# Token Authorization + RefererValidate

**URL:** <https://community.wowza.com/t/token-authorization-referervalidate/53792>\
**Category:** Wowza Video (Formerly Streaming Cloud)\
**Tags:** cdn\
**Created:** [August 12, 2019, 3:52pm UTC](https://community.wowza.com/t/token-authorization-referervalidate/53792 "2019-08-12T15:52:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Silencer](https://avatars.discourse-cdn.com/v4/letter/s/45deac/32.png) [@Silencer](https://community.wowza.com/u/Silencer)\
**Post date:** [August 12, 2019, 3:52pm UTC](https://community.wowza.com/t/token-authorization-referervalidate/53792/1 "2019-08-12T15:52:41Z")

</div>

Hi,

I currently use secure token v2 + RefererValidate to protect my stream that only work under my domain.

Now, I need CDN for one of my stream , I connect stream target to wowza cdn.

For secure token , I setup Token Authorization and Trusted Shared Secret.

I would like to know

1 : RefererValidate work with wowz CDN

2 : I use sample php code to generate “Generate query parameters”

, but nothing output. Is there a more simple hash generate code like secure token V2?

---

<div class="post-metadata">

**Author:** ![Silencer](https://avatars.discourse-cdn.com/v4/letter/s/45deac/32.png) [@Silencer](https://community.wowza.com/u/Silencer)\
**Post date:** [August 12, 2019, 3:52pm UTC](https://community.wowza.com/t/token-authorization-referervalidate/53792/2 "2019-08-12T15:52:34Z")

</div>

for secure token v2 , I used this code to generate hash

\<?php $wowzastart = '0'; $wowzaend = strtotime(date('d-m-Y H:i')) + 1800; $secret = 'mysecret'; $wowzatoken = 'tokenname'; $hashstr = hash('sha512', 'stream-path?'.$secret.'&'.$wowzatoken.'endtime='.$wowzaend.'&'.$wowzatoken.'starttime='.$wowzastart.'', true); $usableHash= strtr(base64\_encode($hashstr), '+/', '-\_'); echo "http://wowza-ip/stream-path/playlist.m3u8?".$wowzatoken."endtime=".$wowzaend."&".$wowzatoken."starttime=".$wowzastart."&".$wowzatoken."hash=".$usableHash.""; ?\>

hash will output and work well.

---

<div class="post-metadata">

**Author:** ![Silencer](https://avatars.discourse-cdn.com/v4/letter/s/45deac/32.png) [@Silencer](https://community.wowza.com/u/Silencer)\
**Post date:** [August 12, 2019, 1:23pm UTC](https://community.wowza.com/t/token-authorization-referervalidate/53792/3 "2019-08-12T13:23:06Z")

</div>

In wowza cloud **token Query Parameters,**

Download the source code  
(AkamaiToken.php - An Akamai EdgeAuth Token 2.0 implementation for PHP \* \* author: James Mutton [jmutton@akamai.com](mailto:jmutton@akamai.com))

add the require parameters , but nothing output.

---

<div class="post-metadata">

**Author:** ![Mac\_Hill](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/mac_hill/32/434_2.png) [@Mac\_Hill](https://community.wowza.com/u/Mac_Hill)\
**Post date:** [August 14, 2019, 2:04pm UTC](https://community.wowza.com/t/token-authorization-referervalidate/53792/4 "2019-08-14T14:04:00Z")

</div>

Hello @Silencer,

As you discovered, the Wowza Streaming Engine secure token will not work with the Wowza CDN. The Akamai CDN token auth handles all security playback requests.  
If you have additional questions, please [submit a support request](https://store.wowza.com/portal/help/cloud).

Regards,  
Mac
