Sample code for 30+ languages & platforms
JavaScript Requires Chilkat v11.0.0+

Etsy OAuth1 Authorization

See more Etsy Examples

Demonstrates 3-legged OAuth1 authorization for Etsy.
Note
This example is intended for running within a Chilkat.Js embedded JavaScript engine. All Chilkat JavaScript examples require Chilkat v11.4.0 or greater.
JavaScript
var success = false;

var consumerKey = "keystring";
var consumerSecret = "shared_secret";

//  Specify one or more SPACE separated scopes as query params in the requestTokenUrl
//  See https://www.etsy.com/developers/documentation/getting_started/oauth#section_permission_scopes
var requestTokenUrl = "https://openapi.etsy.com/v2/oauth/request_token?scope=email_r%20listings_r%20listings_w%20listings_d";
var authorizeUrl = "https://www.etsy.com/oauth/signin";
var accessTokenUrl = "https://openapi.etsy.com/v2/oauth/access_token";

//  The port number is picked at random. It's some unused port that won't likely conflict with anything else..
var callbackUrl = "http://localhost:3017/";
var callbackLocalPort = 3017;

//  The 1st step in 3-legged OAuth1.0a is to send a POST to the request token URL to obtain an OAuth Request Token
var http = new CkHttp();

http.OAuth1 = true;
http.OAuthConsumerKey = consumerKey;
http.OAuthConsumerSecret = consumerSecret;
http.OAuthCallback = callbackUrl;

var req = new CkHttpRequest();
req.HttpVerb = "POST";
req.ContentType = "application/x-www-form-urlencoded";

var resp = new CkHttpResponse();
success = http.HttpReq(requestTokenUrl,req,resp);
if (success == false) {
    console.log(http.LastErrorText);
    return;
}

//  If successful, the resp.BodyStr contains something like this:  
//  login_url=https%3A%2F%2Fwww.etsy.com%2Foauth%2Fsignin%3Foauth_consumer_key%3D9ad9l1omxzbwfr2niq0ce1ly%26oauth_token%3D7116b4d0c72c2736561853d9e50113%26service%3Dv2_prod&oauth_token=7116b4d0c72c2736561853d9e50113&oauth_token_secret=3b7612b5d3&oauth_callback_confirmed=true&oauth_consumer_key=9ad9l1omxzbwfr2niq0ce1ly&oauth_callback=http%3A%2F%2Flocalhost%3A3017%2F
console.log(resp.BodyStr);

//  We'll need this for later..
var hashTab = new CkHashtable();
hashTab.AddQueryParams(resp.BodyStr);

var requestToken = hashTab.LookupStr("oauth_token");
var requestTokenSecret = hashTab.LookupStr("oauth_token_secret");
http.OAuthTokenSecret = requestTokenSecret;

console.log("oauth_token = " + requestToken);
console.log("oauth_token_secret = " + requestTokenSecret);

//  ---------------------------------------------------------------------------
//  The next step is to form a URL to send to the authorizeUrl
//  This is an HTTP GET that we load into a popup browser.
var sbUrlForBrowser = new CkStringBuilder();
sbUrlForBrowser.Append(authorizeUrl);
sbUrlForBrowser.Append("?");
sbUrlForBrowser.Append(resp.BodyStr);
var url = sbUrlForBrowser.GetAsString();

//  When the url is loaded into a browser, the response from Etsy will redirect back to localhost:3017
//  We'll need to start a socket that is listening on port 3017 for the callback from the browser.
var listenSock = new CkSocket();

var backLog = 5;
success = listenSock.BindAndListen(callbackLocalPort,backLog);
if (success == false) {
    console.log(listenSock.LastErrorText);
    return;
}

//  Wait for the browser's connection in a background thread.
//  (We'll send load the URL into the browser following this..)
//  Wait a max of 60 seconds before giving up.
var sock = new CkSocket();
var maxWaitMs = 60000;
// task: CkTask
var task = listenSock.AcceptNextAsync(maxWaitMs,sock);
task.Run();

//  Launch the system's default browser navigated to the URL.
var oauth2 = new CkOAuth2();
success = oauth2.LaunchBrowser(url);
if (success == false) {
    console.log(oauth2.LastErrorText);
    return;
}

//  Wait for the listenSock's task to complete.
success = task.Wait(maxWaitMs);
if (!success || (task.StatusInt !== 7) || (task.TaskSuccess !== true)) {
    if (!success) {
        //  The task.LastErrorText applies to the Wait method call.
        console.log(task.LastErrorText);
    }
    else {
        //  The ResultErrorText applies to the underlying task method call (i.e. the AcceptNextConnection)
        console.log(task.Status);
        console.log(task.ResultErrorText);
    }

    return;
}

//  If we get to this point, the connection from the browser arrived and was accepted.

