Sample code for 30+ languages & platforms
React Native Requires Chilkat v11.0.0+

PRODA Get OAuth2 Access Token using JWT

See more PRODA Examples

Demonstrates how to get an OAuth2 access token for the PRODA Australian Government Online Services using a JWT.

Chilkat React Native Downloads

React Native
import { Http, HttpRequest, HttpResponse, JsonObject, Jwt, PrivateKey } from '@chilkat/react-native'

async function chilkatExample() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  // First create a JWT to be sent in the POST to https://vnd.proda.humanservices.gov.au/mga/sps/oauth/oauth20/token

  const privKey = new PrivateKey();

  // Load an RSA private key from a PEM file.
  // Chilkat provides alternative methods to load from other formats, or to load from a string or binary data.
  try {
    privKey.loadEncryptedPemFile('qa_data/pem/rsa_passwd.pem', 'passwd');
  } catch {
    console.log(privKey.lastErrorText);
    return;
  }

  const jwt = new Jwt();

  // Build the JOSE header
  const jose = new JsonObject();
  // Use RS256.  Pass the string "RS384" or "RS512" to use RSA with SHA-384 or SHA-512.
  jose.appendString('alg', 'RS256');
  jose.appendString('typ', 'JWT');
  jose.appendString('kid', 'test-device');

  // Now build the JWT claims (also known as the payload)
  const claims = new JsonObject();
  claims.appendString('iss', '9646844092');
  claims.appendString('sub', 'test-device');
  claims.appendString('aud', 'https://proda.humanservices.gov.au');

  // Set the timestamp of when the JWT was created to now.
  const curDateTime = jwt.genNumericDate(0);
  claims.addIntAt(-1, 'iat', curDateTime);

  // Set the timestamp defining an expiration time (end time) for the token
  // to be now + 1 hour (3600 seconds)
  claims.addIntAt(-1, 'exp', curDateTime + 3600);

  // Produce the smallest possible JWT:
  jwt.autoCompact = true;

  // Create the JWT token.  This is where the RSA signature is created.
  const jwtToken = jwt.createJwtPk(jose.emit(), claims.emit(), privKey);

  // ---------------------------------------------------------------------
  // Build and send the POST, which should look something like this:

  // POST https://vnd.proda.humanservices.gov.au/mga/sps/oauth/oauth20/token HTTP/1.1
  // Content-Type: application/x-www-form-urlencoded
  // Content-Length: 666
  // Host: vnd.proda.humanservices.gov.au
  // 
  // grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Ajwt-bearer&assertion=<jwt>&client_id=VendorClient03

  const http = new Http();

  const req = new HttpRequest();
  req.httpVerb = 'POST';
  req.contentType = 'application/x-www-form-urlencoded';

  // Add the request params.
  req.addParam('grant_type', 'urn:ietf:params:oauth:grant-type:jwt-bearer');
  req.addParam('assertion', jwtToken);
  req.addParam('client_id', 'VendorClient03');

  const resp = new HttpResponse();
  try {
    await http.httpReqAsync('https://vnd.proda.humanservices.gov.au/mga/sps/oauth/oauth20/token', req, resp);
  } catch {
    console.log(http.lastErrorText);
    return;
  }

  console.log(`Response status code = ${resp.statusCode}`);
  console.log('Response body:');
  console.log(resp.bodyStr);
}