Sample code for 30+ languages & platforms
Zig

Plaza API (bol.com) HMAC-SHA256 Authentication

See more Encryption Examples

Demonstrates how to compute the Authorization header for bol.com using HMAC-SHA256.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example assumes the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();

    crypt.setEncodingMode("base64");
    crypt.setHashAlgorithm("sha256");
    crypt.setMacAlgorithm("hmac");

    const public_key = "oRNWbHFXtAECmhnZmEndcjLIaSKbRMVE";
    const private_key = "MaQHPOnmYkPZNgeRziPnQyyOJYytUbcFBVJBvbMKoDdpPqaZbaOiLUTWzPAkpPsZFZbJHrcoltdgpZolyNcgvvBaKcmkqFjucFzXhDONTsPAtHHyccQlLUZpkOuywMiOycDWcCySFsgpDiyGnCWCZJkNTtVdPxbSUTWVIFQiUxaPDYDXRQAVVTbSVZArAZkaLDLOoOvPzxSdhnkkJWzlQDkqsXNKfAIgAldrmyfROSyCGMCfvzdQdUQEaYZTPEoA";

    // The string to sign is this:
    // http_verb +'\n\n'+ content_type +'\n'+ x_bol_date +'\n'+ 'x-bol-date:'+ x_bol_date +'\n'+ uri

    const http_verb = "GET";
    const content_type = "application/xml";
    const x_bol_date = "Wed, 17 Feb 2016 00:00:00 GMT";
    const uri = "/services/rest/orders/v2";

    // IMPORTANT: Notice the use of underscore and hyphen (dash) chars in x-bol-date vs. x_bol_date.
    // In one place hypens are used.  In two places, underscore chars are used.
    const sb = try chilkat.StringBuilder.init();
    defer sb.deinit();
    sb.append(http_verb) catch {};
    sb.append("\n\n") catch {};
    sb.append(content_type) catch {};
    sb.append("\n") catch {};
    sb.append(x_bol_date) catch {};
    sb.append("\nx-bol-date:") catch {};
    sb.append(x_bol_date) catch {};
    sb.append("\n") catch {};
    sb.append(uri) catch {};
    std.debug.print("[{s}]\n", .{try sb.getAsString(alloc)});

    // Set the HMAC key:
    crypt.setMacKeyEncoded(private_key, "ascii") catch {};
    const mac = try crypt.macStringENC(alloc, try sb.getAsString(alloc));

    // The answer should be: nqzLWvXI1eBhBXrRx5NF23V5hS8Q1xWCloJzPi/RAts=
    std.debug.print("{s}\n", .{mac});

    // The last step is to append the public key with the signature
    const sb_header = try chilkat.StringBuilder.init();
    defer sb_header.deinit();
    sb_header.append(public_key) catch {};
    sb_header.append(":") catch {};
    sb_header.append(mac) catch {};

    const hdr_value = try sb_header.getAsString(alloc);
    std.debug.print("{s}\n", .{hdr_value});
}