Sample code for 30+ languages & platforms
React Native

Plaza API (bol.com) HMAC-SHA256 Authentication

See more Encryption Examples

Demonstrates how to compute the Authorization header for bol.com using HMAC-SHA256.

Chilkat React Native Downloads

React Native
import { Crypt2, StringBuilder } from '@chilkat/react-native'

function chilkatExample() {
  // This example assumes the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  const crypt = new Crypt2();

  crypt.encodingMode = 'base64';
  crypt.hashAlgorithm = 'sha256';
  crypt.macAlgorithm = 'hmac';

  const publicKey = 'oRNWbHFXtAECmhnZmEndcjLIaSKbRMVE';
  const privateKey = 'MaQHPOnmYkPZNgeRziPnQyyOJYytUbcFBVJBvbMKoDdpPqaZbaOiLUTWzPAkpPsZFZbJHrcoltdgpZolyNcgvvBaKcmkqFjucFzXhDONTsPAtHHyccQlLUZpkOuywMiOycDWcCySFsgpDiyGnCWCZJkNTtVdPxbSUTWVIFQiUxaPDYDXRQAVVTbSVZArAZkaLDLOoOvPzxSdhnkkJWzlQDkqsXNKfAIgAldrmyfROSyCGMCfvzdQdUQEaYZTPEoA';

  // The string to sign is this:
  // http_verb +'\n\n'+ content_type +'\n'+ x_bol_date +'\n'+ 'x-bol-date:'+ x_bol_date +'\n'+ uri

  const httpVerb = 'GET';
  const contentType = 'application/xml';
  const xBolDate = 'Wed, 17 Feb 2016 00:00:00 GMT';
  const uri = '/services/rest/orders/v2';

  // IMPORTANT: Notice the use of underscore and hyphen (dash) chars in x-bol-date vs. x_bol_date.
  // In one place hypens are used.  In two places, underscore chars are used.
  const sb = new StringBuilder();
  sb.append(httpVerb);
  sb.append('\n\n');
  sb.append(contentType);
  sb.append('\n');
  sb.append(xBolDate);
  sb.append('\nx-bol-date:');
  sb.append(xBolDate);
  sb.append('\n');
  sb.append(uri);
  console.log(`[${sb.getAsString()}]`);

  // Set the HMAC key:
  crypt.setMacKeyEncoded(privateKey, 'ascii');
  const mac = crypt.macStringENC(sb.getAsString());

  // The answer should be: nqzLWvXI1eBhBXrRx5NF23V5hS8Q1xWCloJzPi/RAts=
  console.log(mac);

  // The last step is to append the public key with the signature
  const sbHeader = new StringBuilder();
  sbHeader.append(publicKey);
  sbHeader.append(':');
  sbHeader.append(mac);

  const hdrValue = sbHeader.getAsString();
  console.log(hdrValue);
}