Sample code for 30+ languages & platforms
Zig

Docusign JSON Web Token (JWT) Grant

See more DocuSign Examples

Demonstrates how to obtain an access token using the JSON Web Token (JWT) Grant. This is good for service integrations where authorization and authentication is automated and cannot have interactive Docusign account owner interaction. Consent for the access is obtained beforehand in various ways. See Obtaining Consent.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // 1. Assume we have already requested and obtained application consent.
    //    (See Request Docusign Application Consent
    //
    // 2. Create a JWT Token.
    //
    const priv_key = try chilkat.PrivateKey.init();
    defer priv_key.deinit();

    // Load an RSA private key from a PEM file.
    priv_key.loadPemFile("qa_data/pem/docusign_private_rsa_key.pem") catch {
        std.debug.print("{s}\n", .{try priv_key.getLastErrorText(alloc)});
        return;
    };

    const jwt = try chilkat.Jwt.init();
    defer jwt.deinit();

    // Build the JOSE header
    const jose = try chilkat.JsonObject.init();
    defer jose.deinit();
    // Use RS256.  Pass the string "RS384" or "RS512" to use RSA with SHA-384 or SHA-512.
    try jose.appendString("alg", "RS256");
    try jose.appendString("typ", "JWT");

    // Now build the JWT claims (also known as the payload)
    const claims = try chilkat.JsonObject.init();
    defer claims.deinit();

    // Replace these with actual values.
    // The client ID is also known as the "integration key" in Docusign.
    try claims.appendString("iss", "MY_DOCUSIGN_CLIENT_ID");
    // In your DocuSign Admin/Account/UserProfile, this is the API Username, such as 14612117-2530-4982-8c49-ba8766303272
    try claims.appendString("sub", "DOCUSIGN_USER_ID");
    try claims.appendString("aud", "account-d.docusign.com");
    try claims.appendString("scope", "signature");

    // Set the timestamp of when the JWT was created to now.
    const cur_date_time = jwt.genNumericDate(0);
    try claims.addIntAt(-1, "iat", cur_date_time);

    // Set the "not process before" timestamp to now.
    try claims.addIntAt(-1, "nbf", cur_date_time);

    // Set the timestamp defining an expiration time (end time) for the token
    // to be now + 1 hour (3600 seconds)
    try claims.addIntAt(-1, "exp", cur_date_time + 3600);

    // Produce the smallest possible JWT:
    jwt.setAutoCompact(true);

    // Create the JWT token.  This is where the RSA signature is created.
    const token = try jwt.createJwtPk(alloc, try jose.emit(alloc), try claims.emit(alloc), priv_key);

    std.debug.print("{s}\n", .{token});

    // Do the following CURL statement to get the response JSON which contains the access token.
    // curl --data "grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer&assertion=YOUR_JSON_WEB_TOKEN"
    //      --request POST https://account-d.docusign.com/oauth/token
    const http = try chilkat.Http.init();
    defer http.deinit();

    const req = try chilkat.HttpRequest.init();
    defer req.deinit();
    req.addParam("grant_type", "urn:ietf:params:oauth:grant-type:jwt-bearer");
    req.addParam("assertion", token);

    req.setHttpVerb("POST");
    req.setContentType("application/x-www-form-urlencoded");

    const resp = try chilkat.HttpResponse.init();
    defer resp.deinit();
    http.httpReq("https://account-d.docusign.com/oauth/token", req, resp) catch {
        std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("response status = {d}\n", .{resp.getStatusCode()});
    if (resp.getStatusCode() != 200) {
        std.debug.print("{s}\n", .{try resp.getBodyStr(alloc)});
        std.debug.print("Failed.\n", .{});
    } else {
        // Save the access token to a file for use in subsequent requests..
        // (Or you may simply persiste the access token in memory for your applicaton to use for subsequent REST API calls..)
        try resp.saveBodyText(true, "qa_data/tokens/docusign.json");
        std.debug.print("{s}\n", .{try resp.getBodyStr(alloc)});
        std.debug.print("Success.\n", .{});
    }
}