4e-2383-486f-b76a-11fbb15d8134",{"id":146,"url":13,"linktype":14,"fieldtype":15,"cached_url":147},"bb04690f-fe98-4ce6-80be-05b950f2364f","features\u002F","Features",{"_uid":150,"link":151,"title":154,"new_tab":24,"component":119},"64f8a41f-c181-433d-bc0a-fc94e71ecbf6",{"id":152,"url":13,"linktype":14,"fieldtype":15,"cached_url":153},"c450c58d-761d-48c0-a9af-0b064611689b","pricing","Pricing",{"_uid":156,"link":157,"title":160,"new_tab":24,"component":119},"6e0b287f-fd8c-4146-9e0e-0ab0b5c9ce3c",{"id":158,"url":13,"linktype":14,"fieldtype":15,"cached_url":159},"fab20ad9-e76a-4947-b709-3a6fdfa88028","blog\u002Fcategories\u002Fproduct-updates","Product Updates",{"_uid":162,"link":163,"title":166,"new_tab":24,"component":119},"47e5a074-a6b5-4f1c-8c2f-89a2ae9f83eb",{"id":164,"url":13,"linktype":14,"fieldtype":15,"cached_url":165},"d2c83612-d611-47f3-a3b4-ca7fe08540b8","changelogs\u002F","Changelogs",{"_uid":168,"link":169,"title":172,"new_tab":24,"component":119},"b5c08774-542f-4ffd-b357-c94d674488b9",{"id":170,"url":13,"linktype":14,"fieldtype":15,"cached_url":171},"08876121-0df3-4ed9-aa11-902b3e41cd02","whats-next","What's Next",{"_uid":174,"link":175,"title":178,"new_tab":24,"component":119},"9c2704ed-6d9f-43e1-9e67-c8d91c083288",{"id":176,"url":13,"linktype":14,"fieldtype":15,"cached_url":177},"056a7857-b18f-4025-8f97-91a38fc19bc8","compare\u002F","Compare",{"_uid":180,"link":181,"title":183,"new_tab":24,"component":119},"5f2db35b-674b-406a-8fa7-d246633af9fe",{"id":13,"url":182,"linktype":31,"fieldtype":15,"cached_url":182},"https:\u002F\u002Fadmin.foxy.io\u002Fsign-up","Try Foxy Free",{"_uid":185,"name":186,"items":187,"component":138},"63fa1f29-4252-4640-9922-fe310e69e54a","Security",[188,194,200],{"_uid":189,"link":190,"title":193,"new_tab":24,"component":119},"1158ddb6-9eb0-466f-8eb6-7ca2ae66c8b8",{"id":191,"url":13,"linktype":14,"fieldtype":15,"cached_url":192},"1f58fb2c-8681-4742-b6e8-09999beae9f6","security-contact","Security Contact",{"_uid":195,"link":196,"title":199,"new_tab":24,"component":119},"9a79c54a-6022-4dfd-854b-766f5e4703ba",{"id":197,"url":13,"linktype":14,"fieldtype":15,"cached_url":198},"55cbfcc3-425a-4261-8037-54e919851d2d","pci","PCI Compliance",{"_uid":201,"link":202,"title":205,"new_tab":24,"component":119},"0b85f5b6-9534-4071-b323-b39d053dd4d7",{"id":203,"url":13,"linktype":14,"fieldtype":15,"cached_url":204},"c3ac0fe3-83e2-4879-afbd-d4c83e1590df","help\u002Farticles\u002Four-official-domains-public-code","Domains & Codebases",{"_uid":207,"name":208,"items":209,"component":138},"998ded67-d107-49f4-8154-ca6be51671ec","Support",[210,213,216,219,222],{"_uid":211,"link":212,"title":16,"new_tab":24,"component":119},"594ffd35-3049-4004-bb08-0db568ebd819",{"id":54,"url":13,"linktype":14,"fieldtype":15,"cached_url":55},{"_uid":214,"link":215,"title":32,"new_tab":33,"component":119},"0a1a55ab-a985-4f9d-8b42-26da714d0c1c",{"id":13,"url":30,"linktype":31,"fieldtype":15,"cached_url":30},{"_uid":217,"link":218,"title":38,"new_tab":33,"component":119},"61e0b7c8-aadf-419b-a339-b3ccabc65bf4",{"id":13,"url":37,"linktype":31,"fieldtype":15,"cached_url":37},{"_uid":220,"link":221,"title":43,"new_tab":33,"component":119},"fd67a89e-1c54-4d31-94b5-64be999062d6",{"id":13,"url":42,"linktype":31,"fieldtype":15,"cached_url":42},{"_uid":223,"link":224,"title":49,"new_tab":24,"component":119},"231a6f71-e996-4ad4-b033-d4d5542f34f0",{"id":47,"url":13,"linktype":14,"fieldtype":15,"cached_url":48},"footer","Get started with our *unlimited free trial*.",[228,235],{"_uid":229,"link":230,"text":233,"component":234},"f0b77210-2632-45a2-8436-e57cad84d01a",{"id":231,"url":13,"linktype":14,"fieldtype":15,"cached_url":232},"60ba16a2-c1f4-485f-b978-8d2eeeafbf5a","terms-of-service","Terms of Service","footer___bottom_links",{"_uid":236,"link":237,"text":240,"component":234},"4bd497b0-993f-4b4d-a5b7-8a49c7c8fec9",{"id":238,"url":13,"linktype":14,"fieldtype":15,"cached_url":239},"332302b9-1d18-4016-b9c8-9b33c72d782b","privacy-policy","Privacy Policy","No credit card