Sample code for 30+ languages & platforms
React Native

HMRC Validate Fraud Prevention Headers

See more HTTP Misc Examples

Demonstrates how to test (validate) HMRC fraud prevention headers.

Chilkat React Native Downloads

React Native
import { JsonObject, Rest, StringBuilder } from '@chilkat/react-native'

async function chilkatExample() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  const rest = new Rest();

  try {
    await rest.connectAsync('test-api.service.hmrc.gov.uk', 443, true, true);
  } catch {
    console.log(rest.lastErrorText);
    return;
  }

  // Load the previously fetched access token.
  const json = new JsonObject();
  json.loadFile('qa_data/tokens/hmrc.json');
  const accessToken = json.stringOf('access_token');
  console.log(`Using access toke: ${accessToken}`);

  const sbAuthHeaderValue = new StringBuilder();
  sbAuthHeaderValue.append('Bearer ');
  sbAuthHeaderValue.append(accessToken);

  rest.addHeader('Accept', 'application/vnd.hmrc.1.0+json');
  rest.addHeader('Authorization', sbAuthHeaderValue.getAsString());

  // Add the fraud prevention headers.
  // See https://developer.service.hmrc.gov.uk/api-documentation/docs/fraud-prevention
  rest.addHeader('gov-client-connection-method', 'DESKTOP_APP_DIRECT');

  // This should be generated by an application and persistently stored on the device. The identifier should not expire.
  rest.addHeader('gov-client-device-id', 'beec798b-b366-47fa-b1f8-92cede14a1ce');

  // See https://developer.service.hmrc.gov.uk/api-documentation/docs/fraud-prevention
  rest.addHeader('gov-client-user-ids', 'os=user123');

  // Your local IP addresses (comma separated), such as addresses beginning with "192.168." or "172.16."
  rest.addHeader('gov-client-local-ips', '172.16.16.23');
  // You'll need to find a way to get your MAC address.  Chilkat does not yet provide this ability...
  rest.addHeader('gov-client-mac-addresses', '7C%3AD3%3A0A%3A25%3ADA%3A1C');

  rest.addHeader('gov-client-timezone', 'UTC+00:00');

  // You can probably just hard-code these so they're always the same with each request.
  rest.addHeader('gov-client-window-size', 'width=1256&height=800');
  rest.addHeader('gov-client-screens', 'width=1920&height=1080&scaling-factor=1&colour-depth=16');
  rest.addHeader('gov-client-user-agent', 'Windows/Server%202012 (Dell%20Inc./OptiPlex%20980)');
  rest.addHeader('gov-vendor-version', 'My%20Desktop%20Software=1.2.3.build4286');

  let responseStr: string;
  try {
    responseStr = await rest.fullRequestNoBodyAsync('GET', '/test/fraud-prevention-headers/validate');
  } catch {
    console.log(rest.lastErrorText);
    return;
  }

  // If the status code is 200, then the fraud prevention headers were validated.
  // The JSON response may include some warnings..
  console.log(`Response status code = ${rest.responseStatusCode}`);
  console.log('Response JSON body: ');
  console.log(responseStr);
}