[{"data":1,"prerenderedAt":983},["ShallowReactive",2],{"header:help":3,"footer:default":67,"story:navigation\u002Fsearch:help":250,"story:help\u002Fcategories":288,"story:help\u002Farticles\u002Fsign-product-forms-with-hmac":314,"no-guide:sign-product-forms-with-hmac":59,"article:\u002Fhelp\u002Farticles\u002Fsign-product-forms-with-hmac":721,"story:contact":739,"help:tree:79675f4b-0ab8-41cd-8a21-8ab9c8c3af18":928,"_apollo:default":982},{"name":4,"created_at":5,"published_at":6,"updated_at":7,"id":8,"uuid":9,"content":10,"slug":57,"full_slug":58,"sort_by_date":59,"position":60,"tag_list":61,"is_startpage":24,"parent_id":62,"meta_data":59,"group_id":63,"first_published_at":64,"release_id":59,"lang":65,"path":59,"alternates":66,"default_full_slug":59,"translated_slugs":59},"Help Center Header","2024-08-09T18:06:34.939Z","2024-10-21T21:58:39.217Z","2024-10-21T21:58:39.232Z",10082752,"3e9b88f7-c163-4657-a2f2-62532d600fad",{"_uid":11,"link":12,"badge":16,"items":17,"title":13,"buttons":50,"new_tab":24,"submenu":51,"alignment":13,"component":52,"badge_link":53,"top_menu_items":56},"e5645a1a-f991-40e8-8d67-e40ebc082b5a",{"id":13,"url":13,"linktype":14,"fieldtype":15,"cached_url":13},"","story","multilink","Help Center",[18,27,34,39,44],{"_uid":19,"link":20,"title":23,"new_tab":24,"submenu":25,"component":26},"5cbe2861-1f49-4166-97da-a4dddd8105e3",{"id":21,"url":13,"linktype":14,"fieldtype":15,"cached_url":22},"4c0a2d99-ec30-4579-8ef1-6bf5564d4839","help\u002Fcategories\u002F","Articles",false,[],"header___item",{"_uid":28,"link":29,"title":32,"new_tab":33,"component":26},"1c8edeb5-b9e9-4cb8-b1c6-c1f292f7d7cd",{"id":13,"url":30,"linktype":31,"fieldtype":15,"cached_url":30},"https:\u002F\u002Fwiki.foxycart.com\u002F","url","Documentation",true,{"_uid":35,"link":36,"title":38,"new_tab":33,"component":26},"8d7df70e-f087-4da0-b616-6f0e9a5af35c",{"id":13,"url":37,"linktype":31,"fieldtype":15,"cached_url":37},"https:\u002F\u002Fapi.foxycart.com\u002F","API Documentation",{"_uid":40,"link":41,"title":43,"new_tab":33,"component":26},"f76e7944-23d5-4652-87e4-cdae79272762",{"id":13,"url":42,"linktype":31,"fieldtype":15,"cached_url":42},"https:\u002F\u002Fstatus.foxy.io\u002F","System Status",{"_uid":45,"link":46,"title":49,"new_tab":24,"component":26},"0de16771-4c84-466c-a1da-d8568113c71f",{"id":47,"url":13,"linktype":14,"fieldtype":15,"cached_url":48},"01e4e370-f9b9-45af-8fa9-f15540699b0d","contact","Contact Us",[],[],"header",{"id":54,"url":13,"linktype":14,"fieldtype":15,"cached_url":55},"4a679eb7-662d-4ea4-a976-5a2acbf0b663","help\u002F",[],"help-header","navigation\u002Fhelp-header",null,20,[],10082747,"71b81c2e-5e09-48a1-a397-a3c72fcd344a","2022-09-21T14:50:25.655Z","default",[],{"name":68,"created_at":69,"published_at":70,"updated_at":71,"id":72,"uuid":73,"content":74,"slug":243,"full_slug":244,"sort_by_date":59,"position":245,"tag_list":246,"is_startpage":24,"parent_id":62,"meta_data":59,"group_id":247,"first_published_at":248,"release_id":59,"lang":65,"path":59,"alternates":249,"default_full_slug":59,"translated_slugs":59},"Default Footer","2024-08-09T18:06:59.024Z","2025-09-04T06:24:46.223Z","2025-09-04T06:24:46.241Z",10082753,"e59e67ac-248a-482f-84a1-53d4f318186a",{"_uid":75,"about":76,"logos":77,"socials":82,"sections":108,"component":225,"cta_title":226,"bottom_links":227,"cta_subtitle":241,"cta_button_link":242,"cta_button_text":183},"830983f5-c4c4-43c8-b150-86a5e3fa6dc8","Foxy’s hosted cart & payment page allow you to sell anything, using your existing website or platform.",[78],{"id":79,"alt":13,"name":13,"focus":13,"title":13,"filename":80,"copyright":13,"fieldtype":81},14760,"https:\u002F\u002Fa-us.storyblok.com\u002Ff\u002F1001040\u002Fx\u002F3b030847ec\u002Fb-corp.svg","asset",[83,90,96,102],{"_uid":84,"icon":85,"link":86,"name":88,"component":89},"faf0a618-ea94-42ea-9182-03be18c43216","fa-facebook",{"id":13,"url":87,"linktype":31,"fieldtype":15,"cached_url":87},"https:\u002F\u002Fwww.facebook.com\u002Ffoxycart","Facebook","footer___social",{"_uid":91,"icon":92,"link":93,"name":95,"component":89},"14309c18-7e79-423e-b375-34555bac0811","fa-instagram",{"id":13,"url":94,"linktype":31,"fieldtype":15,"cached_url":94},"https:\u002F\u002Fwww.instagram.com\u002Ffoxy_io","Instagram",{"_uid":97,"icon":98,"link":99,"name":101,"component":89},"8f7fe7cf-0dd3-4596-8334-226ea466716a","fa-linkedin",{"id":13,"url":100,"linktype":31,"fieldtype":15,"cached_url":100},"https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Ffoxycart.com","LinkedIn",{"_uid":103,"icon":104,"link":105,"name":107,"component":89},"90a675b4-dd97-40b5-be09-00a87223d4c5","fa-youtube",{"id":13,"url":106,"linktype":31,"fieldtype":15,"cached_url":106},"https:\u002F\u002Fwww.youtube.com\u002Fuser\u002Ffoxycart","Youtube",[109,139,184,206],{"_uid":110,"name":111,"items":112,"component":138},"82849945-282f-488c-b18d-a8d2252f514a","Company",[113,120,126,132],{"_uid":114,"link":115,"title":118,"new_tab":24,"component":119},"1f699ab1-938b-4d9d-9825-aabcbe6f57fe",{"id":116,"url":13,"linktype":14,"fieldtype":15,"cached_url":117},"63634293-a749-4226-9439-9f38ee6dcda0","about-us","About Us","footer___menu_items",{"_uid":121,"link":122,"title":125,"new_tab":24,"component":119},"b26b00f1-a0e7-4be2-8ab3-428b8cc841f8",{"id":123,"url":13,"linktype":14,"fieldtype":15,"cached_url":124},"26cb7c55-faed-4a77-a291-1552d4111b3e","how-foxy-works","How Foxy Works",{"_uid":127,"link":128,"title":131,"new_tab":24,"component":119},"b40c68a0-1ceb-4226-9515-6176534f61fe",{"id":129,"url":13,"linktype":14,"fieldtype":15,"cached_url":130},"dc6657d7-7f4f-4c0d-b781-e971b038ee26","for-good","Foxy For Good",{"_uid":133,"link":134,"title":137,"new_tab":24,"component":119},"3ad0c134-bef9-4fff-b891-e09f16109036",{"id":135,"url":13,"linktype":14,"fieldtype":15,"cached_url":136},"23cae210-baf4-4588-9862-d09f4f52ccd2","brand-assets","Brand Assets","footer___section",{"_uid":140,"name":141,"items":142,"component":138},"a6805fa8-ac60-47f1-b8f0-f27aded0afbe","Product",[143,149,155,161,167,173,179],{"_uid":144,"link":145,"title":148,"new_tab":24,"component":119},"b39c8a4e-2383-486f-b76a-11fbb15d8134",{"id":146,"url":13,"linktype":14,"fieldtype":15,"cached_url":147},"bb04690f-fe98-4ce6-80be-05b950f2364f","features\u002F","Features",{"_uid":150,"link":151,"title":154,"new_tab":24,"component":119},"64f8a41f-c181-433d-bc0a-fc94e71ecbf6",{"id":152,"url":13,"linktype":14,"fieldtype":15,"cached_url":153},"c450c58d-761d-48c0-a9af-0b064611689b","pricing","Pricing",{"_uid":156,"link":157,"title":160,"new_tab":24,"component":119},"6e0b287f-fd8c-4146-9e0e-0ab0b5c9ce3c",{"id":158,"url":13,"linktype":14,"fieldtype":15,"cached_url":159},"fab20ad9-e76a-4947-b709-3a6fdfa88028","blog\u002Fcategories\u002Fproduct-updates","Product Updates",{"_uid":162,"link":163,"title":166,"new_tab":24,"component":119},"47e5a074-a6b5-4f1c-8c2f-89a2ae9f83eb",{"id":164,"url":13,"linktype":14,"fieldtype":15,"cached_url":165},"d2c83612-d611-47f3-a3b4-ca7fe08540b8","changelogs\u002F","Changelogs",{"_uid":168,"link":169,"title":172,"new_tab":24,"component":119},"b5c08774-542f-4ffd-b357-c94d674488b9",{"id":170,"url":13,"linktype":14,"fieldtype":15,"cached_url":171},"08876121-0df3-4ed9-aa11-902b3e41cd02","whats-next","What's