Sample code for 30+ languages & platforms
VB.NET

SharePoint -- Get Server Form Digest Value

Demonstrates how to get a server form digest value to be placed in the X-RequestDigest HTTP request header for POST, PUT, MERGE, and DELETE requests. A form digest value is typically valid for 1800 seconds (i.e. 30 minutes). This example persists the value to a file, and only requests a new form digest value if the existing one is near expiration.

Chilkat VB.NET Downloads

VB.NET
Dim success As Boolean = False

' This requires the Chilkat API to have been previously unlocked.
' See Global Unlock Sample for sample code.

' First, let's see if we already have a persisted form digest value
' that hasn't yet expired.
Dim fac As New Chilkat.FileAccess
Dim xml As New Chilkat.Xml

' My example code (below) persists the form digest XML in this format:
' 
' 	<savedFormDigestValue>
' 	<d:ExpireDateTime>2017-04-12T20:46:39Z</d:ExpireDateTime>
' 	<d:FormDigestValue>0x3059FFB920651834540F3E6792EA73F5746B302E953FF4E808E485DB1E6C2836C7CF924644995F092453B02A94DE14A7962674B7B16780AF16EAFB8C246BCDC7,12 Apr 2017 17:08:22 -0000</d:FormDigestValue>
' 	</savedFormDigestValue>
' 

Dim dtExpire As New Chilkat.CkDateTime
Dim dtNow As New Chilkat.CkDateTime

Dim formDigestXmlFile As String = "qa_data/sharepoint/savedFormDigestValue.xml"
If (fac.FileExists(formDigestXmlFile) = True) Then

    xml.LoadXmlFile(formDigestXmlFile)

    ' Get the expire date/time
    dtExpire.SetFromTimestamp(xml.GetChildContent("d:ExpireDateTime"))

    ' Get the current date/time
    dtNow.SetFromCurrentSystemTime()

    ' Get both times as Unix time values
    Dim tNow As Integer = dtNow.GetAsUnixTime(False)
    Dim tExpire As Integer = dtExpire.GetAsUnixTime(False)

    ' If tNow >= tExpire, then fall through.
    ' Otherwise, just use the cached digest value.
    If (tNow < tExpire) Then
        Debug.WriteLine("Cached digest value is not yet expired.")
        Debug.WriteLine("X-RequestDigest: " & xml.GetChildContent("d:FormDigestValue"))
        Exit Sub
    End If


End If


' If we got to this point, the cached digest value either does not exist, or expired.

Dim http As New Chilkat.Http

' If SharePoint Windows classic authentication is used, then set the 
' Login, Password, LoginDomain, and NtlmAuth properties.
http.Login = "SHAREPOINT_USERNAME"
http.Password = "SHAREPOINT_PASSWORD"
http.LoginDomain = "SHAREPOINT_NTLM_DOMAIN"
http.NtlmAuth = True

' The more common case is to use SharePoint Online authentication (via the SPOIDCRL cookie).
' If so, do not set Login, Password, LoginDomain, and NtlmAuth, and instead
' establish the cookie as shown at SharePoint Online Authentication

' When creating, updating, and deleting SharePoint entities, we'll need
' to first get the server's form digest value to send in the X-RequestDigest header.
' This can be retrieved by making a POST request with an empty body to
' http://<site url>/_api/contextinfo and extracting the value of the
' d:FormDigestValue node in the XML that the contextinfo endpoint returns.

' Apparently, SharePoint needs an "Accept" request header equal to "application/xml",
' otherwise SharePoint will return an utterly incomprehensible and useless error message.
Dim savedAccept As String = http.Accept
http.Accept = "application/xml"

' Note: The last argument ("utf-8") is meaningless here because the body is empty.
Dim resp As New Chilkat.HttpResponse
success = http.HttpStr("POST","https://SHAREPOINT_HTTPS_DOMAIN/_api/contextinfo","","utf-8","application/xml",resp)
If (success = False) Then
    Debug.WriteLine(http.LastErrorText)
    Exit Sub
End If


' Restore the default Accept header
http.Accept = savedAccept

If (resp.StatusCode <> 200) Then
    ' A response status code not equal to 200 indicates failure.
    Debug.WriteLine("Response status code = " & resp.StatusCode)
    Debug.WriteLine("Response body:")
    Debug.WriteLine(resp.BodyStr)
    Exit Sub
End If


xml.LoadXml(resp.BodyStr)

' The response XML looks like this:

' <?xml version="1.0" encoding="utf-8" ?>
' <d:GetContextWebInformation xmlns:d="http://schemas.microsoft.com/ado/2007/08/dataservices" xmlns:m="http://schemas.microsoft.com/ado/2007/08/dataservices/metadata" xmlns:georss="http://www.georss.org/georss" xmlns:gml="http://www.opengis.net/gml" m:type="SP.ContextWebInformation">
'     <d:FormDigestTimeoutSeconds m:type="Edm.Int32">1800</d:FormDigestTimeoutSeconds>
'     <d:FormDigestValue>0x3059FFB920651834540F3E6792EA73F5746B302E953FF4E808E485DB1E6C2836C7CF924644995F092453B02A94DE14A7962674B7B16780AF16EAFB8C246BCDC7,12 Apr 2017 17:08:22 -0000</d:FormDigestValue>
'     <d:LibraryVersion>15.0.4569.1000</d:LibraryVersion>
'     <d:SiteFullUrl>https://SHAREPOINT_HTTPS_DOMAIN</d:SiteFullUrl>
'     <d:SupportedSchemaVersions m:type="Collection(Edm.String)">
'         <d:element>14.0.0.0</d:element>
'         <d:element>15.0.0.0</d:element>
'     </d:SupportedSchemaVersions>
'     <d:WebFullUrl>https://SHAREPOINT_HTTPS_DOMAIN</d:WebFullUrl>
' </d:GetContextWebInformation>
' 

' Cache the digest value, and also an expiration time.  If this code is run again
' before the digest expires, we'll just get it from the file.
Dim xml2 As New Chilkat.Xml

xml2.Tag = "savedFormDigestValue"
xml2.NewChild2("d:FormDigestValue",xml.GetChildContent("d:FormDigestValue"))

Dim timeoutInSec As Integer = xml.GetChildIntValue("d:FormDigestTimeoutSeconds")
Debug.WriteLine("Timeout in seconds = " & timeoutInSec)

' Convert this to an expire timestamp.
' Let's make it expire 30 seconds prior to the actual timeout, just to be safe.
If (timeoutInSec > 30) Then
    timeoutInSec = timeoutInSec - 30
End If


dtExpire.SetFromCurrentSystemTime()
dtExpire.AddSeconds(timeoutInSec)
xml2.NewChild2("d:ExpireDateTime",dtExpire.GetAsTimestamp(False))

' Persist the digest and expire time to a file.
xml2.SaveXml(formDigestXmlFile)

Debug.WriteLine("Here is the new form digest value:")
Debug.WriteLine("X-RequestDigest: " & xml.GetChildContent("d:FormDigestValue"))