Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

Get ETK Public Key (api-acpt.ehealth.fgov.be)

See more Belgian eHealth Platform Examples

The following URL returns JSON, which contains a PKCS7 signed data:
https://api-acpt.ehealth.fgov.be/etee/v1/etks?identifier=12345678901&type=SSIN

This example extracts the signed data, validates it, and then extracts the public key from the certificate (obtained from signed content in the PKCS7)

Note: The URL above uses "12345678901" which is not valid. You should replace it with a valid number.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const http = try chilkat.Http.init();
    defer http.deinit();

    const json_str = http.quickGetStr(alloc, "https://api-acpt.ehealth.fgov.be/etee/v1/etks?identifier=12345678901&type=SSIN") catch {
        std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("{s}\n", .{json_str});

    // The JSON contains something like this:

    // [
    //     {
    //         "key": {
    //             "applicationIdentifier": "",
    //             "ssin": "12345678901"
    //         },
    //         "value": "MIAGCSq....AAAAAAAA=="
    //     }
    // ]

    // Note: The above is a JSON array (not a JSON object)
    // It should be loaded into a Chilkat JSON array.
    const jarr = try chilkat.JsonArray.init();
    defer jarr.deinit();
    jarr.load(json_str) catch {
        std.debug.print("Failed to load JSON.\n", .{});
        return;
    };

    const json = try jarr.objectAt(0);
    defer json.deinit();
    const bd_pkcs7 = try chilkat.BinData.init();
    defer bd_pkcs7.deinit();
    bd_pkcs7.appendEncoded(try json.stringOf(alloc, "value"), "base64") catch {};

    // Let's verify the PKCS7, and then examine the signing cert,
    // and get the signing cert's public key.
    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();

    // Validate the signedData PKCS7, and replace the contents of bdPkcs7 with the extracted signed content.
    crypt.opaqueVerifyBd(bd_pkcs7) catch {
        std.debug.print("{s}\n", .{try crypt.getLastErrorText(alloc)});
        return;
    };

    // The signed content is the DER of a certificate.
    // In other words, bdPkcs7 now contains a certificate.
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    cert.loadFromBd(bd_pkcs7) catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    // Show some certificate information:
    std.debug.print("Subject: {s}\n", .{try cert.getSubjectDN(alloc)});
    std.debug.print("Serial: {s}\n", .{try cert.getSerialNumber(alloc)});
    std.debug.print("Issuer: {s}\n", .{try cert.getIssuerDN(alloc)});

    // Let's get the cert's public key...
    const pub_key = try chilkat.PublicKey.init();
    defer pub_key.deinit();
    cert.getPublicKey(pub_key) catch {};

    // OK, you now have the public key and can do whatever is needed..
    std.debug.print("{s}\n", .{try pub_key.getKeyType(alloc)});
    std.debug.print("{d}\n", .{pub_key.getKeySize()});
}