When building imgix URLs by hand or with a custom library, append s last and verify the digest is 32 lowercase hex characters. Pass parameters unencoded to the signing function and let the library handle encoding. If signatures fail, compare your signature base string against the documented token plus path plus query construction.

Context: Official docs (imgix library blueprint): the s signature parameter must be the last parameter in a secured imgix URL, the hash must be lowercase hex, and it must be exactly 32 characters. Libraries that append tracking params or the ixlib marker after s, or that uppercase the hex digest, produce URLs that fail validation. The signature base is token plus path plus query, with special characters in the path kept percent-encoded.