Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Duo Auth API - Async Auth

See more Duo Auth MFA Examples

If you enable async, then your application will be able to retrieve real-time status updates from the authentication process, rather than receiving no information until the process is complete.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example assumes the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const integration_key = "DIMS3V5QDVG9J9ABRXC4";
    const secret_key = "HWVQ46nubLBxhnRlKddTltWIi3hL0fIQF2qTvLab";

    const http = try chilkat.Http.init();
    defer http.deinit();

    http.setAccept("application/json");

    // Use your own hostname here:
    var url: [:0]const u8 = "https://api-a03782e1.duosecurity.com/auth/v2/auth";

    // This example requires Chilkat v9.5.0.89 or greater because Chilkat will automatically
    // generate and send the HMAC signature for the requires based on the integration key and secret key.
    http.setLogin(integration_key);
    http.setPassword(secret_key);

    const req = try chilkat.HttpRequest.init();
    defer req.deinit();
    req.addParam("username", "matt");
    req.addParam("factor", "push");
    // The device ID can be obtained from the preauth response.  See Duo Preauth Example
    req.addParam("device", "DP6GYVTQ5NK82BMR851F");
    // Add the async param to get an immediate response, then periodically check for updates to find out when the MFA authentication completes for fails.
    req.addParam("async", "1");

    req.setHttpVerb("POST");
    req.setContentType("application/x-www-form-urlencoded");

    const resp = try chilkat.HttpResponse.init();
    defer resp.deinit();
    http.httpReq(url, req, resp) catch {
        std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("status code = {d}\n", .{resp.getStatusCode()});

    const json = try chilkat.JsonObject.init();
    defer json.deinit();
    try json.load(try resp.getBodyStr(alloc));
    json.setEmitCompact(false);
    std.debug.print("{s}\n", .{try json.emit(alloc)});

    if (resp.getStatusCode() != 200) {
        return;
    }

    // Sample successful output:

    // status code = 200

    // {
    //   "stat": "OK",
    //   "response": {
    //     "txid": "45f7c92b-f45f-4862-8545-e0f58e78075a"
    //   }
    // }

    const txid = try json.stringOf(alloc, "response.txid");

    // Use your own hostname here:
    const sb_url = try chilkat.StringBuilder.init();
    defer sb_url.deinit();
    sb_url.append("https://api-a03782e1.duosecurity.com/auth/v2/auth_status?txid=") catch {};
    sb_url.append(txid) catch {};
    url = try sb_url.getAsString(alloc);

    std.debug.print("Auth status URL: {s}\n", .{url});

    const sb_result = try chilkat.StringBuilder.init();
    defer sb_result.deinit();
    var response_status: [:0]const u8 = "";
    var response_status_msg: [:0]const u8 = "";

    // Wait for a response...
    var i: i32 = 0;
    const max_wait_iterations = 100;
    while (i < max_wait_iterations) {
        // Wait 3 seconds.
        http.sleepMs(3000);

        std.debug.print("Polling...\n", .{});

        http.httpNoBody("GET", url, resp) catch {
            std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
            return;
        };

        if (resp.getStatusCode() != 200) {
            std.debug.print("error status code = {d}\n", .{resp.getStatusCode()});
            std.debug.print("{s}\n", .{try resp.getBodyStr(alloc)});
            std.debug.print("Failed.\n", .{});
            return;
        }

        // Sample response:

        //     {
        //       "stat": "OK",
        //       "response": {
        //         "result": "waiting",
        //         "status": "pushed",
        //         "status_msg": "Pushed a login request to your phone..."
        //       }
        //     }

        json.load(try resp.getBodyStr(alloc)) catch {};

        // The responseResult can be "allow", "deny", or "waiting"
        sb_result.clear();
        json.stringOfSb("response.result", sb_result) catch {};
        response_status = try json.stringOf(alloc, "response.status");
        response_status_msg = try json.stringOf(alloc, "response.status_msg");

        std.debug.print("{s}\n", .{try sb_result.getAsString(alloc)});
        std.debug.print("{s}\n", .{response_status});
        std.debug.print("{s}\n", .{response_status_msg});
        std.debug.print("\n", .{});

        if (sb_result.contentsEqual("waiting", true)) {
            i = i + 1;
        } else {
            // Force loop exit..
            i = max_wait_iterations;
        }
    }

    std.debug.print("Finished.\n", .{});
}