[{"data":1,"prerenderedAt":3040},["ShallowReactive",2],{"header:help":3,"footer:default":67,"story:navigation\u002Fsearch:help":250,"story:help\u002Fcategories":288,"story:help\u002Fcategories\u002Fproduct-security":314,"help:guides:ff9269e2-2402-422e-aa80-19acc150b78a":341,"help:categories:ff9269e2-2402-422e-aa80-19acc150b78a":342,"help:tree:ff9269e2-2402-422e-aa80-19acc150b78a":343,"help:articles:ff9269e2-2402-422e-aa80-19acc150b78a":371,"story:contact":2852,"_apollo:default":3039},{"name":4,"created_at":5,"published_at":6,"updated_at":7,"id":8,"uuid":9,"content":10,"slug":57,"full_slug":58,"sort_by_date":59,"position":60,"tag_list":61,"is_startpage":24,"parent_id":62,"meta_data":59,"group_id":63,"first_published_at":64,"release_id":59,"lang":65,"path":59,"alternates":66,"default_full_slug":59,"translated_slugs":59},"Help Center Header","2024-08-09T18:06:34.939Z","2024-10-21T21:58:39.217Z","2024-10-21T21:58:39.232Z",10082752,"3e9b88f7-c163-4657-a2f2-62532d600fad",{"_uid":11,"link":12,"badge":16,"items":17,"title":13,"buttons":50,"new_tab":24,"submenu":51,"alignment":13,"component":52,"badge_link":53,"top_menu_items":56},"e5645a1a-f991-40e8-8d67-e40ebc082b5a",{"id":13,"url":13,"linktype":14,"fieldtype":15,"cached_url":13},"","story","multilink","Help Center",[18,27,34,39,44],{"_uid":19,"link":20,"title":23,"new_tab":24,"submenu":25,"component":26},"5cbe2861-1f49-4166-97da-a4dddd8105e3",{"id":21,"url":13,"linktype":14,"fieldtype":15,"cached_url":22},"4c0a2d99-ec30-4579-8ef1-6bf5564d4839","help\u002Fcategories\u002F","Articles",false,[],"header___item",{"_uid":28,"link":29,"title":32,"new_tab":33,"component":26},"1c8edeb5-b9e9-4cb8-b1c6-c1f292f7d7cd",{"id":13,"url":30,"linktype":31,"fieldtype":15,"cached_url":30},"https:\u002F\u002Fwiki.foxycart.com\u002F","url","Documentation",true,{"_uid":35,"link":36,"title":38,"new_tab":33,"component":26},"8d7df70e-f087-4da0-b616-6f0e9a5af35c",{"id":13,"url":37,"linktype":31,"fieldtype":15,"cached_url":37},"https:\u002F\u002Fapi.foxycart.com\u002F","API Documentation",{"_uid":40,"link":41,"title":43,"new_tab":33,"component":26},"f76e7944-23d5-4652-87e4-cdae79272762",{"id":13,"url":42,"linktype":31,"fieldtype":15,"cached_url":42},"https:\u002F\u002Fstatus.foxy.io\u002F","System Status",{"_uid":45,"link":46,"title":49,"new_tab":24,"component":26},"0de16771-4c84-466c-a1da-d8568113c71f",{"id":47,"url":13,"linktype":14,"fieldtype":15,"cached_url":48},"01e4e370-f9b9-45af-8fa9-f15540699b0d","contact","Contact Us",[],[],"header",{"id":54,"url":13,"linktype":14,"fieldtype":15,"cached_url":55},"4a679eb7-662d-4ea4-a976-5a2acbf0b663","help\u002F",[],"help-header","navigation\u002Fhelp-header",null,20,[],10082747,"71b81c2e-5e09-48a1-a397-a3c72fcd344a","2022-09-21T14:50:25.655Z","default",[],{"name":68,"created_at":69,"published_at":70,"updated_at":71,"id":72,"uuid":73,"content":74,"slug":243,"full_slug":244,"sort_by_date":59,"position":245,"tag_list":246,"is_startpage":24,"parent_id":62,"meta_data":59,"group_id":247,"first_published_at":248,"release_id":59,"lang":65,"path":59,"alternates":249,"default_full_slug":59,"translated_slugs":59},"Default Footer","2024-08-09T18:06:59.024Z","2025-09-04T06:24:46.223Z","2025-09-04T06:24:46.241Z",10082753,"e59e67ac-248a-482f-84a1-53d4f318186a",{"_uid":75,"about":76,"logos":77,"socials":82,"sections":108,"component":225,"cta_title":226,"bottom_links":227,"cta_subtitle":241,"cta_button_link":242,"cta_button_text":183},"830983f5-c4c4-43c8-b150-86a5e3fa6dc8","Foxy’s hosted cart & payment page allow you to sell anything, using your existing website or platform.",[78],{"id":79,"alt":13,"name":13,"focus":13,"title":13,"filename":80,"copyright":13,"fieldtype":81},14760,"https:\u002F\u002Fa-us.storyblok.com\u002Ff\u002F1001040\u002Fx\u002F3b030847ec\u002Fb-corp.svg","asset",[83,90,96,102],{"_uid":84,"icon":85,"link":86,"name":88,"component":89},"faf0a618-ea94-42ea-9182-03be18c43216","fa-facebook",{"id":13,"url":87,"linktype":31,"fieldtype":15,"cached_url":87},"https:\u002F\u002Fwww.facebook.com\u002Ffoxycart","Facebook","footer___social",{"_uid":91,"icon":92,"link":93,"name":95,"component":89},"14309c18-7e79-423e-b375-34555bac0811","fa-instagram",{"id":13,"url":94,"linktype":31,"fieldtype":15,"cached_url":94},"https:\u002F\u002Fwww.instagram.com\u002Ffoxy_io","Instagram",{"_uid":97,"icon":98,"link":99,"name":101,"component":89},"8f7fe7cf-0dd3-4596-8334-226ea466716a","fa-linkedin",{"id":13,"url":100,"linktype":31,"fieldtype":15,"cached_url":100},"https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Ffoxycart.com","LinkedIn",{"_uid":103,"icon":104,"link":105,"name":107,"component":89},"90a675b4-dd97-40b5-be09-00a87223d4c5","fa-youtube",{"id":13,"url":106,"linktype":31,"fieldtype":15,"cached_url":106},"https:\u002F\u002Fwww.youtube.com\u002Fuser\u002Ffoxycart","Youtube",[109,139,184,206],{"_uid":110,"name":111,"items":112,"component":138},"82849945-282f-488c-b18d-a8d2252f514a","Company",[113,120,126,132],{"_uid":114,"link":115,"title":118,"new_tab":24,"component":119},"1f699ab1-938b-4d9d-9825-aabcbe6f57fe",{"id":116,"url":13,"linktype":14,"fieldtype":15,"cached_url":117},"63634293-a749-4226-9439-9f38ee6dcda0","about-us","About Us","footer___menu_items",{"_uid":121,"link":122,"title":125,"new_tab":24,"component":119},"b26b00f1-a0e7-4be2-8ab3-428b8cc841f8",{"id":123,"url":13,"linktype":14,"fieldtype":15,"cached_url":124},"26cb7c55-faed-4a77-a291-1552d4111b3e","how-foxy-works","How Foxy Works",{"_uid":127,"link":128,"title":131,"new_tab":24,"component":119},"b40c68a0-1ceb-4226-9515-6176534f61fe",{"id":129,"url":13,"linktype":14,"fieldtype":15,"cached_url":130},"dc6657d7-7f4f-4c0d-b781-e971b038ee26","for-good","Foxy For Good",{"_uid":133,"link":134,"title":137,"new_tab":24,"component":119},"3ad0c134-bef9-4fff-b891-e09f16109036",{"id":135,"url":13,"linktype":14,"fieldtype":15,"cached_url":136},"23cae210-baf4-4588-9862-d09f4f52ccd2","brand-assets","Brand Assets","footer___section",{"_uid":140,"name":141,"items":142,"component":138},"a6805fa8-ac60-47f1-b8f0-f27aded0afbe","Product",[143,149,155,161,167,173,179],{"_uid":144,"link":145,"title":148,"new_tab":24,"component":119},"b39c8a4e-2383-486f-b76a-11fbb15d8134",{"id":146,"url":13,"linktype":14,"fieldtype":15,"cached_url":147},"bb04690f-fe98-4ce6-80be-05b950f2364f","features\u002F","Features",{"_uid":150,"link":151,"title":154,"new_tab":24,"component":119},"64f8a41f-c181-433d-bc0a-fc94e71ecbf6",{"id":152,"url":13,"linktype":14,"fieldtype":15,"cached_url":153},"c450c58d-761d-48c0-a9af-0b064611689b","pricing","Pricing",{"_uid":156,"link":157,"title":160,"new_tab":24,"component":119},"6e0b287f-fd8c-4146-9e0e-0ab0b5c9ce3c",{"id":158,"url":13,"linktype":14,"fieldtype":15,"cached_url":159},"fab20ad9-e76a-4947-b709-3a6fdfa88028","blog\u002Fcategories\u002Fproduct-updates","Product Updates",{"_uid":162,"link":163,"title":166,"new_tab":24,"component":119},"47e5a074-a6b5-4f1c-8c2f-89a2ae9f83eb",{"id":164,"url":13,"linktype":14,"fieldtype":15,"cached_url":165},"d2c83612-d611-47f3-a3b4-ca7fe08540b8","changelogs\u002F","Changelogs",{"_uid":168,"link":169,"title":172,"new_tab":24,"component":119},"b5c08774-542f-4ffd-b357-c94d674488b9",{"id":170,"url":13,"linktype":14,"fieldtype":15,"cached_url":171},"08876121-0df3-4ed9-aa11-902b3e41cd02","whats-next","What's Next",{"_uid":174,"link":175,"title":178,"new_tab":24,"component":119},"9c2704ed-6d9f-43e1-9e67-c8d91c083288",{"id":176,"url":13,"linktype":14,"fieldtype":15,"cached_url":177},"056a7857-b18f-4025-8f97-91a38fc19bc8","compare\u002F","Compare",{"_uid":180,"link":181,"title":183,"new_tab":24,"component":119},"5f2db35b-674b-406a-8fa7-d246633af9fe",{"id":13,"url":182,"linktype":31,"fieldtype":15,"cached_url":182},"https:\u002F\u002Fadmin.foxy.io\u002Fsign-up","Try Foxy Free",{"_uid":185,"name":186,"items":187,"component":138},"63fa1f29-4252-4640-9922-fe310e69e54a","Security",[188,194,200],{"_uid":189,"link":190,"title":193,"new_tab":24,"component":119},"1158ddb6-9eb0-466f-8eb6-7ca2ae66c8b8",{"id":191,"url":13,"linktype":14,"fieldtype":15,"cached_url":192},"1f58fb2c-8681-4742-b6e8-09999beae9f6","security-contact","Security Contact",{"_uid":195,"link":196,"title":199,"new_tab":24,"component":119},"9a79c54a-6022-4dfd-854b-766f5e4703ba",{"id":197,"url":13,"linktype":14,"fieldtype":15,"cached_url":198},"55cbfcc3-425a-4261-8037-54e919851d2d","pci","PCI Compliance",{"_uid":201,"link":202,"title":205,"new_tab":24,"component":119},"0b85f5b6-9534-4071-b323-b39d053dd4d7",{"id":203,"url":13,"linktype":14,"fieldtype":15,"cached_url":204},"c3ac0fe3-83e2-4879-afbd-d4c83e1590df","help\u002Farticles\u002Four-official-domains-public-code","Domains & Codebases",{"_uid":207,"name":208,"items":209,"component":138},"998ded67-d107-49f4-8154-ca6be51671ec","Support",[210,213,216,219,222],{"_uid":211,"link":212,"title":16,"new_tab":24,"component":119},"594ffd35-3049-4004-bb08-0db568ebd819",{"id":54,"url":13,"linktype":14,"fieldtype":15,"cached_url":55},{"_uid":214,"link":215,"title":32,"new_tab":33,"component":119},"0a1a55ab-a985-4f9d-8b42-26da714d0c1c",{"id":13,"url":30,"linktype":31,"fieldtype":15,"cached_url":30},{"_uid":217,"link":218,"title":38,"new_tab":33,"component":119},"61e0b7c8-aadf-419b-a339-b3ccabc65bf4",{"id":13,"url":37,"linktype":31,"fieldtype":15,"cached_url":37},{"_uid":220,"link":221,"title":43,"new_tab":33,"component":119},"fd67a89e-1c54-4d31-94b5-64be999062d6",{"id":13,"url":42,"linktype":31,"fieldtype":15,"cached_url":42},{"_uid":223,"link":224,"title":49,"new_tab":24,"component":119},"231a6f71-e996-4ad4-b033-d4d5542f34f0",{"id":47,"url":13,"linktype":14,"fieldtype":15,"cached_url":48},"footer","Get started with our *unlimited free trial*.",[228,235],{"_uid":229,"link":230,"text":233,"component":234},"f0b77210-2632-45a2-8436-e57cad84d01a",{"id":231,"url":13,"linktype":14,"fieldtype":15,"cached_url":232},"60ba16a2-c1f4-485f-b978-8d2eeeafbf5a","terms-of-service","Terms of Service","footer___bottom_links",{"_uid":236,"link":237,"text":240,"component":234},"4bd497b0-993f-4b4d-a5b7-8a49c7c8fec9",{"id":238,"url":13,"linktype":14,"fieldtype":15,"cached_url":239},"332302b9-1d18-4016-b9c8-9b33c72d782b","privacy-policy","Privacy Policy","No credit card required.",{"id":13,"url":182,"linktype":31,"fieldtype":15,"cached_url":182},"default-footer","navigation\u002Fdefault-footer",50,[],"11006268-07f9-41e9-96f3-c51fb723399d","2022-09-21T20:39:02.357Z",[],{"name":251,"created_at":252,"published_at":253,"updated_at":254,"id":255,"uuid":256,"content":257,"slug":279,"full_slug":282,"sort_by_date":59,"position":283,"tag_list":284,"is_startpage":24,"parent_id":62,"meta_data":59,"group_id":285,"first_published_at":286,"release_id":59,"lang":65,"path":59,"alternates":287,"default_full_slug":59,"translated_slugs":59},"Search","2024-10-21T22:08:54.973Z","2025-05-26T09:17:25.790Z","2025-05-26T09:17:25.804Z",13592003,"14cbc359-9ac1-4a7a-a8de-ad4ac8ef26d4",{"_uid":258,"name":251,"indices":259,"summary":13,"component":279,"primary_image":280},"5e4a56e8-76f1-4790-b3a7-70f1be97d042",[260,265,269,274],{"key":261,"_uid":262,"icon":13,"name":263,"component":264},"all","c12a3210-7323-4273-8217-5215e52efe84","All","index",{"key":266,"_uid":267,"icon":268,"name":23,"component":264},"help_center_article","5acff080-95e4-44d3-8dcf-1b19720af382","fa-file-alt",{"key":270,"_uid":271,"icon":272,"name":273,"component":264},"help_center_guide","b8fbc206-c083-471e-a1f0-0ebeb90a669d","fa-book","Guides",{"key":275,"_uid":276,"icon":277,"name":278,"component":264},"blog_post","23419e83-2e56-4c4c-8a05-9fd1b3c9a9bd","fa-file-image","Blog