Sample code for 30+ languages & platforms
Zig Requires Chilkat v11.0.0+

PRODA Get OAuth2 Access Token using JWT

See more PRODA Examples

Demonstrates how to get an OAuth2 access token for the PRODA Australian Government Online Services using a JWT.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // First create a JWT to be sent in the POST to https://vnd.proda.humanservices.gov.au/mga/sps/oauth/oauth20/token

    const priv_key = try chilkat.PrivateKey.init();
    defer priv_key.deinit();

    // Load an RSA private key from a PEM file.
    // Chilkat provides alternative methods to load from other formats, or to load from a string or binary data.
    priv_key.loadEncryptedPemFile("qa_data/pem/rsa_passwd.pem", "passwd") catch {
        std.debug.print("{s}\n", .{try priv_key.getLastErrorText(alloc)});
        return;
    };

    const jwt = try chilkat.Jwt.init();
    defer jwt.deinit();

    // Build the JOSE header
    const jose = try chilkat.JsonObject.init();
    defer jose.deinit();
    // Use RS256.  Pass the string "RS384" or "RS512" to use RSA with SHA-384 or SHA-512.
    try jose.appendString("alg", "RS256");
    try jose.appendString("typ", "JWT");
    try jose.appendString("kid", "test-device");

    // Now build the JWT claims (also known as the payload)
    const claims = try chilkat.JsonObject.init();
    defer claims.deinit();
    try claims.appendString("iss", "9646844092");
    try claims.appendString("sub", "test-device");
    try claims.appendString("aud", "https://proda.humanservices.gov.au");

    // Set the timestamp of when the JWT was created to now.
    const cur_date_time = jwt.genNumericDate(0);
    try claims.addIntAt(-1, "iat", cur_date_time);

    // Set the timestamp defining an expiration time (end time) for the token
    // to be now + 1 hour (3600 seconds)
    try claims.addIntAt(-1, "exp", cur_date_time + 3600);

    // Produce the smallest possible JWT:
    jwt.setAutoCompact(true);

    // Create the JWT token.  This is where the RSA signature is created.
    const jwt_token = try jwt.createJwtPk(alloc, try jose.emit(alloc), try claims.emit(alloc), priv_key);

    // ---------------------------------------------------------------------
    // Build and send the POST, which should look something like this:

    // POST https://vnd.proda.humanservices.gov.au/mga/sps/oauth/oauth20/token HTTP/1.1
    // Content-Type: application/x-www-form-urlencoded
    // Content-Length: 666
    // Host: vnd.proda.humanservices.gov.au
    //
    // grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Ajwt-bearer&assertion=<jwt>&client_id=VendorClient03

    const http = try chilkat.Http.init();
    defer http.deinit();

    const req = try chilkat.HttpRequest.init();
    defer req.deinit();
    req.setHttpVerb("POST");
    req.setContentType("application/x-www-form-urlencoded");

    // Add the request params.
    req.addParam("grant_type", "urn:ietf:params:oauth:grant-type:jwt-bearer");
    req.addParam("assertion", jwt_token);
    req.addParam("client_id", "VendorClient03");

    const resp = try chilkat.HttpResponse.init();
    defer resp.deinit();
    http.httpReq("https://vnd.proda.humanservices.gov.au/mga/sps/oauth/oauth20/token", req, resp) catch {
        std.debug.print("{s}\n", .{try http.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Response status code = {d}\n", .{resp.getStatusCode()});
    std.debug.print("Response body:\n", .{});
    std.debug.print("{s}\n", .{try resp.getBodyStr(alloc)});
}