# Call API authentication with OAuth

**URL:** <https://community.glideapps.com/t/call-api-authentication-with-oauth/67875>\
**Category:** Ask for Help\
**Tags:** api\
**Created:** [November 16, 2023, 6:48pm UTC](https://community.glideapps.com/t/call-api-authentication-with-oauth/67875 "2023-11-16T18:48:10Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Nate\_H](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/nate_h/32/44900_2.png) [@Nate\_H](https://community.glideapps.com/u/Nate_H)\
**Post date:** [November 21, 2023, 7:45pm UTC](https://community.glideapps.com/t/call-api-authentication-with-oauth/67875/6 "2023-11-21T19:45:45Z")

</div>

I got this working and wanted to document here for anyone who might stumble across this later. I was able to generate and correctly sign an OAuth 1.0 header using a combination of templates, encode text, and JavaScript.

Major caveat, this is not secure. I understand that Glide executes Javascript locally and my code contains the private consumer and token secrets. I am comfortable with this for my use case as this is internal only and I have taken mitigating steps within the endpoint application.

After gathering keys, URLs, etc., into a helper table I created all the components of the OAuth 1.0 header and base string using template columns.

- Format Date column to get a Unix timestamp
- Javascript code to create the random nonce value.
- Encode text to encode all the strings, values and URLs to percent-encoding

The signing was the missing piece - found this code snippet in this [thread](https://community.glideapps.com/t/getting-a-error-when-trying-to-add-my-rep-in-experimental-code-column/65714/42) after trying a bunch of other things that didn’t work for various reasons.

> [@Getting a error when trying to add my rep in experimental code column](https://community.glideapps.com/t/getting-a-error-when-trying-to-add-my-rep-in-experimental-code-column/65714/44):
>
> ```auto
> const CryptoJS = await import('https://cdn.skypack.dev/crypto-js');
> 
> const message = 'hello';
> const secretKey = 'secret';
> 
> const hmac = CryptoJS.HmacSHA1(message, secretKey);
> 
> const hashHex = CryptoJS.enc.Hex.stringify(hmac);
> 
> return hashHex;
> 
> ```

There was a LOT of trial and error to finally get this to work, but it’s up and running now! Thanks @Rev for taking the time and pointing me in a direction which ultimately led to this solution.

I would love to see support for OAuth 1.0 and 2.0 in the Call API action - I think there would be a ton of value there.

---

_[View the full topic](https://community.glideapps.com/t/call-api-authentication-with-oauth/67875)._