Posts","search",{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":281},{},"navigation\u002Fsearch",60,[],"11e1fd31-95cd-4fc9-b736-8b8910663e6c","2024-10-21T23:17:05.904Z",[],{"name":23,"created_at":289,"published_at":290,"updated_at":291,"id":292,"uuid":21,"content":293,"slug":307,"full_slug":22,"sort_by_date":59,"position":308,"tag_list":309,"is_startpage":33,"parent_id":310,"meta_data":59,"group_id":311,"first_published_at":312,"release_id":59,"lang":65,"path":59,"alternates":313,"default_full_slug":59,"translated_slugs":59},"2022-09-19T14:42:29.685Z","2024-07-30T18:17:22.506Z","2024-07-30T18:17:22.525Z",2660,{"_uid":294,"icon":13,"name":23,"guides":295,"pinned":24,"summary":296,"category":13,"component":297,"blog_posts":298,"content_hub":24,"icon_custom":299,"case_studies":300,"faq_sections":301,"help_articles":302,"featured_guides":303,"mailbox_category":13,"featured_articles":304,"featured_blog_posts":305,"featured_case_studies":306},"d6dae89a-907a-4bf7-82de-fe2ba875ee6e",[],"Get your questions answered with our browsable knowledge base.","help_center_category",[],{"id":59,"alt":59,"name":13,"focus":59,"title":59,"filename":13,"copyright":59,"fieldtype":81},[],[],[],[],[],[],[],"categories",530,[],2658,"19ebcdd2-027f-47f5-9a5b-a8992c959578","2022-09-19T16:24:39.219Z",[],{"name":315,"created_at":316,"published_at":317,"updated_at":318,"id":319,"uuid":320,"content":321,"slug":335,"full_slug":336,"sort_by_date":59,"position":337,"tag_list":338,"is_startpage":24,"parent_id":310,"meta_data":59,"group_id":339,"first_published_at":317,"release_id":59,"lang":65,"path":59,"alternates":340,"default_full_slug":59,"translated_slugs":59},"Product Security","2026-06-29T20:00:54.676Z","2026-06-29T20:37:32.009Z","2026-06-29T20:37:32.025Z",192813689601883,"ff9269e2-2402-422e-aa80-19acc150b78a",{"_uid":322,"icon":13,"name":315,"type":323,"pinned":24,"summary":324,"category":325,"component":297,"blog_posts":326,"icon_custom":327,"case_studies":329,"faq_sections":330,"featured_guides":331,"mailbox_category":13,"featured_articles":332,"featured_blog_posts":333,"featured_case_studies":334},"bd9968b0-6d3b-4a2b-a7bc-79263044b475","simple","How to enable and implement HMAC product validation, including signing product links, forms, and bundled products.","389d5512-29ba-4a93-9cfa-9491d1618f73",[],{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":328},{},[],[],[],[],[],[],"product-security","help\u002Fcategories\u002Fproduct-security",-420,[],"9b6ea296-0666-48d6-b896-39e524ea24ac",[],[],[],[288,344],{"name":345,"created_at":346,"published_at":347,"updated_at":348,"id":349,"uuid":325,"content":350,"slug":364,"full_slug":365,"sort_by_date":59,"position":366,"tag_list":367,"is_startpage":24,"parent_id":310,"meta_data":59,"group_id":368,"first_published_at":369,"release_id":59,"lang":65,"path":59,"alternates":370,"default_full_slug":59,"translated_slugs":59},"Products","2023-01-19T16:20:53.075Z","2024-06-05T04:29:14.851Z","2024-06-05T04:29:14.872Z",28236,{"_uid":351,"icon":352,"name":345,"guides":353,"pinned":24,"summary":354,"category":13,"component":297,"blog_posts":355,"content_hub":24,"icon_custom":356,"case_studies":357,"faq_sections":358,"help_articles":359,"featured_guides":360,"mailbox_category":13,"featured_articles":361,"featured_blog_posts":362,"featured_case_studies":363},"3551f6e8-765a-4b8d-8587-2e2eda4d2b23","fa-tags",[],"How products work, supported product types, inventory management, and more.",[],{"id":59,"alt":59,"name":13,"focus":59,"title":59,"filename":13,"copyright":59,"fieldtype":81},[],[],[],[],[],[],[],"products","help\u002Fcategories\u002Fproducts",150,[],"c025c7a7-0d20-4244-938a-c8d6588e1269","2023-01-19T17:25:32.570Z",[],[372,456,1209,1432,1656,1814,2046,2416,2683],{"name":373,"created_at":374,"published_at":375,"updated_at":376,"id":377,"uuid":378,"content":379,"slug":449,"full_slug":450,"sort_by_date":59,"position":451,"tag_list":452,"is_startpage":24,"parent_id":453,"meta_data":59,"group_id":454,"first_published_at":375,"release_id":59,"lang":65,"path":59,"alternates":455,"default_full_slug":59,"translated_slugs":59},"Enable HMAC product validation","2026-06-29T20:04:58.663Z","2026-06-29T20:50:24.676Z","2026-06-29T20:50:24.692Z",192814688984927,"cdecda3c-ef27-4388-aa3f-cd4bc6fc2fb3",{"_uid":380,"body":381,"name":373,"image":445,"pinned":24,"summary":447,"category":320,"component":266,"related_articles":448},"9b017b68-99b8-4d65-8ca4-faec79209b44",{"type":382,"content":383},"doc",[384,391,396,401,419,430,435,440],{"type":385,"attrs":386,"content":387},"paragraph",{"textAlign":59},[388],{"text":389,"type":390},"Before signed product links and forms will be validated by Foxy, you need to enable cart validation in your store settings.","text",{"type":385,"attrs":392,"content":393},{"textAlign":59},[394],{"text":395,"type":390},"## Steps",{"type":385,"attrs":397,"content":398},{"textAlign":59},[399],{"text":400,"type":390},"1. Go to the [Foxy admin](https:\u002F\u002Fadmin.foxy.io).",{"type":385,"attrs":402,"content":403},{"textAlign":59},[404,406,411,413,417],{"text":405,"type":390},"2. Go to ",{"text":407,"type":390,"marks":408},"Settings",[409],{"type":410},"bold",{"text":412,"type":390}," > ",{"text":414,"type":390,"marks":415},"Cart",[416],{"type":410},{"text":418,"type":390},".",{"type":385,"attrs":420,"content":421},{"textAlign":59},[422,424,428],{"text":423,"type":390},"3. Under the ",{"text":425,"type":390,"marks":426},"Advanced",[427],{"type":410},{"text":429,"type":390}," section, enable the \"Prevent product link and form tampering\" option.",{"type":385,"attrs":431,"content":432},{"textAlign":59},[433],{"text":434,"type":390},"## Notes",{"type":385,"attrs":436,"content":437},{"textAlign":59},[438],{"text":439,"type":390},"- Once enabled, validation is all or nothing — every parameter on every add-to-cart link and form must be signed. Unsigned parameters will be rejected.",{"type":385,"attrs":441,"content":442},{"textAlign":59},[443],{"text":444,"type":390},"- Enable this setting only once you have signed all of your existing links and forms, or you will break your add-to-cart functionality.",{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":446},{},"How to turn on HMAC product validation in your store settings.",[],"enable-hmac-product-validation","help\u002Farticles\u002Fenable-hmac-product-validation",-2470,[],2659,"3dd8d456-e0c4-4396-89e5-6d6243183af5",[],{"name":457,"created_at":458,"published_at":459,"updated_at":460,"id":461,"uuid":462,"content":463,"slug":1203,"full_slug":1204,"sort_by_date":59,"position":1205,"tag_list":1206,"is_startpage":24,"parent_id":453,"meta_data":59,"group_id":1207,"first_published_at":459,"release_id":59,"lang":65,"path":59,"alternates":1208,"default_full_slug":59,"translated_slugs":59},"HMAC excluded parameters reference","2026-06-29T20:35:18.607Z","2026-06-29T20:50:23.187Z","2026-06-29T20:50:23.205Z",192822143483757,"3169dac3-f1cc-485e-b93e-7e044b801e92",{"_uid":464,"body":465,"name":457,"image":1199,"pinned":24,"summary":1201,"category":320,"component":266,"related_articles":1202},"b0854d6a-1cca-45e3-847a-e984ae8424fd",{"type":382,"content":466},[467,472,479,722,727,1110,1115,1120],{"type":385,"attrs":468,"content":469},{"textAlign":59},[470],{"text":471,"type":390},"When HMAC validation is enabled, most product parameters must be signed. The following parameters are exempt — signing them is unnecessary and may cause errors.",{"type":473,"attrs":474,"content":476},"heading",{"level":475,"textAlign":59},2,[477],{"text":478,"type":390},"Cart options",{"type":480,"content":481},"table",[482,503,537,557,577,597,622,642,662,682,702],{"type":483,"content":484},"tableRow",[485,495],{"type":486,"attrs":487,"content":489},"tableHeader",{"colspan":488,"rowspan":488,"colwidth":59},1,[490],{"type":385,"attrs":491,"content":492},{"textAlign":59},[493],{"text":494,"type":390},"Parameter",{"type":486,"attrs":496,"content":497},{"colspan":488,"rowspan":488,"colwidth":59},[498],{"type":385,"attrs":499,"content":500},{"textAlign":59},[501],{"text":502,"type":390},"Description",{"type":483,"content":504},[505,517],{"type":506,"attrs":507,"content":508},"tableCell",{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[509],{"type":385,"attrs":510,"content":511},{"textAlign":59},[512],{"text":513,"type":390,"marks":514},"cart",[515],{"type":516},"code",{"type":506,"attrs":518,"content":519},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[520],{"type":385,"attrs":521,"content":522},{"textAlign":59},[523,525,529,531,535],{"text":524,"type":390},"Cart action (e.g. ",{"text":526,"type":390,"marks":527},"checkout",[528],{"type":516},{"text":530,"type":390},", ",{"text":532,"type":390,"marks":533},"add",[534],{"type":516},{"text":536,"type":390},")",{"type":483,"content":538},[539,549],{"type":506,"attrs":540,"content":541},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[542],{"type":385,"attrs":543,"content":544},{"textAlign":59},[545],{"text":546,"type":390,"marks":547},"fcsid",[548],{"type":516},{"type":506,"attrs":550,"content":551},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[552],{"type":385,"attrs":553,"content":554},{"textAlign":59},[555],{"text":556,"type":390},"Session ID",{"type":483,"content":558},[559,569],{"type":506,"attrs":560,"content":561},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[562],{"type":385,"attrs":563,"content":564},{"textAlign":59},[565],{"text":566,"type":390,"marks":567},"empty",[568],{"type":516},{"type":506,"attrs":570,"content":571},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[572],{"type":385,"attrs":573,"content":574},{"textAlign":59},[575],{"text":576,"type":390},"Empties the cart",{"type":483,"content":578},[579,589],{"type":506,"attrs":580,"content":581},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[582],{"type":385,"attrs":583,"content":584},{"textAlign":59},[585],{"text":586,"type":390,"marks":587},"coupon",[588],{"type":516},{"type":506,"attrs":590,"content":591},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[592],{"type":385,"attrs":593,"content":594},{"textAlign":59},[595],{"text":596,"type":390},"Coupon code",{"type":483,"content":598},[599,609],{"type":506,"attrs":600,"content":601},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[602],{"type":385,"attrs":603,"content":604},{"textAlign":59},[605],{"text":606,"type":390,"marks":607},"output",[608],{"type":516},{"type":506,"attrs":610,"content":611},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[612],{"type":385,"attrs":613,"content":614},{"textAlign":59},[615,617,621],{"text":616,"type":390},"Output format (e.g. ",{"text":618,"type":390,"marks":619},"json",[620],{"type":516},{"text":536,"type":390},{"type":483,"content":623},[624,634],{"type":506,"attrs":625,"content":626},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[627],{"type":385,"attrs":628,"content":629},{"textAlign":59},[630],{"text":631,"type":390,"marks":632},"sub_token",[633],{"type":516},{"type":506,"attrs":635,"content":636},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[637],{"type":385,"attrs":638,"content":639},{"textAlign":59},[640],{"text":641,"type":390},"Subscription token",{"type":483,"content":643},[644,654],{"type":506,"attrs":645,"content":646},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[647],{"type":385,"attrs":648,"content":649},{"textAlign":59},[650],{"text":651,"type":390,"marks":652},"redirect",[653],{"type":516},{"type":506,"attrs":655,"content":656},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[657],{"type":385,"attrs":658,"content":659},{"textAlign":59},[660],{"text":661,"type":390},"Redirect URL after add to cart",{"type":483,"content":663},[664,674],{"type":506,"attrs":665,"content":666},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[667],{"type":385,"attrs":668,"content":669},{"textAlign":59},[670],{"text":671,"type":390,"marks":672},"callback",[673],{"type":516},{"type":506,"attrs":675,"content":676},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[677],{"type":385,"attrs":678,"content":679},{"textAlign":59},[680],{"text":681,"type":390},"JSONP