Next",{"_uid":174,"link":175,"title":178,"new_tab":24,"component":119},"9c2704ed-6d9f-43e1-9e67-c8d91c083288",{"id":176,"url":13,"linktype":14,"fieldtype":15,"cached_url":177},"056a7857-b18f-4025-8f97-91a38fc19bc8","compare\u002F","Compare",{"_uid":180,"link":181,"title":183,"new_tab":24,"component":119},"5f2db35b-674b-406a-8fa7-d246633af9fe",{"id":13,"url":182,"linktype":31,"fieldtype":15,"cached_url":182},"https:\u002F\u002Fadmin.foxy.io\u002Fsign-up","Try Foxy Free",{"_uid":185,"name":186,"items":187,"component":138},"63fa1f29-4252-4640-9922-fe310e69e54a","Security",[188,194,200],{"_uid":189,"link":190,"title":193,"new_tab":24,"component":119},"1158ddb6-9eb0-466f-8eb6-7ca2ae66c8b8",{"id":191,"url":13,"linktype":14,"fieldtype":15,"cached_url":192},"1f58fb2c-8681-4742-b6e8-09999beae9f6","security-contact","Security Contact",{"_uid":195,"link":196,"title":199,"new_tab":24,"component":119},"9a79c54a-6022-4dfd-854b-766f5e4703ba",{"id":197,"url":13,"linktype":14,"fieldtype":15,"cached_url":198},"55cbfcc3-425a-4261-8037-54e919851d2d","pci","PCI Compliance",{"_uid":201,"link":202,"title":205,"new_tab":24,"component":119},"0b85f5b6-9534-4071-b323-b39d053dd4d7",{"id":203,"url":13,"linktype":14,"fieldtype":15,"cached_url":204},"c3ac0fe3-83e2-4879-afbd-d4c83e1590df","help\u002Farticles\u002Four-official-domains-public-code","Domains & Codebases",{"_uid":207,"name":208,"items":209,"component":138},"998ded67-d107-49f4-8154-ca6be51671ec","Support",[210,213,216,219,222],{"_uid":211,"link":212,"title":16,"new_tab":24,"component":119},"594ffd35-3049-4004-bb08-0db568ebd819",{"id":54,"url":13,"linktype":14,"fieldtype":15,"cached_url":55},{"_uid":214,"link":215,"title":32,"new_tab":33,"component":119},"0a1a55ab-a985-4f9d-8b42-26da714d0c1c",{"id":13,"url":30,"linktype":31,"fieldtype":15,"cached_url":30},{"_uid":217,"link":218,"title":38,"new_tab":33,"component":119},"61e0b7c8-aadf-419b-a339-b3ccabc65bf4",{"id":13,"url":37,"linktype":31,"fieldtype":15,"cached_url":37},{"_uid":220,"link":221,"title":43,"new_tab":33,"component":119},"fd67a89e-1c54-4d31-94b5-64be999062d6",{"id":13,"url":42,"linktype":31,"fieldtype":15,"cached_url":42},{"_uid":223,"link":224,"title":49,"new_tab":24,"component":119},"231a6f71-e996-4ad4-b033-d4d5542f34f0",{"id":47,"url":13,"linktype":14,"fieldtype":15,"cached_url":48},"footer","Get started with our *unlimited free trial*.",[228,235],{"_uid":229,"link":230,"text":233,"component":234},"f0b77210-2632-45a2-8436-e57cad84d01a",{"id":231,"url":13,"linktype":14,"fieldtype":15,"cached_url":232},"60ba16a2-c1f4-485f-b978-8d2eeeafbf5a","terms-of-service","Terms of Service","footer___bottom_links",{"_uid":236,"link":237,"text":240,"component":234},"4bd497b0-993f-4b4d-a5b7-8a49c7c8fec9",{"id":238,"url":13,"linktype":14,"fieldtype":15,"cached_url":239},"332302b9-1d18-4016-b9c8-9b33c72d782b","privacy-policy","Privacy Policy","No credit card required.",{"id":13,"url":182,"linktype":31,"fieldtype":15,"cached_url":182},"default-footer","navigation\u002Fdefault-footer",50,[],"11006268-07f9-41e9-96f3-c51fb723399d","2022-09-21T20:39:02.357Z",[],{"name":251,"created_at":252,"published_at":253,"updated_at":254,"id":255,"uuid":256,"content":257,"slug":279,"full_slug":282,"sort_by_date":59,"position":283,"tag_list":284,"is_startpage":24,"parent_id":62,"meta_data":59,"group_id":285,"first_published_at":286,"release_id":59,"lang":65,"path":59,"alternates":287,"default_full_slug":59,"translated_slugs":59},"Search","2024-10-21T22:08:54.973Z","2025-05-26T09:17:25.790Z","2025-05-26T09:17:25.804Z",13592003,"14cbc359-9ac1-4a7a-a8de-ad4ac8ef26d4",{"_uid":258,"name":251,"indices":259,"summary":13,"component":279,"primary_image":280},"5e4a56e8-76f1-4790-b3a7-70f1be97d042",[260,265,269,274],{"key":261,"_uid":262,"icon":13,"name":263,"component":264},"all","c12a3210-7323-4273-8217-5215e52efe84","All","index",{"key":266,"_uid":267,"icon":268,"name":23,"component":264},"help_center_article","5acff080-95e4-44d3-8dcf-1b19720af382","fa-file-alt",{"key":270,"_uid":271,"icon":272,"name":273,"component":264},"help_center_guide","b8fbc206-c083-471e-a1f0-0ebeb90a669d","fa-book","Guides",{"key":275,"_uid":276,"icon":277,"name":278,"component":264},"blog_post","23419e83-2e56-4c4c-8a05-9fd1b3c9a9bd","fa-file-image","Blog Posts","search",{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":281},{},"navigation\u002Fsearch",60,[],"11e1fd31-95cd-4fc9-b736-8b8910663e6c","2024-10-21T23:17:05.904Z",[],{"name":23,"created_at":289,"published_at":290,"updated_at":291,"id":292,"uuid":21,"content":293,"slug":307,"full_slug":22,"sort_by_date":59,"position":308,"tag_list":309,"is_startpage":33,"parent_id":310,"meta_data":59,"group_id":311,"first_published_at":312,"release_id":59,"lang":65,"path":59,"alternates":313,"default_full_slug":59,"translated_slugs":59},"2022-09-19T14:42:29.685Z","2024-07-30T18:17:22.506Z","2024-07-30T18:17:22.525Z",2660,{"_uid":294,"icon":13,"name":23,"guides":295,"pinned":24,"summary":296,"category":13,"component":297,"blog_posts":298,"content_hub":24,"icon_custom":299,"case_studies":300,"faq_sections":301,"help_articles":302,"featured_guides":303,"mailbox_category":13,"featured_articles":304,"featured_blog_posts":305,"featured_case_studies":306},"d6dae89a-907a-4bf7-82de-fe2ba875ee6e",[],"Get your questions answered with our browsable knowledge base.","help_center_category",[],{"id":59,"alt":59,"name":13,"focus":59,"title":59,"filename":13,"copyright":59,"fieldtype":81},[],[],[],[],[],[],[],"categories",530,[],2658,"19ebcdd2-027f-47f5-9a5b-a8992c959578","2022-09-19T16:24:39.219Z",[],{"name":315,"created_at":316,"published_at":317,"updated_at":318,"id":319,"uuid":320,"content":321,"slug":714,"full_slug":715,"sort_by_date":59,"position":716,"tag_list":717,"is_startpage":24,"parent_id":718,"meta_data":59,"group_id":719,"first_published_at":317,"release_id":59,"lang":65,"path":59,"alternates":720,"default_full_slug":59,"translated_slugs":59},"Sign product forms with HMAC","2026-06-29T20:17:58.619Z","2026-06-29T20:50:24.473Z","2026-06-29T20:50:24.502Z",192817883676515,"79675f4b-0ab8-41cd-8a21-8ab9c8c3af18",{"_uid":322,"body":323,"name":315,"image":709,"pinned":24,"summary":711,"category":712,"component":266,"related_articles":713},"18faf735-5cc8-40f4-ab7c-243bf91f3c0e",{"type":324,"content":325},"doc",[326,340,347,352,388,404,430,436,441,446,451,507,512,544,549,554,569,574,591,596,610,615],{"type":327,"attrs":328,"content":329},"paragraph",{"textAlign":59},[330,333,338],{"text":331,"type":332},"Signing a product form with HMAC means generating a SHA-256 hash for each input and appending it to the input’s ","text",{"text":334,"type":332,"marks":335},"name",[336],{"type":337},"code",{"text":339,"type":332}," attribute. Foxy checks these hashes when the form is submitted — any