required.",{"id":13,"url":182,"linktype":31,"fieldtype":15,"cached_url":182},"default-footer","navigation\u002Fdefault-footer",50,[],"11006268-07f9-41e9-96f3-c51fb723399d","2022-09-21T20:39:02.357Z",[],{"name":251,"created_at":252,"published_at":253,"updated_at":254,"id":255,"uuid":256,"content":257,"slug":279,"full_slug":282,"sort_by_date":59,"position":283,"tag_list":284,"is_startpage":24,"parent_id":62,"meta_data":59,"group_id":285,"first_published_at":286,"release_id":59,"lang":65,"path":59,"alternates":287,"default_full_slug":59,"translated_slugs":59},"Search","2024-10-21T22:08:54.973Z","2025-05-26T09:17:25.790Z","2025-05-26T09:17:25.804Z",13592003,"14cbc359-9ac1-4a7a-a8de-ad4ac8ef26d4",{"_uid":258,"name":251,"indices":259,"summary":13,"component":279,"primary_image":280},"5e4a56e8-76f1-4790-b3a7-70f1be97d042",[260,265,269,274],{"key":261,"_uid":262,"icon":13,"name":263,"component":264},"all","c12a3210-7323-4273-8217-5215e52efe84","All","index",{"key":266,"_uid":267,"icon":268,"name":23,"component":264},"help_center_article","5acff080-95e4-44d3-8dcf-1b19720af382","fa-file-alt",{"key":270,"_uid":271,"icon":272,"name":273,"component":264},"help_center_guide","b8fbc206-c083-471e-a1f0-0ebeb90a669d","fa-book","Guides",{"key":275,"_uid":276,"icon":277,"name":278,"component":264},"blog_post","23419e83-2e56-4c4c-8a05-9fd1b3c9a9bd","fa-file-image","Blog Posts","search",{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":281},{},"navigation\u002Fsearch",60,[],"11e1fd31-95cd-4fc9-b736-8b8910663e6c","2024-10-21T23:17:05.904Z",[],{"name":23,"created_at":289,"published_at":290,"updated_at":291,"id":292,"uuid":21,"content":293,"slug":307,"full_slug":22,"sort_by_date":59,"position":308,"tag_list":309,"is_startpage":33,"parent_id":310,"meta_data":59,"group_id":311,"first_published_at":312,"release_id":59,"lang":65,"path":59,"alternates":313,"default_full_slug":59,"translated_slugs":59},"2022-09-19T14:42:29.685Z","2024-07-30T18:17:22.506Z","2024-07-30T18:17:22.525Z",2660,{"_uid":294,"icon":13,"name":23,"guides":295,"pinned":24,"summary":296,"category":13,"component":297,"blog_posts":298,"content_hub":24,"icon_custom":299,"case_studies":300,"faq_sections":301,"help_articles":302,"featured_guides":303,"mailbox_category":13,"featured_articles":304,"featured_blog_posts":305,"featured_case_studies":306},"d6dae89a-907a-4bf7-82de-fe2ba875ee6e",[],"Get your questions answered with our browsable knowledge base.","help_center_category",[],{"id":59,"alt":59,"name":13,"focus":59,"title":59,"filename":13,"copyright":59,"fieldtype":81},[],[],[],[],[],[],[],"categories",530,[],2658,"19ebcdd2-027f-47f5-9a5b-a8992c959578","2022-09-19T16:24:39.219Z",[],{"name":315,"created_at":316,"published_at":317,"updated_at":318,"id":319,"uuid":320,"content":321,"slug":542,"full_slug":543,"sort_by_date":59,"position":544,"tag_list":545,"is_startpage":24,"parent_id":546,"meta_data":59,"group_id":547,"first_published_at":317,"release_id":59,"lang":65,"path":59,"alternates":548,"default_full_slug":59,"translated_slugs":59},"Product security overview","2026-06-29T20:03:50.117Z","2026-06-29T20:50:24.931Z","2026-06-29T20:50:24.953Z",192814408224605,"10982047-b16a-4880-b28b-9d116e2720aa",{"_uid":322,"body":323,"name":315,"image":537,"pinned":33,"summary":539,"category":540,"component":266,"related_articles":541},"dc706817-7362-4368-8282-f891426ab855",{"type":324,"content":325},"doc",[326,333,340,345,391,396,401,406,419,424,429,453,469,489,494],{"type":327,"attrs":328,"content":329},"paragraph",{"textAlign":59},[330],{"text":331,"type":332},"Foxy’s HMAC product validation is a cryptographic method to prevent customers from tampering with your add-to-cart links and forms — for example, modifying a product’s price, code, or category before submitting to the cart.","text",{"type":334,"attrs":335,"content":337},"heading",{"level":336,"textAlign":59},2,[338],{"text":339,"type":332},"Do you need it?",{"type":327,"attrs":341,"content":342},{"textAlign":59},[343],{"text":344,"type":332},"Without HMAC validation enabled, product parameters in your links and forms are visible and modifiable by anyone with basic web knowledge. Whether that’s a problem depends on your situation:",{"type":346,"content":347},"bullet_list",[348,361,380],{"type":349,"content":350},"list_item",[351],{"type":327,"attrs":352,"content":353},{"textAlign":59},[354,359],{"text":355,"type":332,"marks":356},"Low