callback",{"type":483,"content":683},[684,694],{"type":506,"attrs":685,"content":686},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[687],{"type":385,"attrs":688,"content":689},{"textAlign":59},[690],{"text":691,"type":390,"marks":692},"_",[693],{"type":516},{"type":506,"attrs":695,"content":696},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[697],{"type":385,"attrs":698,"content":699},{"textAlign":59},[700],{"text":701,"type":390},"Cache-busting parameter",{"type":483,"content":703},[704,714],{"type":506,"attrs":705,"content":706},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[707],{"type":385,"attrs":708,"content":709},{"textAlign":59},[710],{"text":711,"type":390,"marks":712},"locale",[713],{"type":516},{"type":506,"attrs":715,"content":716},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[717],{"type":385,"attrs":718,"content":719},{"textAlign":59},[720],{"text":721,"type":390},"Locale override",{"type":473,"attrs":723,"content":724},{"level":475,"textAlign":59},[725],{"text":726,"type":390},"Checkout prepopulation",{"type":480,"content":728},[729,738,750,762,774,786,798,810,822,834,846,858,870,882,894,906,918,930,942,954,966,978,990,1002,1014,1026,1038,1050,1062,1074,1086,1098],{"type":483,"content":730},[731],{"type":486,"attrs":732,"content":733},{"colspan":488,"rowspan":488,"colwidth":59},[734],{"type":385,"attrs":735,"content":736},{"textAlign":59},[737],{"text":494,"type":390},{"type":483,"content":739},[740],{"type":506,"attrs":741,"content":742},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[743],{"type":385,"attrs":744,"content":745},{"textAlign":59},[746],{"text":747,"type":390,"marks":748},"customer_email",[749],{"type":516},{"type":483,"content":751},[752],{"type":506,"attrs":753,"content":754},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[755],{"type":385,"attrs":756,"content":757},{"textAlign":59},[758],{"text":759,"type":390,"marks":760},"billing_first_name",[761],{"type":516},{"type":483,"content":763},[764],{"type":506,"attrs":765,"content":766},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[767],{"type":385,"attrs":768,"content":769},{"textAlign":59},[770],{"text":771,"type":390,"marks":772},"billing_last_name",[773],{"type":516},{"type":483,"content":775},[776],{"type":506,"attrs":777,"content":778},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[779],{"type":385,"attrs":780,"content":781},{"textAlign":59},[782],{"text":783,"type":390,"marks":784},"billing_address1",[785],{"type":516},{"type":483,"content":787},[788],{"type":506,"attrs":789,"content":790},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[791],{"type":385,"attrs":792,"content":793},{"textAlign":59},[794],{"text":795,"type":390,"marks":796},"billing_address2",[797],{"type":516},{"type":483,"content":799},[800],{"type":506,"attrs":801,"content":802},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[803],{"type":385,"attrs":804,"content":805},{"textAlign":59},[806],{"text":807,"type":390,"marks":808},"billing_city",[809],{"type":516},{"type":483,"content":811},[812],{"type":506,"attrs":813,"content":814},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[815],{"type":385,"attrs":816,"content":817},{"textAlign":59},[818],{"text":819,"type":390,"marks":820},"billing_state",[821],{"type":516},{"type":483,"content":823},[824],{"type":506,"attrs":825,"content":826},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[827],{"type":385,"attrs":828,"content":829},{"textAlign":59},[830],{"text":831,"type":390,"marks":832},"billing_postal_code",[833],{"type":516},{"type":483,"content":835},[836],{"type":506,"attrs":837,"content":838},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[839],{"type":385,"attrs":840,"content":841},{"textAlign":59},[842],{"text":843,"type":390,"marks":844},"billing_country",[845],{"type":516},{"type":483,"content":847},[848],{"type":506,"attrs":849,"content":850},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[851],{"type":385,"attrs":852,"content":853},{"textAlign":59},[854],{"text":855,"type":390,"marks":856},"billing_phone",[857],{"type":516},{"type":483,"content":859},[860],{"type":506,"attrs":861,"content":862},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[863],{"type":385,"attrs":864,"content":865},{"textAlign":59},[866],{"text":867,"type":390,"marks":868},"billing_company",[869],{"type":516},{"type":483,"content":871},[872],{"type":506,"attrs":873,"content":874},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[875],{"type":385,"attrs":876,"content":877},{"textAlign":59},[878],{"text":879,"type":390,"marks":880},"customer_first_name",[881],{"type":516},{"type":483,"content":883},[884],{"type":506,"attrs":885,"content":886},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[887],{"type":385,"attrs":888,"content":889},{"textAlign":59},[890],{"text":891,"type":390,"marks":892},"customer_last_name",[893],{"type":516},{"type":483,"content":895},[896],{"type":506,"attrs":897,"content":898},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[899],{"type":385,"attrs":900,"content":901},{"textAlign":59},[902],{"text":903,"type":390,"marks":904},"customer_address1",[905],{"type":516},{"type":483,"content":907},[908],{"type":506,"attrs":909,"content":910},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[911],{"type":385,"attrs":912,"content":913},{"textAlign":59},[914],{"text":915,"type":390,"marks":916},"customer_address2",[917],{"type":516},{"type":483,"content":919},[920],{"type":506,"attrs":921,"content":922},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[923],{"type":385,"attrs":924,"content":925},{"textAlign":59},[926],{"text":927,"type":390,"marks":928},"customer_city",[929],{"type":516},{"type":483,"content":931},[932],{"type":506,"attrs":933,"content":934},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[935],{"type":385,"attrs":936,"content":937},{"textAlign":59},[938],{"text":939,"type":390,"marks":940},"customer_postal_code",[941],{"type":516},{"type":483,"content":943},[944],{"type":506,"attrs":945,"content":946},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[947],{"type":385,"attrs":948,"content":949},{"textAlign":59},[950],{"text":951,"type":390,"marks":952},"customer_country",[953],{"type":516},{"type":483,"content":955},[956],{"type":506,"attrs":957,"content":958},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[959],{"type":385,"attrs":960,"content":961},{"textAlign":59},[962],{"text":963,"type":390,"marks":964},"customer_phone",[965],{"type":516},{"type":483,"content":967},[968],{"type":506,"attrs":969,"content":970},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[971],{"type":385,"attrs":972,"content":973},{"textAlign":59},[974],{"text":975,"type":390,"marks":976},"customer_company",[977],{"type":516},{"type":483,"content":979},[980],{"type":506,"attrs":981,"content":982},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[983],{"type":385,"attrs":984,"content":985},{"textAlign":59},[986],{"text":987,"type":390,"marks":988},"shipping_first_name",[989],{"type":516},{"type":483,"content":991},[992],{"type":506,"attrs":993,"content":994},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[995],{"type":385,"attrs":996,"content":997},{"textAlign":59},[998],{"text":999,"type":390,"marks":1000},"shipping_last_name",[1001],{"type":516},{"type":483,"content":1003},[1004],{"type":506,"attrs":1005,"content":1006},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1007],{"type":385,"attrs":1008,"content":1009},{"textAlign":59},[1010],{"text":1011,"type":390,"marks":1012},"shipping_address1",[1013],{"type":516},{"type":483,"content":1015},[1016],{"type":506,"attrs":1017,"content":1018},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1019],{"type":385,"attrs":1020,"content":1021},{"textAlign":59},[1022],{"text":1023,"type":390,"marks":1024},"shipping_address2",[1025],{"type":516},{"type":483,"content":1027},[1028],{"type":506,"attrs":1029,"content":1030},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1031],{"type":385,"attrs":1032,"content":1033},{"textAlign":59},[1034],{"text":1035,"type":390,"marks":1036},"shipping_city",[1037],{"type":516},{"type":483,"content":1039},[1040],{"type":506,"attrs":1041,"content":1042},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1043],{"type":385,"attrs":1044,"content":1045},{"textAlign":59},[1046],{"text":1047,"type":390,"marks":1048},"shipping_state",[1049],{"type":516},{"type":483,"content":1051},[1052],{"type":506,"attrs":1053,"content":1054},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1055],{"type":385,"attrs":1056,"content":1057},{"textAlign":59},[1058],{"text":1059,"type":390,"marks":1060},"shipping_region",[1061],{"type":516},{"type":483,"content":1063},[1064],{"type":506,"attrs":1065,"content":1066},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1067],{"type":385,"attrs":1068,"content":1069},{"textAlign":59},[1070],{"text":1071,"type":390,"marks":1072},"shipping_postal_code",[1073],{"type":516},{"type":483,"content":1075},[1076],{"type":506,"attrs":1077,"content":1078},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1079],{"type":385,"attrs":1080,"content":1081},{"textAlign":59},[1082],{"text":1083,"type":390,"marks":1084},"shipping_country",[1085],{"type":516},{"type":483,"content":1087},[1088],{"type":506,"attrs":1089,"content":1090},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1091],{"type":385,"attrs":1092,"content":1093},{"textAlign":59},[1094],{"text":1095,"type":390,"marks":1096},"shipping_phone",[1097],{"type":516},{"type":483,"content":1099},[1100],{"type":506,"attrs":1101,"content":1102},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1103],{"type":385,"attrs":1104,"content":1105},{"textAlign":59},[1106],{"text":1107,"type":390,"marks":1108},"shipping_company",[1109],{"type":516},{"type":473,"attrs":1111,"content":1112},{"level":475,"textAlign":59},[1113],{"text":1114,"type":390},"Name prefixes",{"type":385,"attrs":1116,"content":1117},{"textAlign":59},[1118],{"text":1119,"type":390},"Parameters using the following name prefixes are also exempt:",{"type":480,"content":1121},[1122,1139,1159,1179],{"type":483,"content":1123},[1124,1132],{"type":486,"attrs":1125,"content":1126},{"colspan":488,"rowspan":488,"colwidth":59},[1127],{"type":385,"attrs":1128,"content":1129},{"textAlign":59},[1130],{"text":1131,"type":390},"Prefix",{"type":486,"attrs":1133,"content":1134},{"colspan":488,"rowspan":488,"colwidth":59},[1135],{"type":385,"attrs":1136,"content":1137},{"textAlign":59},[1138],{"text":502,"type":390},{"type":483,"content":1140},[1141,1151],{"type":506,"attrs":1142,"content":1143},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1144],{"type":385,"attrs":1145,"content":1146},{"textAlign":59},[1147],{"text":1148,"type":390,"marks":1149},"h:",[1150],{"type":516},{"type":506,"attrs":1152,"content":1153},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1154],{"type":385,"attrs":1155,"content":1156},{"textAlign":59},[1157],{"text":1158,"type":390},"Session variables — visible server-side only, not in the cart",{"type":483,"content":1160},[1161,1171],{"type":506,"attrs":1162,"content":1163},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1164],{"type":385,"attrs":1165,"content":1166},{"textAlign":59},[1167],{"text":1168,"type":390,"marks":1169},"x:",[1170],{"type":516},{"type":506,"attrs":1172,"content":1173},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1174],{"type":385,"attrs":1175,"content":1176},{"textAlign":59},[1177],{"text":1178,"type":390},"Excluded variables — passed through to the datafeed but ignored by the cart",{"type":483,"content":1180},[1181,1191],{"type":506,"attrs":1182,"content":1183},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1184],{"type":385,"attrs":1185,"content":1186},{"textAlign":59},[1187],{"text":1188,"type":390,"marks":1189},"__",[1190],{"type":516},{"type":506,"attrs":1192,"content":1193},{"colspan":488,"rowspan":488,"colwidth":59,"backgroundColor":59},[1194],{"type":385,"attrs":1195,"content":1196},{"textAlign":59},[1197],{"text":1198,"type":390},"Double underscore — internal use",{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":1200},{},"Parameters