unsigned or modified value is rejected.",{"type":341,"attrs":342,"content":344},"heading",{"level":343,"textAlign":59},2,[345],{"text":346,"type":332},"How signing works",{"type":327,"attrs":348,"content":349},{"textAlign":59},[350],{"text":351,"type":332},"For each input, concatenate three values in this order:",{"type":353,"attrs":354,"content":356},"ordered_list",{"order":355},1,[357,368,378],{"type":358,"content":359},"list_item",[360],{"type":327,"attrs":361,"content":362},{"textAlign":59},[363,365],{"text":364,"type":332},"The product ",{"text":337,"type":332,"marks":366},[367],{"type":337},{"type":358,"content":369},[370],{"type":327,"attrs":371,"content":372},{"textAlign":59},[373,375],{"text":374,"type":332},"The input’s ",{"text":334,"type":332,"marks":376},[377],{"type":337},{"type":358,"content":379},[380],{"type":327,"attrs":381,"content":382},{"textAlign":59},[383,384],{"text":374,"type":332},{"text":385,"type":332,"marks":386},"value",[387],{"type":337},{"type":327,"attrs":389,"content":390},{"textAlign":59},[391,393,396,398,402],{"text":392,"type":332},"Then HMAC SHA-256 that string using your store’s API key, and append the resulting 64-character hash to the ",{"text":334,"type":332,"marks":394},[395],{"type":337},{"text":397,"type":332}," attribute using double pipes (",{"text":399,"type":332,"marks":400},"||",[401],{"type":337},{"text":403,"type":332},").",{"type":327,"attrs":405,"content":406},{"textAlign":59},[407,409,412,414,418,420,423,424,428],{"text":408,"type":332},"For example, a product with ",{"text":337,"type":332,"marks":410},[411],{"type":337},{"text":413,"type":332}," of ",{"text":415,"type":332,"marks":416},"abc123",[417],{"type":337},{"text":419,"type":332}," and ",{"text":334,"type":332,"marks":421},[422],{"type":337},{"text":413,"type":332},{"text":425,"type":332,"marks":426},"Example T-Shirt",[427],{"type":337},{"text":429,"type":332},":",{"type":431,"attrs":432,"content":433},"code_block",{"class":59},[434],{"text":435,"type":332},"hash_hmac('sha256', 'abc123nameExample T-Shirt', $api_key);\n",{"type":327,"attrs":437,"content":438},{"textAlign":59},[439],{"text":440,"type":332},"The signed input looks like this:",{"type":431,"attrs":442,"content":443},{"class":59},[444],{"text":445,"type":332},"\u003Cinput type=\"hidden\" name=\"name||f8d3b7b993380dee31ee467984397ed8dc5feec3eb464bc55264cbe33fd691ac\" value=\"Example T-Shirt\" \u002F>\n",{"type":341,"attrs":447,"content":448},{"level":343,"textAlign":59},[449],{"text":450,"type":332},"Steps",{"type":353,"attrs":452,"content":453},{"order":355},[454,476,483,500],{"type":358,"content":455},[456],{"type":327,"attrs":457,"content":458},{"textAlign":59},[459,461,464,466,469,471,474],{"text":460,"type":332},"For each product input, concatenate the product ",{"text":337,"type":332,"marks":462},[463],{"type":337},{"text":465,"type":332},", input ",{"text":334,"type":332,"marks":467},[468],{"type":337},{"text":470,"type":332},", and input ",{"text":385,"type":332,"marks":472},[473],{"type":337},{"text":475,"type":332}," into a single string.",{"type":358,"content":477},[478],{"type":327,"attrs":479,"content":480},{"textAlign":59},[481],{"text":482,"type":332},"Generate an HMAC SHA-256 hash of that string using your store’s API key.",{"type":358,"content":484},[485],{"type":327,"attrs":486,"content":487},{"textAlign":59},[488,490,493,495,498],{"text":489,"type":332},"Append ",{"text":399,"type":332,"marks":491},[492],{"type":337},{"text":494,"type":332}," and the hash to the input’s ",{"text":334,"type":332,"marks":496},[497],{"type":337},{"text":499,"type":332}," attribute.",{"type":358,"content":501},[502],{"type":327,"attrs":503,"content":504},{"textAlign":59},[505],{"text":506,"type":332},"Repeat for every input on every add-to-cart form.",{"type":341,"attrs":508,"content":509},{"level":343,"textAlign":59},[510],{"text":511,"type":332},"Select and radio inputs",{"type":327,"attrs":513,"content":514},{"textAlign":59},[515,517,521,522,526,528,531,533,537,539,542],{"text":516,"type":332},"For ",{"text":518,"type":332,"marks":519},"\u003Cselect>",[520],{"type":337},{"text":419,"type":332},{"text":523,"type":332,"marks":524},"\u003Cradio>",[525],{"type":337},{"text":527,"type":332}," elements, append the hash to the ",{"text":385,"type":332,"marks":529},[530],{"type":337},{"text":532,"type":332}," attribute of each ",{"text":534,"type":332,"marks":535},"\u003Coption>",[536],{"type":337},{"text":538,"type":332}," rather than the ",{"text":334,"type":332,"marks":540},[541],{"type":337},{"text":543,"type":332},". The concatenation is the same — code, name, and value:",{"type":431,"attrs":545,"content":546},{"class":59},[547],{"text":548,"type":332},"\u003Cselect name=\"size\">\n  \u003Coption value=\"small{p-2}||14696b9ff099727a798a5b59d71bc1540a5481adfd957ed2252acf8aec83914a\">Small\u003C\u002Foption>\n  \u003Coption value=\"medium||713800d729f987d4609a8b83b60932e64f64690b4c2842b7d6522a62fe514af4\">Medium\u003C\u002Foption>\n  \u003Coption value=\"large{p+3}||c8d37d7c32c3c4fc9fe9703e8cc3456020aa9319dd18816d7f887c6f9c616708\">Large\u003C\u002Foption>\n\u003C\u002Fselect>\n",{"type":341,"attrs":550,"content":551},{"level":343,"textAlign":59},[552],{"text":553,"type":332},"PHP helper function",{"type":327,"attrs":555,"content":556},{"textAlign":59},[557,559,562,564,567],{"text":558,"type":332},"If you are using PHP, you can use this helper function to generate signed ",{"text":334,"type":332,"marks":560},[561],{"type":337},{"text":563,"type":332}," or ",{"text":385,"type":332,"marks":565},[566],{"type":337},{"text":568,"type":332}," attributes:",{"type":431,"attrs":570,"content":571},{"class":59},[572],{"text":573,"type":332},"function get_verification($var_name, $var_value, $var_code, $var_parent_code = \"\", $for_value = false) {\n    $api_key = \"your_api_key_here\";\n    $encodingval = htmlspecialchars($var_code . $var_parent_code . $var_name . $var_value);\n    $label = ($for_value) ? $var_value : $var_name;\n    return $label . '||' . hash_hmac('sha256', $encodingval, $api_key) . ($var_value === \"--OPEN--\" ? \"||open\" : \"\");\n}\n",{"type":327,"attrs":575,"content":576},{"textAlign":59},[577,579,583,585,589],{"text":578,"type":332},"Pass ",{"text":580,"type":332,"marks":581},"true",[582],{"type":337},{"text":584,"type":332}," as the fifth argument (",{"text":586,"type":332,"marks":587},"$for_value",[588],{"type":337},{"text":590,"type":332},") when signing select or radio option values:",{"type":431,"attrs":592,"content":593},{"class":59},[594],{"text":595,"type":332},"\u003Coption value=\"\u003C?php echo get_verification('size', 'small{p-2}', 'abc123', '', true); ?