# SecureToken - Custom parameters how to

**URL:** <https://community.wowza.com/t/securetoken-custom-parameters-how-to/55167>\
**Category:** Wowza Streaming Engine\
**Created:** [May 13, 2020, 11:50am UTC](https://community.wowza.com/t/securetoken-custom-parameters-how-to/55167 "2020-05-13T11:50:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dorota\_Szafer-Kwasik](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/dorota_szafer-kwasik/32/1150_2.png) [@Dorota\_Szafer-Kwasik](https://community.wowza.com/u/Dorota_Szafer-Kwasik)\
**Post date:** [May 13, 2020, 11:50am UTC](https://community.wowza.com/t/securetoken-custom-parameters-how-to/55167/1 "2020-05-13T11:50:02Z")

</div>

I find this: “You can add a unique customer-specific hash parameter to ensure that a unique SecureToken hash is generated per customer”. [link](https://www.wowza.com/docs/how-to-protect-streaming-using-securetoken-in-wowza-streaming-engine#Custom-parameters) Does anyone have ready in PHP? What do I need to do to add this parameter? Thanks

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [May 13, 2020, 3:54pm UTC](https://community.wowza.com/t/securetoken-custom-parameters-how-to/55167/2 "2020-05-13T15:54:24Z")

</div>

That is the sample we share to be able to generate the correct security token hash using the example PHP code. If you have an issue, please submit a support ticket and we’ll take a look why it didn’t work. Hopefully it works though!

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [May 13, 2020, 3:51pm UTC](https://community.wowza.com/t/securetoken-custom-parameters-how-to/55167/3 "2020-05-13T15:51:36Z")

</div>

```auto

```

**\<?php**

_/\*_

_\* Modify the following variables as needed_

_\*/_

_/\*_

_$clientIP = null; // provide client IP optionally_

_// $clientIP = $\_SERVER[‘REMOTE\_ADDR’];_

_$host = “[REPLACE-WITH-HOST-IP]”; // your ip/host_

_$url= “http://”.$host.":1935/";_

_$stream = “[replace-with-app-name]/[replace-with-stream-name]”; // your stream_

_$start = time();_

_$end = strtotime("+30 minutes"); //time() + $validity;_

_$secret = “[replace-with-secret]”; // your secret_

_$tokenName = “[replace-with-token-name]”;_

_\*/_

$clientIP = null; _// provide client IP optionally_

_// $clientIP = $\_SERVER[‘REMOTE\_ADDR’];_

$host = “[yourserver.com](http://yourserver.com)”; _// your ip/host_

$url= “http://” **.** $host\*\*.\*\*":1935/";

$stream = “live/myStream”; _// your stream_

$start = time();

$validity = 1000; _// validity in seconds_

$end = time() + $validity;

$secret = “coolSecret”; _// your secret_

$tokenName = “wowzatoken”;

$params = **array** ("{$tokenName}starttime=" **.** $start, “{$tokenName}endtime=” **.** $end, $secret);

**if** (!is\_null($clientIP)){

$params[] = $clientIP;

}

sort($params);

$string4Hashing = $stream\*\*.\*\*"?";

**foreach** ($params **as** $entry){

$string4Hashing **.** = $entry\*\*.\*\*"&";

}

$string4Hashing = preg\_replace("/(&)$/","", $string4Hashing);

$hash = hash(‘sha256’, $string4Hashing, true); _// generate the hash string_

**echo** $string4Hashing;

**echo** “  
”;

$base64Hash = strtr(base64\_encode($hash), ‘+/’, ‘-\_’); _// Base64 encode the hashed string_

$playbackURL = $url\*\*. **$stream**. **"/playlist.m3u8?"**. **$tokenName**. **“starttime=”**. **$start**. **"&"**. **$tokenName**. **“endtime=”**. **$end**. **"&"**. **$tokenName**. **“hash=”**.\*\*$base64Hash;

**echo** $base64Hash;

**echo** “  
”;

**echo** $playbackURL;

**echo** “  
”;

**?\>**

---

<div class="post-metadata">

**Author:** ![Dorota\_Szafer-Kwasik](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/dorota_szafer-kwasik/32/1150_2.png) [@Dorota\_Szafer-Kwasik](https://community.wowza.com/u/Dorota_Szafer-Kwasik)\
**Post date:** [May 13, 2020, 4:50pm UTC](https://community.wowza.com/t/securetoken-custom-parameters-how-to/55167/4 "2020-05-13T16:50:08Z")

</div>

ok… I know it

first:

when I determine this:

$ clientIP = null;

it works.

when I determine this:

$ clientIP = $ \_SERVER [‘REMOTE\_ADDR’];

…did not work…

Secondly:

the information I found is about Custom Parameters:

“You can add a unique customer-specific hash parameter to ensure that a unique SecureToken hash is generated per customer”

What do I have to do to generate a token for a specific IP of the viewer? Is it possible?

Copying the stream address and running it on another computer under VLC is possible. Is there a way to prevent direct stream playback without a browser?

Thank you.

---

<div class="post-metadata">

**Author:** ![Rose\_Power-Wowza\_Com](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/rose_power-wowza_com/32/431_2.png) [@Rose\_Power-Wowza\_Com](https://community.wowza.com/u/Rose_Power-Wowza_Com)\
**Post date:** [May 13, 2020, 6:12pm UTC](https://community.wowza.com/t/securetoken-custom-parameters-how-to/55167/5 "2020-05-13T18:12:00Z")

</div>

The IP of the viewer is the same as the clientIP, so for the one you said was working, you’re good to go.

You just have to be able to populate this variable correctly; You need to figure out how to obtain this via php. I don’t have info here in our docs on how to get that, but I guess there is a lot of info online according to the engineers. Feel free to [submit a support ticket](https://www.wowza.com/support/open-ticket) if you’d like an engineer to work directly with you on this.