that do not need to be signed when using HMAC product validation.",[],"hmac-excluded-parameters-reference","help\u002Farticles\u002Fhmac-excluded-parameters-reference",-2540,[],"2b937a65-c609-413d-906d-166b22f4ffe4",[],{"name":1210,"created_at":1211,"published_at":1212,"updated_at":1213,"id":1214,"uuid":1215,"content":1216,"slug":1426,"full_slug":1427,"sort_by_date":59,"position":1428,"tag_list":1429,"is_startpage":24,"parent_id":453,"meta_data":59,"group_id":1430,"first_published_at":1212,"release_id":59,"lang":65,"path":59,"alternates":1431,"default_full_slug":59,"translated_slugs":59},"Product security overview","2026-06-29T20:03:50.117Z","2026-06-29T20:50:24.931Z","2026-06-29T20:50:24.953Z",192814408224605,"10982047-b16a-4880-b28b-9d116e2720aa",{"_uid":1217,"body":1218,"name":1210,"image":1422,"pinned":33,"summary":1424,"category":320,"component":266,"related_articles":1425},"dc706817-7362-4368-8282-f891426ab855",{"type":382,"content":1219},[1220,1225,1230,1235,1279,1284,1289,1294,1306,1311,1316,1340,1356,1376,1381],{"type":385,"attrs":1221,"content":1222},{"textAlign":59},[1223],{"text":1224,"type":390},"Foxy’s HMAC product validation is a cryptographic method to prevent customers from tampering with your add-to-cart links and forms — for example, modifying a product’s price, code, or category before submitting to the cart.",{"type":473,"attrs":1226,"content":1227},{"level":475,"textAlign":59},[1228],{"text":1229,"type":390},"Do you need it?",{"type":385,"attrs":1231,"content":1232},{"textAlign":59},[1233],{"text":1234,"type":390},"Without HMAC validation enabled, product parameters in your links and forms are visible and modifiable by anyone with basic web knowledge. Whether that’s a problem depends on your situation:",{"type":1236,"content":1237},"bullet_list",[1238,1250,1268],{"type":1239,"content":1240},"list_item",[1241],{"type":385,"attrs":1242,"content":1243},{"textAlign":59},[1244,1248],{"text":1245,"type":390,"marks":1246},"Low volume stores",[1247],{"type":410},{"text":1249,"type":390}," often manage risk by manually reviewing orders before fulfilment.",{"type":1239,"content":1251},[1252],{"type":385,"attrs":1253,"content":1254},{"textAlign":59},[1255,1259,1261,1267],{"text":1256,"type":390,"marks":1257},"Higher volume stores",[1258],{"type":410},{"text":1260,"type":390}," may verify orders automatically by comparing transaction data against their database via the ",{"text":1262,"type":390,"marks":1263},"Foxy API",[1264],{"type":1265,"attrs":1266},"link",{"href":37,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":418,"type":390},{"type":1239,"content":1269},[1270],{"type":385,"attrs":1271,"content":1272},{"textAlign":59},[1273,1277],{"text":1274,"type":390,"marks":1275},"Any store",[1276],{"type":410},{"text":1278,"type":390}," that wants to prevent spoofed orders at the point of submission should implement HMAC validation.",{"type":385,"attrs":1280,"content":1281},{"textAlign":59},[1282],{"text":1283,"type":390},"If you’re concerned about price or product spoofing, HMAC validation is the most robust solution.",{"type":473,"attrs":1285,"content":1286},{"level":475,"textAlign":59},[1287],{"text":1288,"type":390},"How it works",{"type":385,"attrs":1290,"content":1291},{"textAlign":59},[1292],{"text":1293,"type":390},"When HMAC validation is enabled, Foxy requires every product parameter in your links and forms to be cryptographically signed using your store’s API key. Unsigned or tampered values are rejected before the product is added to the cart.",{"type":385,"attrs":1295,"content":1296},{"textAlign":59},[1297,1299,1304],{"text":1298,"type":390},"Signing is all or nothing — if validation is enabled, every parameter on every add-to-cart link and form must be signed. See ",{"text":457,"type":390,"marks":1300},[1301],{"type":1265,"attrs":1302},{"href":1303,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fhmac-excluded-parameters-reference",{"text":1305,"type":390}," for the small number of parameters that are exempt.",{"type":473,"attrs":1307,"content":1308},{"level":475,"textAlign":59},[1309],{"text":1310,"type":390},"Implementation options",{"type":385,"attrs":1312,"content":1313},{"textAlign":59},[1314],{"text":1315,"type":390},"There are three ways to implement HMAC signing:",{"type":385,"attrs":1317,"content":1318},{"textAlign":59},[1319,1323,1325,1331,1333,1339],{"text":1320,"type":390,"marks":1321},"PHP auto-sign library",[1322],{"type":410},{"text":1324,"type":390}," — the recommended approach for most stores. A PHP script automatically signs all links and forms on an entire HTML page, making it straightforward to add to an existing site or CMS. See ",{"text":1326,"type":390,"marks":1327},"Sign product forms with HMAC",[1328],{"type":1265,"attrs":1329},{"href":1330,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-product-forms-with-hmac",{"text":1332,"type":390}," and ",{"text":1334,"type":390,"marks":1335},"Sign product links with HMAC",[1336],{"type":1265,"attrs":1337},{"href":1338,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-product-links-with-hmac",{"text":418,"type":390},{"type":385,"attrs":1341,"content":1342},{"textAlign":59},[1343,1347,1349,1355],{"text":1344,"type":390,"marks":1345},"Manual admin tool",[1346],{"type":410},{"text":1348,"type":390}," — for static sites or one-off forms. Paste your link or form into the Foxy admin and it returns a signed version. See ",{"text":1350,"type":390,"marks":1351},"Use the admin tool to sign products with HMAC",[1352],{"type":1265,"attrs":1353},{"href":1354,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fuse-the-admin-tool-to-sign-products-with-hmac",{"text":418,"type":390},{"type":385,"attrs":1357,"content":1358},{"textAlign":59},[1359,1363,1365,1369,1370,1374],{"text":1360,"type":390,"marks":1361},"Custom implementation",[1362],{"type":410},{"text":1364,"type":390}," — sign parameters yourself in any language using HMAC SHA-256. See ",{"text":1326,"type":390,"marks":1366},[1367],{"type":1265,"attrs":1368},{"href":1330,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":1332,"type":390},{"text":1334,"type":390,"marks":1371},[1372],{"type":1265,"attrs":1373},{"href":1338,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":1375,"type":390}," for implementation details.",{"type":473,"attrs":1377,"content":1378},{"level":475,"textAlign":59},[1379],{"text":1380,"type":390},"Notes",{"type":1236,"content":1382},[1383,1396,1408],{"type":1239,"content":1384},[1385],{"type":385,"attrs":1386,"content":1387},{"textAlign":59},[1388,1390,1395],{"text":1389,"type":390},"HMAC validation must be enabled in your store settings before signed links and forms will be validated. See ",{"text":373,"type":390,"marks":1391},[1392],{"type":1265,"attrs":1393},{"href":1394,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fenable-hmac-product-validation",{"text":418,"type":390},{"type":1239,"content":1397},[1398],{"type":385,"attrs":1399,"content":1400},{"textAlign":59},[1401,1403,1406],{"text":1402,"type":390},"A ",{"text":516,"type":390,"marks":1404},[1405],{"type":516},{"text":1407,"type":390}," value is required on every product. Without it there is nothing to tie signed parameters to a specific product.",{"type":1239,"content":1409},[1410],{"type":385,"attrs":1411,"content":1412},{"textAlign":59},[1413,1415,1420],{"text":1414,"type":390},"Validation prevents tampering with existing parameters and blocks the addition of unsigned parameters, but it does not prevent a user from ",{"text":1416,"type":390,"marks":1417},"removing",[1418],{"type":1419},"italic",{"text":1421,"type":390}," a parameter. If you use price modifiers, set the base price at the upper limit and adjust downward rather than upward.",{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":1423},{},"What HMAC product validation is, when to use it, and the different ways to implement it.",[],"product-security-overview","help\u002Farticles\u002Fproduct-security-overview",-2460,[],"72c0e65c-dc2b-43d9-bcab-f6e0e846548c",[],{"name":1433,"created_at":1434,"published_at":1435,"updated_at":1436,"id":1437,"uuid":1438,"content":1439,"slug":1650,"full_slug":1651,"sort_by_date":59,"position":1652,"tag_list":1653,"is_startpage":24,"parent_id":453,"meta_data":59,"group_id":1654,"first_published_at":1435,"release_id":59,"lang":65,"path":59,"alternates":1655,"default_full_slug":59,"translated_slugs":59},"Sign bundled products with HMAC","2026-06-29T20:23:05.407Z","2026-06-29T20:50:23.674Z","2026-06-29T20:50:23.697Z",192819140276070,"1a658f41-e64c-4462-b450-2762dc7c4409",{"_uid":1440,"body":1441,"name":1433,"image":1646,"pinned":24,"summary":1648,"category":320,"component":266,"related_articles":1649},"632e1eb3-f4dc-429e-aed2-f02c35fe16c5",{"type":382,"content":1442},[1443,1448,1452,1472,1498,1504,1513,1518,1523,1566,1571,1581,1586,1591,1596,1600],{"type":385,"attrs":1444,"content":1445},{"textAlign":59},[1446],{"text":1447,"type":390},"Signing bundled products with HMAC requires a small change to the standard signing process. Because child products often have a different price when sold as part of a bundle, Foxy requires the hash for each child product parameter to include both the child code and the parent code.",{"type":473,"attrs":1449,"content":1450},{"level":475,"textAlign":59},[1451],{"text":1288,"type":390},{"type":385,"attrs":1453,"content":1454},{"textAlign":59},[1455,1457,1460,1462,1465,1467,1470],{"text":1456,"type":390},"For child product parameters, concatenate the child ",{"text":516,"type":390,"marks":1458},[1459],{"type":516},{"text":1461,"type":390}," and parent ",{"text":516,"type":390,"marks":1463},[1464],{"type":516},{"text":1466,"type":390}," together (in that order, no separator) and use that combined string as the ",{"text":516,"type":390,"marks":1468},[1469],{"type":516},{"text":1471,"type":390}," when generating the hash.",{"type":385,"attrs":1473,"content":1474},{"textAlign":59},[1475,1477,1480,1482,1486,1488,1491,1492,1496],{"text":1476,"type":390},"For example, a child product with ",{"text":516,"type":390,"marks":1478},[1479],{"type":516},{"text":1481,"type":390}," of ",{"text":1483,"type":390,"marks":1484},"poster",[1485],{"type":516},{"text":1487,"type":390}," belonging to a parent with ",{"text":516,"type":390,"marks":1489},[1490],{"type":516},{"text":1481,"type":390},{"text":1493,"type":390,"marks":1494},"shirt",[1495],{"type":516},{"text":1497,"type":390},":",{"type":1499,"attrs":1500,"content":1501},"code_block",{"class":59},[1502],{"text":1503,"type":390},"hash_hmac('sha256', 'postershirtnameMy Poster', $api_key);\nhash_hmac('sha256', 'postershirtprice1.99', $api_key);\n",{"type":385,"attrs":1505,"content":1506},{"textAlign":59},[1507,1509,1512],{"text":1508,"type":390},"The parent product is signed as normal using only its own ",{"text":516,"type":390,"marks":1510},[1511],{"type":516},{"text":1497,"type":390},{"type":1499,"attrs":1514,"content":1515},{"class":59},[1516],{"text":1517,"type":390},"hash_hmac('sha256', 'shirtnameExample T-Shirt', $api_key);\nhash_hmac('sha256', 'shirtprice25', $api_key);\n",{"type":473,"attrs":1519,"content":1520},{"level":475,"textAlign":59},[1521],{"text":1522,"type":390},"Steps",{"type":1524,"attrs":1525,"content":1526},"ordered_list",{"order":488},[1527,1538,1559],{"type":1239,"content":1528},[1529],{"type":385,"attrs":1530,"content":1531},{"textAlign":59},[1532,1534,1537],{"text":1533,"type":390},"Sign the parent product parameters as normal, using only the parent ",{"text":516,"type":390,"marks":1535},[1536],{"type":516},{"text":418,"type":390},{"type":1239,"content":1539},[1540],{"type":385,"attrs":1541,"content":1542},{"textAlign":59},[1543,1545,1548,1550,1553,1555,1558],{"text":1544,"type":390},"For each child product parameter, concatenate the child ",{"text":516,"type":390,"marks":1546},[1547],{"type":516},{"text":1549,"type":390}," + parent ",{"text":516,"type":390,"marks":1551},[1552],{"type":516},{"text":1554,"type":390}," into a single string and use that as the ",{"text":516,"type":390,"marks":1556},[1557],{"type":516},{"text":1471,"type":390},{"type":1239,"content":1560},[1561],{"type":385,"attrs":1562,"content":1563},{"textAlign":59},[1564],{"text":1565,"type":390},"Apply the resulting hashes to the child product inputs as you would for any other signed field.",{"type":473,"attrs":1567,"content":1568},{"level":475,"textAlign":59},[1569],{"text":1570,"type":390},"PHP helper function",{"type":385,"attrs":1572,"content":1573},{"textAlign":59},[1574,1576,1579],{"text":1575,"type":390},"Pass the parent ",{"text":516,"type":390,"marks":1577},[1578],{"type":516},{"text":1580,"type":390}," as the fourth argument to the helper function when signing child product parameters:",{"type":1499,"attrs":1582,"content":1583},{"class":59},[1584],{"text":1585,"type":390},"get_verification('code', 'poster', 'poster', 'shirt');\nget_verification('name', 'My Poster', 'poster', 'shirt');\nget_verification('price', '1.99', 'poster', 'shirt');\n",{"type":385,"attrs":1587,"content":1588},{"textAlign":59},[1589],{"text":1590,"type":390},"In a form, the signed child product inputs look like this:",{"type":1499,"attrs":1592,"content":1593},{"class":59},[1594],{"text":1595,"type":390},"\u003Cinput type=\"hidden\" name=\"\u003C?php echo get_verification('code', 'poster', 'poster', 'shirt'); ?