volume stores",[357],{"type":358},"bold",{"text":360,"type":332}," often manage risk by manually reviewing orders before fulfilment.",{"type":349,"content":362},[363],{"type":327,"attrs":364,"content":365},{"textAlign":59},[366,370,372,378],{"text":367,"type":332,"marks":368},"Higher volume stores",[369],{"type":358},{"text":371,"type":332}," may verify orders automatically by comparing transaction data against their database via the ",{"text":373,"type":332,"marks":374},"Foxy API",[375],{"type":376,"attrs":377},"link",{"href":37,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":379,"type":332},".",{"type":349,"content":381},[382],{"type":327,"attrs":383,"content":384},{"textAlign":59},[385,389],{"text":386,"type":332,"marks":387},"Any store",[388],{"type":358},{"text":390,"type":332}," that wants to prevent spoofed orders at the point of submission should implement HMAC validation.",{"type":327,"attrs":392,"content":393},{"textAlign":59},[394],{"text":395,"type":332},"If you’re concerned about price or product spoofing, HMAC validation is the most robust solution.",{"type":334,"attrs":397,"content":398},{"level":336,"textAlign":59},[399],{"text":400,"type":332},"How it works",{"type":327,"attrs":402,"content":403},{"textAlign":59},[404],{"text":405,"type":332},"When HMAC validation is enabled, Foxy requires every product parameter in your links and forms to be cryptographically signed using your store’s API key. Unsigned or tampered values are rejected before the product is added to the cart.",{"type":327,"attrs":407,"content":408},{"textAlign":59},[409,411,417],{"text":410,"type":332},"Signing is all or nothing — if validation is enabled, every parameter on every add-to-cart link and form must be signed. See ",{"text":412,"type":332,"marks":413},"HMAC excluded parameters reference",[414],{"type":376,"attrs":415},{"href":416,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fhmac-excluded-parameters-reference",{"text":418,"type":332}," for the small number of parameters that are exempt.",{"type":334,"attrs":420,"content":421},{"level":336,"textAlign":59},[422],{"text":423,"type":332},"Implementation options",{"type":327,"attrs":425,"content":426},{"textAlign":59},[427],{"text":428,"type":332},"There are three ways to implement HMAC signing:",{"type":327,"attrs":430,"content":431},{"textAlign":59},[432,436,438,444,446,452],{"text":433,"type":332,"marks":434},"PHP auto-sign library",[435],{"type":358},{"text":437,"type":332}," — the recommended approach for most stores. A PHP script automatically signs all links and forms on an entire HTML page, making it straightforward to add to an existing site or CMS. See ",{"text":439,"type":332,"marks":440},"Sign product forms with HMAC",[441],{"type":376,"attrs":442},{"href":443,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-product-forms-with-hmac",{"text":445,"type":332}," and ",{"text":447,"type":332,"marks":448},"Sign product links with HMAC",[449],{"type":376,"attrs":450},{"href":451,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-product-links-with-hmac",{"text":379,"type":332},{"type":327,"attrs":454,"content":455},{"textAlign":59},[456,460,462,468],{"text":457,"type":332,"marks":458},"Manual admin tool",[459],{"type":358},{"text":461,"type":332}," — for static sites or one-off forms. Paste your link or form into the Foxy admin and it returns a signed version. See ",{"text":463,"type":332,"marks":464},"Use the admin tool to sign products with HMAC",[465],{"type":376,"attrs":466},{"href":467,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fuse-the-admin-tool-to-sign-products-with-hmac",{"text":379,"type":332},{"type":327,"attrs":470,"content":471},{"textAlign":59},[472,476,478,482,483,487],{"text":473,"type":332,"marks":474},"Custom implementation",[475],{"type":358},{"text":477,"type":332}," — sign parameters yourself in any language using HMAC SHA-256. See ",{"text":439,"type":332,"marks":479},[480],{"type":376,"attrs":481},{"href":443,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":445,"type":332},{"text":447,"type":332,"marks":484},[485],{"type":376,"attrs":486},{"href":451,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":488,"type":332}," for