# Hash generation using SecureToken version 2

**URL:** <https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011>\
**Category:** Wowza Streaming Engine\
**Created:** [September 29, 2014, 3:43pm UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011 "2014-09-29T15:43:02Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Regulus\_Paredes](https://avatars.discourse-cdn.com/v4/letter/r/57b2e6/32.png) [@Regulus\_Paredes](https://community.wowza.com/u/Regulus_Paredes)\
**Post date:** [September 29, 2014, 3:43pm UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/1 "2014-09-29T15:43:02Z")

</div>

Hi to all,

I just want to ask how to generate the securetoken hash on the [https://www.wowza.com/docs/how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine](https://www.wowza.com/docs/how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine) documentation (How to protect streaming using SecureToken in Wowza Streaming Engine) specifically the following:

“Important: The client web server should generate the hash when it generates the client webpage. You shouldn’t use JavaScript code in the client webpage to generate the hash as the code is visible in the webpage source and would pose a potential security risk.”

Can anyone provide a **sample code** on how to do this?

I would like also ask how did you arrive on the wowzatokenhash=m20I4XSU1Emt zHmz8PbbRsX5OcVi7Km-qI1J3acEV-c= on the RTSP example below?

From the string “vod/_myInstance_/sample.mp4?wowzatokenCustomParameter=abcdef&wowzatokenendtime=1500000000&xyzSharedSecret” , what operations are done to arrive at the wowzatokenhash=m20I4XSU1Emt zHmz8PbbRsX5OcVi7Km-qI1J3acEV-c= ?

RTSP example

This example is based on an RTSP VOD request where the application instance is specified in the URL. The default query parameter prefix (wowzatoken) is used, a custom public query parameter is included in the hash generation, and the SecureToken end time is specified. The client IP address isn’t included in the hash generation and the the SecureToken start time isn’t specified (SecureToken playback security is enabled immediately).

Content URL: rtsp://192.168.1.1:1935/vod/sample.mp4

Content path: vod/_myInstance_/sample.mp4

Custom SecureToken public query parameter: wowzatokenCustomParameter=myValue

Token end time: wowzatokenendtime=1500000000

The parameters used to create the string used for hashing (not in alphabetical order):

wowzatokenendtime=1500000000

wowzatokenCustomParameter=abcdef

xyzSharedSecret

String used for hashing (in required alphabetical order):

vod/_myInstance_/sample.mp4?wowzatokenCustomParameter=abcdef&wowzatokenendtime=1500000000&xyzSharedSecret

RTSP URL sent to server:

rtsp://10.0.2.31:1935/vod/_myInstance_/sample.mp4?wowzatokenendtime=1500000000&wowzatokenCustomParameter=abcdef&wowzatokenhash=m20I4XSU1Emt zHmz8PbbRsX5OcVi7Km-qI1J3acEV-c=

Thanks a lot for the help.

Regulus

---

<div class="post-metadata">

**Author:** ![Zoran](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/zoran/32/385_2.png) [@Zoran](https://community.wowza.com/u/Zoran)\
**Post date:** [September 30, 2014, 10:23pm UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/2 "2014-09-30T22:23:32Z")

</div>

Hi,

You will also need to use the wowzatokenstarttime parameter when generating the hash string. This parameter is mandatory.

In your particular case, you should use the following string for generating the hash key:

vod/_myInstance_/sample.mp4?wowzatokenCustomParameter=abcdef&wowzatokenendtime=1500000000&wowzatokenstarttime=1412108004&xyzSharedSecret

Regards,

Zoran

---

<div class="post-metadata">

**Author:** ![Lisa\_Wong](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@Lisa\_Wong](https://community.wowza.com/u/Lisa_Wong)\
**Post date:** [January 5, 2015, 10:36am UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/3 "2015-01-05T10:36:08Z")

</div>

The **starttime** and **endtime** parameters are optional.

Note that if no **starttime** is specified, the Streaming Engine will start as soon as the request is received. If no **endtime** is specified, then the token does not expire. For the majority of workflows, you will want to specify an endtime, otherwise your content is not protected by the SecureToken as you’d expect. However, there are customers who have a use case where they want a non-expiring **endtime** and so it is not a required field.

I will request an update to the Support article [How to protect streaming using SecureToken in Wowza Streaming Engine](https://www.wowza.com/docs/how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine#hash). Thank you for the feedback.