>\" value=\"poster\" \u002F>\n\u003Cinput type=\"hidden\" name=\"\u003C?php echo get_verification('name', 'My Poster', 'poster', 'shirt'); ?>\" value=\"My Poster\" \u002F>\n\u003Cinput type=\"hidden\" name=\"\u003C?php echo get_verification('price', '1.99', 'poster', 'shirt'); ?>\" value=\"1.99\" \u002F>\n\u003Cinput type=\"hidden\" name=\"\u003C?php echo get_verification('parent_code', 'shirt', 'poster', 'shirt'); ?>\" value=\"shirt\" \u002F>\n",{"type":473,"attrs":1597,"content":1598},{"level":475,"textAlign":59},[1599],{"text":1380,"type":390},{"type":1236,"content":1601},[1602,1615,1628],{"type":1239,"content":1603},[1604],{"type":385,"attrs":1605,"content":1606},{"textAlign":59},[1607,1609,1613],{"text":1608,"type":390},"The combined code format is ",{"text":1610,"type":390,"marks":1611},"{childcode}{parentcode}",[1612],{"type":516},{"text":1614,"type":390}," with no separator.",{"type":1239,"content":1616},[1617],{"type":385,"attrs":1618,"content":1619},{"textAlign":59},[1620,1622,1626],{"text":1621,"type":390},"The ",{"text":1623,"type":390,"marks":1624},"parent_code",[1625],{"type":516},{"text":1627,"type":390}," parameter itself must also be signed using the same combined code.",{"type":1239,"content":1629},[1630],{"type":385,"attrs":1631,"content":1632},{"textAlign":59},[1633,1635,1639,1641,1645],{"text":1634,"type":390},"For select or radio inputs on child products, append the hash to the ",{"text":1636,"type":390,"marks":1637},"value",[1638],{"type":516},{"text":1640,"type":390}," attribute as you would for any other form — see ",{"text":1326,"type":390,"marks":1642},[1643],{"type":1265,"attrs":1644},{"href":1330,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":418,"type":390},{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":1647},{},"How to sign add to cart links and forms for bundled products using HMAC.",[],"sign-bundled-products-with-hmac","help\u002Farticles\u002Fsign-bundled-products-with-hmac",-2510,[],"80018a87-ad0f-4509-bb5c-a7a65c348b6a",[],{"name":1657,"created_at":1658,"published_at":1659,"updated_at":1660,"id":1661,"uuid":1662,"content":1663,"slug":1808,"full_slug":1809,"sort_by_date":59,"position":1810,"tag_list":1811,"is_startpage":24,"parent_id":453,"meta_data":59,"group_id":1812,"first_published_at":1659,"release_id":59,"lang":65,"path":59,"alternates":1813,"default_full_slug":59,"translated_slugs":59},"Sign multiple products in one form with HMAC","2026-06-29T20:24:07.630Z","2026-06-29T20:50:23.441Z","2026-06-29T20:50:23.464Z",192819395141479,"6a02ac99-b4cd-4dbe-8fb9-8359354b481a",{"_uid":1664,"body":1665,"name":1657,"image":1804,"pinned":24,"summary":1806,"category":320,"component":266,"related_articles":1807},"6710a8fb-34d8-49f3-9412-210b4f2d39c0",{"type":382,"content":1666},[1667,1683,1687,1692,1697,1702,1713,1718,1723,1728,1739,1743],{"type":385,"attrs":1668,"content":1669},{"textAlign":59},[1670,1672,1676,1677,1681],{"text":1671,"type":390},"Foxy supports adding multiple products in a single form submission using numeric prefixes on parameter names (e.g. ",{"text":1673,"type":390,"marks":1674},"2:name",[1675],{"type":516},{"text":530,"type":390},{"text":1678,"type":390,"marks":1679},"2:price",[1680],{"type":516},{"text":1682,"type":390},"). When signing these forms with HMAC, generate the hash without the numeric prefix.",{"type":473,"attrs":1684,"content":1685},{"level":475,"textAlign":59},[1686],{"text":1288,"type":390},{"type":385,"attrs":1688,"content":1689},{"textAlign":59},[1690],{"text":1691,"type":390},"Strip the numeric prefix before generating the hash. The prefix is only used to group parameters in the form — it is not part of the value Foxy verifies against.",{"type":385,"attrs":1693,"content":1694},{"textAlign":59},[1695],{"text":1696,"type":390},"For example, a form with two products:",{"type":1499,"attrs":1698,"content":1699},{"class":59},[1700],{"text":1701,"type":390},"\u003Cinput type=\"hidden\" name=\"name\" value=\"Example T-Shirt\" \u002F>\n\u003Cinput type=\"hidden\" name=\"code\" value=\"abc123\" \u002F>\n\u003Cinput type=\"hidden\" name=\"price\" value=\"25\" \u002F>\n\u003Cinput type=\"hidden\" name=\"2:name\" value=\"Baseball Hat\" \u002F>\n\u003Cinput type=\"hidden\" name=\"2:code\" value=\"hat123\" \u002F>\n\u003Cinput type=\"hidden\" name=\"2:price\" value=\"15\" \u002F>\n",{"type":385,"attrs":1703,"content":1704},{"textAlign":59},[1705,1707,1711],{"text":1706,"type":390},"The hashes are generated without the ",{"text":1708,"type":390,"marks":1709},"2:",[1710],{"type":516},{"text":1712,"type":390}," prefix:",{"type":1499,"attrs":1714,"content":1715},{"class":59},[1716],{"text":1717,"type":390},"hash_hmac('sha256', 'abc123nameExample T-Shirt', $api_key); \u002F\u002F First product\nhash_hmac('sha256', 'hat123nameBaseball Hat', $api_key);    \u002F\u002F Second product — no \"2:\" prefix\n",{"type":385,"attrs":1719,"content":1720},{"textAlign":59},[1721],{"text":1722,"type":390},"The signed form inputs look like this:",{"type":1499,"attrs":1724,"content":1725},{"class":59},[1726],{"text":1727,"type":390},"\u003Cinput type=\"hidden\" name=\"name||[hash]\" value=\"Example T-Shirt\" \u002F>\n\u003Cinput type=\"hidden\" name=\"code||[hash]\" value=\"abc123\" \u002F>\n\u003Cinput type=\"hidden\" name=\"price||[hash]\" value=\"25\" \u002F>\n\u003Cinput type=\"hidden\" name=\"2:name||[hash]\" value=\"Baseball Hat\" \u002F>\n\u003Cinput type=\"hidden\" name=\"2:code||[hash]\" value=\"hat123\" \u002F>\n\u003Cinput type=\"hidden\" name=\"2:price||[hash]\" value=\"15\" \u002F>\n",{"type":385,"attrs":1729,"content":1730},{"textAlign":59},[1731,1733,1737],{"text":1732,"type":390},"The numeric prefix is kept in the ",{"text":1734,"type":390,"marks":1735},"name",[1736],{"type":516},{"text":1738,"type":390}," attribute of the input — it is only excluded from the string passed to the hash function.",{"type":473,"attrs":1740,"content":1741},{"level":475,"textAlign":59},[1742],{"text":1380,"type":390},{"type":1236,"content":1744},[1745,1768,1786],{"type":1239,"content":1746},[1747],{"type":385,"attrs":1748,"content":1749},{"textAlign":59},[1750,1752,1756,1758,1762,1763,1766],{"text":1751,"type":390},"A product with no numeric prefix is treated by Foxy as ",{"text":1753,"type":390,"marks":1754},"1:",[1755],{"type":516},{"text":1757,"type":390},". It is good practice to prefix all products explicitly (e.g. ",{"text":1759,"type":390,"marks":1760},"1:name",[1761],{"type":516},{"text":530,"type":390},{"text":1673,"type":390,"marks":1764},[1765],{"type":516},{"text":1767,"type":390},") to avoid any ambiguity.",{"type":1239,"content":1769},[1770],{"type":385,"attrs":1771,"content":1772},{"textAlign":59},[1773,1775,1778,1780,1785],{"text":1774,"type":390},"Each product’s parameters are still hashed using only that product’s own ",{"text":516,"type":390,"marks":1776},[1777],{"type":516},{"text":1779,"type":390}," — not a combined code. For bundled products within a multi-product form, see ",{"text":1433,"type":390,"marks":1781},[1782],{"type":1265,"attrs":1783},{"href":1784,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-bundled-products-with-hmac",{"text":418,"type":390},{"type":1239,"content":1787},[1788],{"type":385,"attrs":1789,"content":1790},{"textAlign":59},[1791,1793,1797,1799,1803],{"text":1792,"type":390},"All other signing rules apply — every parameter must be signed, open fields use ",{"text":1794,"type":390,"marks":1795},"--OPEN--",[1796],{"type":516},{"text":1798,"type":390},", and select\u002Fradio inputs use the value attribute. See ",{"text":1326,"type":390,"marks":1800},[1801],{"type":1265,"attrs":1802},{"href":1330,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":418,"type":390},{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":1805},{},"How to sign add to cart forms that add more than one product at a time using HMAC.",[],"sign-multiple-products-in-one-form-with-hmac","help\u002Farticles\u002Fsign-multiple-products-in-one-form-with-hmac",-2520,[],"8be11f4f-045e-4211-828a-cd56cec8d441",[],{"name":1815,"created_at":1816,"published_at":1817,"updated_at":1818,"id":1819,"uuid":1820,"content":1821,"slug":2040,"full_slug":2041,"sort_by_date":59,"position":2042,"tag_list":2043,"is_startpage":24,"parent_id":453,"meta_data":59,"group_id":2044,"first_published_at":1817,"release_id":59,"lang":65,"path":59,"alternates":2045,"default_full_slug":59,"translated_slugs":59},"Sign open (user-editable) fields with HMAC","2026-06-29T20:22:07.271Z","2026-06-29T20:50:23.922Z","2026-06-29T20:50:23.937Z",192818902151013,"d45142c0-4880-45a0-be87-65d816a29c83",{"_uid":1822,"body":1823,"name":1815,"image":2036,"pinned":24,"summary":2038,"category":320,"component":266,"related_articles":2039},"a8a2d385-8256-44f1-81f6-4bdab7233ca9",{"type":382,"content":1824},[1825,1841,1845,1866,1885,1890,1895,1900,1904,1953,1957,1967,1972,1987,1991],{"type":385,"attrs":1826,"content":1827},{"textAlign":59},[1828,1830,1834,1836,1839],{"text":1829,"type":390},"By default, HMAC signing requires a known value at the time of signing. For fields where the value is entered by the customer — such as ",{"text":1831,"type":390,"marks":1832},"quantity",[1833],{"type":516},{"text":1835,"type":390}," or a custom message field — you use the ",{"text":1794,"type":390,"marks":1837},[1838],{"type":516},{"text":1840,"type":390}," keyword instead of a real value, which tells Foxy to accept whatever the customer enters.",{"type":473,"attrs":1842,"content":1843},{"level":475,"textAlign":59},[1844],{"text":1288,"type":390},{"type":385,"attrs":1846,"content":1847},{"textAlign":59},[1848,1850,1853,1855,1859,1861,1864],{"text":1849,"type":390},"Instead of concatenating the actual value, use the string ",{"text":1794,"type":390,"marks":1851},[1852],{"type":516},{"text":1854,"type":390}," as the value when generating the hash. Append ",{"text":1856,"type":390,"marks":1857},"||open",[1858],{"type":516},{"text":1860,"type":390}," after the hash in the ",{"text":1734,"type":390,"marks":1862},[1863],{"type":516},{"text":1865,"type":390}," attribute to tell Foxy the field accepts user-generated values.",{"type":385,"attrs":1867,"content":1868},{"textAlign":59},[1869,1871,1874,1876,1879,1880,1884],{"text":1870,"type":390},"For example, for a ",{"text":1831,"type":390,"marks":1872},[1873],{"type":516},{"text":1875,"type":390}," field on a product with ",{"text":516,"type":390,"marks":1877},[1878],{"type":516},{"text":1481,"type":390},{"text":1881,"type":390,"marks":1882},"abc123",[1883],{"type":516},{"text":1497,"type":390},{"type":1499,"attrs":1886,"content":1887},{"class":59},[1888],{"text":1889,"type":390},"hash_hmac('sha256', 