implementation details.",{"type":334,"attrs":490,"content":491},{"level":336,"textAlign":59},[492],{"text":493,"type":332},"Notes",{"type":346,"content":495},[496,510,523],{"type":349,"content":497},[498],{"type":327,"attrs":499,"content":500},{"textAlign":59},[501,503,509],{"text":502,"type":332},"HMAC validation must be enabled in your store settings before signed links and forms will be validated. See ",{"text":504,"type":332,"marks":505},"Enable HMAC product validation",[506],{"type":376,"attrs":507},{"href":508,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fenable-hmac-product-validation",{"text":379,"type":332},{"type":349,"content":511},[512],{"type":327,"attrs":513,"content":514},{"textAlign":59},[515,517,521],{"text":516,"type":332},"A ",{"text":518,"type":332,"marks":519},"code",[520],{"type":518},{"text":522,"type":332}," value is required on every product. Without it there is nothing to tie signed parameters to a specific product.",{"type":349,"content":524},[525],{"type":327,"attrs":526,"content":527},{"textAlign":59},[528,530,535],{"text":529,"type":332},"Validation prevents tampering with existing parameters and blocks the addition of unsigned parameters, but it does not prevent a user from ",{"text":531,"type":332,"marks":532},"removing",[533],{"type":534},"italic",{"text":536,"type":332}," a parameter. If you use price modifiers, set the base price at the upper limit and adjust downward rather than upward.",{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":538},{},"What HMAC product validation is, when to use it, and the different ways to implement it.","ff9269e2-2402-422e-aa80-19acc150b78a",[],"product-security-overview","help\u002Farticles\u002Fproduct-security-overview",-2460,[],2659,"72c0e65c-dc2b-43d9-bcab-f6e0e846548c",[],{"html":550,"sections":551,"segments":561},"\u003Cp>Foxy’s HMAC product validation is a cryptographic method to prevent customers from tampering with your add-to-cart links and forms — for example, modifying a product’s price, code, or category before submitting to the cart.\u003C\u002Fp>\u003Csection id=\"do-you-need-it\" data-title=\"Do you need it?\" data-title-node=\"H2\">\u003Chr class=\"my-8\" style=\"margin-left: -48px; margin-right: -40vw\">\u003Ch2 data-anchor-id=\"do-you-need-it\">Do you need it?\u003C\u002Fh2>\u003Cp>Without HMAC validation enabled, product parameters in your links and forms are visible and modifiable by anyone with basic web knowledge. Whether that’s a problem depends on your situation:\u003C\u002Fp>\u003Cul>\u003Cli>\u003Cp>\u003Cstrong>Low volume stores\u003C\u002Fstrong> often manage risk by manually reviewing orders before fulfilment.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>\u003Cstrong>Higher volume stores\u003C\u002Fstrong> may verify orders automatically by comparing transaction data against their database via the \u003Ca href=\"https:\u002F\u002Fapi.foxycart.com\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Foxy API\u003C\u002Fa>.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>\u003Cstrong>Any store\u003C\u002Fstrong> that wants to prevent spoofed orders at the point of submission should implement HMAC validation.\u003C\u002Fp>\u003C\u002Fli>\u003C\u002Ful>\u003Cp>If you’re concerned about price or product spoofing, HMAC validation is the most robust solution.\u003C\u002Fp>\u003C\u002Fsection>\u003Csection id=\"how-it-works\" data-title=\"How it works\" data-title-node=\"H2\">\u003Chr class=\"my-8\" style=\"margin-left: -48px; margin-right: -40vw\">\u003Ch2 data-anchor-id=\"how-it-works\">How it works\u003C\u002Fh2>\u003Cp>When HMAC validation is enabled, Foxy requires every product parameter in your links and forms to be cryptographically signed using your store’s API key. Unsigned or tampered values are rejected before the product is added to the cart.\u003C\u002Fp>\u003Cp>Signing is all or nothing — if validation is enabled, every parameter on every add-to-cart link and form must be signed. See \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fhmac-excluded-parameters-reference\" class=\"\">HMAC excluded parameters reference\u003C\u002Fa> for the small number of parameters that are exempt.