>\">Small\u003C\u002Foption>\n",{"type":327,"attrs":597,"content":598},{"textAlign":59},[599,601,608],{"text":600,"type":332},"For a fully automatic approach that signs an entire HTML page at once, see the ",{"text":602,"type":332,"marks":603},"FoxyCart Cart Validation PHP library on GitHub",[604],{"type":605,"attrs":606},"link",{"href":607,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Fgithub.com\u002Ffoxycart\u002Ffoxycart-cart-validation",{"text":609,"type":332},".",{"type":341,"attrs":611,"content":612},{"level":343,"textAlign":59},[613],{"text":614,"type":332},"Notes",{"type":616,"content":617},"bullet_list",[618,647,667,681,695],{"type":358,"content":619},[620],{"type":327,"attrs":621,"content":622},{"textAlign":59},[623,625,628,630,633,635,639,641,645],{"text":624,"type":332},"Every input that relates to a product must be signed — not just ",{"text":334,"type":332,"marks":626},[627],{"type":337},{"text":629,"type":332},", ",{"text":337,"type":332,"marks":631},[632],{"type":337},{"text":634,"type":332},", and ",{"text":636,"type":332,"marks":637},"price",[638],{"type":337},{"text":640,"type":332},". An unsigned ",{"text":642,"type":332,"marks":643},"size",[644],{"type":337},{"text":646,"type":332}," option with a price modifier could be used to manipulate the price.",{"type":358,"content":648},[649],{"type":327,"attrs":650,"content":651},{"textAlign":59},[652,654,658,660,666],{"text":653,"type":332},"For open (user-editable) fields such as ",{"text":655,"type":332,"marks":656},"quantity",[657],{"type":337},{"text":659,"type":332},", see ",{"text":661,"type":332,"marks":662},"Sign open fields with HMAC",[663],{"type":605,"attrs":664},{"href":665,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-open-user-editable-fields-with-hmac",{"text":609,"type":332},{"type":358,"content":668},[669],{"type":327,"attrs":670,"content":671},{"textAlign":59},[672,674,680],{"text":673,"type":332},"For bundled products, see ",{"text":675,"type":332,"marks":676},"Sign bundled products with HMAC",[677],{"type":605,"attrs":678},{"href":679,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-bundled-products-with-hmac",{"text":609,"type":332},{"type":358,"content":682},[683],{"type":327,"attrs":684,"content":685},{"textAlign":59},[686,688,694],{"text":687,"type":332},"For multiple products in one form, see ",{"text":689,"type":332,"marks":690},"Sign multiple products in one form with HMAC",[691],{"type":605,"attrs":692},{"href":693,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-multiple-products-in-one-form-with-hmac",{"text":609,"type":332},{"type":358,"content":696},[697],{"type":327,"attrs":698,"content":699},{"textAlign":59},[700,702,708],{"text":701,"type":332},"For parameters that do not need to be signed, see ",{"text":703,"type":332,"marks":704},"HMAC excluded parameters reference",[705],{"type":605,"attrs":706},{"href":707,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fhmac-excluded-parameters-reference",{"text":609,"type":332},{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":710},{},"How to sign your add to cart form inputs with HMAC to prevent tampering.","ff9269e2-2402-422e-aa80-19acc150b78a",[],"sign-product-forms-with-hmac","help\u002Farticles\u002Fsign-product-forms-with-hmac",-2480,[],2659,"41ea04bf-0b7d-4d21-8e54-be88d75b84c2",[],{"html":722,"sections":723,"segments":735},"\u003Cp>Signing a product form with HMAC means generating a SHA-256 hash for each input and appending it to the input’s \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode> attribute. Foxy checks these hashes when the form is submitted — any unsigned or modified value is rejected.\u003C\u002Fp>\u003Csection id=\"how-signing-works\" data-title=\"How signing works\" data-title-node=\"H2\">\u003Chr class=\"my-8\" style=\"margin-left: -48px; margin-right: -40vw\">\u003Ch2 data-anchor-id=\"how-signing-works\">How signing works\u003C\u002Fh2>\u003Cp>For each input, concatenate three values in this order:\u003C\u002Fp>\u003Col class=\"step step-icon-sm step-dashed step-border-last-0 mt-3\">\u003Cli class=\"step-item\">\u003Cdiv class=\"step-content-wrapper\">\u003Cspan class=\"step-icon step-icon-soft-primary\">1\u003C\u002Fspan>\u003Cdiv class=\"w-100 overflow-hidden\">\u003Cdiv class=\"step-content mt-2\">\u003Cp>The product \u003Ccode class=\"badge bg-soft-danger text-danger\">code\u003C\u002Fcode>\u003C\u002Fp>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fli>\u003Cli class=\"step-item\">\u003Cdiv class=\"step-content-wrapper\">\u003Cspan class=\"step-icon step-icon-soft-primary\">2\u003C\u002Fspan>\u003Cdiv class=\"w-100 overflow-hidden\">\u003Cdiv class=\"step-content mt-2\">\u003Cp>The input’s \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode>\u003C\u002Fp>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fli>\u003Cli class=\"step-item\">\u003Cdiv class=\"step-content-wrapper\">\u003Cspan class=\"step-icon step-icon-soft-primary\">3\u003C\u002Fspan>\u003Cdiv class=\"w-100 overflow-hidden\">\u003Cdiv class=\"step-content mt-2\">\u003Cp>The input’s \u003Ccode class=\"badge bg-soft-danger text-danger\">value\u003C\u002Fcode>\u003C\u002Fp>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Then HMAC SHA-256 that string using your store’s API key, and append the resulting 64-character hash to the \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode> attribute using double pipes (\u003Ccode class=\"badge bg-soft-danger text-danger\">||\u003C\u002Fcode>).\u003C\u002Fp>\u003Cp>For example, a product with \u003Ccode class=\"badge bg-soft-danger text-danger\">code\u003C\u002Fcode> of \u003Ccode class=\"badge bg-soft-danger text-danger\">abc123\u003C\u002Fcode> and \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode> of \u003Ccode class=\"badge bg-soft-danger text-danger\">Example T-Shirt\u003C\u002Fcode>:\u003C\u002Fp>\u003Cdiv class=\"position-relative w-100 overflow-hidden rounded-2\" data-code-block>\u003Cdiv class=\"d-flex justify-content-end border-bottom\" style=\"background:#2b2c3b;\">\u003Cbutton type=\"button\" class=\"btn btn-link btn-sm text-light\" title=\"Copy\" data-code-button>\u003Cspan data-code-default style=\"\">\u003Ci class=\"fal fa-copy me-2\">\u003C\u002Fi> Copy \u003C\u002Fspan>\u003Cspan class=\"text-success\" data-code-success style=\"display:none;\">\u003Ci class=\"fal fa-check ms-2\">\u003C\u002Fi> Copied \u003C\u002Fspan>\u003C\u002Fbutton>\u003C\u002Fdiv>\u003Cdiv class=\"small\">\u003Cpre class=\"hljs p-2\" data-code-content>hash_hmac(&#x27;sha256&#x27;, &#x27;abc123nameExample T-Shirt&#x27;, $api_key);\n\u003C\u002Fpre>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cp>The signed input looks like this:\u003C\u002Fp>\u003Cdiv class=\"position-relative w-100 overflow-hidden rounded-2\" data-code-block>\u003Cdiv class=\"d-flex justify-content-end border-bottom\" style=\"background:#2b2c3b;\">\u003Cbutton type=\"button\" class=\"btn btn-link btn-sm text-light\" title=\"Copy\" data-code-button>\u003Cspan data-code-default style=\"\">\u003Ci class=\"fal fa-copy me-2\">\u003C\u002Fi> Copy \u003C\u002Fspan>\u003Cspan class=\"text-success\" data-code-success style=\"display:none;\">\u003Ci class=\"fal fa-check ms-2\">\u003C\u002Fi> Copied \u003C\u002Fspan>\u003C\u002Fbutton>\u003C\u002Fdiv>\u003Cdiv class=\"small\">\u003Cpre