'abc123quantity--OPEN--', $api_key);\n",{"type":385,"attrs":1891,"content":1892},{"textAlign":59},[1893],{"text":1894,"type":390},"The signed input looks like this:",{"type":1499,"attrs":1896,"content":1897},{"class":59},[1898],{"text":1899,"type":390},"\u003Cinput type=\"text\" name=\"quantity||753d51d4675bfb6f0aec5e6fbfd8a2e32cbea620c15a181567b052d350469c50||open\" value=\"\" \u002F>\n",{"type":473,"attrs":1901,"content":1902},{"level":475,"textAlign":59},[1903],{"text":1522,"type":390},{"type":1524,"attrs":1905,"content":1906},{"order":488},[1907,1923,1930],{"type":1239,"content":1908},[1909],{"type":385,"attrs":1910,"content":1911},{"textAlign":59},[1912,1914,1917,1919,1922],{"text":1913,"type":390},"For each user-editable field, concatenate the product ",{"text":516,"type":390,"marks":1915},[1916],{"type":516},{"text":1918,"type":390},", field name, and the string ",{"text":1794,"type":390,"marks":1920},[1921],{"type":516},{"text":418,"type":390},{"type":1239,"content":1924},[1925],{"type":385,"attrs":1926,"content":1927},{"textAlign":59},[1928],{"text":1929,"type":390},"Generate an HMAC SHA-256 hash of that string using your store’s API key.",{"type":1239,"content":1931},[1932],{"type":385,"attrs":1933,"content":1934},{"textAlign":59},[1935,1937,1941,1943,1946,1948,1951],{"text":1936,"type":390},"Append ",{"text":1938,"type":390,"marks":1939},"||",[1940],{"type":516},{"text":1942,"type":390},", the hash, and ",{"text":1856,"type":390,"marks":1944},[1945],{"type":516},{"text":1947,"type":390}," to the field’s ",{"text":1734,"type":390,"marks":1949},[1950],{"type":516},{"text":1952,"type":390}," attribute.",{"type":473,"attrs":1954,"content":1955},{"level":475,"textAlign":59},[1956],{"text":1570,"type":390},{"type":385,"attrs":1958,"content":1959},{"textAlign":59},[1960,1962,1965],{"text":1961,"type":390},"The PHP helper function handles open fields automatically. Pass ",{"text":1794,"type":390,"marks":1963},[1964],{"type":516},{"text":1966,"type":390}," as the value:",{"type":1499,"attrs":1968,"content":1969},{"class":59},[1970],{"text":1971,"type":390},"get_verification('quantity', '--OPEN--', 'abc123');\n",{"type":385,"attrs":1973,"content":1974},{"textAlign":59},[1975,1977,1980,1982,1985],{"text":1976,"type":390},"The function detects ",{"text":1794,"type":390,"marks":1978},[1979],{"type":516},{"text":1981,"type":390}," and appends ",{"text":1856,"type":390,"marks":1983},[1984],{"type":516},{"text":1986,"type":390}," to the output automatically.",{"type":473,"attrs":1988,"content":1989},{"level":475,"textAlign":59},[1990],{"text":1380,"type":390},{"type":1236,"content":1992},[1993,2004,2016,2029],{"type":1239,"content":1994},[1995],{"type":385,"attrs":1996,"content":1997},{"textAlign":59},[1998,1999,2002],{"text":1621,"type":390},{"text":1856,"type":390,"marks":2000},[2001],{"type":516},{"text":2003,"type":390}," suffix is required. Without it, Foxy will not accept user-generated values in that field.",{"type":1239,"content":2005},[2006],{"type":385,"attrs":2007,"content":2008},{"textAlign":59},[2009,2011,2014],{"text":2010,"type":390},"Do not use ",{"text":1794,"type":390,"marks":2012},[2013],{"type":516},{"text":2015,"type":390}," as a real product value — it will allow that field to be freely modified by the customer.",{"type":1239,"content":2017},[2018],{"type":385,"attrs":2019,"content":2020},{"textAlign":59},[2021,2023,2027],{"text":2022,"type":390},"Curly brackets ",{"text":2024,"type":390,"marks":2025},"{ }",[2026],{"type":516},{"text":2028,"type":390}," are stripped from any open field value, preventing customers from injecting price, weight, code, or category modifiers.",{"type":1239,"content":2030},[2031],{"type":385,"attrs":2032,"content":2033},{"textAlign":59},[2034],{"text":2035,"type":390},"Open fields should still be signed — do not skip them or leave them unsigned.",{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":2037},{},"How to sign form fields that accept user input, such as quantity, using HMAC.",[],"sign-open-user-editable-fields-with-hmac","help\u002Farticles\u002Fsign-open-user-editable-fields-with-hmac",-2500,[],"a613a33b-ff58-42e2-9258-ee13ff7719f2",[],{"name":1326,"created_at":2047,"published_at":2048,"updated_at":2049,"id":2050,"uuid":2051,"content":2052,"slug":2410,"full_slug":2411,"sort_by_date":59,"position":2412,"tag_list":2413,"is_startpage":24,"parent_id":453,"meta_data":59,"group_id":2414,"first_published_at":2048,"release_id":59,"lang":65,"path":59,"alternates":2415,"default_full_slug":59,"translated_slugs":59},"2026-06-29T20:17:58.619Z","2026-06-29T20:50:24.473Z","2026-06-29T20:50:24.502Z",192817883676515,"79675f4b-0ab8-41cd-8a21-8ab9c8c3af18",{"_uid":2053,"body":2054,"name":1326,"image":2406,"pinned":24,"summary":2408,"category":320,"component":266,"related_articles":2409},"18faf735-5cc8-40f4-ab7c-243bf91f3c0e",{"type":382,"content":2055},[2056,2066,2071,2076,2108,2123,2145,2150,2154,2159,2163,2216,2221,2253,2258,2262,2277,2282,2299,2304,2316,2320],{"type":385,"attrs":2057,"content":2058},{"textAlign":59},[2059,2061,2064],{"text":2060,"type":390},"Signing a product form with HMAC means generating a SHA-256 hash for each input and appending it to the input’s ",{"text":1734,"type":390,"marks":2062},[2063],{"type":516},{"text":2065,"type":390}," attribute. Foxy checks these hashes when the form is submitted — any unsigned or modified value is rejected.",{"type":473,"attrs":2067,"content":2068},{"level":475,"textAlign":59},[2069],{"text":2070,"type":390},"How signing works",{"type":385,"attrs":2072,"content":2073},{"textAlign":59},[2074],{"text":2075,"type":390},"For each input, concatenate three values in this order:",{"type":1524,"attrs":2077,"content":2078},{"order":488},[2079,2089,2099],{"type":1239,"content":2080},[2081],{"type":385,"attrs":2082,"content":2083},{"textAlign":59},[2084,2086],{"text":2085,"type":390},"The product ",{"text":516,"type":390,"marks":2087},[2088],{"type":516},{"type":1239,"content":2090},[2091],{"type":385,"attrs":2092,"content":2093},{"textAlign":59},[2094,2096],{"text":2095,"type":390},"The input’s ",{"text":1734,"type":390,"marks":2097},[2098],{"type":516},{"type":1239,"content":2100},[2101],{"type":385,"attrs":2102,"content":2103},{"textAlign":59},[2104,2105],{"text":2095,"type":390},{"text":1636,"type":390,"marks":2106},[2107],{"type":516},{"type":385,"attrs":2109,"content":2110},{"textAlign":59},[2111,2113,2116,2118,2121],{"text":2112,"type":390},"Then HMAC SHA-256 that string using your store’s API key, and append the resulting 64-character hash to the ",{"text":1734,"type":390,"marks":2114},[2115],{"type":516},{"text":2117,"type":390}," attribute using double pipes (",{"text":1938,"type":390,"marks":2119},[2120],{"type":516},{"text":2122,"type":390},").",{"type":385,"attrs":2124,"content":2125},{"textAlign":59},[2126,2128,2131,2132,2135,2136,2139,2140,2144],{"text":2127,"type":390},"For example, a product with ",{"text":516,"type":390,"marks":2129},[2130],{"type":516},{"text":1481,"type":390},{"text":1881,"type":390,"marks":2133},[2134],{"type":516},{"text":1332,"type":390},{"text":1734,"type":390,"marks":2137},[2138],{"type":516},{"text":1481,"type":390},{"text":2141,"type":390,"marks":2142},"Example T-Shirt",[2143],{"type":516},{"text":1497,"type":390},{"type":1499,"attrs":2146,"content":2147},{"class":59},[2148],{"text":2149,"type":390},"hash_hmac('sha256', 'abc123nameExample T-Shirt', $api_key);\n",{"type":385,"attrs":2151,"content":2152},{"textAlign":59},[2153],{"text":1894,"type":390},{"type":1499,"attrs":2155,"content":2156},{"class":59},[2157],{"text":2158,"type":390},"\u003Cinput type=\"hidden\" name=\"name||f8d3b7b993380dee31ee467984397ed8dc5feec3eb464bc55264cbe33fd691ac\" value=\"Example T-Shirt\" \u002F>\n",{"type":473,"attrs":2160,"content":2161},{"level":475,"textAlign":59},[2162],{"text":1522,"type":390},{"type":1524,"attrs":2164,"content":2165},{"order":488},[2166,2188,2194,2209],{"type":1239,"content":2167},[2168],{"type":385,"attrs":2169,"content":2170},{"textAlign":59},[2171,2173,2176,2178,2181,2183,2186],{"text":2172,"type":390},"For each product input, concatenate the product ",{"text":516,"type":390,"marks":2174},[2175],{"type":516},{"text":2177,"type":390},", input ",{"text":1734,"type":390,"marks":2179},[2180],{"type":516},{"text":2182,"type":390},", and input ",{"text":1636,"type":390,"marks":2184},[2185],{"type":516},{"text":2187,"type":390}," into a single string.",{"type":1239,"content":2189},[2190],{"type":385,"attrs":2191,"content":2192},{"textAlign":59},[2193],{"text":1929,"type":390},{"type":1239,"content":2195},[2196],{"type":385,"attrs":2197,"content":2198},{"textAlign":59},[2199,2200,2203,2205,2208],{"text":1936,"type":390},{"text":1938,"type":390,"marks":2201},[2202],{"type":516},{"text":2204,"type":390}," and the hash to the input’s ",{"text":1734,"type":390,"marks":2206},[2207],{"type":516},{"text":1952,"type":390},{"type":1239,"content":2210},[2211],{"type":385,"attrs":2212,"content":2213},{"textAlign":59},[2214],{"text":2215,"type":390},"Repeat for every input on every add-to-cart form.",{"type":473,"attrs":2217,"content":2218},{"level":475,"textAlign":59},[2219],{"text":2220,"type":390},"Select and radio inputs",{"type":385,"attrs":2222,"content":2223},{"textAlign":59},[2224,2226,2230,2231,2235,2237,2240,2242,2246,2248,2251],{"text":2225,"type":390},"For ",{"text":2227,"type":390,"marks":2228},"\u003Cselect>",[2229],{"type":516},{"text":1332,"type":390},{"text":2232,"type":390,"marks":2233},"\u003Cradio>",[2234],{"type":516},{"text":2236,"type":390}," elements, append the hash to the ",{"text":1636,"type":390,"marks":2238},[2239],{"type":516},{"text":2241,"type":390}," attribute of each ",{"text":2243,"type":390,"marks":2244},"\u003Coption>",[2245],{"type":516},{"text":2247,"type":390}," rather than the ",{"text":1734,"type":390,"marks":2249},[2250],{"type":516},{"text":2252,"type":390},". The concatenation is the same — code, name, and value:",{"type":1499,"attrs":2254,"content":2255},{"class":59},[2256],{"text":2257,"type":390},"\u003Cselect name=\"size\">\n  \u003Coption value=\"small{p-2}||14696b9ff099727a798a5b59d71bc1540a5481adfd957ed2252acf8aec83914a\">Small\u003C\u002Foption>\n  \u003Coption value=\"medium||713800d729f987d4609a8b83b60932e64f64690b4c2842b7d6522a62fe514af4\">Medium\u003C\u002Foption>\n  \u003Coption value=\"large{p+3}||c8d37d7c32c3c4fc9fe9703e8cc3456020aa9319dd18816d7f887c6f9c616708\">Large\u003C\u002Foption>\n\u003C\u002Fselect>\n",{"type":473,"attrs":2259,"content":2260},{"level":475,"textAlign":59},[2261],{"text":1570,"type":390},{"type":385,"attrs":2263,"content":2264},{"textAlign":59},[2265,2267,2270,2272,2275],{"text":2266,"type":390},"If you are using PHP, you can use this helper function to generate signed ",{"text":1734,"type":390,"marks":2268},[2269],{"type":516},{"text":2271,"type":390}," or ",{"text":1636,"type":390,"marks":2273},[2274],{"type":516},{"text":2276,"type":390}," attributes:",{"type":1499,"attrs":2278,"content":2279},{"class":59},[2280],{"text":2281,"type":390},"function get_verification($var_name, $var_value, $var_code, $var_parent_code = \"\", $for_value = false) {\n    $api_key = \"your_api_key_here\";\n    $encodingval = htmlspecialchars($var_code . $var_parent_code . $var_name . $var_value);\n    $label = ($for_value) ? $var_value : $var_name;\n    return $label . '||' . hash_hmac('sha256', $encodingval, $api_key) . ($var_value === \"--OPEN--\" ? \"||open\" : \"\");\n}\n",{"type":385,"attrs":2283,"content":2284},{"textAlign":59},[2285,2287,2291,2293,2297],{"text":2286,"type":390},"Pass ",{"text":2288,"type":390,"marks":2289},"true",[2290],{"type":516},{"text":2292,"type":390}," as the fifth argument (",{"text":2294,"type":390,"marks":2295},"$for_value",[2296],{"type":516},{"text":2298,"type":390},") when signing select or radio option values:",{"type":1499,"attrs":2300,"content":2301},{"class":59},[2302],{"text":2303,"type":390},"\u003Coption value=\"\u003C?php echo get_verification('size', 'small{p-2}', 'abc123', '', true); ?