\u003C\u002Fp>\u003C\u002Fsection>\u003Csection id=\"implementation-options\" data-title=\"Implementation options\" data-title-node=\"H2\">\u003Chr class=\"my-8\" style=\"margin-left: -48px; margin-right: -40vw\">\u003Ch2 data-anchor-id=\"implementation-options\">Implementation options\u003C\u002Fh2>\u003Cp>There are three ways to implement HMAC signing:\u003C\u002Fp>\u003Cp>\u003Cstrong>PHP auto-sign library\u003C\u002Fstrong> — the recommended approach for most stores. A PHP script automatically signs all links and forms on an entire HTML page, making it straightforward to add to an existing site or CMS. See \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-product-forms-with-hmac\" class=\"\">Sign product forms with HMAC\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-product-links-with-hmac\" class=\"\">Sign product links with HMAC\u003C\u002Fa>.\u003C\u002Fp>\u003Cp>\u003Cstrong>Manual admin tool\u003C\u002Fstrong> — for static sites or one-off forms. Paste your link or form into the Foxy admin and it returns a signed version. See \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fuse-the-admin-tool-to-sign-products-with-hmac\" class=\"\">Use the admin tool to sign products with HMAC\u003C\u002Fa>.\u003C\u002Fp>\u003Cp>\u003Cstrong>Custom implementation\u003C\u002Fstrong> — sign parameters yourself in any language using HMAC SHA-256. See \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-product-forms-with-hmac\" class=\"\">Sign product forms with HMAC\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-product-links-with-hmac\" class=\"\">Sign product links with HMAC\u003C\u002Fa> for implementation details.\u003C\u002Fp>\u003C\u002Fsection>\u003Csection id=\"notes\" data-title=\"Notes\" data-title-node=\"H2\">\u003Chr class=\"my-8\" style=\"margin-left: -48px; margin-right: -40vw\">\u003Ch2 data-anchor-id=\"notes\">Notes\u003C\u002Fh2>\u003Cul>\u003Cli>\u003Cp>HMAC validation must be enabled in your store settings before signed links and forms will be validated. See \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fenable-hmac-product-validation\" class=\"\">Enable HMAC product validation\u003C\u002Fa>.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>A \u003Ccode class=\"badge bg-soft-danger text-danger\">code\u003C\u002Fcode> value is required on every product. Without it there is nothing to tie signed parameters to a specific product.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>Validation prevents tampering with existing parameters and blocks the addition of unsigned parameters, but it does not prevent a user from \u003Cem>removing\u003C\u002Fem> a parameter. If you use price modifiers, set the base price at the upper limit and adjust downward rather than upward.\u003C\u002Fp>\u003C\u002Fli>\u003C\u002Ful>\u003C\u002Fsection>",[552,555,557,559],{"id":553,"title":339,"level":554},"do-you-need-it","H2",{"id":556,"title":400,"level":554},"how-it-works",{"id":558,"title":423,"level":554},"implementation-options",{"id":560,"title":493,"level":554},"notes",[562],{"type":563,"content":564},"html","\u003Cp>Foxy’s HMAC product validation is a cryptographic method to prevent customers from tampering with your add-to-cart links and forms — for example, modifying a product’s price, code, or category before submitting to the cart.\u003C\u002Fp>\u003Ch2>Do you need it?\u003C\u002Fh2>\u003Cp>Without HMAC validation enabled, product parameters in your links and forms are visible and modifiable by anyone with basic web knowledge. Whether that’s a problem depends on your situation:\u003C\u002Fp>\u003Cul>\u003Cli>\u003Cp>\u003Cstrong>Low volume stores\u003C\u002Fstrong> often manage risk by manually reviewing orders before fulfilment.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>\u003Cstrong>Higher volume stores\u003C\u002Fstrong> may verify orders automatically by comparing transaction data against their database via the \u003Ca href=\"https:\u002F\u002Fapi.foxycart.com\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">Foxy API\u003C\u002Fa>.