class=\"hljs p-2\" data-code-content>\u003Cspan class=\"hljs-tag\">&lt;\u003Cspan class=\"hljs-name\">input\u003C\u002Fspan> \u003Cspan class=\"hljs-attr\">type\u003C\u002Fspan>=\u003Cspan class=\"hljs-string\">&quot;hidden&quot;\u003C\u002Fspan> \u003Cspan class=\"hljs-attr\">name\u003C\u002Fspan>=\u003Cspan class=\"hljs-string\">&quot;name||f8d3b7b993380dee31ee467984397ed8dc5feec3eb464bc55264cbe33fd691ac&quot;\u003C\u002Fspan> \u003Cspan class=\"hljs-attr\">value\u003C\u002Fspan>=\u003Cspan class=\"hljs-string\">&quot;Example T-Shirt&quot;\u003C\u002Fspan> \u002F&gt;\u003C\u002Fspan>\n\u003C\u002Fpre>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\u003Csection id=\"steps\" data-title=\"Steps\" data-title-node=\"H2\">\u003Chr class=\"my-8\" style=\"margin-left: -48px; margin-right: -40vw\">\u003Ch2 data-anchor-id=\"steps\">Steps\u003C\u002Fh2>\u003Col class=\"step step-icon-sm step-dashed step-border-last-0 mt-3\">\u003Cli class=\"step-item\">\u003Cdiv class=\"step-content-wrapper\">\u003Cspan class=\"step-icon step-icon-soft-primary\">1\u003C\u002Fspan>\u003Cdiv class=\"w-100 overflow-hidden\">\u003Cdiv class=\"step-content mt-2\">\u003Cp>For each product input, concatenate the product \u003Ccode class=\"badge bg-soft-danger text-danger\">code\u003C\u002Fcode>, input \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode>, and input \u003Ccode class=\"badge bg-soft-danger text-danger\">value\u003C\u002Fcode> into a single string.\u003C\u002Fp>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fli>\u003Cli class=\"step-item\">\u003Cdiv class=\"step-content-wrapper\">\u003Cspan class=\"step-icon step-icon-soft-primary\">2\u003C\u002Fspan>\u003Cdiv class=\"w-100 overflow-hidden\">\u003Cdiv class=\"step-content mt-2\">\u003Cp>Generate an HMAC SHA-256 hash of that string using your store’s API key.\u003C\u002Fp>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fli>\u003Cli class=\"step-item\">\u003Cdiv class=\"step-content-wrapper\">\u003Cspan class=\"step-icon step-icon-soft-primary\">3\u003C\u002Fspan>\u003Cdiv class=\"w-100 overflow-hidden\">\u003Cdiv class=\"step-content mt-2\">\u003Cp>Append \u003Ccode class=\"badge bg-soft-danger text-danger\">||\u003C\u002Fcode> and the hash to the input’s \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode> attribute.\u003C\u002Fp>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fli>\u003Cli class=\"step-item\">\u003Cdiv class=\"step-content-wrapper\">\u003Cspan class=\"step-icon step-icon-soft-primary\">4\u003C\u002Fspan>\u003Cdiv class=\"w-100 overflow-hidden\">\u003Cdiv class=\"step-content mt-2\">\u003Cp>Repeat for every input on every add-to-cart form.\u003C\u002Fp>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fsection>\u003Csection id=\"select-and-radio-inputs\" data-title=\"Select and radio inputs\" data-title-node=\"H2\">\u003Chr class=\"my-8\" style=\"margin-left: -48px; margin-right: -40vw\">\u003Ch2 data-anchor-id=\"select-and-radio-inputs\">Select and radio inputs\u003C\u002Fh2>\u003Cp>For \u003Ccode class=\"badge bg-soft-danger text-danger\">&lt;select&gt;\u003C\u002Fcode> and \u003Ccode class=\"badge bg-soft-danger text-danger\">&lt;radio&gt;\u003C\u002Fcode> elements, append the hash to the \u003Ccode class=\"badge bg-soft-danger text-danger\">value\u003C\u002Fcode> attribute of each \u003Ccode class=\"badge bg-soft-danger text-danger\">&lt;option&gt;\u003C\u002Fcode> rather than the \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode>. The concatenation is the same — code, name, and value:\u003C\u002Fp>\u003Cdiv class=\"position-relative w-100 overflow-hidden rounded-2\" data-code-block>\u003Cdiv class=\"d-flex justify-content-end border-bottom\" style=\"background:#2b2c3b;\">\u003Cbutton type=\"button\" class=\"btn btn-link btn-sm text-light\" title=\"Copy\" data-code-button>\u003Cspan data-code-default style=\"\">\u003Ci class=\"fal fa-copy me-2\">\u003C\u002Fi> Copy \u003C\u002Fspan>\u003Cspan class=\"text-success\" data-code-success style=\"display:none;\">\u003Ci class=\"fal fa-check ms-2\">\u003C\u002Fi> Copied \u003C\u002Fspan>\u003C\u002Fbutton>\u003C\u002Fdiv>\u003Cdiv class=\"small\">\u003Cpre class=\"hljs p-2\" data-code-content>\u003Cspan class=\"hljs-tag\">&lt;\u003Cspan class=\"hljs-name\">select\u003C\u002Fspan> \u003Cspan class=\"hljs-attr\">name\u003C\u002Fspan>=\u003Cspan class=\"hljs-string\">&quot;size&quot;\u003C\u002Fspan>&gt;\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-tag\">&lt;\u003Cspan class=\"hljs-name\">option\u003C\u002Fspan> \u003Cspan class=\"hljs-attr\">value\u003C\u002Fspan>=\u003Cspan class=\"hljs-string\">&quot;small{p-2}||14696b9ff099727a798a5b59d71bc1540a5481adfd957ed2252acf8aec83914a&quot;\u003C\u002Fspan>&gt;\u003C\u002Fspan>Small\u003Cspan class=\"hljs-tag\">&lt;\u002F\u003Cspan class=\"hljs-name\">option\u003C\u002Fspan>&gt;\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-tag\">&lt;\u003Cspan class=\"hljs-name\">option\u003C\u002Fspan> \u003Cspan class=\"hljs-attr\">value\u003C\u002Fspan>=\u003Cspan class=\"hljs-string\">&quot;medium||713800d729f987d4609a8b83b60932e64f64690b4c2842b7d6522a62fe514af4&quot;\u003C\u002Fspan>&gt;\u003C\u002Fspan>Medium\u003Cspan class=\"hljs-tag\">&lt;\u002F\u003Cspan class=\"hljs-name\">option\u003C\u002Fspan>&gt;\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-tag\">&lt;\u003Cspan class=\"hljs-name\">option\u003C\u002Fspan> \u003Cspan class=\"hljs-attr\">value\u003C\u002Fspan>=\u003Cspan class=\"hljs-string\">&quot;large{p+3}||c8d37d7c32c3c4fc9fe9703e8cc3456020aa9319dd18816d7f887c6f9c616708&quot;\u003C\u002Fspan>&gt;\u003C\u002Fspan>Large\u003Cspan class=\"hljs-tag\">&lt;\u002F\u003Cspan class=\"hljs-name\">option\u003C\u002Fspan>&gt;\u003C\u002Fspan>\n\u003Cspan class=\"hljs-tag\">&lt;\u002F\u003Cspan class=\"hljs-name\">select\u003C\u002Fspan>&gt;\u003C\u002Fspan>\n\u003C\u002Fpre>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\u003Csection id=\"php-helper-function\" data-title=\"PHP helper function\" data-title-node=\"H2\">\u003Chr class=\"my-8\" style=\"margin-left: -48px; margin-right: -40vw\">\u003Ch2 data-anchor-id=\"php-helper-function\">PHP helper function\u003C\u002Fh2>\u003Cp>If you are using PHP, you can use this helper function to generate signed \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode> or \u003Ccode class=\"badge bg-soft-danger text-danger\">value\u003C\u002Fcode> attributes:\u003C\u002Fp>\u003Cdiv class=\"position-relative w-100 overflow-hidden rounded-2\" data-code-block>\u003Cdiv class=\"d-flex justify-content-end border-bottom\" style=\"background:#2b2c3b;\">\u003Cbutton type=\"button\" class=\"btn btn-link btn-sm text-light\" title=\"Copy\" data-code-button>\u003Cspan data-code-default style=\"\">\u003Ci class=\"fal fa-copy me-2\">\u003C\u002Fi> Copy \u003C\u002Fspan>\u003Cspan class=\"text-success\" data-code-success style=\"display:none;\">\u003Ci class=\"fal fa-check ms-2\">\u003C\u002Fi> Copied \u003C\u002Fspan>\u003C\u002Fbutton>\u003C\u002Fdiv>\u003Cdiv