-Lisa

---

<div class="post-metadata">

**Author:** ![Gerome\_Bruneau](https://avatars.discourse-cdn.com/v4/letter/g/53a042/32.png) [@Gerome\_Bruneau](https://community.wowza.com/u/Gerome_Bruneau)\
**Post date:** [December 18, 2014, 10:03am UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/4 "2014-12-18T10:03:39Z")

</div>

> Hey!
> 
> We got success HASH
> 
> Do not belive support. :'-((((((((
> 
> All parameters are mandatory
> 
> So we have Shared Secret:c7800e7e5afc8c0b
> 
> I take Zoran code and put there my string like this
> 
> {code}
> 
> $hashstr = hash(‘sha256’, ‘live/_definst_/test.stream?c7800e7e5afc8c0b&wowzatokenendtime=0&wowzatokenstarttime=0’, true); # IMPORTANT to set third parameter equals to TRUE
> 
> $usableHash= strtr(base64\_encode($hashstr), ‘+/’, ‘-\_’);
> 
> echo $usableHash;
> 
> {code}
> 
> result was: cfGUWrQ-PONy6fhWSR9cyEtnXYpAQeJqrBsES\_jzqJw=
> 
> You have to get result and put it to rtmp URL like this one:
> 
> rtmp://{skipped\_IP}:1935/live/_definst_/test.stream?wowzatokenendtime=0&wowzatokenstarttime=0&wowzatokenhash=cfGUWrQ-PONy6fhWSR9cyEtnXYpAQeJqrBsES\_jzqJw=
> 
> ATTENTION!!!
> 
> wowzatokenendtime=0&wowzatokenstarttime=0 They are not OPTIONAL

Since yesterday I was sticking to the support note instructions and couldn’t figure why the SecureToken wasn’t working properly.

I followed your instructions and managed to hash !

[The support note _How to protect streaming using SecureToken in Wowza Streaming Engine_](https://www.wowza.com/docs/how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine#hash) should be updated by the Wowza team…

Akavjik, thanks for your advices.

---

<div class="post-metadata">

**Author:** ![Zoran](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/zoran/32/385_2.png) [@Zoran](https://community.wowza.com/u/Zoran)\
**Post date:** [October 8, 2014, 11:02pm UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/5 "2014-10-08T23:02:43Z")

</div>

Dave,

You are correct. I take that back 🙂

The starttime and endtime parameters are optional.

The input parameters for the hash calculation are not dependant on the type of streaming protocol you are using. Whether the protocol is RTMP, RTSP or HTTP based, the stream name, secret key and/or endtime, starttime are not changed.

Also, to generate the correct hash key to be used in the playback URL, don’t forget to Base64 encode the hash key resulted form the PHP code Dave mentioned:

```auto
$hashstr = hash('sha256', 'vod/_myInstance_/sample.mp4?wowzatokenCustomParameter=abcdef&wowzatokenendtime=1500000000&xyzSharedSecret', true);
$usableHash= strtr(base64_encode($hashstr), '+/', '-_');

```

Zoran

---

<div class="post-metadata">

**Author:** ![David\_Haddon](https://avatars.discourse-cdn.com/v4/letter/d/ed8c4c/32.png) [@David\_Haddon](https://community.wowza.com/u/David_Haddon)\
**Post date:** [October 8, 2014, 12:51pm UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/6 "2014-10-08T12:51:38Z")

</div>

Regulus,

In php, you should be able to create the hash using:

```auto
$hashstr = hash('sha256','vod/_myInstance_/sample.mp4?wowzatokenCustomParameter=abcdef&wowzatokenendtime=1500000000&xyzSharedSecret');

```

Zoran,

> You will also need to use the wowzatokenstarttime parameter when generating the hash string. This parameter is mandatory.
> 
> This is contradictory to the information on [https://www.wowza.com/docs/how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine#parameters](https://www.wowza.com/docs/how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine#parameters) where it says that the starttime is optional.
> 
> Also, do the shown examples use real hash values? I suspect not as the calculated Hash vaules are the same for both RTSP and Smooth examples, even though the input hash parameters are different.

---

<div class="post-metadata">

**Author:** ![David\_Haddon](https://avatars.discourse-cdn.com/v4/letter/d/ed8c4c/32.png) [@David\_Haddon](https://community.wowza.com/u/David_Haddon)\
**Post date:** [October 23, 2014, 10:49am UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/7 "2014-10-23T10:49:02Z")

</div>

Zoran, yes, the [+/] to [-\_] swap is important!! I had missed that bit.