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>\u003Cstrong>Any store\u003C\u002Fstrong> that wants to prevent spoofed orders at the point of submission should implement HMAC validation.\u003C\u002Fp>\u003C\u002Fli>\u003C\u002Ful>\u003Cp>If you’re concerned about price or product spoofing, HMAC validation is the most robust solution.\u003C\u002Fp>\u003Ch2>How it works\u003C\u002Fh2>\u003Cp>When HMAC validation is enabled, Foxy requires every product parameter in your links and forms to be cryptographically signed using your store’s API key. Unsigned or tampered values are rejected before the product is added to the cart.\u003C\u002Fp>\u003Cp>Signing is all or nothing — if validation is enabled, every parameter on every add-to-cart link and form must be signed. See \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fhmac-excluded-parameters-reference\" class=\"\">HMAC excluded parameters reference\u003C\u002Fa> for the small number of parameters that are exempt.\u003C\u002Fp>\u003Ch2>Implementation options\u003C\u002Fh2>\u003Cp>There are three ways to implement HMAC signing:\u003C\u002Fp>\u003Cp>\u003Cstrong>PHP auto-sign library\u003C\u002Fstrong> — the recommended approach for most stores. A PHP script automatically signs all links and forms on an entire HTML page, making it straightforward to add to an existing site or CMS. See \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-product-forms-with-hmac\" class=\"\">Sign product forms with HMAC\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-product-links-with-hmac\" class=\"\">Sign product links with HMAC\u003C\u002Fa>.\u003C\u002Fp>\u003Cp>\u003Cstrong>Manual admin tool\u003C\u002Fstrong> — for static sites or one-off forms. Paste your link or form into the Foxy admin and it returns a signed version. See \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fuse-the-admin-tool-to-sign-products-with-hmac\" class=\"\">Use the admin tool to sign products with HMAC\u003C\u002Fa>.\u003C\u002Fp>\u003Cp>\u003Cstrong>Custom implementation\u003C\u002Fstrong> — sign parameters yourself in any language using HMAC SHA-256. See \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-product-forms-with-hmac\" class=\"\">Sign product forms with HMAC\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-product-links-with-hmac\" class=\"\">Sign product links with HMAC\u003C\u002Fa> for implementation details.\u003C\u002Fp>\u003Ch2>Notes\u003C\u002Fh2>\u003Cul>\u003Cli>\u003Cp>HMAC validation must be enabled in your store settings before signed links and forms will be validated. See \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fenable-hmac-product-validation\" class=\"\">Enable HMAC product validation\u003C\u002Fa>.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>A \u003Ccode class=\"badge bg-soft-danger text-danger\">code\u003C\u002Fcode> value is required on every product. Without it there is nothing to tie signed parameters to a specific product.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>Validation prevents tampering with existing parameters and blocks the addition of unsigned parameters, but it does not prevent a user from \u003Cem>removing\u003C\u002Fem> a parameter. If you use price modifiers, set the base price at the upper limit and adjust downward rather than upward.\u003C\u002Fp>\u003C\u002Fli>\u003C\u002Ful>",{"name":566,"created_at":567,"published_at":568,"updated_at":569,"id":570,"uuid":47,"content":571,"slug":48,"full_slug":48,"sort_by_date":59,"position":748,"tag_list":749,"is_startpage":24,"parent_id":59,"meta_data":59,"group_id":750,"first_published_at":751,"release_id":59,"lang":65,"path":59,"alternates":752,"default_full_slug":59,"translated_slugs":59},"Contact","2022-09-23T19:56:58.957Z","2025-05-08T18:24:40.382Z","2025-05-08T18:24:40.392Z",3138,{"seo":572,"_uid":575,"title":576,"action":577,"fields":578,"method":724,"columns":725,"subtitle":739,"component":48,"button_text":745,"submit_title":746,"submit_subtitle":747},{"_uid":573,"title":566,"plugin":574,"description":13},"24ff7574-3bcc-48d2-85b5-e529dfea1cc4","meta-fields","8f54f1da-9d8f-49b2-89e7-840e886491cb","We're here to