# How to Do get Token with PHP to make app secure

**URL:** <https://openvidu.discourse.group/t/how-to-do-get-token-with-php-to-make-app-secure/876>\
**Category:** How to implement?\
**Tags:** v2\
**Created:** [May 20, 2020, 12:15pm UTC](https://openvidu.discourse.group/t/how-to-do-get-token-with-php-to-make-app-secure/876 "2020-05-20T12:15:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kamal](https://avatars.discourse-cdn.com/v4/letter/k/a698b9/32.png) [@kamal](https://openvidu.discourse.group/u/kamal)\
**Post date:** [May 20, 2020, 12:15pm UTC](https://openvidu.discourse.group/t/how-to-do-get-token-with-php-to-make-app-secure/876/1 "2020-05-20T12:15:32Z")

</div>

For those who use PHP below is a code for getting token in PHP using REST API using curl. I am not professional developer but may help someone.  
This code can be used as index.php in webcomponent demo.

 My first Secure APP 

```
<script src="app.js"></script>
<script src="openvidu-webcomponent-2.14.0.js"></script>
<link rel="stylesheet" href="openvidu-webcomponent-2.14.0.css">

```

\<?php define(OPENVIDU\_SERVER\_URL, "https://yourOpenViduServer"); define(OPENVIDU\_SERVER\_SECRET,"YOUR\_SECRET"); define(SESSEION\_NAME,"ROOM1"); if (createSession(SESSEION\_NAME)) { $token1= createToken(SESSEION\_NAME); $token2= createToken(SESSEION\_NAME);} function createSession($sessionName) { $url = OPENVIDU\_SERVER\_URL . '/api/sessions'; $BASE64AUTH= 'Basic ' . base64\_encode('OPENVIDUAPP:' . OPENVIDU\_SERVER\_SECRET); $headers = array('Authorization:' . $BASE64AUTH ,'Content-Type:application/json'); $data = '{ "customSessionId" : ' .'"' . $sessionName .'"'. ' , "recordingMode" : "ALWAYS" , "outputMode" : "INDIVIDUAL" }'; $ch = curl\_init(); curl\_setopt($ch, CURLOPT\_URL, $url); curl\_setopt($ch, CURLOPT\_HTTPHEADER, $headers); curl\_setopt($ch, CURLOPT\_RETURNTRANSFER, true); curl\_setopt($ch, CURLOPT\_POST, TRUE); curl\_setopt($ch, CURLOPT\_POSTFIELDS, $data); $result = curl\_exec($ch); if (!curl\_errno($ch)) { switch ($http\_code = curl\_getinfo($ch, CURLINFO\_HTTP\_CODE)) { case 200: # OK curl\_close($ch); return true; case 400: curl\_close; return false; case 409: # OK curl\_close; return true; //break; default: // echo 'Unexpected HTTP code: ', $http\_code, "\n"; curl\_close; return false; } } } function createToken($sessionName) { $url = OPENVIDU\_SERVER\_URL . '/api/tokens'; //echo ($url); $BASE64AUTH= 'Basic ' . base64\_encode('OPENVIDUAPP:' . OPENVIDU\_SERVER\_SECRET); $headers = array('Authorization:' . $BASE64AUTH ,'Content-Type:application/json'); $data = '{ "session" : ' .'"' . $sessionName .'"'. ' , "role" : "MODERATOR", "data" : "Userdata" }'; $ch = curl\_init(); curl\_setopt($ch, CURLOPT\_URL, $url); curl\_setopt($ch, CURLOPT\_HTTPHEADER, $headers); curl\_setopt($ch, CURLOPT\_RETURNTRANSFER, true); curl\_setopt($ch, CURLOPT\_POST, TRUE); //curl\_setopt($ch, CURLOPT\_CUSTOMREQUEST, 'PUT'); //curl\_setopt($ch, CURLOPT\_POSTFIELDS, json\_encode($data)); curl\_setopt($ch, CURLOPT\_POSTFIELDS, $data); $result = curl\_exec($ch); // Check HTTP status code if (!curl\_errno($ch)) { switch ($http\_code = curl\_getinfo($ch, CURLINFO\_HTTP\_CODE)) { case 200: # OK $token = json\_decode($result, true); curl\_close($ch); //echo ($token['token']); return ($token['token']); case 400: //echo ("Problem with Body parameter"); //echo($result); curl\_close; return false; case 404: curl\_close; return false; //return true; //break; default: // echo 'Unexpected HTTP code: ', $http\_code, "\n"; curl\_close; return false; } } } ?\>

```
<!-- Form to connect to a video-session -->
<div id="main" style="text-align: center;">
   
    <form onsubmit="joinSession(); return false" style="padding: 80px; margin: auto">
        <p>
            <label>Session:</label>
            <input type="text" id="sessionName" value=<? echo (SESSEION_NAME); ?> required>
        </p>
        <p>
            <label>User:</label>
            <input type="text" id="user" value="User1">
        </p>
        <p>
            <input type="submit" value="JOIN">
        </p>
    </form>
</div>
<script>
function joinSession() {

var sessionName = document.getElementById('sessionName').value;
var user = document.getElementById('user').value;
var webComponent = document.querySelector('openvidu-webcomponent');
var tokens = [];

if(webComponent.getAttribute("openvidu-secret") != undefined && webComponent.getAttribute("openvidu-server-url") != undefined ){
   location.reload();
}else {
	
    var token1 = "<? echo $token1 ?>" 
    var token2 = "<? echo $token2 ?>" 
	
    tokens.push(token1, token2);
    webComponent.sessionConfig = { sessionName, user, tokens, ovSettings };
}

```

}

```
</script>

<!-- OpenVidu Web Component -->
<openvidu-webcomponent style="display: none"></openvidu-webcomponent>

```

---

<div class="post-metadata">

**Author:** ![micael.gallego](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/micael.gallego/32/2_2.png) [@micael.gallego](https://openvidu.discourse.group/u/micael.gallego)\
**Post date:** [May 23, 2020, 12:11am UTC](https://openvidu.discourse.group/t/how-to-do-get-token-with-php-to-make-app-secure/876/2 "2020-05-23T00:11:10Z")

</div>

Hello @kamal,

Thank you for the code, but it is very bad formatted.

Can you publish it again or put in a GitHub gist so we can link to it?

Thank you

---

<div class="post-metadata">

**Author:** ![kamal](https://avatars.discourse-cdn.com/v4/letter/k/a698b9/32.png) [@kamal](https://openvidu.discourse.group/u/kamal)\
**Post date:** [May 23, 2020, 4:37am UTC](https://openvidu.discourse.group/t/how-to-do-get-token-with-php-to-make-app-secure/876/3 "2020-05-23T04:37:33Z")

</div>

Sorry. Please find below from GitHub gist

> <https://gist.github.com/quidlab/456ebecd4030034fef6c902031c6b40e>

---

<div class="post-metadata">

**Author:** ![micael.gallego](https://yyz2.discourse-cdn.com/free1/user_avatar/openvidu.discourse.group/micael.gallego/32/2_2.png) [@micael.gallego](https://openvidu.discourse.group/u/micael.gallego)\
**Post date:** [May 24, 2020, 11:32pm UTC](https://openvidu.discourse.group/t/how-to-do-get-token-with-php-to-make-app-secure/876/4 "2020-05-24T23:32:51Z")

</div>

Thank you!! I’m sure it will help other PHP developers.
