Sample code for 30+ languages & platforms
Zig

Get Access Token using a Pre-Created JSON Web Token

See more ABN AMRO Examples

Demonstrates how to get an access token using a pre-created JSON Web Token (JWT).

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // We're going to duplicate this CURL statement:
    // curl -X POST https://api-sandbox.abnamro.com/v1/oauth/token \
    // -H "Content-Type: application/x-www-form-urlencoded" \
    // -H "API-Key: xxxxxx" \
    // -d 'client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer&grant_type=client_credentials&client_assertion=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ4eHh4eHgiLCJleHAiOiIxNDk5OTQ3NjY4IiwiaXNzIjoibWUiLCJhdWQiOiJodHRwczovL2F1dGgtc2FuZGJveC5hYm5hbXJvLmNvbS9vYXV0aC90b2tlbiJ9.jGwHKG_YjgKpR8NPpaLu6nJ97obeP2vcxg6fOWBKdJ0&scope=tikkie'

    // Load our pre-creaed private key PEM file.
    // Note: Please share your public key along with your app name and developer email id at api.support@nl.abnamro.com.
    // Token generation will not work unless public key is associated with your app.
    const privkey = try chilkat.PrivateKey.init();
    defer privkey.deinit();

    privkey.loadPemFile("qa_data/pem/abnAmroPrivateKey.pem") catch {
        std.debug.print("{s}\n", .{try privkey.getLastErrorText(alloc)});
        return;
    };

    // Create the JWT.
    const jwt = try chilkat.Jwt.init();
    defer jwt.deinit();

    // Create the header:
    // {
    //     "typ": "JWT",
    //     "alg": "RS256"
    // }
    const json_header = try chilkat.JsonObject.init();
    defer json_header.deinit();
    json_header.updateString("typ", "JWT") catch {};
    json_header.updateString("alg", "RS256") catch {};

    // Create the payload:
    // {
    //     "nbf": 1499947668,
    //     "exp": 1499948668,
    //     "iss": "me",
    //     "sub": "anApiKey",
    //     "aud": "https://auth-sandbox.abnamro.com/oauth/token"
    // }
    const json_payload = try chilkat.JsonObject.init();
    defer json_payload.deinit();

    const cur_date_time = jwt.genNumericDate(0);

    // Set the "not process before" timestamp to now.
    try json_payload.addIntAt(-1, "nbf", cur_date_time);

    // Set the timestamp defining an expiration time (end time) for the token
    // to be now + 1 hour (3600 seconds)
    try json_payload.addIntAt(-1, "exp", cur_date_time + 3600);

    json_payload.updateString("iss", "me") catch {};
    json_payload.updateString("sub", "anApiKey") catch {};
    json_payload.updateString("aud", "https://auth-sandbox.abnamro.com/oauth/token") catch {};

    // Produce the smallest possible JWT:
    jwt.setAutoCompact(true);

    const jwt_str = jwt.createJwtPk(alloc, try json_header.emit(alloc), try json_payload.emit(alloc), privkey) catch {
        std.debug.print("{s}\n", .{try jwt.getLastErrorText(alloc)});
        return;
    };

    const http = try chilkat.Http.init();
    defer http.deinit();

    const req = try chilkat.HttpRequest.init();
    defer req.deinit();
    req.addParam("client_assertion_type", "urn:ietf:params:oauth:client-assertion-type:jwt-bearer");
    req.addParam("grant_type", "client_credentials");
    req.addParam("client_assertion", jwt_str);
    req.addParam("scope", "tikkie");

    req.setHttpVerb("POST");
    req.setContentType("application/x-www-form-urlencoded");

    const resp = try chilkat.HttpResponse.init();
    defer resp.deinit();
    http.httpReq("https://api-sandbox.abnamro.com/v1/oauth/token", req, resp) catch {
        std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
        return;
    };

    if (resp.getStatusCode() != 200) {
        std.debug.print("{s}\n", .{try resp.getBodyStr(alloc)});
        return;
    }

    // Get the JSON result:
    // {
    //     "access_token": "{your access token}",
    //     "expires_in": "{duration of validity in seconds}",
    //     "scope": "{scope(s) for which the access token is valid}",
    //     "token_type": "{it is always Bearer}"
    // }
    const json = try chilkat.JsonObject.init();
    defer json.deinit();
    json.load(try resp.getBodyStr(alloc)) catch {};
    std.debug.print("access_token: {s}\n", .{try json.stringOf(alloc, "access_token")});
    std.debug.print("token_type: {s}\n", .{try json.stringOf(alloc, "token_type")});
    std.debug.print("expires_in: {s}\n", .{try json.stringOf(alloc, "expires_in")});
    std.debug.print("scope: {s}\n", .{try json.stringOf(alloc, "scope")});
}