Sample code for 30+ languages & platforms
SQL Server

Http Digest Authentication

Demonstrates the DigestAuth property to do HTTP Digest Authentication.

Chilkat SQL Server Downloads

SQL Server
-- Important: See this note about string length limitations for strings returned by sp_OAMethod calls.
--
CREATE PROCEDURE ChilkatSample
AS
BEGIN
    DECLARE @hr int
    DECLARE @iTmp0 int
    -- Important: Do not use nvarchar(max).  See the warning about using nvarchar(max).
    DECLARE @sTmp0 nvarchar(4000)
    -- This example requires the Chilkat API to have been previously unlocked.
    -- See Global Unlock Sample for sample code.

    DECLARE @http int
    EXEC @hr = sp_OACreate 'Chilkat.Http', @http OUT
    IF @hr <> 0
    BEGIN
        PRINT 'Failed to create ActiveX component'
        RETURN
    END

    -- To use HTTP Digest Authentication:
    EXEC sp_OASetProperty @http, 'Login', 'myLogin'
    EXEC sp_OASetProperty @http, 'Password', 'myPassword'
    EXEC sp_OASetProperty @http, 'DigestAuth', 1

    -- If you would like to see the HTTP session log to see how 
    -- HTTP digest authentication worked.
    EXEC sp_OASetProperty @http, 'SessionLogFilename', 'c:/temp/qa_output/sessionLog.txt'

    -- Run the test using this URL with the credentials above.  
    -- (Works while httpbin.org keeps the test endpoint available.)
    DECLARE @jsonResponse nvarchar(4000)
    EXEC sp_OAMethod @http, 'QuickGetStr', @jsonResponse OUT, 'https://httpbin.org/digest-auth/auth/myLogin/myPassword'
    EXEC sp_OAGetProperty @http, 'LastMethodSuccess', @iTmp0 OUT
    IF @iTmp0 = 0
      BEGIN
        EXEC sp_OAGetProperty @http, 'LastErrorText', @sTmp0 OUT
        PRINT @sTmp0
        EXEC @hr = sp_OADestroy @http
        RETURN
      END


    EXEC sp_OAGetProperty @http, 'LastStatus', @iTmp0 OUT
    PRINT 'Response status code: ' + @iTmp0


    PRINT @jsonResponse

    -- Output:

    -- Response status code: 200
    -- {
    --   "authenticated": true, 
    --   "user": "myLogin"
    -- }

    -- -----------------------------------------------
    -- Here are the contents of the sessionLog.txt

    -- ---- Sending Sat, 30 Aug 2025 11:23:12 GMT ----
    -- GET /digest-auth/auth/myLogin/myPassword HTTP/1.1
    -- Host: httpbin.org
    -- Accept: */*
    -- Accept-Encoding: gzip
    -- 
    -- 
    -- ---- Received Sat, 30 Aug 2025 11:23:12 GMT ----
    -- HTTP/1.1 401 UNAUTHORIZED
    -- Date: Sat, 30 Aug 2025 11:23:12 GMT
    -- Content-Type: text/html; charset=utf-8
    -- Content-Length: 0
    -- Connection: keep-alive
    -- Server: gunicorn/19.9.0
    -- WWW-Authenticate: Digest realm="me@kennethreitz.com", nonce="fbc6733e2f4d126e7a92d19918f42b0f", qop="auth", opaque="5a14177dc4089cb22c019e6df4fdaadf", algorithm=MD5, stale=FALSE
    -- Set-Cookie: stale_after=never; Path=/
    -- Set-Cookie: fake=fake_value; Path=/
    -- Access-Control-Allow-Origin: *
    -- Access-Control-Allow-Credentials: true
    -- 
    -- 
    -- ---- Sending Sat, 30 Aug 2025 11:23:12 GMT ----
    -- GET /digest-auth/auth/myLogin/myPassword HTTP/1.1
    -- Host: httpbin.org
    -- Accept: */*
    -- Accept-Encoding: gzip
    -- Authorization: Digest ****
    -- 
    -- 
    -- ---- Received Sat, 30 Aug 2025 11:23:12 GMT ----
    -- HTTP/1.1 200 OK
    -- Date: Sat, 30 Aug 2025 11:23:13 GMT
    -- Content-Type: application/json
    -- Content-Length: 50
    -- Connection: keep-alive
    -- Server: gunicorn/19.9.0
    -- Set-Cookie: fake=fake_value; Path=/
    -- Access-Control-Allow-Origin: *
    -- Access-Control-Allow-Credentials: true
    -- 
    -- {
    --   "authenticated": true, 
    --   "user": "myLogin"
    -- }

    EXEC @hr = sp_OADestroy @http


END
GO