Xbase++
Xbase++
Get Access Token using a Pre-Created JSON Web Token
See more ABN AMRO Examples
Demonstrates how to get an access token using a pre-created JSON Web Token (JWT).Chilkat Xbase++ Downloads
LOCAL nSuccess
LOCAL oPrivkey
LOCAL oJwt
LOCAL oJsonHeader
LOCAL oJsonPayload
LOCAL nCurDateTime
LOCAL cJwtStr
LOCAL oHttp
LOCAL oReq
LOCAL oResp
LOCAL oJson
nSuccess := 0
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// We're going to duplicate this CURL statement:
// curl -X POST https://api-sandbox.abnamro.com/v1/oauth/token \
// -H "Content-Type: application/x-www-form-urlencoded" \
// -H "API-Key: xxxxxx" \
// -d 'client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer&grant_type=client_credentials&client_assertion=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ4eHh4eHgiLCJleHAiOiIxNDk5OTQ3NjY4IiwiaXNzIjoibWUiLCJhdWQiOiJodHRwczovL2F1dGgtc2FuZGJveC5hYm5hbXJvLmNvbS9vYXV0aC90b2tlbiJ9.jGwHKG_YjgKpR8NPpaLu6nJ97obeP2vcxg6fOWBKdJ0&scope=tikkie'
// Load our pre-creaed private key PEM file.
// Note: Please share your public key along with your app name and developer email id at api.support@nl.abnamro.com.
// Token generation will not work unless public key is associated with your app.
oPrivkey := CreateObject("Chilkat.PrivateKey")
nSuccess := oPrivkey:LoadPemFile("qa_data/pem/abnAmroPrivateKey.pem")
IF (nSuccess == 0)
? oPrivkey:LastErrorText
oPrivkey:destroy()
RETURN
ENDIF
// Create the JWT.
oJwt := CreateObject("Chilkat.Jwt")
// Create the header:
// {
// "typ": "JWT",
// "alg": "RS256"
// }
oJsonHeader := CreateObject("Chilkat.JsonObject")
oJsonHeader:UpdateString("typ", "JWT")
oJsonHeader:UpdateString("alg", "RS256")
// Create the payload:
// {
// "nbf": 1499947668,
// "exp": 1499948668,
// "iss": "me",
// "sub": "anApiKey",
// "aud": "https://auth-sandbox.abnamro.com/oauth/token"
// }
oJsonPayload := CreateObject("Chilkat.JsonObject")
nCurDateTime := oJwt:GenNumericDate(0)
// Set the "not process before" timestamp to now.
nSuccess := oJsonPayload:AddIntAt(-1, "nbf", nCurDateTime)
// Set the timestamp defining an expiration time (end time) for the token
// to be now + 1 hour (3600 seconds)
nSuccess := oJsonPayload:AddIntAt(-1, "exp", nCurDateTime + 3600)
oJsonPayload:UpdateString("iss", "me")
oJsonPayload:UpdateString("sub", "anApiKey")
oJsonPayload:UpdateString("aud", "https://auth-sandbox.abnamro.com/oauth/token")
// Produce the smallest possible JWT:
oJwt:AutoCompact := 1
cJwtStr := oJwt:CreateJwtPk(oJsonHeader:Emit(), oJsonPayload:Emit(), oPrivkey)
IF (oJwt:LastMethodSuccess == 0)
? oJwt:LastErrorText
oPrivkey:destroy()
oJwt:destroy()
oJsonHeader:destroy()
oJsonPayload:destroy()
RETURN
ENDIF
oHttp := CreateObject("Chilkat.Http")
oReq := CreateObject("Chilkat.HttpRequest")
oReq:AddParam("client_assertion_type", "urn:ietf:params:oauth:client-assertion-type:jwt-bearer")
oReq:AddParam("grant_type", "client_credentials")
oReq:AddParam("client_assertion", cJwtStr)
oReq:AddParam("scope", "tikkie")
oReq:HttpVerb := "POST"
oReq:ContentType := "application/x-www-form-urlencoded"
oResp := CreateObject("Chilkat.HttpResponse")
nSuccess := oHttp:HttpReq("https://api-sandbox.abnamro.com/v1/oauth/token", oReq, oResp)
IF (nSuccess == 0)
? oHttp:LastErrorText
oPrivkey:destroy()
oJwt:destroy()
oJsonHeader:destroy()
oJsonPayload:destroy()
oHttp:destroy()
oReq:destroy()
oResp:destroy()
RETURN
ENDIF
IF (oResp:StatusCode != 200)
? oResp:BodyStr
oPrivkey:destroy()
oJwt:destroy()
oJsonHeader:destroy()
oJsonPayload:destroy()
oHttp:destroy()
oReq:destroy()
oResp:destroy()
RETURN
ENDIF
// Get the JSON result:
// {
// "access_token": "{your access token}",
// "expires_in": "{duration of validity in seconds}",
// "scope": "{scope(s) for which the access token is valid}",
// "token_type": "{it is always Bearer}"
// }
oJson := CreateObject("Chilkat.JsonObject")
oJson:Load(oResp:BodyStr)
? "access_token: " + oJson:StringOf("access_token")
? "token_type: " + oJson:StringOf("token_type")
? "expires_in: " + oJson:StringOf("expires_in")
? "scope: " + oJson:StringOf("scope")
oPrivkey:destroy()
oJwt:destroy()
oJsonHeader:destroy()
oJsonPayload:destroy()
oHttp:destroy()
oReq:destroy()
oResp:destroy()
oJson:destroy()