Sample code for 30+ languages & platforms
Node.js

Twitter OAuth1 Authorization (3-legged)

See more OAuth1 Examples

Demonstrates 3-legged OAuth1 authorization for Twitter.

This example is deprecated and no longer valid.

Chilkat Node.js Downloads

Node.js
NODEJS_PRELUDE

function chilkatExample() {

    var success = false;

    var consumerKey = "TWITTER_CONSUMER_KEY";
    var consumerSecret = "TWITTER_CONSUMER_SECRET";

    var requestTokenUrl = "https://api.twitter.com/oauth/request_token";
    var authorizeUrl = "https://api.twitter.com/oauth/authorize";
    var accessTokenUrl = "https://api.twitter.com/oauth/access_token";

    //  The port number is picked at random. It's some unused port that won't likely conflict with anything else..
    var callbackUrl = "http://localhost:3017/";
    var callbackLocalPort = 3017;

    //  The 1st step in 3-legged OAuth1.0a is to send a POST to the request token URL to obtain an OAuth Request Token
    var http = new chilkat.Http();

    http.OAuth1 = true;
    http.OAuthConsumerKey = consumerKey;
    http.OAuthConsumerSecret = consumerSecret;

    var req = new chilkat.HttpRequest();
    req.AddParam("oauth_callback",callbackUrl);

    req.HttpVerb = "POST";
    req.ContentType = "application/x-www-form-urlencoded";

    var resp = new chilkat.HttpResponse();
    success = http.HttpReq(requestTokenUrl,req,resp);
    if (success == false) {
        console.log(http.LastErrorText);
        return;
    }

    //  If successful, the resp.BodyStr contains something like this:  
    //  oauth_token=-Wa_KwAAAAAAxfEPAAABV8Qar4Q&oauth_token_secret=OfHY4tZBX2HK4f7yIw76WYdvnl99MVGB&oauth_callback_confirmed=true
    console.log(resp.BodyStr);

    if (resp.StatusCode !== 200) {
        console.log("Failed response status code: " + resp.StatusCode);
        return;
    }

    var hashTab = new chilkat.Hashtable();
    hashTab.AddQueryParams(resp.BodyStr);

    var requestToken = hashTab.LookupStr("oauth_token");
    var requestTokenSecret = hashTab.LookupStr("oauth_token_secret");
    http.OAuthTokenSecret = requestTokenSecret;

    console.log("oauth_token = " + requestToken);
    console.log("oauth_token_secret = " + requestTokenSecret);

    //  ---------------------------------------------------------------------------
    //  The next step is to form a URL to send to the authorizeUrl
    //  This is an HTTP GET that we load into a popup browser.
    var sbUrlForBrowser = new chilkat.StringBuilder();
    sbUrlForBrowser.Append(authorizeUrl);
    sbUrlForBrowser.Append("?oauth_token=");
    sbUrlForBrowser.Append(requestToken);
    var url = sbUrlForBrowser.GetAsString();

    //  Launch the system's default browser navigated to the URL.
    var oauth2 = new chilkat.OAuth2();
    success = oauth2.LaunchBrowser(url);
    if (success == false) {
        console.log(oauth2.LastErrorText);
        return;
    }

    //  When the url is loaded into a browser, the response from Twitter will redirect back to localhost:3017
    //  We'll need to start a socket that is listening on port 3017 for the callback from the browser.
    var listenSock = new chilkat.Socket();

    var backLog = 5;
    success = listenSock.BindAndListen(callbackLocalPort,backLog);
    if (success == false) {
        console.log(listenSock.LastErrorText);
        return;
    }

    //  Wait for the browser's connection in a background thread.
    //  (We'll send load the URL into the browser following this..)
    //  Wait a max of 60 seconds before giving up.
    var sock = new chilkat.Socket();
    var maxWaitMs = 60000;
    // task: Task
    var task = listenSock.AcceptNextAsync(maxWaitMs,sock);
    task.Run();

    //  Wait for the listenSock's task to complete.
    success = task.Wait(maxWaitMs);
    if (!success || (task.StatusInt !== 7) || (task.TaskSuccess !== true)) {
        if (!success) {
            //  The task.LastErrorText applies to the Wait method call.
            console.log(task.LastErrorText);
        }
        else {
            //  The ResultErrorText applies to the underlying task method call (i.e. the AcceptNextConnection)
            console.log(task.Status);
            console.log(task.ResultErrorText);
        }

        return;
    }

    //  If we get to this point, the connection from the browser arrived and was accepted.

