Sample code for 30+ languages & platforms
Xbase++

Get Access Token using a Pre-Created JSON Web Token

See more ABN AMRO Examples

Demonstrates how to get an access token using a pre-created JSON Web Token (JWT).

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oPrivkey
LOCAL oJwt
LOCAL oJsonHeader
LOCAL oJsonPayload
LOCAL nCurDateTime
LOCAL cJwtStr
LOCAL oHttp
LOCAL oReq
LOCAL oResp
LOCAL oJson

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  We're going to duplicate this CURL statement:
//  curl -X POST https://api-sandbox.abnamro.com/v1/oauth/token \
//  -H "Content-Type: application/x-www-form-urlencoded" \
//  -H "API-Key: xxxxxx" \
//  -d 'client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer&grant_type=client_credentials&client_assertion=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ4eHh4eHgiLCJleHAiOiIxNDk5OTQ3NjY4IiwiaXNzIjoibWUiLCJhdWQiOiJodHRwczovL2F1dGgtc2FuZGJveC5hYm5hbXJvLmNvbS9vYXV0aC90b2tlbiJ9.jGwHKG_YjgKpR8NPpaLu6nJ97obeP2vcxg6fOWBKdJ0&scope=tikkie'

//  Load our pre-creaed private key PEM file.
//  Note: Please share your public key along with your app name and developer email id at api.support@nl.abnamro.com. 
//  Token generation will not work unless public key is associated with your app.
oPrivkey := CreateObject("Chilkat.PrivateKey")

nSuccess := oPrivkey:LoadPemFile("qa_data/pem/abnAmroPrivateKey.pem")
IF (nSuccess == 0)
    ? oPrivkey:LastErrorText
    oPrivkey:destroy()
    RETURN
ENDIF

//  Create the JWT.
oJwt := CreateObject("Chilkat.Jwt")

//  Create the header:
//  {
//      "typ": "JWT",
//      "alg": "RS256"
//  }
oJsonHeader := CreateObject("Chilkat.JsonObject")
oJsonHeader:UpdateString("typ", "JWT")
oJsonHeader:UpdateString("alg", "RS256")

//  Create the payload:
//  {
//      "nbf": 1499947668,
//      "exp": 1499948668,
//      "iss": "me",
//      "sub": "anApiKey",
//      "aud": "https://auth-sandbox.abnamro.com/oauth/token"
//  }
oJsonPayload := CreateObject("Chilkat.JsonObject")

nCurDateTime := oJwt:GenNumericDate(0)

//  Set the "not process before" timestamp to now.
nSuccess := oJsonPayload:AddIntAt(-1, "nbf", nCurDateTime)

//  Set the timestamp defining an expiration time (end time) for the token
//  to be now + 1 hour (3600 seconds)
nSuccess := oJsonPayload:AddIntAt(-1, "exp", nCurDateTime + 3600)

oJsonPayload:UpdateString("iss", "me")
oJsonPayload:UpdateString("sub", "anApiKey")
oJsonPayload:UpdateString("aud", "https://auth-sandbox.abnamro.com/oauth/token")

//  Produce the smallest possible JWT:
oJwt:AutoCompact := 1

cJwtStr := oJwt:CreateJwtPk(oJsonHeader:Emit(), oJsonPayload:Emit(), oPrivkey)
IF (oJwt:LastMethodSuccess == 0)
    ? oJwt:LastErrorText
    oPrivkey:destroy()
    oJwt:destroy()
    oJsonHeader:destroy()
    oJsonPayload:destroy()
    RETURN
ENDIF

oHttp := CreateObject("Chilkat.Http")

oReq := CreateObject("Chilkat.HttpRequest")
oReq:AddParam("client_assertion_type", "urn:ietf:params:oauth:client-assertion-type:jwt-bearer")
oReq:AddParam("grant_type", "client_credentials")
oReq:AddParam("client_assertion", cJwtStr)
oReq:AddParam("scope", "tikkie")

oReq:HttpVerb := "POST"
oReq:ContentType := "application/x-www-form-urlencoded"

oResp := CreateObject("Chilkat.HttpResponse")
nSuccess := oHttp:HttpReq("https://api-sandbox.abnamro.com/v1/oauth/token", oReq, oResp)
IF (nSuccess == 0)
    ? oHttp:LastErrorText
    oPrivkey:destroy()
    oJwt:destroy()
    oJsonHeader:destroy()
    oJsonPayload:destroy()
    oHttp:destroy()
    oReq:destroy()
    oResp:destroy()
    RETURN
ENDIF

IF (oResp:StatusCode != 200)
    ? oResp:BodyStr
    oPrivkey:destroy()
    oJwt:destroy()
    oJsonHeader:destroy()
    oJsonPayload:destroy()
    oHttp:destroy()
    oReq:destroy()
    oResp:destroy()
    RETURN
ENDIF

//  Get the JSON result:
//  {
//      "access_token": "{your access token}",
//      "expires_in": "{duration of validity in seconds}",
//      "scope": "{scope(s) for which the access token is valid}",
//      "token_type": "{it is always Bearer}"
//  }
oJson := CreateObject("Chilkat.JsonObject")
oJson:Load(oResp:BodyStr)
? "access_token: " + oJson:StringOf("access_token")
? "token_type: " + oJson:StringOf("token_type")
? "expires_in: " + oJson:StringOf("expires_in")
? "scope: " + oJson:StringOf("scope")

oPrivkey:destroy()
oJwt:destroy()
oJsonHeader:destroy()
oJsonPayload:destroy()
oHttp:destroy()
oReq:destroy()
oResp:destroy()
oJson:destroy()