>\">Small\u003C\u002Foption>\n",{"type":385,"attrs":2305,"content":2306},{"textAlign":59},[2307,2309,2315],{"text":2308,"type":390},"For a fully automatic approach that signs an entire HTML page at once, see the ",{"text":2310,"type":390,"marks":2311},"FoxyCart Cart Validation PHP library on GitHub",[2312],{"type":1265,"attrs":2313},{"href":2314,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Fgithub.com\u002Ffoxycart\u002Ffoxycart-cart-validation",{"text":418,"type":390},{"type":473,"attrs":2317,"content":2318},{"level":475,"textAlign":59},[2319],{"text":1380,"type":390},{"type":1236,"content":2321},[2322,2350,2369,2381,2394],{"type":1239,"content":2323},[2324],{"type":385,"attrs":2325,"content":2326},{"textAlign":59},[2327,2329,2332,2333,2336,2338,2342,2344,2348],{"text":2328,"type":390},"Every input that relates to a product must be signed — not just ",{"text":1734,"type":390,"marks":2330},[2331],{"type":516},{"text":530,"type":390},{"text":516,"type":390,"marks":2334},[2335],{"type":516},{"text":2337,"type":390},", and ",{"text":2339,"type":390,"marks":2340},"price",[2341],{"type":516},{"text":2343,"type":390},". An unsigned ",{"text":2345,"type":390,"marks":2346},"size",[2347],{"type":516},{"text":2349,"type":390}," option with a price modifier could be used to manipulate the price.",{"type":1239,"content":2351},[2352],{"type":385,"attrs":2353,"content":2354},{"textAlign":59},[2355,2357,2360,2362,2368],{"text":2356,"type":390},"For open (user-editable) fields such as ",{"text":1831,"type":390,"marks":2358},[2359],{"type":516},{"text":2361,"type":390},", see ",{"text":2363,"type":390,"marks":2364},"Sign open fields with HMAC",[2365],{"type":1265,"attrs":2366},{"href":2367,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-open-user-editable-fields-with-hmac",{"text":418,"type":390},{"type":1239,"content":2370},[2371],{"type":385,"attrs":2372,"content":2373},{"textAlign":59},[2374,2376,2380],{"text":2375,"type":390},"For bundled products, see ",{"text":1433,"type":390,"marks":2377},[2378],{"type":1265,"attrs":2379},{"href":1784,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":418,"type":390},{"type":1239,"content":2382},[2383],{"type":385,"attrs":2384,"content":2385},{"textAlign":59},[2386,2388,2393],{"text":2387,"type":390},"For multiple products in one form, see ",{"text":1657,"type":390,"marks":2389},[2390],{"type":1265,"attrs":2391},{"href":2392,"uuid":59,"anchor":59,"target":59,"linktype":31},"https:\u002F\u002Ffoxy.io\u002Fhelp\u002Farticles\u002Fsign-multiple-products-in-one-form-with-hmac",{"text":418,"type":390},{"type":1239,"content":2395},[2396],{"type":385,"attrs":2397,"content":2398},{"textAlign":59},[2399,2401,2405],{"text":2400,"type":390},"For parameters that do not need to be signed, see ",{"text":457,"type":390,"marks":2402},[2403],{"type":1265,"attrs":2404},{"href":1303,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":418,"type":390},{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":2407},{},"How to sign your add to cart form inputs with HMAC to prevent tampering.",[],"sign-product-forms-with-hmac","help\u002Farticles\u002Fsign-product-forms-with-hmac",-2480,[],"41ea04bf-0b7d-4d21-8e54-be88d75b84c2",[],{"name":1334,"created_at":2417,"published_at":2418,"updated_at":2419,"id":2420,"uuid":2421,"content":2422,"slug":2677,"full_slug":2678,"sort_by_date":59,"position":2679,"tag_list":2680,"is_startpage":24,"parent_id":453,"meta_data":59,"group_id":2681,"first_published_at":2418,"release_id":59,"lang":65,"path":59,"alternates":2682,"default_full_slug":59,"translated_slugs":59},"2026-06-29T20:20:12.658Z","2026-06-29T20:50:24.188Z","2026-06-29T20:50:24.204Z",192818432696164,"5b6a5904-6fa8-4f24-8516-1ac5da980a58",{"_uid":2423,"body":2424,"name":1334,"image":2673,"pinned":24,"summary":2675,"category":320,"component":266,"related_articles":2676},"fa6c8c8d-5847-439c-85c0-494408567ea2",{"type":382,"content":2425},[2426,2431,2435,2440,2466,2475,2502,2507,2511,2550,2554,2559,2563,2568,2573,2578,2607,2611],{"type":385,"attrs":2427,"content":2428},{"textAlign":59},[2429],{"text":2430,"type":390},"Signing a product link with HMAC means generating a SHA-256 hash for each parameter and appending it to the parameter name. Foxy checks these hashes when the link is used — any unsigned or modified parameter is rejected.",{"type":473,"attrs":2432,"content":2433},{"level":475,"textAlign":59},[2434],{"text":2070,"type":390},{"type":385,"attrs":2436,"content":2437},{"textAlign":59},[2438],{"text":2439,"type":390},"For each parameter, concatenate three values in this order:",{"type":1524,"attrs":2441,"content":2442},{"order":488},[2443,2452,2459],{"type":1239,"content":2444},[2445],{"type":385,"attrs":2446,"content":2447},{"textAlign":59},[2448,2449],{"text":2085,"type":390},{"text":516,"type":390,"marks":2450},[2451],{"type":516},{"type":1239,"content":2453},[2454],{"type":385,"attrs":2455,"content":2456},{"textAlign":59},[2457],{"text":2458,"type":390},"The parameter name",{"type":1239,"content":2460},[2461],{"type":385,"attrs":2462,"content":2463},{"textAlign":59},[2464],{"text":2465,"type":390},"The parameter value",{"type":385,"attrs":2467,"content":2468},{"textAlign":59},[2469,2471,2474],{"text":2470,"type":390},"Then HMAC SHA-256 that string using your store’s API key, and append the resulting 64-character hash to the parameter name using double pipes (",{"text":1938,"type":390,"marks":2472},[2473],{"type":516},{"text":2122,"type":390},{"type":385,"attrs":2476,"content":2477},{"textAlign":59},[2478,2479,2482,2483,2486,2487,2490,2491,2495,2497,2501],{"text":2127,"type":390},{"text":516,"type":390,"marks":2480},[2481],{"type":516},{"text":1481,"type":390},{"text":1881,"type":390,"marks":2484},[2485],{"type":516},{"text":1332,"type":390},{"text":1734,"type":390,"marks":2488},[2489],{"type":516},{"text":1481,"type":390},{"text":2492,"type":390,"marks":2493},"My Widget",[2494],{"type":516},{"text":2496,"type":390}," priced at ",{"text":2498,"type":390,"marks":2499},"1.99",[2500],{"type":516},{"text":1497,"type":390},{"type":1499,"attrs":2503,"content":2504},{"class":59},[2505],{"text":2506,"type":390},"hash_hmac('sha256', 'abc123nameMy Widget', $api_key);\nhash_hmac('sha256', 'abc123codemycode', $api_key);\nhash_hmac('sha256', 'abc123price1.99', $api_key);\n",{"type":473,"attrs":2508,"content":2509},{"level":475,"textAlign":59},[2510],{"text":1522,"type":390},{"type":1524,"attrs":2512,"content":2513},{"order":488},[2514,2526,2532,2543],{"type":1239,"content":2515},[2516],{"type":385,"attrs":2517,"content":2518},{"textAlign":59},[2519,2521,2524],{"text":2520,"type":390},"For each parameter, concatenate the product ",{"text":516,"type":390,"marks":2522},[2523],{"type":516},{"text":2525,"type":390},", parameter name, and parameter value into a single string.",{"type":1239,"content":2527},[2528],{"type":385,"attrs":2529,"content":2530},{"textAlign":59},[2531],{"text":1929,"type":390},{"type":1239,"content":2533},[2534],{"type":385,"attrs":2535,"content":2536},{"textAlign":59},[2537,2538,2541],{"text":1936,"type":390},{"text":1938,"type":390,"marks":2539},[2540],{"type":516},{"text":2542,"type":390}," and the hash to the parameter name in the URL.",{"type":1239,"content":2544},[2545],{"type":385,"attrs":2546,"content":2547},{"textAlign":59},[2548],{"text":2549,"type":390},"Repeat for every parameter on every add-to-cart link.",{"type":473,"attrs":2551,"content":2552},{"level":475,"textAlign":59},[2553],{"text":1570,"type":390},{"type":385,"attrs":2555,"content":2556},{"textAlign":59},[2557],{"text":2558,"type":390},"If you are using PHP, you can use this helper function to generate signed parameter names:",{"type":1499,"attrs":2560,"content":2561},{"class":59},[2562],{"text":2281,"type":390},{"type":385,"attrs":2564,"content":2565},{"textAlign":59},[2566],{"text":2567,"type":390},"To build a signed link using the helper:",{"type":1499,"attrs":2569,"content":2570},{"class":59},[2571],{"text":2572,"type":390},"$atc  = \"?\";\n$atc .= get_verification(\"name\", \"My Widget\", \"mycode\") . \"=\" . urlencode(\"My Widget\");\n$atc .= \"&\" . get_verification(\"code\", \"mycode\", \"mycode\") . \"=\" . urlencode(\"mycode\");\n$atc .= \"&\" . get_verification(\"price\", \"1.99\", \"mycode\") . \"=\" . urlencode(\"1.99\");\n",{"type":473,"attrs":2574,"content":2575},{"level":475,"textAlign":59},[2576],{"text":2577,"type":390},"Spaces and special characters",{"type":385,"attrs":2579,"content":2580},{"textAlign":59},[2581,2583,2587,2589,2593,2595,2599,2601,2605],{"text":2582,"type":390},"When a parameter value contains spaces or special characters, pass the raw string to the hashing function but URL-encode the value in the link itself. In PHP, use ",{"text":2584,"type":390,"marks":2585},"urlencode()",[2586],{"type":516},{"text":2588,"type":390}," for this. For example, ",{"text":2590,"type":390,"marks":2591},"\"Black & White T-shirt\"",[2592],{"type":516},{"text":2594,"type":390}," is passed as-is to ",{"text":2596,"type":390,"marks":2597},"get_verification()",[2598],{"type":516},{"text":2600,"type":390},", but written as ",{"text":2602,"type":390,"marks":2603},"Black+%26+White+T-shirt",[2604],{"type":516},{"text":2606,"type":390}," in the URL.",{"type":473,"attrs":2608,"content":2609},{"level":475,"textAlign":59},[2610],{"text":1380,"type":390},{"type":1236,"content":2612},[2613,2620,2632,2643,2655,2666],{"type":1239,"content":2614},[2615],{"type":385,"attrs":2616,"content":2617},{"textAlign":59},[2618],{"text":2619,"type":390},"Every parameter that relates to a product must be signed. An unsigned parameter with a price modifier could be used to manipulate the price.",{"type":1239,"content":2621},[2622],{"type":385,"attrs":2623,"content":2624},{"textAlign":59},[2625,2627,2631],{"text":2626,"type":390},"For open (user-editable) fields, see ",{"text":2363,"type":390,"marks":2628},[2629],{"type":1265,"attrs":2630},{"href":2367,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":418,"type":390},{"type":1239,"content":2633},[2634],{"type":385,"attrs":2635,"content":2636},{"textAlign":59},[2637,2638,2642],{"text":2375,"type":390},{"text":1433,"type":390,"marks":2639},[2640],{"type":1265,"attrs":2641},{"href":1784,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":418,"type":390},{"type":1239,"content":2644},[2645],{"type":385,"attrs":2646,"content":2647},{"textAlign":59},[2648,2650,2654],{"text":2649,"type":390},"For multiple products in one link, see ",{"text":1657,"type":390,"marks":2651},[2652],{"type":1265,"attrs":2653},{"href":2392,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":418,"type":390},{"type":1239,"content":2656},[2657],{"type":385,"attrs":2658,"content":2659},{"textAlign":59},[2660,2661,2665],{"text":2400,"type":390},{"text":457,"type":390,"marks":2662},[2663],{"type":1265,"attrs":2664},{"href":1303,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":418,"type":390},{"type":1239,"content":2667},[2668],{"type":385,"attrs":2669,"content":2670},{"textAlign":59},[2671],{"text":2672,"type":390},"Forms with many signed parameters may push Internet Explorer (up to IE8) past its 2,083-character URL limit for GET submissions. POST submissions are unaffected.",{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":2674},{},"How to sign your add to cart links with HMAC to prevent parameter