Sample code for 30+ languages & platforms
Dart Requires Chilkat v11.0.0+

Get ETK Public Key (api-acpt.ehealth.fgov.be)

See more Belgian eHealth Platform Examples

The following URL returns JSON, which contains a PKCS7 signed data:
https://api-acpt.ehealth.fgov.be/etee/v1/etks?identifier=12345678901&type=SSIN

This example extracts the signed data, validates it, and then extracts the public key from the certificate (obtained from signed content in the PKCS7)

Note: The URL above uses "12345678901" which is not valid. You should replace it with a valid number.

Chilkat Dart Downloads

Dart
import 'package:chilkat/chilkat.dart';

void main() {
  // This example requires the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  final http = CkHttp();

  final String jsonStr;
  try {
    jsonStr = http.quickGetStr('https://api-acpt.ehealth.fgov.be/etee/v1/etks?identifier=12345678901&type=SSIN');
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  print(jsonStr);

  // The JSON contains something like this:

  // [
  //     {
  //         "key": {
  //             "applicationIdentifier": "",
  //             "ssin": "12345678901"
  //         },
  //         "value": "MIAGCSq....AAAAAAAA=="
  //     }
  // ]

  // Note: The above is a JSON array (not a JSON object)
  // It should be loaded into a Chilkat JSON array.
  final jarr = CkJsonArray();
  try {
    jarr.load(jsonStr);
  } on ChilkatException {
    print('Failed to load JSON.');
    return;
  }

  final json = jarr.objectAt(0);
  final bdPkcs7 = CkBinData();
  bdPkcs7.appendEncoded(json.stringOf('value'), 'base64');

  // Let's verify the PKCS7, and then examine the signing cert,
  // and get the signing cert's public key.
  final crypt = CkCrypt2();

  // Validate the signedData PKCS7, and replace the contents of bdPkcs7 with the extracted signed content.
  try {
    crypt.opaqueVerifyBd(bdPkcs7);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // The signed content is the DER of a certificate.
  // In other words, bdPkcs7 now contains a certificate.
  final cert = CkCert();
  try {
    cert.loadFromBd(bdPkcs7);
  } on ChilkatException catch (e) {
    print(e.lastErrorText);
    return;
  }

  // Show some certificate information:
  print('Subject: ${cert.subjectDN}');
  print('Serial: ${cert.serialNumber}');
  print('Issuer: ${cert.issuerDN}');

  // Let's get the cert's public key...
  final pubKey = CkPublicKey();
  cert.getPublicKey(pubKey);

  // OK, you now have the public key and can do whatever is needed..
  print(pubKey.keyType);
  print(pubKey.keySize);
}