Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

ETrade OAuth1 Authorization (3-legged) Step 2

See more ETrade Examples

Demonstrates the final step in 3-legged OAuth1 authorization for the ETrade REST API. Example uses the OAuth1 verifier code that was copy-and-pasted from the browser in the 1st step. The end result of this final OAuth1 step is an access token that can be used to make ETrade REST API calls.

See https://apisb.etrade.com/docs/api/authorization/get_access_token.html

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const consumer_key = "ETRADE_CONSUMER_KEY";
    const consumer_secret = "ETRADE_CONSUMER_SECRET";

    const access_token_url = "https://apisb.etrade.com/oauth/access_token";

    const http = try chilkat.Http.init();
    defer http.deinit();

    http.setOAuth1(true);
    http.setOAuthConsumerKey(consumer_key);
    http.setOAuthConsumerSecret(consumer_secret);
    http.setOAuthCallback("oob");

    const json_request_token = try chilkat.JsonObject.init();
    defer json_request_token.deinit();
    try json_request_token.loadFile("qa_data/tokens/etrade_request_token.json");
    const request_token = try json_request_token.stringOf(alloc, "oauth_token");
    const request_token_secret = try json_request_token.stringOf(alloc, "oauth_token_secret");

    // ------------------------------------------------------------------------------
    // Exchange the OAuth Request Token for an OAuth Access Token.

    http.setOAuthToken(request_token);
    http.setOAuthTokenSecret(request_token_secret);

    // This is the verifier that was interactively copy-and-pasted from the browser back to our app.
    http.setOAuthVerifier("NJ07S");

    // Use the explicit string "INCLUDE_OAUTH_TOKEN" to tell Chilkat to include the "oauth_token" param in the Authorization header field
    http.setUncommonOptions("INCLUDE_OAUTH_TOKEN");

    const resp = try chilkat.HttpResponse.init();
    defer resp.deinit();
    http.httpNoBody("GET", access_token_url, resp) catch {
        std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
        return;
    };

    // Make sure a successful response was received.
    if (resp.getStatusCode() != 200) {
        std.debug.print("{s}\n", .{try resp.getStatusLine(alloc)});
        std.debug.print("{s}\n", .{try resp.getHeader(alloc)});
        std.debug.print("{s}\n", .{try resp.getBodyStr(alloc)});
        return;
    }

    // If successful, the resp.BodyStr contains something like this:
    // oauth_token=85123455-fF41296Bi3daM8eCo9Y5vZabcdxXpRv864plYPOjr&oauth_token_secret=afiYJOgabcdSfGae7BDvJVVTwys8fUGpra5guZxbmFBZo
    std.debug.print("{s}\n", .{try resp.getBodyStr(alloc)});

    const hash_tab = try chilkat.Hashtable.init();
    defer hash_tab.deinit();
    hash_tab.addQueryParams(try resp.getBodyStr(alloc)) catch {};

    const access_token = try hash_tab.lookupStr(alloc, "oauth_token");
    const access_token_secret = try hash_tab.lookupStr(alloc, "oauth_token_secret");

    // The access token + secret is what should be saved and used for
    // subsequent REST API calls.
    std.debug.print("Access Token = {s}\n", .{access_token});
    std.debug.print("Access Token Secret = {s}\n", .{access_token_secret});

    // Save this access token for future calls.
    // Just in case we need user_id and screen_name, save those also..
    const json = try chilkat.JsonObject.init();
    defer json.deinit();
    json.appendString("oauth_token", access_token) catch {};
    json.appendString("oauth_token_secret", access_token_secret) catch {};

    const fac = try chilkat.FileAccess.init();
    defer fac.deinit();
    fac.writeEntireTextFile("qa_data/tokens/etrade.json", try json.emit(alloc), "utf-8", false) catch {};

    std.debug.print("Success.\n", .{});
}