Sample code for 30+ languages & platforms
Xbase++ Requires Chilkat v11.0.0+

PRODA Get OAuth2 Access Token using JWT

See more PRODA Examples

Demonstrates how to get an OAuth2 access token for the PRODA Australian Government Online Services using a JWT.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oPrivKey
LOCAL oJwt
LOCAL oJose
LOCAL oClaims
LOCAL nCurDateTime
LOCAL cJwtToken
LOCAL oHttp
LOCAL oReq
LOCAL oResp

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  First create a JWT to be sent in the POST to https://vnd.proda.humanservices.gov.au/mga/sps/oauth/oauth20/token

oPrivKey := CreateObject("Chilkat.PrivateKey")

//  Load an RSA private key from a PEM file.
//  Chilkat provides alternative methods to load from other formats, or to load from a string or binary data.
nSuccess := oPrivKey:LoadEncryptedPemFile("qa_data/pem/rsa_passwd.pem", "passwd")
IF (nSuccess == 0)
    ? oPrivKey:LastErrorText
    oPrivKey:destroy()
    RETURN
ENDIF

oJwt := CreateObject("Chilkat.Jwt")

//  Build the JOSE header
oJose := CreateObject("Chilkat.JsonObject")
//  Use RS256.  Pass the string "RS384" or "RS512" to use RSA with SHA-384 or SHA-512.
nSuccess := oJose:AppendString("alg", "RS256")
nSuccess := oJose:AppendString("typ", "JWT")
nSuccess := oJose:AppendString("kid", "test-device")

//  Now build the JWT claims (also known as the payload)
oClaims := CreateObject("Chilkat.JsonObject")
nSuccess := oClaims:AppendString("iss", "9646844092")
nSuccess := oClaims:AppendString("sub", "test-device")
nSuccess := oClaims:AppendString("aud", "https://proda.humanservices.gov.au")

//  Set the timestamp of when the JWT was created to now.
nCurDateTime := oJwt:GenNumericDate(0)
nSuccess := oClaims:AddIntAt(-1, "iat", nCurDateTime)

//  Set the timestamp defining an expiration time (end time) for the token
//  to be now + 1 hour (3600 seconds)
nSuccess := oClaims:AddIntAt(-1, "exp", nCurDateTime + 3600)

//  Produce the smallest possible JWT:
oJwt:AutoCompact := 1

//  Create the JWT token.  This is where the RSA signature is created.
cJwtToken := oJwt:CreateJwtPk(oJose:Emit(), oClaims:Emit(), oPrivKey)

//  ---------------------------------------------------------------------
//  Build and send the POST, which should look something like this:

//  POST https://vnd.proda.humanservices.gov.au/mga/sps/oauth/oauth20/token HTTP/1.1
//  Content-Type: application/x-www-form-urlencoded
//  Content-Length: 666
//  Host: vnd.proda.humanservices.gov.au
//  
//  grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Ajwt-bearer&assertion=<jwt>&client_id=VendorClient03

oHttp := CreateObject("Chilkat.Http")

oReq := CreateObject("Chilkat.HttpRequest")
oReq:HttpVerb := "POST"
oReq:ContentType := "application/x-www-form-urlencoded"

//  Add the request params.
oReq:AddParam("grant_type", "urn:ietf:params:oauth:grant-type:jwt-bearer")
oReq:AddParam("assertion", cJwtToken)
oReq:AddParam("client_id", "VendorClient03")

oResp := CreateObject("Chilkat.HttpResponse")
nSuccess := oHttp:HttpReq("https://vnd.proda.humanservices.gov.au/mga/sps/oauth/oauth20/token", oReq, oResp)
IF (nSuccess == 0)
    ? oHttp:LastErrorText
    oPrivKey:destroy()
    oJwt:destroy()
    oJose:destroy()
    oClaims:destroy()
    oHttp:destroy()
    oReq:destroy()
    oResp:destroy()
    RETURN
ENDIF

? "Response status code = " + Str(oResp:StatusCode)
? "Response body:"
? oResp:BodyStr

oPrivKey:destroy()
oJwt:destroy()
oJose:destroy()
oClaims:destroy()
oHttp:destroy()
oReq:destroy()
oResp:destroy()