Sample code for 30+ languages & platforms
Xbase++ Requires Chilkat v11.0.0+

Verify Signature of Alexa Custom Skill Request

See more HTTP Misc Examples

This example verifies the signature of an Alexa Custom Skill Request.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL cSignature
LOCAL cCertChainUrl
LOCAL cJsonBody
LOCAL oHttp
LOCAL oSbPem
LOCAL oPem
LOCAL oCert
LOCAL oPubKey
LOCAL oRsa
LOCAL nBVerified

nSuccess := 0

//  This example assumes you have a web service that will receive requests from Alexa.
//  A sample request sent by Alexa will look like the following:

//  Connection: Keep-Alive
//  Content-Length: 2583
//  Content-Type: application/json; charset=utf-8
//  Accept: application/json
//  Accept-Charset: utf-8
//  Host: your.web.server.com
//  User-Agent: Apache-HttpClient/4.5.x (Java/1.8.0_172)
//  Signature: dSUmPwxc9...aKAf8mpEXg==
//  SignatureCertChainUrl: https://s3.amazonaws.com/echo.api/echo-api-cert-6-ats.pem
//  
//  {"version":"1.0","session":{"new":true,"sessionId":"amzn1.echo-api.session.433 ... }}

//  First, assume we've written code to get the 3 pieces of data we need:
cSignature := "dSUmPwxc9...aKAf8mpEXg=="
cCertChainUrl := "https://s3.amazonaws.com/echo.api/echo-api-cert-6-ats.pem"
cJsonBody := '{"version":"1.0","session":{"new":true,"sessionId":"amzn1.echo-api.session.433 ... }}'

//  To validate the signature, we do the following:

//  First, download the PEM-encoded X.509 certificate chain that Alexa used to sign the message 
oHttp := CreateObject("Chilkat.Http")
oSbPem := CreateObject("Chilkat.StringBuilder")
nSuccess := oHttp:QuickGetSb(cCertChainUrl, oSbPem)
IF (nSuccess == 0)
    ? oHttp:LastErrorText
    oHttp:destroy()
    oSbPem:destroy()
    RETURN
ENDIF

oPem := CreateObject("Chilkat.Pem")
nSuccess := oPem:LoadPem(oSbPem:GetAsString(), "passwordNotUsed")
IF (nSuccess == 0)
    ? oPem:LastErrorText
    oHttp:destroy()
    oSbPem:destroy()
    oPem:destroy()
    RETURN
ENDIF

//  The 1st certificate should be the signing certificate.
oCert := oPem:GetCert(0)
IF (oPem:LastMethodSuccess == 0)
    ? oPem:LastErrorText
    oHttp:destroy()
    oSbPem:destroy()
    oPem:destroy()
    RETURN
ENDIF

//  Get the public key from the cert.
oPubKey := CreateObject("Chilkat.PublicKey")
oCert:GetPublicKey(oPubKey)

oCert:destroy()

//  Use the public key extracted from the signing certificate to decrypt the encrypted signature to produce the asserted hash value.
oRsa := CreateObject("Chilkat.Rsa")
nSuccess := oRsa:UsePublicKey(oPubKey)
IF (nSuccess == 0)
    ? oCert:LastErrorText
    oHttp:destroy()
    oSbPem:destroy()
    oPem:destroy()
    oPubKey:destroy()
    oRsa:destroy()
    RETURN
ENDIF

//  RSA "decrypt" the signature.
//  (Amazon's documentation is confusing, because we're simply verifiying the signature against the SHA-1 hash
//  of the request body.  This happens in a single call to VerifyStringENC...)
oRsa:EncodingMode := "base64"
nBVerified := oRsa:VerifyStringENC(cJsonBody, "sha1", cSignature)
IF (nBVerified == 1)
    ? "The signature is verified against the JSON body of the request. Yay!"
ELSE
    ? "Sorry, not verified.  Crud!"
ENDIF

oHttp:destroy()
oSbPem:destroy()
oPem:destroy()
oPubKey:destroy()
oRsa:destroy()