//  We no longer need the listen socket...
//  Stop listening on port 3017.
listenSock.Close(10);

//  Read the start line of the request..
var startLine = sock.ReceiveUntilMatch("\r\n");
if (sock.LastMethodSuccess == false) {
    console.log(sock.LastErrorText);
    return;
}

//  Read the request header.
var requestHeader = sock.ReceiveUntilMatch("\r\n\r\n");
if (sock.LastMethodSuccess == false) {
    console.log(sock.LastErrorText);
    return;
}

//  The browser SHOULD be sending us a GET request, and therefore there is no body to the request.
//  Once the request header is received, we have all of it.
//  We can now send our HTTP response.
var sbResponseHtml = new CkStringBuilder();
sbResponseHtml.Append("<html><body><p>Chilkat thanks you!</b></body</html>");

var sbResponse = new CkStringBuilder();
sbResponse.Append("HTTP/1.1 200 OK\r\n");
sbResponse.Append("Content-Length: ");
sbResponse.AppendInt(sbResponseHtml.Length);
sbResponse.Append("\r\n");
sbResponse.Append("Content-Type: text/html\r\n");
sbResponse.Append("\r\n");
sbResponse.AppendSb(sbResponseHtml);

sock.SendString(sbResponse.GetAsString());
sock.Close(50);

//  The information we need is in the startLine.
//  For example, the startLine will look like this:
//   GET /?oauth_token=a3bc8bec84acc31418b68a532e9511&oauth_verifier=b5558d37 HTTP/1.1
var sbStartLine = new CkStringBuilder();
sbStartLine.Append(startLine);
var numReplacements = sbStartLine.Replace("GET /?","");
numReplacements = sbStartLine.Replace(" HTTP/1.1","");
sbStartLine.Trim();

//  oauth_token=a3bc8bec84acc31418b68a532e9511&oauth_verifier=b5558d37
console.log("startline: " + sbStartLine.GetAsString());

hashTab.Clear();
hashTab.AddQueryParams(sbStartLine.GetAsString());

requestToken = hashTab.LookupStr("oauth_token");
var authVerifier = hashTab.LookupStr("oauth_verifier");

//  ------------------------------------------------------------------------------
//  Finally , we must exchange the OAuth Request Token for an OAuth Access Token.

http.OAuthToken = requestToken;
http.OAuthVerifier = authVerifier;

req.HttpVerb = "POST";
req.ContentType = "application/x-www-form-urlencoded";

success = http.HttpReq(accessTokenUrl,req,resp);
if (success == false) {
    console.log(http.LastErrorText);
    return;
}

//  Make sure a successful response was received.
if (resp.StatusCode !== 200) {
    console.log(resp.StatusLine);
    console.log(resp.Header);
    console.log(resp.BodyStr);
    return;
}

//  If successful, the resp.BodyStr contains something like this:
//  oauth_token=7898d7ba280dc791586dcfd26b37a9&oauth_token_secret=f2a7c267aa
console.log(resp.BodyStr);

hashTab.Clear();
hashTab.AddQueryParams(resp.BodyStr);

var accessToken = hashTab.LookupStr("oauth_token");
var accessTokenSecret = hashTab.LookupStr("oauth_token_secret");

//  The access token + secret is what should be saved and used for
//  subsequent REST API calls.
console.log("Access Token = " + accessToken);
console.log("Access Token Secret = " + accessTokenSecret);

//  Save this access token for future calls.
//  Just in case we need user_id and screen_name, save those also..
var json = new CkJsonObject();
json.AppendString("oauth_token",accessToken);
json.AppendString("oauth_token_secret",accessTokenSecret);

var fac = new CkFileAccess();
fac.WriteEntireTextFile("qa_data/tokens/etsy.json",json.Emit(),"utf-8",false);

console.log("Success.");