# Simple user authentication demo with Wrench

**URL:** <https://community.wowza.com/t/simple-user-authentication-demo-with-wrench/42719>\
**Category:** Wowza Developer Dojo\
**Created:** [December 2, 2014, 9:39pm UTC](https://community.wowza.com/t/simple-user-authentication-demo-with-wrench/42719 "2014-12-02T21:39:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![system](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/system/32/447_2.png) [@system](https://community.wowza.com/u/system)\
**Post date:** [December 2, 2014, 9:39pm UTC](https://community.wowza.com/t/simple-user-authentication-demo-with-wrench/42719/1 "2014-12-02T21:39:12Z")

</div>

Hi,

I have this product called [Wrench](https://streamtoolbox.com/wrench) which generally addresses numerous system integration cases between Wowza and the surrounding system, let that be an online streaming site with paid events/minutes, or simply stream user encoder authentication and authorization. I am focusing now on making easier to understand how to set up and use this product, so created a [dedicated GitHub page](http://github.com/jantekb/streamtoolbox-examples) with downloadable examples and related YouTube videos that showcase the examples.

I am ready with the first example pack and video and wanted to share this here with anyone interested.

Regards,

wtb

[video=youtube;vDln3bqVmIk][https://www.youtube.com/watch?v=vDln3bqVmIk[/video]](https://www.youtube.com/watch?v=vDln3bqVmIk%5B/video%5D)

---

<div class="post-metadata">

**Author:** ![system](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/system/32/447_2.png) [@system](https://community.wowza.com/u/system)\
**Post date:** [February 14, 2015, 9:28pm UTC](https://community.wowza.com/t/simple-user-authentication-demo-with-wrench/42719/2 "2015-02-14T21:28:05Z")

</div>

The latest version (2015.02.14) of Wrench now comes with a new feature which allows you to hook on external [webservice to perform authentication or authorization](https://streamtoolbox.com/webservice-authentication-authorization) on your stream players.

The way it works is that Wrench resolves the token parsed from the URL to a valid username (or if you don’t want this, it assumes anonymous as username), and then reaches out via HTTP POST to your webservice to make the decision. You’ll get a JSON message like this:

```auto
{"streamName": "mystream", "userName":"john", "token":"54ddec75e2294", "applicationName":"live", "applicationInstance":"_definst_"}

```

And you can respond with

```auto
{"result": "allow/deny"}

```

, and your service written in your favourite language is making the decision.

The takeaway message is that you can get **full control** over who can watch which stream in which application, etc. [Click here](https://streamtoolbox.com/webservice-authentication-authorization) to find out the details.

Regards,

wtb
