# SecureToken Generation not accepting generated urls

**URL:** <https://community.wowza.com/t/securetoken-generation-not-accepting-generated-urls/97395>\
**Category:** Wowza Streaming Engine\
**Created:** [July 14, 2024, 11:49pm UTC](https://community.wowza.com/t/securetoken-generation-not-accepting-generated-urls/97395 "2024-07-14T23:49:04Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Daniel\_Rossi1](https://avatars.discourse-cdn.com/v4/letter/d/35a633/32.png) [@Daniel\_Rossi1](https://community.wowza.com/u/Daniel_Rossi1)\
**Post date:** [July 14, 2024, 11:49pm UTC](https://community.wowza.com/t/securetoken-generation-not-accepting-generated-urls/97395/1 "2024-07-14T23:49:04Z")

</div>

I’m trying to generate tokens. I wish it was simple like PEM certificate JWT tokens which is more secure than salt secret key based tokens.

My helper method looks like this so far

```
public static function generateWowzaToken(string $streamName, string $clientIP, int $expiry) {

    $wowzaContentPath = self::getContentPath($streamName);

    $wowzaSecureToken = config('video.wowzaTokenSecret');
    $wowzaTokenPrefix = config('video.wowzaTokenPrefix');
    $wowzaLiveApp = config('video.wowzaLiveApp');
    //$wowzaContentPath = $wowzaLiveApp."/".$streamName."/".$streamName;
    $wowzaSecureTokenStartTime = $wowzaTokenPrefix ."starttime=". time() ;
    $wowzaSecureTokenEndTime = $wowzaTokenPrefix ."endtime=". (time() + $expiry );
    $hashstr = $wowzaContentPath ."?". $clientIP ."&".$wowzaSecureToken ."&". $wowzaSecureTokenEndTime ."&". $wowzaSecureTokenStartTime;

    $hash = hash(config('video.wowzaHashAlgorithm'), $hashstr , true);

    $usableHash=strtr(base64_encode($hash), '+/', '-_');
    return $wowzaSecureTokenEndTime."&".$wowzaSecureTokenStartTime."&".$wowzaTokenPrefix ."hash=$usableHash";
    //$url = $wowzaContentURL ."?". $wowzaTokenPrefix ."=$usableHash";
}

```

And generates urls like

/live/livestream/livestream/playlist.m3u8?tendtime=1720999771&tstarttime=1720999471&thash=jY-nlnk-JEPsN7b-ASArtkdRvKUj6\_ggIVwtcVd21VY73v9f9FxLpM9R4VNKAovCnGHuoQslF6gQktkp5xSysw==

Wowza isn’t accepting the connection and all I get is a log like this without an indication what the problem is

HTTPStreamerAdapterCupertinoStreamer.onPlaylist[live/livestream/livestream/playlist.m3u8?tendtime=1720999771&tstarttime=1720999471&thash=jY-nlnk-JEPsN7b-ASArtkdRvKUj6\_ggIVwtcVd21VY73v9f9FxLpM9R4VNKAovCnGHuoQslF6gQktkp5xSysw==]: Session not accepted[1788740773]

My test token server config looks like

 ![Screenshot 2024-07-15 094720](https://us1.discourse-cdn.com/flex002/uploads/wowza1/original/2X/7/7353b7d16184cffb6ce3b28e1128f3b347cccec3.png)

---

<div class="post-metadata">

**Author:** ![Scott\_Kellicker2](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/scott_kellicker2/32/1337_2.png) [@Scott\_Kellicker2](https://community.wowza.com/u/Scott_Kellicker2)\
**Post date:** [July 15, 2024, 4:00pm UTC](https://community.wowza.com/t/securetoken-generation-not-accepting-generated-urls/97395/2 "2024-07-15T16:00:15Z")

</div>

There are some Application level properties that might give you more info. All boolean. Set them to true

securityDebugLogRejections  
securityDebugLogDetails

Also my remembrance of Secure Token is the tokens need to be starttime, endtime, etc. You seem to be using different URL params

ScottK  
Streaming Video Consultant  
scott@blankcanvas.video

---

<div class="post-metadata">

**Author:** ![Daniel\_Rossi1](https://avatars.discourse-cdn.com/v4/letter/d/35a633/32.png) [@Daniel\_Rossi1](https://community.wowza.com/u/Daniel_Rossi1)\
**Post date:** [July 15, 2024, 5:21pm UTC](https://community.wowza.com/t/securetoken-generation-not-accepting-generated-urls/97395/3 "2024-07-15T17:21:42Z")

</div>

Its really bonkers and confusing. Its alphabetical order therefore endtime then starttime. Many code examples do the same. A test tool to generate tokens might have been helpful. Ill try those log configs thanks.