help.","https:\u002F\u002Fusebasin.com\u002Ff\u002F029f48d65402",[579,584,588,695,698,703,718],{"_uid":580,"name":581,"type":332,"label":582,"options":13,"required":33,"component":583,"placeholder":13},"9a70b226-2036-4f90-a052-b3efa61c5896","name","Name","form___field",{"_uid":585,"name":586,"type":586,"label":587,"options":13,"required":33,"component":583,"placeholder":13},"86ba35be-ff43-4a28-8633-14052a8f6622","email","Email Address",{"_uid":589,"name":590,"type":591,"label":592,"options":593,"required":33,"component":583,"conditions":594,"placeholder":13},"3f827475-492c-4f97-aa1e-2386ac263b6c","topic","select","Topic","Presales, Support, Billing, Partnerships, Order Enquiry, Other",[595,649,659,666,674,682,688],{"_uid":596,"equals":597,"fields":598,"component":648},"e21d97dd-e68e-4fa6-ba97-bc40f3041dde","Order Enquiry",[599],{"_uid":600,"body":601,"type":646,"title":13,"component":647},"b64992bc-6d53-48b8-b7a0-d81e5a062e50",{"type":324,"content":602},[603],{"type":327,"content":604},[605,607,614,616,618,619,623,625,629,637,639,644],{"text":606,"type":332},"We are ",{"text":608,"type":332,"marks":609},"Foxy.io",[610],{"type":376,"attrs":611},{"href":612,"uuid":59,"anchor":59,"custom":613,"target":59,"linktype":31},"http:\u002F\u002FFoxy.io",{},{"text":615,"type":332},", an ecommerce platform powering ecommerce for other merchants. We do not sell products, and are unable to assist with questions about order statuses or refunds for any merchants using our platform. Please contact the merchant you ordered from for assistance. If you’d like to report a store using Foxy for fraudulent practices, please select ‘other’ in the subject.",{"type":617},"hard_break",{"type":617},{"text":620,"type":332,"marks":621},"NOTE:",[622],{"type":358},{"text":624,"type":332}," We are ",{"text":626,"type":332,"marks":627},"not ",[628],{"type":534},{"text":630,"type":332,"marks":631},"Foxy.in",[632,636],{"type":376,"attrs":633},{"href":634,"uuid":59,"anchor":59,"custom":635,"target":59,"linktype":31},"http:\u002F\u002FFoxy.in",{},{"type":534},{"text":638,"type":332},". We are not in any way affiliated with ",{"text":630,"type":332,"marks":640},[641],{"type":376,"attrs":642},{"href":634,"uuid":59,"anchor":59,"custom":643,"target":59,"linktype":31},{},{"text":645,"type":332},", and cannot help in any way with your order from that website.","danger","global___alert","form___condition",{"_uid":650,"equals":651,"fields":652,"component":648},"8765c3e1-25cf-44aa-b8ea-fc6094acf9c3","Presales",[653],{"_uid":654,"name":655,"type":656,"label":13,"options":13,"required":24,"component":583,"conditions":657,"placeholder":13,"default_value":658},"cf464f8e-d643-4f6e-af29-d3abffaf7380","department_email_address","hidden",[],"hello@foxy.io",{"_uid":660,"equals":208,"fields":661,"component":648},"4007b6d8-77e5-421d-bd1e-6f336dd853fb",[662],{"_uid":663,"name":655,"type":656,"label":13,"options":13,"required":24,"component":583,"conditions":664,"placeholder":13,"default_value":665},"7b4c6aa5-a68c-45e0-9ce1-0a36af10c0c2",[],"help@foxy.io",{"_uid":667,"equals":668,"fields":669,"component":648},"1dbb8f11-613d-43cd-9e09-1b94f6e19219","Billing",[670],{"_uid":671,"name":655,"type":656,"label":13,"options":13,"required":24,"component":583,"conditions":672,"placeholder":13,"default_value":673},"a0ac0d1b-bc4f-4a6c-a682-581d450b0b73",[],"help+billing@foxy.io",{"_uid":675,"equals":676,"fields":677,"component":648},"a0a53a50-7172-4a29-ba58-181e38874e12","Partnerships",[678],{"_uid":679,"name":655,"type":656,"label":13,"options":13,"required":24,"component":583,"conditions":680,"placeholder":13,"default_value":681},"7aa011d9-f374-4aed-b5a5-929b54aaf152",[],"partners@foxy.io",{"_uid":683,"equals":597,"fields":684,"component":648},"a4cd431f-25d5-41c7-bfdc-02c908c8fb47",[685],{"_uid":686,"name":655,"type":656,"label":13,"options":13,"required":24,"component":583,"conditions":687,"placeholder":13,"default_value":658},"f5d52168-d6ae-451b-94ee-2ced1cbd28ad",[],{"_uid":689,"equals":690,"fields":691,"component":648},"25aba1ed-eb41-4bbc-aa89-f7a7167ea86e","Other",[692],{"_uid":693,"name":655,"type":656,"label":13,"options":13,"required":24,"component":583,"conditions":694,"placeholder":13,"default_value":658},"f40dfaef-c203-4b71-bf4e-e1b43cef192b",[],{"_uid":696,"component":697},"e9c53a05-f40a-4510-aaf8-bc072a235a0c","form___subject",{"_uid":699,"name":700,"type":701,"label":702,"options":13,"required":33,"component":583,"placeholder":13},"a4c4d385-fff4-4978-99fb-b68cfea623d6","message","textarea","Message",{"_uid":704,"name":705,"type":591,"label":706,"options":707,"required":33,"component":583,"conditions":708,"placeholder":13},"8a3c9f85-f438-427d-9c7a-d7b295a14b5b","existing_user","Are