class=\"small\">\u003Cpre class=\"hljs p-2\" data-code-content>function get_verification($var_name, $var_value, $var_code, $var_parent_code = &quot;&quot;, $for_value = false) {\n    $api_key = &quot;your_api_key_here&quot;;\n    $encodingval = htmlspecialchars($var_code . $var_parent_code . $var_name . $var_value);\n    $label = ($for_value) ? $var_value : $var_name;\n    return $label . &#x27;||&#x27; . hash_hmac(&#x27;sha256&#x27;, $encodingval, $api_key) . ($var_value === &quot;--OPEN--&quot; ? &quot;||open&quot; : &quot;&quot;);\n}\n\u003C\u002Fpre>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cp>Pass \u003Ccode class=\"badge bg-soft-danger text-danger\">true\u003C\u002Fcode> as the fifth argument (\u003Ccode class=\"badge bg-soft-danger text-danger\">$for_value\u003C\u002Fcode>) when signing select or radio option values:\u003C\u002Fp>\u003Cdiv class=\"position-relative w-100 overflow-hidden rounded-2\" data-code-block>\u003Cdiv class=\"d-flex justify-content-end border-bottom\" style=\"background:#2b2c3b;\">\u003Cbutton type=\"button\" class=\"btn btn-link btn-sm text-light\" title=\"Copy\" data-code-button>\u003Cspan data-code-default style=\"\">\u003Ci class=\"fal fa-copy me-2\">\u003C\u002Fi> Copy \u003C\u002Fspan>\u003Cspan class=\"text-success\" data-code-success style=\"display:none;\">\u003Ci class=\"fal fa-check ms-2\">\u003C\u002Fi> Copied \u003C\u002Fspan>\u003C\u002Fbutton>\u003C\u002Fdiv>\u003Cdiv class=\"small\">\u003Cpre class=\"hljs p-2\" data-code-content>\u003Cspan class=\"hljs-tag\">&lt;\u003Cspan class=\"hljs-name\">option\u003C\u002Fspan> \u003Cspan class=\"hljs-attr\">value\u003C\u002Fspan>=\u003Cspan class=\"hljs-string\">&quot;&lt;?php echo get_verification(&#x27;size&#x27;, &#x27;small{p-2}&#x27;, &#x27;abc123&#x27;, &#x27;&#x27;, true); ?&gt;&quot;\u003C\u002Fspan>&gt;\u003C\u002Fspan>Small\u003Cspan class=\"hljs-tag\">&lt;\u002F\u003Cspan class=\"hljs-name\">option\u003C\u002Fspan>&gt;\u003C\u002Fspan>\n\u003C\u002Fpre>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cp>For a fully automatic approach that signs an entire HTML page at once, see the \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ffoxycart\u002Ffoxycart-cart-validation\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">FoxyCart Cart Validation PHP library on GitHub\u003C\u002Fa>.\u003C\u002Fp>\u003C\u002Fsection>\u003Csection id=\"notes\" data-title=\"Notes\" data-title-node=\"H2\">\u003Chr class=\"my-8\" style=\"margin-left: -48px; margin-right: -40vw\">\u003Ch2 data-anchor-id=\"notes\">Notes\u003C\u002Fh2>\u003Cul>\u003Cli>\u003Cp>Every input that relates to a product must be signed — not just \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode>, \u003Ccode class=\"badge bg-soft-danger text-danger\">code\u003C\u002Fcode>, and \u003Ccode class=\"badge bg-soft-danger text-danger\">price\u003C\u002Fcode>. An unsigned \u003Ccode class=\"badge bg-soft-danger text-danger\">size\u003C\u002Fcode> option with a price modifier could be used to manipulate the price.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>For open (user-editable) fields such as \u003Ccode class=\"badge bg-soft-danger text-danger\">quantity\u003C\u002Fcode>, see \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-open-user-editable-fields-with-hmac\" class=\"\">Sign open fields with HMAC\u003C\u002Fa>.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>For bundled products, see \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-bundled-products-with-hmac\" class=\"\">Sign bundled products with HMAC\u003C\u002Fa>.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>For multiple products in one form, see \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-multiple-products-in-one-form-with-hmac\" class=\"\">Sign multiple products in one form with HMAC\u003C\u002Fa>.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>For parameters that do not need to be signed, see \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fhmac-excluded-parameters-reference\" class=\"\">HMAC excluded parameters reference\u003C\u002Fa>.\u003C\u002Fp>\u003C\u002Fli>\u003C\u002Ful>\u003C\u002Fsection>",[724,727,729,731,733],{"id":725,"title":346,"level":726},"how-signing-works","H2",{"id":728,"title":450,"level":726},"steps",{"id":730,"title":511,"level":726},"select-and-radio-inputs",{"id":732,"title":553,"level":726},"php-helper-function",{"id":734,"title":614,"level":726},"notes",[736],{"type":737,"content":738},"html","\u003Cp>Signing a product form with HMAC means generating a SHA-256 hash for each input and appending it to the input’s \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode> attribute. Foxy checks these hashes when the form is submitted — any unsigned or modified value is rejected.\u003C\u002Fp>\u003Ch2>How signing works\u003C\u002Fh2>\u003Cp>For each input, concatenate three values in this order:\u003C\u002Fp>\u003Col order=\"1\">\u003Cli>\u003Cp>The product \u003Ccode class=\"badge bg-soft-danger text-danger\">code\u003C\u002Fcode>\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>The input’s \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode>\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>The input’s \u003Ccode class=\"badge bg-soft-danger text-danger\">value\u003C\u002Fcode>\u003C\u002Fp>\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Then HMAC SHA-256 that string using your store’s API key, and append the resulting 64-character hash to the \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode> attribute using double pipes (\u003Ccode class=\"badge bg-soft-danger text-danger\">||\u003C\u002Fcode>).\u003C\u002Fp>\u003Cp>For example, a product with \u003Ccode class=\"badge bg-soft-danger text-danger\">code\u003C\u002Fcode> of \u003Ccode class=\"badge bg-soft-danger text-danger\">abc123\u003C\u002Fcode> and \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode> of \u003Ccode class=\"badge bg-soft-danger text-danger\">Example T-Shirt\u003C\u002Fcode>:\u003C\u002Fp>\u003Cpre>\u003Ccode>hash_hmac(&#039;sha256&#039;, &#039;abc123nameExample T-Shirt&#039;, $api_key);\n\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp>The signed input looks like this:\u003C\u002Fp>\u003Cpre>\u003Ccode>&lt;input type=&quot;hidden&quot; name=&quot;name||f8d3b7b993380dee31ee467984397ed8dc5feec3eb464bc55264cbe33fd691ac&quot; value=&quot;Example T-Shirt&quot; \u002F&gt;\n\u003C\u002Fcode>\u003C\u002Fpre>\u003Ch2>Steps\u003C\u002Fh2>\u003Col order=\"1\">\u003Cli>\u003Cp>For each product input, concatenate the product \u003Ccode class=\"badge bg-soft-danger text-danger\">code\u003C\u002Fcode>, input \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode>, and input \u003Ccode class=\"badge bg-soft-danger text-danger\">value\u003C\u002Fcode> into a single string.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>Generate an HMAC SHA-256 hash of that string using your store’s API key.