Product Security

Preventing add-to-cart link and form tampering with HMAC signing — implementing it manually, with the admin's builder, or via a signing service.

Product security overview

What HMAC product validation is, why it protects against link and form tampering, and the different ways to implement it — manually, with the admin's builder, or via a signing service.

Enable HMAC product validation

How to turn on cart validation in Settings > Cart to prevent add-to-cart link and form tampering — and why every link must be signed before enabling it.

HMAC excluded parameters reference

A reference for parameters exempt from HMAC signing — cart options, checkout pre-population fields, and the h:, x:, and utm_ name prefixes.

Sign bundled products with HMAC

How HMAC signing differs for bundled products — child product parameters combine the child and parent code together before hashing, unlike standalone product signing.

Sign multiple products in one form with HMAC

How HMAC signing changes when a single form adds more than one product at once — each product's parameters use an index prefix and must be hashed separately.

Sign open (user-editable) fields with HMAC

How to sign form fields customers fill in themselves, like quantity, using the --OPEN-- keyword and ||open suffix instead of a fixed value.

Sign product forms with HMAC

How to generate and apply HMAC SHA-256 hashes to add-to-cart form inputs to prevent tampering, including handling select and radio fields and a PHP helper function.

Sign product links with HMAC

How to generate and apply HMAC SHA-256 hashes to add-to-cart link parameters to prevent tampering, including a PHP helper function and handling spaces or special characters.

Use the admin tool to sign products with HMAC

How to build automatically-signed add-to-cart links and forms using the Link & Form Builder — useful for static sites or anyone who doesn't want to implement signing themselves.