---

<div class="post-metadata">

**Author:** ![Scott\_Kellicker2](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/scott_kellicker2/32/1337_2.png) [@Scott\_Kellicker2](https://community.wowza.com/u/Scott_Kellicker2)\
**Post date:** [July 15, 2024, 5:29pm UTC](https://community.wowza.com/t/securetoken-generation-not-accepting-generated-urls/97395/4 "2024-07-15T17:29:16Z")

</div>

I don’t think the order matters but looks like you have different named params. (tstarttime versus and starttime)

---

<div class="post-metadata">

**Author:** ![Daniel\_Rossi1](https://avatars.discourse-cdn.com/v4/letter/d/35a633/32.png) [@Daniel\_Rossi1](https://community.wowza.com/u/Daniel_Rossi1)\
**Post date:** [July 15, 2024, 5:44pm UTC](https://community.wowza.com/t/securetoken-generation-not-accepting-generated-urls/97395/5 "2024-07-15T17:44:28Z")

</div>

It gives me this. The hash created is different but not explaining what its using for hashing  
[live/livestream]ModuleCoreSecurity:hashCalculated: HK\_0tcXAcK41K-26OLgAP-

hashed: live/livestream/livestream?127.0.0.1&QD916610KDolfi4nafEiUdOhAiPG2vfVGEOPFpLGWPVSMZPB&tendtime=0&tstarttime=0

[live/livestream]SecureTokenDef:Hash o9YEfaZhWbYWHb-hbSpXvvvUdG8jWm9lACrLwxNq62IQxJ1HPADcBoC27z5X7rff-qFo9M9RhldYi8fqt\_ojvQ==, doesn’t match hash calculated, HK\_0tcXAcK41K-26OLgAP-E3TpjpfLATYHpn0jvC2\_USyHZwL6daJm9oagauh\_mUdneEB4dtlJJ2dfIzn5S0bw==

---

<div class="post-metadata">

**Author:** ![Daniel\_Rossi1](https://avatars.discourse-cdn.com/v4/letter/d/35a633/32.png) [@Daniel\_Rossi1](https://community.wowza.com/u/Daniel_Rossi1)\
**Post date:** [July 15, 2024, 5:55pm UTC](https://community.wowza.com/t/securetoken-generation-not-accepting-generated-urls/97395/6 "2024-07-15T17:55:02Z")

</div>

tstarttime is the token prefix of t and starttime. That is also what it’s hashing. My side is the same hashing path.

live/livestream/livestream?127.0.0.1&QD916610KDolfi4nafEiUdOhAiPG2vfVGEOPFpLGWPVSMZPB&tendtime=0&tstarttime=0

---

<div class="post-metadata">

**Author:** ![Daniel\_Rossi1](https://avatars.discourse-cdn.com/v4/letter/d/35a633/32.png) [@Daniel\_Rossi1](https://community.wowza.com/u/Daniel_Rossi1)\
**Post date:** [July 15, 2024, 5:58pm UTC](https://community.wowza.com/t/securetoken-generation-not-accepting-generated-urls/97395/7 "2024-07-15T17:58:34Z")

</div>

never mind. Im sorry. The content path wasnt being generated for the hash due to not returning it ! it looks like this now

live/livestream/livestream?127.0.0.1&QD916610KDolfi4nafEiUdOhAiPG2vfVGEOPFpLGWPVSMZPB&tendtime=0&tstarttime=0sha512

```
class Helper
{
public static function generateWowzaToken(string $streamName, string $clientIP, int $expiry) {

    $wowzaContentPath = self::getContentPath($streamName);

    $wowzaSecureToken = config('video.wowzaTokenSecret');
    $wowzaTokenPrefix = config('video.wowzaTokenPrefix');
    $wowzaLiveApp = config('video.wowzaLiveApp');
    //$wowzaContentPath = $wowzaLiveApp."/".$streamName."/".$streamName;
    //$wowzaSecureTokenStartTime = $wowzaTokenPrefix ."starttime=". time() ;
    //$wowzaSecureTokenEndTime = $wowzaTokenPrefix ."endtime=". (time() + $expiry );
    $wowzaSecureTokenStartTime = $wowzaTokenPrefix ."starttime=0";
    $wowzaSecureTokenEndTime = $wowzaTokenPrefix ."endtime=0";
    $hashstr = $wowzaContentPath ."?". $clientIP ."&".$wowzaSecureToken ."&". $wowzaSecureTokenEndTime ."&". $wowzaSecureTokenStartTime;
    //$hashstr = $wowzaContentPath ."?". $clientIP ."&".$wowzaSecureToken ."&". $wowzaSecureTokenStartTime ."&". $wowzaSecureTokenEndTime;

    print($hashstr);
    print(config('video.wowzaHashAlgorithm'));
    $hash = hash(config('video.wowzaHashAlgorithm'), $hashstr , true);

    $usableHash=strtr(base64_encode($hash), '+/', '-_');
    return $wowzaSecureTokenEndTime."&".$wowzaSecureTokenStartTime."&".$wowzaTokenPrefix ."hash=$usableHash";
    //$url = $wowzaContentURL ."?". $wowzaTokenPrefix ."=$usableHash";
}

public static function getContentPath(string $streamName) {
    return config('video.wowzaLiveApp').'/'.$streamName.'/'.$streamName;
}

```

}

---

<div class="post-metadata">

**Author:** ![Scott\_Kellicker2](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/scott_kellicker2/32/1337_2.png) [@Scott\_Kellicker2](https://community.wowza.com/u/Scott_Kellicker2)\
**Post date:** [July 15, 2024, 10:58pm UTC](https://community.wowza.com/t/securetoken-generation-not-accepting-generated-urls/97395/8 "2024-07-15T22:58:07Z")

</div>

Ah by mistake – forgot about that. The default is “wowzatoken” and you are using “t”