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>Append \u003Ccode class=\"badge bg-soft-danger text-danger\">||\u003C\u002Fcode> and the hash to the input’s \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode> attribute.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>Repeat for every input on every add-to-cart form.\u003C\u002Fp>\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>Select and radio inputs\u003C\u002Fh2>\u003Cp>For \u003Ccode class=\"badge bg-soft-danger text-danger\">&lt;select&gt;\u003C\u002Fcode> and \u003Ccode class=\"badge bg-soft-danger text-danger\">&lt;radio&gt;\u003C\u002Fcode> elements, append the hash to the \u003Ccode class=\"badge bg-soft-danger text-danger\">value\u003C\u002Fcode> attribute of each \u003Ccode class=\"badge bg-soft-danger text-danger\">&lt;option&gt;\u003C\u002Fcode> rather than the \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode>. The concatenation is the same — code, name, and value:\u003C\u002Fp>\u003Cpre>\u003Ccode>&lt;select name=&quot;size&quot;&gt;\n  &lt;option value=&quot;small{p-2}||14696b9ff099727a798a5b59d71bc1540a5481adfd957ed2252acf8aec83914a&quot;&gt;Small&lt;\u002Foption&gt;\n  &lt;option value=&quot;medium||713800d729f987d4609a8b83b60932e64f64690b4c2842b7d6522a62fe514af4&quot;&gt;Medium&lt;\u002Foption&gt;\n  &lt;option value=&quot;large{p+3}||c8d37d7c32c3c4fc9fe9703e8cc3456020aa9319dd18816d7f887c6f9c616708&quot;&gt;Large&lt;\u002Foption&gt;\n&lt;\u002Fselect&gt;\n\u003C\u002Fcode>\u003C\u002Fpre>\u003Ch2>PHP helper function\u003C\u002Fh2>\u003Cp>If you are using PHP, you can use this helper function to generate signed \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode> or \u003Ccode class=\"badge bg-soft-danger text-danger\">value\u003C\u002Fcode> attributes:\u003C\u002Fp>\u003Cpre>\u003Ccode>function get_verification($var_name, $var_value, $var_code, $var_parent_code = &quot;&quot;, $for_value = false) {\n    $api_key = &quot;your_api_key_here&quot;;\n    $encodingval = htmlspecialchars($var_code . $var_parent_code . $var_name . $var_value);\n    $label = ($for_value) ? $var_value : $var_name;\n    return $label . &#039;||&#039; . hash_hmac(&#039;sha256&#039;, $encodingval, $api_key) . ($var_value === &quot;--OPEN--&quot; ? &quot;||open&quot; : &quot;&quot;);\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp>Pass \u003Ccode class=\"badge bg-soft-danger text-danger\">true\u003C\u002Fcode> as the fifth argument (\u003Ccode class=\"badge bg-soft-danger text-danger\">$for_value\u003C\u002Fcode>) when signing select or radio option values:\u003C\u002Fp>\u003Cpre>\u003Ccode>&lt;option value=&quot;&lt;?php echo get_verification(&#039;size&#039;, &#039;small{p-2}&#039;, &#039;abc123&#039;, &#039;&#039;, true); ?&gt;&quot;&gt;Small&lt;\u002Foption&gt;\n\u003C\u002Fcode>\u003C\u002Fpre>\u003Cp>For a fully automatic approach that signs an entire HTML page at once, see the \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ffoxycart\u002Ffoxycart-cart-validation\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"\">FoxyCart Cart Validation PHP library on GitHub\u003C\u002Fa>.\u003C\u002Fp>\u003Ch2>Notes\u003C\u002Fh2>\u003Cul>\u003Cli>\u003Cp>Every input that relates to a product must be signed — not just \u003Ccode class=\"badge bg-soft-danger text-danger\">name\u003C\u002Fcode>, \u003Ccode class=\"badge bg-soft-danger text-danger\">code\u003C\u002Fcode>, and \u003Ccode class=\"badge bg-soft-danger text-danger\">price\u003C\u002Fcode>. An unsigned \u003Ccode class=\"badge bg-soft-danger text-danger\">size\u003C\u002Fcode> option with a price modifier could be used to manipulate the price.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>For open (user-editable) fields such as \u003Ccode class=\"badge bg-soft-danger text-danger\">quantity\u003C\u002Fcode>, see \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-open-user-editable-fields-with-hmac\" class=\"\">Sign open fields with HMAC\u003C\u002Fa>.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>For bundled products, see \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-bundled-products-with-hmac\" class=\"\">Sign bundled products with HMAC\u003C\u002Fa>.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>For multiple products in one form, see \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-multiple-products-in-one-form-with-hmac\" class=\"\">Sign multiple products in one form with HMAC\u003C\u002Fa>.\u003C\u002Fp>\u003C\u002Fli>\u003Cli>\u003Cp>For parameters that do not need to be signed, see \u003Ca href=\"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fhmac-excluded-parameters-reference\" class=\"\">HMAC excluded parameters reference\u003C\u002Fa>.\u003C\u002Fp>\u003C\u002Fli>\u003C\u002Ful>",{"name":740,"created_at":741,"published_at":742,"updated_at":743,"id":744,"uuid":47,"content":745,"slug":48,"full_slug":48,"sort_by_date":59,"position":923,"tag_list":924,"is_startpage":24,"parent_id":59,"meta_data":59,"group_id":925,"first_published_at":926,"release_id":59,"lang":65,"path":59,"alternates":927,"default_full_slug":59,"translated_slugs":59},"Contact","2022-09-23T19:56:58.957Z","2025-05-08T18:24:40.382Z","2025-05-08T18:24:40.392Z",3138,{"seo":746,"_uid":749,"title":750,"action":751,"fields":752,"method":899,"columns":900,"subtitle":914,"component":48,"button_text":920,"submit_title":921,"submit_subtitle":922},{"_uid":747,"title":740,"plugin":748,"description":13},"24ff7574-3bcc-48d2-85b5-e529dfea1cc4","meta-fields","8f54f1da-9d8f-49b2-89e7-840e886491cb","We're here to help.","https:\u002F\u002Fusebasin.com\u002Ff\u002F029f48d65402",[753,757,761,870,873,878,893],{"_uid":754,"name":334,"type":332,"label":755,"options":13,"required":33,"component":756,"placeholder":13},"9a70b226-2036-4f90-a052-b3efa61c5896","Name","form___field",{"_uid":758,"name":759,"type":759,"label":760,"options":13,"required":33,"component":756,"placeholder":13},"86ba35be-ff43-4a28-8633-14052a8f6622","email","Email Address",{"_uid":762,"name":763,"type":764,"label":765,"options":766,"required":33,"component":756,"conditions":767,"placeholder":13},"3f827475-492c-4f97-aa1e-2386ac263b6c","topic","select","Topic","Presales, Support, Billing, Partnerships, Order Enquiry, Other",[768,824,834,841,849,857,863],{"_uid":769,"equals":770,"fields":771,"component":823},"e21d97dd-e68e-4fa6-ba97-bc40f3041dde","Order Enquiry",[772],{"_uid":773,"body":774,"type":821,"title":13,"component":822},"b64992bc-6d53-48b8-b7a0-d81e5a062e50",{"type":324,"content":775},[776],{"type":327,"content":777},[778,780,787,789,791,792,797,799,804,812,814,819],{"text":779,"type":332},"We are ",{"text":781,"type":332,"marks":782},"Foxy.io",[783],{"type":605,"attrs":784},{"href":785,"uuid":59,"anchor":59,"custom":786,"target":59,"linktype":31},"http:\u002F\u002FFoxy.io",{},{"text":788,"type":332},", an ecommerce platform powering ecommerce for other merchants. We do not sell products, and are unable to assist with questions about order statuses or refunds for any merchants using our platform. Please