tampering.",[],"sign-product-links-with-hmac","help\u002Farticles\u002Fsign-product-links-with-hmac",-2490,[],"c57cce4d-532c-4ff9-b4bf-1a4f01cfd8a7",[],{"name":1350,"created_at":2684,"published_at":2685,"updated_at":2686,"id":2687,"uuid":2688,"content":2689,"slug":2846,"full_slug":2847,"sort_by_date":59,"position":2848,"tag_list":2849,"is_startpage":24,"parent_id":453,"meta_data":59,"group_id":2850,"first_published_at":2685,"release_id":59,"lang":65,"path":59,"alternates":2851,"default_full_slug":59,"translated_slugs":59},"2026-06-29T20:33:58.987Z","2026-06-29T20:50:23.255Z","2026-06-29T20:50:23.269Z",192821817347947,"4df213b2-776b-4228-85d1-abfbd5730823",{"_uid":2690,"body":2691,"name":1350,"image":2842,"pinned":24,"summary":2844,"category":320,"component":266,"related_articles":2845},"a79d5d26-3c26-472f-aa37-9cee0f65d9f0",{"type":382,"content":2692},[2693,2698,2702,2811,2815],{"type":385,"attrs":2694,"content":2695},{"textAlign":59},[2696],{"text":2697,"type":390},"The Foxy admin includes a built-in tool that signs product links and forms for you. This is useful for static sites, one-off forms, or any situation where you want to sign a small number of links or forms without implementing a signing library.",{"type":473,"attrs":2699,"content":2700},{"level":475,"textAlign":59},[2701],{"text":1522,"type":390},{"type":1524,"attrs":2703,"content":2704},{"order":488},[2705,2712,2727,2745,2792,2804],{"type":1239,"content":2706},[2707],{"type":385,"attrs":2708,"content":2709},{"textAlign":59},[2710],{"text":2711,"type":390},"Build your product link or form as you normally would, without any HMAC signing applied.",{"type":1239,"content":2713},[2714],{"type":385,"attrs":2715,"content":2716},{"textAlign":59},[2717,2719,2726],{"text":2718,"type":390},"Go to the ",{"text":2720,"type":390,"marks":2721},"Foxy admin",[2722],{"type":1265,"attrs":2723},{"href":2724,"uuid":59,"anchor":59,"target":2725,"linktype":31},"https:\u002F\u002Fadmin.foxycart.com","_self",{"text":418,"type":390},{"type":1239,"content":2728},[2729],{"type":385,"attrs":2730,"content":2731},{"textAlign":59},[2732,2734,2738,2740,2744],{"text":2733,"type":390},"Go to ",{"text":2735,"type":390,"marks":2736},"Store",[2737],{"type":410},{"text":2739,"type":390},", then ",{"text":2741,"type":390,"marks":2742},"Sample Code",[2743],{"type":410},{"text":418,"type":390},{"type":1239,"content":2746},[2747,2758],{"type":385,"attrs":2748,"content":2749},{"textAlign":59},[2750,2752,2756],{"text":2751,"type":390},"Paste your link or form into the text box under ",{"text":2753,"type":390,"marks":2754},"Step 2",[2755],{"type":410},{"text":2757,"type":390},", replacing any code already there.",{"type":1236,"content":2759},[2760,2773],{"type":1239,"content":2761},[2762],{"type":385,"attrs":2763,"content":2764},{"textAlign":59},[2765,2767,2771],{"text":2766,"type":390},"Links must be complete ",{"text":2768,"type":390,"marks":2769},"\u003Ca>",[2770],{"type":516},{"text":2772,"type":390}," elements.",{"type":1239,"content":2774},[2775],{"type":385,"attrs":2776,"content":2777},{"textAlign":59},[2778,2780,2784,2786,2790],{"text":2779,"type":390},"Forms must be complete ",{"text":2781,"type":390,"marks":2782},"\u003Cform>",[2783],{"type":516},{"text":2785,"type":390}," elements with the ",{"text":2787,"type":390,"marks":2788},"action",[2789],{"type":516},{"text":2791,"type":390}," attribute pointing to your store URL.",{"type":1239,"content":2793},[2794],{"type":385,"attrs":2795,"content":2796},{"textAlign":59},[2797,2799,2803],{"text":2798,"type":390},"Click ",{"text":2800,"type":390,"marks":2801},"Encode HTML",[2802],{"type":410},{"text":418,"type":390},{"type":1239,"content":2805},[2806],{"type":385,"attrs":2807,"content":2808},{"textAlign":59},[2809],{"text":2810,"type":390},"Copy the signed HTML from the output box and paste it into your page.",{"type":473,"attrs":2812,"content":2813},{"level":475,"textAlign":59},[2814],{"text":1380,"type":390},{"type":1236,"content":2816},[2817,2824,2831],{"type":1239,"content":2818},[2819],{"type":385,"attrs":2820,"content":2821},{"textAlign":59},[2822],{"text":2823,"type":390},"If you need to update a signed link or form, you cannot edit the signed version directly. Rebuild the original unsigned version, make your changes, and re-encode it.",{"type":1239,"content":2825},[2826],{"type":385,"attrs":2827,"content":2828},{"textAlign":59},[2829],{"text":2830,"type":390},"You can paste multiple links or forms at once and encode them in a single step.",{"type":1239,"content":2832},[2833],{"type":385,"attrs":2834,"content":2835},{"textAlign":59},[2836,2837,2841],{"text":1389,"type":390},{"text":373,"type":390,"marks":2838},[2839],{"type":1265,"attrs":2840},{"href":1394,"uuid":59,"anchor":59,"target":59,"linktype":31},{"text":418,"type":390},{"id":59,"alt":59,"name":13,"focus":59,"title":59,"source":59,"filename":13,"copyright":59,"fieldtype":81,"meta_data":2843},{},"How to use the admin to manually sign product links and forms with HMAC.",[],"use-the-admin-tool-to-sign-products-with-hmac","help\u002Farticles\u002Fuse-the-admin-tool-to-sign-products-with-hmac",-2530,[],"d4f7a49c-2d3d-4908-a566-a4763241505b",[],{"name":2853,"created_at":2854,"published_at":2855,"updated_at":2856,"id":2857,"uuid":47,"content":2858,"slug":48,"full_slug":48,"sort_by_date":59,"position":3034,"tag_list":3035,"is_startpage":24,"parent_id":59,"meta_data":59,"group_id":3036,"first_published_at":3037,"release_id":59,"lang":65,"path":59,"alternates":3038,"default_full_slug":59,"translated_slugs":59},"Contact","2022-09-23T19:56:58.957Z","2025-05-08T18:24:40.382Z","2025-05-08T18:24:40.392Z",3138,{"seo":2859,"_uid":2862,"title":2863,"action":2864,"fields":2865,"method":3010,"columns":3011,"subtitle":3025,"component":48,"button_text":3031,"submit_title":3032,"submit_subtitle":3033},{"_uid":2860,"title":2853,"plugin":2861,"description":13},"24ff7574-3bcc-48d2-85b5-e529dfea1cc4","meta-fields","8f54f1da-9d8f-49b2-89e7-840e886491cb","We're here to help.","https:\u002F\u002Fusebasin.com\u002Ff\u002F029f48d65402",[2866,2870,2874,2981,2984,2989,3004],{"_uid":2867,"name":1734,"type":390,"label":2868,"options":13,"required":33,"component":2869,"placeholder":13},"9a70b226-2036-4f90-a052-b3efa61c5896","Name","form___field",{"_uid":2871,"name":2872,"type":2872,"label":2873,"options":13,"required":33,"component":2869,"placeholder":13},"86ba35be-ff43-4a28-8633-14052a8f6622","email","Email Address",{"_uid":2875,"name":2876,"type":2877,"label":2878,"options":2879,"required":33,"component":2869,"conditions":2880,"placeholder":13},"3f827475-492c-4f97-aa1e-2386ac263b6c","topic","select","Topic","Presales, Support, Billing, Partnerships, Order Enquiry, Other",[2881,2935,2945,2952,2960,2968,2974],{"_uid":2882,"equals":2883,"fields":2884,"component":2934},"e21d97dd-e68e-4fa6-ba97-bc40f3041dde","Order Enquiry",[2885],{"_uid":2886,"body":2887,"type":2932,"title":13,"component":2933},"b64992bc-6d53-48b8-b7a0-d81e5a062e50",{"type":382,"content":2888},[2889],{"type":385,"content":2890},[2891,2893,2900,2902,2904,2905,2909,2911,2915,2923,2925,2930],{"text":2892,"type":390},"We are ",{"text":2894,"type":390,"marks":2895},"Foxy.io",[2896],{"type":1265,"attrs":2897},{"href":2898,"uuid":59,"anchor":59,"custom":2899,"target":59,"linktype":31},"http:\u002F\u002FFoxy.io",{},{"text":2901,"type":390},", an ecommerce platform powering ecommerce for other merchants. We do not sell products, and are unable to assist with questions about order statuses or refunds for any merchants using our platform. Please contact the merchant you ordered from for assistance. If you’d like to report a store using Foxy for fraudulent practices, please select ‘other’ in the subject.",{"type":2903},"hard_break",{"type":2903},{"text":2906,"type":390,"marks":2907},"NOTE:",[2908],{"type":410},{"text":2910,"type":390}," We are ",{"text":2912,"type":390,"marks":2913},"not ",[2914],{"type":1419},{"text":2916,"type":390,"marks":2917},"Foxy.in",[2918,2922],{"type":1265,"attrs":2919},{"href":2920,"uuid":59,"anchor":59,"custom":2921,"target":59,"linktype":31},"http:\u002F\u002FFoxy.in",{},{"type":1419},{"text":2924,"type":390},". We are not in any way affiliated with ",{"text":2916,"type":390,"marks":2926},[2927],{"type":1265,"attrs":2928},{"href":2920,"uuid":59,"anchor":59,"custom":2929,"target":59,"linktype":31},{},{"text":2931,"type":390},", and cannot help in any way with your order from that website.","danger","global___alert","form___condition",{"_uid":2936,"equals":2937,"fields":2938,"component":2934},"8765c3e1-25cf-44aa-b8ea-fc6094acf9c3","Presales",[2939],{"_uid":2940,"name":2941,"type":2942,"label":13,"options":13,"required":24,"component":2869,"conditions":2943,"placeholder":13,"default_value":2944},"cf464f8e-d643-4f6e-af29-d3abffaf7380","department_email_address","hidden",[],"hello@foxy.io",{"_uid":2946,"equals":208,"fields":2947,"component":2934},"4007b6d8-77e5-421d-bd1e-6f336dd853fb",[2948],{"_uid":2949,"name":2941,"type":2942,"label":13,"options":13,"required":24,"component":2869,"conditions":2950,"placeholder":13,"default_value":2951},"7b4c6aa5-a68c-45e0-9ce1-0a36af10c0c2",[],"help@foxy.io",{"_uid":2953,"equals":2954,"fields":2955,"component":2934},"1dbb8f11-613d-43cd-9e09-1b94f6e19219","Billing",[2956],{"_uid":2957,"name":2941,"type":2942,"label":13,"options":13,"required":24,"component":2869,"conditions":2958,"placeholder":13,"default_value":2959},"a0ac0d1b-bc4f-4a6c-a682-581d450b0b73",[],"help+billing@foxy.io",{"_uid":2961,"equals":2962,"fields":2963,"component":2934},"a0a53a50-7172-4a29-ba58-181e38874e12","Partnerships",[2964],{"_uid":2965,"name":2941,"type":2942,"label":13,"options":13,"required":24,"component":2869,"conditions":2966,"placeholder":13,"default_value":2967},"7aa011d9-f374-4aed-b5a5-929b54aaf152",[],"partners@foxy.io",{"_uid":2969,"equals":2883,"fields":2970,"component":2934},"a4cd431f-25d5-41c7-bfdc-02c908c8fb47",[2971],{"_uid":2972,"name":2941,"type":2942,"label":13,"options":13,"required":24,"component":2869,"conditions":2973,"placeholder":13,"default_value":2944},"f5d52168-d6ae-451b-94ee-2ced1cbd28ad",[],{"_uid":2975,"equals":2976,"fields":2977,"component":2934},"25aba1ed-eb41-4bbc-aa89-f7a7167ea86e","Other",[2978],{"_uid":2979,"name":2941,"type":2942,"label":13,"options":13,"required":24,"component":2869,"conditions":2980,"placeholder":13,"default_value":2944},"f40dfaef-c203-4b71-bf4e-e1b43cef192b",[],{"_uid":2982,"component":2983},"e9c53a05-f40a-4510-aaf8-bc072a235a0c","form___subject",{"_uid":2985,"name":2986,"type":2987,"label":2988,"options":13,"required":33,"component":2869,"placeholder":13},"a4c4d385-fff4-4978-99fb-b68cfea623d6","message","textarea","Message",{"_uid":2990,"name":2991,"type":2877,"label":2992,"options":2993,"required":33,"component":2869,"conditions":2994,"placeholder":13},"8a3c9f85-f438-427d-9c7a-d7b295a14b5b","existing_user","Are you an existing user?","No, Yes",[2995],{"_uid":2996,"equals":2997,"fields":2998,"component":2934},"115933d6-262a-4b59-8fa8-579c5ad73de1","Yes",[2999],{"_uid":3000,"name":3001,"type":390,"label":3002,"options":13,"required":33,"component":2869,"conditions":3003,"placeholder":13},"44b6ff23-98f0-4e95-b7f5-c23e06415c2d","subdomain","Store Subdomain",[],{"_uid":3005,"name":3006,"type":2877,"label":3007,"options":3008,"required":33,"component":2869,"conditions":3009,"placeholder":13},"922a5cef-3af2-4113-8855-36c7910e3ee3","user_type","What type of user are you?","Developer, Designer, Merchant",[],"POST",[3012],{"_uid":3013,"text":3014,"title":3023,"component":3024},"7323b90d-a93a-4bf1-baa9-20d0b7ead61b",{"type":382,"content":3015},[3016],{"type":385,"content":3017},[3018,3020,3021],{"text":3019,"type":390},"855.369.9227",{"type":2903},{"text":3022,"type":390},"9:30am-6pm Central M-F","Pre-sales, Sales, & Partnerships","contact___footer_column",{"type":382,"content":3026},[3027],{"type":385,"content":3028},[3029],{"text":3030,"type":390},"Get in touch to get help from our friendly support team.","Submit","Success!","Your email has been received. We'll get back to you as soon as we can, but it might take a business day. If you don't hear back from us in a timely manner, please check your spam folder to ensure our reply didn't go there.",-80,[],"2fd9fb7d-a48a-4184-acfd-30022d8d6f08","2022-09-23T20:10:45.360Z",[],{},1784562235225]