you an existing user?","No, Yes",[709],{"_uid":710,"equals":711,"fields":712,"component":648},"115933d6-262a-4b59-8fa8-579c5ad73de1","Yes",[713],{"_uid":714,"name":715,"type":332,"label":716,"options":13,"required":33,"component":583,"conditions":717,"placeholder":13},"44b6ff23-98f0-4e95-b7f5-c23e06415c2d","subdomain","Store Subdomain",[],{"_uid":719,"name":720,"type":591,"label":721,"options":722,"required":33,"component":583,"conditions":723,"placeholder":13},"922a5cef-3af2-4113-8855-36c7910e3ee3","user_type","What type of user are you?","Developer, Designer, Merchant",[],"POST",[726],{"_uid":727,"text":728,"title":737,"component":738},"7323b90d-a93a-4bf1-baa9-20d0b7ead61b",{"type":324,"content":729},[730],{"type":327,"content":731},[732,734,735],{"text":733,"type":332},"855.369.9227",{"type":617},{"text":736,"type":332},"9:30am-6pm Central M-F","Pre-sales, Sales, & Partnerships","contact___footer_column",{"type":324,"content":740},[741],{"type":327,"content":742},[743],{"text":744,"type":332},"Get in touch to get help from our friendly support team.","Submit","Success!","Your email has been received. We'll get back to you as soon as we can, but it might take a business day. If you don't hear back from us in a timely manner, please check your spam folder to ensure our reply didn't go there.",-80,[],"2fd9fb7d-a48a-4184-acfd-30022d8d6f08","2022-09-23T20:10:45.360Z",[],[288,754,782],{"name":755,"created_at":756,"published_at":757,"updated_at":758,"id":759,"uuid":760,"content":761,"slug":775,"full_slug":776,"sort_by_date":59,"position":777,"tag_list":778,"is_startpage":24,"parent_id":310,"meta_data":59,"group_id":779,"first_published_at":780,"release_id":59,"lang":65,"path":59,"alternates":781,"default_full_slug":59,"translated_slugs":59},"Products","2023-01-19T16:20:53.075Z","2024-06-05T04:29:14.851Z","2024-06-05T04:29:14.872Z",28236,"389d5512-29ba-4a93-9cfa-9491d1618f73",{"_uid":762,"icon":763,"name":755,"guides":764,"pinned":24,"summary":765,"category":13,"component":297,"blog_posts":766,"content_hub":24,"icon_custom":767,"case_studies":768,"faq_sections":769,"help_articles":770,"featured_guides":771,"mailbox_category":13,"featured_articles":772,"featured_blog_posts":773,"featured_case_studies":774},"3551f6e8-765a-4b8d-8587-2e2eda4d2b23","fa-tags",[],"How products work, supported product types, inventory management, and more.",[],{"id":59,"alt":59,"name":13,"focus":59,"title":59,"filename":13,"copyright":59,"fieldtype":81},[],[],[],[],[],[],[],"products","help\u002Fcategories\u002Fproducts",150,[],"c025c7a7-0d20-4244-938a-c8d6588e1269","2023-01-19T17:25:32.570Z",[],{"name":783,"created_at":784,"published_at":785,"updated_at":786,"id":787,"uuid":540,"content":788,"slug":801,"full_slug":802,"sort_by_date":59,"position":803,"tag_list":804,"is_startpage":24,"parent_id":310,"meta_data":59,"group_id":805,"first_published_at":785,"release_id":59,"lang":65,"path":59,"alternates":806,"default_full_slug":59,"translated_slugs":59},"Product Security","2026-06-29T20:00:54.676Z","2026-06-29T20:37:32.009Z","2026-06-29T20:37:32.025Z",192813689601883,{"_uid":789,"icon":13,"name":783,"type":790,"pinned":24,"summary":791,"category":760,"component":297,"blog_posts":792,"icon_custom":793,"case_studies":795,"faq_sections":796,"featured_guides":797,"mailbox_category":13,"featured_articles":798,"featured_blog_posts":799,"featured_case_studies":800},"bd9968b0-6d3b-4a2b-a7bc-79263044b475","simple","How to enable and implement HMAC product validation, including signing product links, forms, and bundled products.",[],{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":794},{},[],[],[],[],[],[],"product-security","help\u002Fcategories\u002Fproduct-security",-420,[],"9b6ea296-0666-48d6-b896-39e524ea24ac",[],{},1784562224891]