contact the merchant you ordered from for assistance. If you’d like to report a store using Foxy for fraudulent practices, please select ‘other’ in the subject.",{"type":790},"hard_break",{"type":790},{"text":793,"type":332,"marks":794},"NOTE:",[795],{"type":796},"bold",{"text":798,"type":332}," We are ",{"text":800,"type":332,"marks":801},"not ",[802],{"type":803},"italic",{"text":805,"type":332,"marks":806},"Foxy.in",[807,811],{"type":605,"attrs":808},{"href":809,"uuid":59,"anchor":59,"custom":810,"target":59,"linktype":31},"http:\u002F\u002FFoxy.in",{},{"type":803},{"text":813,"type":332},". We are not in any way affiliated with ",{"text":805,"type":332,"marks":815},[816],{"type":605,"attrs":817},{"href":809,"uuid":59,"anchor":59,"custom":818,"target":59,"linktype":31},{},{"text":820,"type":332},", and cannot help in any way with your order from that website.","danger","global___alert","form___condition",{"_uid":825,"equals":826,"fields":827,"component":823},"8765c3e1-25cf-44aa-b8ea-fc6094acf9c3","Presales",[828],{"_uid":829,"name":830,"type":831,"label":13,"options":13,"required":24,"component":756,"conditions":832,"placeholder":13,"default_value":833},"cf464f8e-d643-4f6e-af29-d3abffaf7380","department_email_address","hidden",[],"hello@foxy.io",{"_uid":835,"equals":208,"fields":836,"component":823},"4007b6d8-77e5-421d-bd1e-6f336dd853fb",[837],{"_uid":838,"name":830,"type":831,"label":13,"options":13,"required":24,"component":756,"conditions":839,"placeholder":13,"default_value":840},"7b4c6aa5-a68c-45e0-9ce1-0a36af10c0c2",[],"help@foxy.io",{"_uid":842,"equals":843,"fields":844,"component":823},"1dbb8f11-613d-43cd-9e09-1b94f6e19219","Billing",[845],{"_uid":846,"name":830,"type":831,"label":13,"options":13,"required":24,"component":756,"conditions":847,"placeholder":13,"default_value":848},"a0ac0d1b-bc4f-4a6c-a682-581d450b0b73",[],"help+billing@foxy.io",{"_uid":850,"equals":851,"fields":852,"component":823},"a0a53a50-7172-4a29-ba58-181e38874e12","Partnerships",[853],{"_uid":854,"name":830,"type":831,"label":13,"options":13,"required":24,"component":756,"conditions":855,"placeholder":13,"default_value":856},"7aa011d9-f374-4aed-b5a5-929b54aaf152",[],"partners@foxy.io",{"_uid":858,"equals":770,"fields":859,"component":823},"a4cd431f-25d5-41c7-bfdc-02c908c8fb47",[860],{"_uid":861,"name":830,"type":831,"label":13,"options":13,"required":24,"component":756,"conditions":862,"placeholder":13,"default_value":833},"f5d52168-d6ae-451b-94ee-2ced1cbd28ad",[],{"_uid":864,"equals":865,"fields":866,"component":823},"25aba1ed-eb41-4bbc-aa89-f7a7167ea86e","Other",[867],{"_uid":868,"name":830,"type":831,"label":13,"options":13,"required":24,"component":756,"conditions":869,"placeholder":13,"default_value":833},"f40dfaef-c203-4b71-bf4e-e1b43cef192b",[],{"_uid":871,"component":872},"e9c53a05-f40a-4510-aaf8-bc072a235a0c","form___subject",{"_uid":874,"name":875,"type":876,"label":877,"options":13,"required":33,"component":756,"placeholder":13},"a4c4d385-fff4-4978-99fb-b68cfea623d6","message","textarea","Message",{"_uid":879,"name":880,"type":764,"label":881,"options":882,"required":33,"component":756,"conditions":883,"placeholder":13},"8a3c9f85-f438-427d-9c7a-d7b295a14b5b","existing_user","Are you an existing user?","No, Yes",[884],{"_uid":885,"equals":886,"fields":887,"component":823},"115933d6-262a-4b59-8fa8-579c5ad73de1","Yes",[888],{"_uid":889,"name":890,"type":332,"label":891,"options":13,"required":33,"component":756,"conditions":892,"placeholder":13},"44b6ff23-98f0-4e95-b7f5-c23e06415c2d","subdomain","Store Subdomain",[],{"_uid":894,"name":895,"type":764,"label":896,"options":897,"required":33,"component":756,"conditions":898,"placeholder":13},"922a5cef-3af2-4113-8855-36c7910e3ee3","user_type","What type of user are you?","Developer, Designer, Merchant",[],"POST",[901],{"_uid":902,"text":903,"title":912,"component":913},"7323b90d-a93a-4bf1-baa9-20d0b7ead61b",{"type":324,"content":904},[905],{"type":327,"content":906},[907,909,910],{"text":908,"type":332},"855.369.9227",{"type":790},{"text":911,"type":332},"9:30am-6pm Central M-F","Pre-sales, Sales, & Partnerships","contact___footer_column",{"type":324,"content":915},[916],{"type":327,"content":917},[918],{"text":919,"type":332},"Get in touch to get help from our friendly support team.","Submit","Success!","Your email has been received. We'll get back to you as soon as we can, but it might take a business day. If you don't hear back from us in a timely manner, please check your spam folder to ensure our reply didn't go there.",-80,[],"2fd9fb7d-a48a-4184-acfd-30022d8d6f08","2022-09-23T20:10:45.360Z",[],[288,929,957],{"name":930,"created_at":931,"published_at":932,"updated_at":933,"id":934,"uuid":935,"content":936,"slug":950,"full_slug":951,"sort_by_date":59,"position":952,"tag_list":953,"is_startpage":24,"parent_id":310,"meta_data":59,"group_id":954,"first_published_at":955,"release_id":59,"lang":65,"path":59,"alternates":956,"default_full_slug":59,"translated_slugs":59},"Products","2023-01-19T16:20:53.075Z","2024-06-05T04:29:14.851Z","2024-06-05T04:29:14.872Z",28236,"389d5512-29ba-4a93-9cfa-9491d1618f73",{"_uid":937,"icon":938,"name":930,"guides":939,"pinned":24,"summary":940,"category":13,"component":297,"blog_posts":941,"content_hub":24,"icon_custom":942,"case_studies":943,"faq_sections":944,"help_articles":945,"featured_guides":946,"mailbox_category":13,"featured_articles":947,"featured_blog_posts":948,"featured_case_studies":949},"3551f6e8-765a-4b8d-8587-2e2eda4d2b23","fa-tags",[],"How products work, supported product types, inventory management, and more.",[],{"id":59,"alt":59,"name":13,"focus":59,"title":59,"filename":13,"copyright":59,"fieldtype":81},[],[],[],[],[],[],[],"products","help\u002Fcategories\u002Fproducts",150,[],"c025c7a7-0d20-4244-938a-c8d6588e1269","2023-01-19T17:25:32.570Z",[],{"name":958,"created_at":959,"published_at":960,"updated_at":961,"id":962,"uuid":712,"content":963,"slug":976,"full_slug":977,"sort_by_date":59,"position":978,"tag_list":979,"is_startpage":24,"parent_id":310,"meta_data":59,"group_id":980,"first_published_at":960,"release_id":59,"lang":65,"path":59,"alternates":981,"default_full_slug":59,"translated_slugs":59},"Product Security","2026-06-29T20:00:54.676Z","2026-06-29T20:37:32.009Z","2026-06-29T20:37:32.025Z",192813689601883,{"_uid":964,"icon":13,"name":958,"type":965,"pinned":24,"summary":966,"category":935,"component":297,"blog_posts":967,"icon_custom":968,"case_studies":970,"faq_sections":971,"featured_guides":972,"mailbox_category":13,"featured_articles":973,"featured_blog_posts":974,"featured_case_studies":975},"bd9968b0-6d3b-4a2b-a7bc-79263044b475","simple","How to enable and implement HMAC product validation, including signing product links, forms, and bundled products.",[],{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":969},{},[],[],[],[],[],[],"product-security","help\u002Fcategories\u002Fproduct-security",-420,[],"9b6ea296-0666-48d6-b896-39e524ea24ac",[],{},1784562224615]