Just for the next person looking for this, in actionScript (AS3)

```auto
import com.adobe.crypto.SHA256;
var hash:String = SHA256.hashToBase64(hashstring);
var regExp1:RegExp = /\+/g;
var regExp2:RegExp = /\//g;
				
hash=hash.replace(regExp1,'-');
usablehash=hash.replace(regExp2,'_');

```

---

<div class="post-metadata">

**Author:** ![Tim\_Tsai](https://avatars.discourse-cdn.com/v4/letter/t/8edcca/32.png) [@Tim\_Tsai](https://community.wowza.com/u/Tim_Tsai)\
**Post date:** [November 23, 2014, 11:33pm UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/8 "2014-11-23T23:33:38Z")

</div>

Is there a code for c#?

---

<div class="post-metadata">

**Author:** ![Lee\_Wickham](https://avatars.discourse-cdn.com/v4/letter/l/e495f1/32.png) [@Lee\_Wickham](https://community.wowza.com/u/Lee_Wickham)\
**Post date:** [January 7, 2015, 2:38am UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/9 "2015-01-07T02:38:23Z")

</div>

> I will request an update to the Support article [How to protect streaming using SecureToken in Wowza Streaming Engine](https://www.wowza.com/docs/how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine#hash). Thank you for the feedback.
> 
> -Lisa

If I could add its generally very handy to have code examples along with thease types of guides.

e.g

php

asp (classic)

> **[ASP.NET Core | Open-source web framework for .NET](https://dotnet.microsoft.com/en-us/apps/aspnet)**
>
> Build web apps and services that run on Windows, Linux, and macOS using C#, HTML, CSS, and JavaScript. Get started for free on Windows, Linux, or macOS.

that way you will get a lot less support/tutorial requests about how to do this.

---

<div class="post-metadata">

**Author:** ![Eugene\_Borysenko](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@Eugene\_Borysenko](https://community.wowza.com/u/Eugene_Borysenko)\
**Post date:** [December 17, 2014, 5:30pm UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/10 "2014-12-17T17:30:28Z")

</div>

Hey!

We got success HASH

Do not belive support. :’-((((((((

All parameters are mandatory

So we have Shared Secret:c7800e7e5afc8c0b

I take Zoran code and put there my string like this

{code}

$hashstr = hash(‘sha256’, ‘live/_definst_/test.stream?c7800e7e5afc8c0b&wowzatokenendtime=0&wowzatokenstarttime=0’, true); # IMPORTANT to set third parameter equals to TRUE

$usableHash= strtr(base64\_encode($hashstr), ‘+/’, ‘-\_’);

echo $usableHash;

{code}

result was: cfGUWrQ-PONy6fhWSR9cyEtnXYpAQeJqrBsES\_jzqJw=

You have to get result and put it to rtmp URL like this one:

rtmp://{skipped\_IP}:1935/live/_definst_/test.stream?wowzatokenendtime=0&wowzatokenstarttime=0&wowzatokenhash=cfGUWrQ-PONy6fhWSR9cyEtnXYpAQeJqrBsES\_jzqJw=

ATTENTION!!!

wowzatokenendtime=0&wowzatokenstarttime=0 They are not OPTIONAL

---

<div class="post-metadata">

**Author:** ![GukChan\_Jeon](https://avatars.discourse-cdn.com/v4/letter/g/977dab/32.png) [@GukChan\_Jeon](https://community.wowza.com/u/GukChan_Jeon)\
**Post date:** [January 27, 2015, 5:43pm UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/11 "2015-01-27T17:43:29Z")

</div>

> Hey!
> 
> We got success HASH
> 
> Do not belive support. :'-((((((((
> 
> All parameters are mandatory
> 
> So we have Shared Secret:c7800e7e5afc8c0b ← If you see the Shared Secret code on a web page
> 
> There are security issues. How to import a query?
> 
> I take Zoran code and put there my string like this
> 
> {code}
> 
> $hashstr = hash(‘sha256’, ‘live/_definst_/test.stream?c7800e7e5afc8c0b&wowzatokenendtime=0&wowzatokenstarttime=0’, true); # IMPORTANT to set third parameter equals to TRUE
> 
> $usableHash= strtr(base64\_encode($hashstr), ‘+/’, ‘-\_’);
> 
> echo $usableHash;
> 
> {code}
> 
> result was: cfGUWrQ-PONy6fhWSR9cyEtnXYpAQeJqrBsES\_jzqJw=
> 
> You have to get result and put it to rtmp URL like this one:
> 
> rtmp://{skipped\_IP}:1935/live/_definst_/test.stream?wowzatokenendtime=0&wowzatokenstarttime=0&wowzatokenhash=cfGUWrQ-PONy6fhWSR9cyEtnXYpAQeJqrBsES\_jzqJw=
> 
> ATTENTION!!!
> 
> wowzatokenendtime=0&wowzatokenstarttime=0 They are not OPTIONAL

—\> As above may not apply to run properly.Wowza party was set base64 (sha256).

