Sign URLs as the last step of URL construction, after all parameters are final. If a signed URL 403s, check whether anything appended, reordered, or re-encoded a parameter after signing. Keep the secure token server-side and generate signed URLs at render time rather than storing them.

Context: Official docs (imgix, securing assets): signed URLs use an MD5 of the URL plus the source's secure token, appended as the s parameter. If the path or parameters are altered after signing, the URL returns 403 Forbidden instead of the asset. That means any code that tweaks width or height on an already-signed URL breaks it; you must re-sign after every parameter change.