Sample code for 30+ languages & platforms
React Native Requires Chilkat v11.0.0+

Duo Auth API - Async Auth

See more Duo Auth MFA Examples

If you enable async, then your application will be able to retrieve real-time status updates from the authentication process, rather than receiving no information until the process is complete.

Chilkat React Native Downloads

React Native
import { Http, HttpRequest, HttpResponse, JsonObject, StringBuilder } from '@chilkat/react-native'

async function chilkatExample() {
  // This example assumes the Chilkat API to have been previously unlocked.
  // See Global Unlock Sample for sample code.

  const integrationKey = 'DIMS3V5QDVG9J9ABRXC4';
  const secretKey = 'HWVQ46nubLBxhnRlKddTltWIi3hL0fIQF2qTvLab';

  const http = new Http();

  http.accept = 'application/json';

  // Use your own hostname here:
  let url = 'https://api-a03782e1.duosecurity.com/auth/v2/auth';

  // This example requires Chilkat v9.5.0.89 or greater because Chilkat will automatically
  // generate and send the HMAC signature for the requires based on the integration key and secret key.
  http.login = integrationKey;
  http.password = secretKey;

  const req = new HttpRequest();
  req.addParam('username', 'matt');
  req.addParam('factor', 'push');
  // The device ID can be obtained from the preauth response.  See Duo Preauth Example
  req.addParam('device', 'DP6GYVTQ5NK82BMR851F');
  // Add the async param to get an immediate response, then periodically check for updates to find out when the MFA authentication completes for fails.
  req.addParam('async', '1');

  req.httpVerb = 'POST';
  req.contentType = 'application/x-www-form-urlencoded';

  const resp = new HttpResponse();
  try {
    await http.httpReqAsync(url, req, resp);
  } catch {
    console.log(http.lastErrorText);
    return;
  }

  console.log(`status code = ${resp.statusCode}`);

  const json = new JsonObject();
  json.load(resp.bodyStr);
  json.emitCompact = false;
  console.log(json.emit());

  if (resp.statusCode !== 200) {
    return;
  }

  // Sample successful output:

  // status code = 200

  // {
  //   "stat": "OK",
  //   "response": {
  //     "txid": "45f7c92b-f45f-4862-8545-e0f58e78075a"
  //   }
  // }

  const txid = json.stringOf('response.txid');

  // Use your own hostname here:
  const sbUrl = new StringBuilder();
  sbUrl.append('https://api-a03782e1.duosecurity.com/auth/v2/auth_status?txid=');
  sbUrl.append(txid);
  url = sbUrl.getAsString();

  console.log(`Auth status URL: ${url}`);

  const sbResult = new StringBuilder();
  let responseStatus = '';
  let responseStatusMsg = '';

  // Wait for a response...
  let i = 0;
  const maxWaitIterations = 100;
  while (i < maxWaitIterations) {
    // Wait 3 seconds.
    http.sleepMs(3000);

    console.log('Polling...');

    try {
      await http.httpNoBodyAsync('GET', url, resp);
    } catch {
      console.log(http.lastErrorText);
      return;
    }

    if (resp.statusCode !== 200) {
      console.log(`error status code = ${resp.statusCode}`);
      console.log(resp.bodyStr);
      console.log('Failed.');
      return;
    }

    // Sample response:

    // 	{
    // 	  "stat": "OK",
    // 	  "response": {
    // 	    "result": "waiting",
    // 	    "status": "pushed",
    // 	    "status_msg": "Pushed a login request to your phone..."
    // 	  }
    // 	}

    json.load(resp.bodyStr);

    // The responseResult can be "allow", "deny", or "waiting"
    sbResult.clear();
    json.stringOfSb('response.result', sbResult);
    responseStatus = json.stringOf('response.status');
    responseStatusMsg = json.stringOf('response.status_msg');

    console.log(sbResult.getAsString());
    console.log(responseStatus);
    console.log(responseStatusMsg);
    console.log('');

    if (sbResult.contentsEqual('waiting', true)) {
      i++;
    } else {
      // Force loop exit..
      i = maxWaitIterations;
    }
  }

  console.log('Finished.');
}