Why not?

---

<div class="post-metadata">

**Author:** ![GukChan\_Jeon](https://avatars.discourse-cdn.com/v4/letter/g/977dab/32.png) [@GukChan\_Jeon](https://community.wowza.com/u/GukChan_Jeon)\
**Post date:** [January 29, 2015, 11:48am UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/12 "2015-01-29T11:48:30Z")

</div>

> Hey!
> 
> We got success HASH
> 
> Do not belive support. :'-((((((((
> 
> All parameters are mandatory
> 
> So we have Shared Secret:c7800e7e5afc8c0b
> 
> I take Zoran code and put there my string like this
> 
> {code}
> 
> $hashstr = hash(‘sha256’, ‘live/_definst_/test.stream?c7800e7e5afc8c0b&wowzatokenendtime=0&wowzatokenstarttime=0’, true); # IMPORTANT to set third parameter equals to TRUE
> 
> $usableHash= strtr(base64\_encode($hashstr), ‘+/’, ‘-\_’);
> 
> echo $usableHash;
> 
> {code}
> 
> result was: cfGUWrQ-PONy6fhWSR9cyEtnXYpAQeJqrBsES\_jzqJw=
> 
> You have to get result and put it to rtmp URL like this one:
> 
> rtmp://{skipped\_IP}:1935/live/_definst_/test.stream?wowzatokenendtime=0&wowzatokenstarttime=0&wowzatokenhash=cfGUWrQ-PONy6fhWSR9cyEtnXYpAQeJqrBsES\_jzqJw=
> 
> ATTENTION!!!
> 
> wowzatokenendtime=0&wowzatokenstarttime=0 They are not OPTIONAL

rtmp vod example?

“rtmp://x.x.x.x:1935/VOD/mp4:2014/sample.mp4?wowzatokenendtime=xxxxxxxxxxx&wowzatokenhash=xxxxxxxxxxx=&wowzatokenstarttime=0&wowzaplaystart=100000&wowzaplayduration=181000”

- VOD/_definst_/mp4:/2014/sample.mp4? : hash value not matched…

- VOD/mp4:/2014/sample.mp4? : hash value not matched…

- VOD/mp4:2014/sample.mp4? : hash value not matched…

how to regular expression?

---

<div class="post-metadata">

**Author:** ![GukChan\_Jeon](https://avatars.discourse-cdn.com/v4/letter/g/977dab/32.png) [@GukChan\_Jeon](https://community.wowza.com/u/GukChan_Jeon)\
**Post date:** [February 3, 2015, 3:59pm UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/13 "2015-02-03T15:59:17Z")

</div>

> Zoran, yes, the [+/] to [-\_] swap is important!! I had missed that bit.
> 
> Just for the next person looking for this, in actionScript (AS3)
> 
> ```auto
> import com.adobe.crypto.SHA256;
> var hash:String = SHA256.hashToBase64(hashstring);
> var regExp1:RegExp = /\+/g;
> var regExp2:RegExp = /\//g;
> 				
> hash=hash.replace(regExp1,'-');
> usablehash=hash.replace(regExp2,'_');
> 
> ```

When you create a hash on the web page source is shown security is vulnerable

The other way is to make sure what hash?

Can not created on the server-side to create a web page url again?

Or Is there any way to get the wowza directly query the shared secret?

Please help me…

---

<div class="post-metadata">

**Author:** ![Goran\_Iliev](https://avatars.discourse-cdn.com/v4/letter/g/b5a626/32.png) [@Goran\_Iliev](https://community.wowza.com/u/Goran_Iliev)\
**Post date:** [November 30, 2023, 11:41am UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/14 "2023-11-30T11:41:18Z")

</div>

Can someone that understands how this should be configured (either on wowza streaming engine and on client) do a demonstration and share the link to the video (YouTube?) Unfortunaltey I dont get how to generate the sha256 hash from the client.

---

<div class="post-metadata">

**Author:** ![Dorota\_Szafer-Kwasik](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/dorota_szafer-kwasik/32/1150_2.png) [@Dorota\_Szafer-Kwasik](https://community.wowza.com/u/Dorota_Szafer-Kwasik)\
**Post date:** [December 2, 2023, 10:20am UTC](https://community.wowza.com/t/hash-generation-using-securetoken-version-2/44011/15 "2023-12-02T10:20:28Z")

</div>

maybe… search… and ‘everything has already been done’  
[http://community.wowza.com/t/securetoken-between-client-server/46955/2](http://community.wowza.com/t/securetoken-between-client-server/46955/2)
