# Call API authentication with OAuth

**URL:** <https://community.glideapps.com/t/call-api-authentication-with-oauth/67875>\
**Category:** Ask for Help\
**Tags:** api\
**Created:** [November 16, 2023, 6:48pm UTC](https://community.glideapps.com/t/call-api-authentication-with-oauth/67875 "2023-11-16T18:48:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nate\_H](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/nate_h/32/44900_2.png) [@Nate\_H](https://community.glideapps.com/u/Nate_H)\
**Post date:** [November 16, 2023, 6:48pm UTC](https://community.glideapps.com/t/call-api-authentication-with-oauth/67875/1 "2023-11-16T18:48:10Z")

</div>

Second question of the day, look at me go…

Anyway, I am trying to connect Glide with a Netsuite API. Netsuite’s token based authentication is based on OAuth 1.0; is there a (secure) way to generate a signed Authorization header so that I can successfully use Glide’s Call API action to work with Netsuite?

---

<div class="post-metadata">

**Author:** ![Rev](https://avatars.discourse-cdn.com/v4/letter/r/b5a626/32.png) [@Rev](https://community.glideapps.com/u/Rev)\
**Post date:** [November 17, 2023, 3:46am UTC](https://community.glideapps.com/t/call-api-authentication-with-oauth/67875/2 "2023-11-17T03:46:11Z")

</div>

I posted some steps on how I’ve integrated OAuth into my builds, hopefully this helps for your use case.

> [@Oauth Authentication (possibly with Pathfix?](https://community.glideapps.com/t/oauth-authentication-possibly-with-pathfix/66683/6):
>
> While I didn’t use Pathfix, I did manage to set up Oauth with Glide + Make. Use case: Allow my users to connect their own HubSpot accounts to their profile in my Glide project. This allows each user to pull in data that’s relevant to their business (ie contacts, deals, etc). You could do this for any platform. High-level steps: Create a new Make scenario with the first module being a Custom Webhook. Copy the webhook URL and use it as the Redirect URL in the platform you’re setting up OAuth …

---

<div class="post-metadata">

**Author:** ![Nate\_H](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/nate_h/32/44900_2.png) [@Nate\_H](https://community.glideapps.com/u/Nate_H)\
**Post date:** [November 17, 2023, 12:58pm UTC](https://community.glideapps.com/t/call-api-authentication-with-oauth/67875/3 "2023-11-17T12:58:07Z")

</div>

Thank you! I’m going to tinker with this today and see if I can get it working.

---

<div class="post-metadata">

**Author:** ![Nate\_H](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/nate_h/32/44900_2.png) [@Nate\_H](https://community.glideapps.com/u/Nate_H)\
**Post date:** [November 17, 2023, 1:45pm UTC](https://community.glideapps.com/t/call-api-authentication-with-oauth/67875/4 "2023-11-17T13:45:07Z")

</div>

My use case is a bit different - I don’t need (or want) the user to authenticate with Netsuite, I just need Glide to be able to create a signed OAuth 1.0 header so I can POST a JSON into Netsuite based on a record in Glide. Pathfix is a no-go since it looks like they only support pre-defined services anyway.

I think it would be difficult to create a signature externally and somehow pass that back into Glide securely.

Of course I can continue using Zapier for this use case, the idea was to make it more secure and be able to get a response back from the endpoint directly into Glide.

---

<div class="post-metadata">

**Author:** ![Rev](https://avatars.discourse-cdn.com/v4/letter/r/b5a626/32.png) [@Rev](https://community.glideapps.com/u/Rev)\
**Post date:** [November 18, 2023, 11:10am UTC](https://community.glideapps.com/t/call-api-authentication-with-oauth/67875/5 "2023-11-18T11:10:42Z")

</div>

I’m not familiar with Netsuite’s API to help out more, sorry. You may be able to use a template column to create the header. You could then use parts of the output in a Call API column. It may take a bit of creative thinking to get it to work in Glide without an external tool like Make to assist.

---

<div class="post-metadata">

**Author:** ![Nate\_H](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/nate_h/32/44900_2.png) [@Nate\_H](https://community.glideapps.com/u/Nate_H)\
**Post date:** [November 21, 2023, 7:45pm UTC](https://community.glideapps.com/t/call-api-authentication-with-oauth/67875/6 "2023-11-21T19:45:45Z")

</div>

I got this working and wanted to document here for anyone who might stumble across this later. I was able to generate and correctly sign an OAuth 1.0 header using a combination of templates, encode text, and JavaScript.

Major caveat, this is not secure. I understand that Glide executes Javascript locally and my code contains the private consumer and token secrets. I am comfortable with this for my use case as this is internal only and I have taken mitigating steps within the endpoint application.

After gathering keys, URLs, etc., into a helper table I created all the components of the OAuth 1.0 header and base string using template columns.

- Format Date column to get a Unix timestamp
- Javascript code to create the random nonce value.
- Encode text to encode all the strings, values and URLs to percent-encoding

The signing was the missing piece - found this code snippet in this [thread](https://community.glideapps.com/t/getting-a-error-when-trying-to-add-my-rep-in-experimental-code-column/65714/42) after trying a bunch of other things that didn’t work for various reasons.

> [@Getting a error when trying to add my rep in experimental code column](https://community.glideapps.com/t/getting-a-error-when-trying-to-add-my-rep-in-experimental-code-column/65714/44):
>
> ```auto
> const CryptoJS = await import('https://cdn.skypack.dev/crypto-js');
> 
> const message = 'hello';
> const secretKey = 'secret';
> 
> const hmac = CryptoJS.HmacSHA1(message, secretKey);
> 
> const hashHex = CryptoJS.enc.Hex.stringify(hmac);
> 
> return hashHex;
> 
> ```

There was a LOT of trial and error to finally get this to work, but it’s up and running now! Thanks @Rev for taking the time and pointing me in a direction which ultimately led to this solution.

I would love to see support for OAuth 1.0 and 2.0 in the Call API action - I think there would be a ton of value there.