    //  We no longer need the listen socket...
    //  Stop listening on port 3017.
    listenSock.Close(10);

    //  Read the start line of the request..
    var startLine = sock.ReceiveUntilMatch("\r\n");
    if (sock.LastMethodSuccess == false) {
        console.log(sock.LastErrorText);
        return;
    }

    //  Read the request header.
    var requestHeader = sock.ReceiveUntilMatch("\r\n\r\n");
    if (sock.LastMethodSuccess == false) {
        console.log(sock.LastErrorText);
        return;
    }

    //  The browser SHOULD be sending us a GET request, and therefore there is no body to the request.
    //  Once the request header is received, we have all of it.
    //  We can now send our HTTP response.
    var sbResponseHtml = new chilkat.StringBuilder();
    sbResponseHtml.Append("<html><body><p>Chilkat thanks you!</b></body</html>");

    var sbResponse = new chilkat.StringBuilder();
    sbResponse.Append("HTTP/1.1 200 OK\r\n");
    sbResponse.Append("Content-Length: ");
    sbResponse.AppendInt(sbResponseHtml.Length);
    sbResponse.Append("\r\n");
    sbResponse.Append("Content-Type: text/html\r\n");
    sbResponse.Append("\r\n");
    sbResponse.AppendSb(sbResponseHtml);

    sock.SendString(sbResponse.GetAsString());
    sock.Close(50);

    //  The information we need is in the startLine.
    //  For example, the startLine will look like this:
    //   GET /?oauth_token=abcdRQAAZZAAxfBBAAABVabcd_k&oauth_verifier=9rdOq5abcdCe6cn8M3jabcdj3Eabcd HTTP/1.1
    var sbStartLine = new chilkat.StringBuilder();
    sbStartLine.Append(startLine);
    var numReplacements = sbStartLine.Replace("GET /?","");
    numReplacements = sbStartLine.Replace(" HTTP/1.1","");
    sbStartLine.Trim();

    //  oauth_token=abcdRQAAZZAAxfBBAAABVabcd_k&oauth_verifier=9rdOq5abcdCe6cn8M3jabcdj3Eabcd
    console.log("startline: " + sbStartLine.GetAsString());

    hashTab.Clear();
    hashTab.AddQueryParams(sbStartLine.GetAsString());

    requestToken = hashTab.LookupStr("oauth_token");
    var authVerifier = hashTab.LookupStr("oauth_verifier");

    //  ------------------------------------------------------------------------------
    //  Finally , we must exchange the OAuth Request Token for an OAuth Access Token.

    http.OAuthToken = requestToken;
    http.OAuthVerifier = authVerifier;

    //  We don't need the "Authorization: OAuth ..." header for this POST.
    http.OAuth1 = false;
    req.RemoveParam("oauth_callback");
    req.AddParam("oauth_verifier",authVerifier);
    req.AddParam("oauth_token",requestToken);

    req.HttpVerb = "POST";
    req.ContentType = "application/x-www-form-urlencoded";

    success = http.HttpReq(accessTokenUrl,req,resp);
    if (success == false) {
        console.log(http.LastErrorText);
        return;
    }

    //  Make sure a successful response was received.
    if (resp.StatusCode !== 200) {
        console.log(resp.StatusLine);
        console.log(resp.Header);
        console.log(resp.BodyStr);
        return;
    }

    //  If successful, the resp.BodyStr contains something like this:
    //  oauth_token=85123455-fF41296Bi3daM8eCo9Y5vZabcdxXpRv864plYPOjr&oauth_token_secret=afiYJOgabcdSfGae7BDvJVVTwys8fUGpra5guZxbmFBZo&user_id=85612355&screen_name=chilkatsoft&x_auth_expires=0
    console.log(resp.BodyStr);

    hashTab.Clear();
    hashTab.AddQueryParams(resp.BodyStr);

    var accessToken = hashTab.LookupStr("oauth_token");
    var accessTokenSecret = hashTab.LookupStr("oauth_token_secret");
    var userId = hashTab.LookupStr("user_id");
    var screenName = hashTab.LookupStr("screen_name");

    //  The access token + secret is what should be saved and used for
    //  subsequent REST API calls.
    console.log("Access Token = " + accessToken);
    console.log("Access Token Secret = " + accessTokenSecret);
    console.log("user_id = " + userId);
    console.log("screen_name  = " + screenName);

    //  Save this access token for future calls.
    //  Just in case we need user_id and screen_name, save those also..
    var json = new chilkat.JsonObject();
    json.AppendString("oauth_token",accessToken);
    json.AppendString("oauth_token_secret",accessTokenSecret);
    json.AppendString("user_id",userId);
    json.AppendString("screen_name",screenName);

    var fac = new chilkat.FileAccess();
    fac.WriteEntireTextFile("qa_data/tokens/twitter.json",json.Emit(),"utf-8",false);

    console.log("Success.");

}

chilkatExample();