// ============================================================================= // WHost — Next-Gen Hosting Control Panel // // Copyright (c) 2026 WISECP LLC. All rights reserved. // // NOTICE: All information contained herein is, and remains the property of // WISECP LLC. The intellectual and technical concepts contained herein are // proprietary to WISECP LLC and may not be reproduced, disclosed, or used // without express written authorization. // // Website: https://wisecp.com // Contact: hello@wisecp.com // ============================================================================= // // HMAC-SHA256 v2 signing example for the WHost Agent API. // Signature payload: METHOD\nPATH\nTIMESTAMP\nNONCE\nBODY // // Build & run: // go run hmac-example.go // // Environment: // WHOST_BASE_URL e.g. https://your-server:443 // WHOST_API_KEY // WHOST_API_SECRET package main import ( "crypto/hmac" "crypto/rand" "crypto/sha256" "crypto/tls" "encoding/hex" "fmt" "io" "net/http" "os" "strconv" "strings" "time" ) func main() { baseURL := mustEnv("WHOST_BASE_URL") apiKey := mustEnv("WHOST_API_KEY") apiSecret := mustEnv("WHOST_API_SECRET") method := "GET" path := "/api/v1/system/info" body := "" ts := strconv.FormatInt(time.Now().Unix(), 10) nonceBytes := make([]byte, 16) if _, err := rand.Read(nonceBytes); err != nil { fail(err) } nonce := hex.EncodeToString(nonceBytes) // v2 payload: METHOD\nPATH\nTIMESTAMP\nNONCE\nBODY payload := strings.Join([]string{method, path, ts, nonce, body}, "\n") mac := hmac.New(sha256.New, []byte(apiSecret)) mac.Write([]byte(payload)) signature := hex.EncodeToString(mac.Sum(nil)) req, err := http.NewRequest(method, baseURL+path, strings.NewReader(body)) if err != nil { fail(err) } req.Header.Set("X-WHost-Key", apiKey) req.Header.Set("X-WHost-Timestamp", ts) req.Header.Set("X-WHost-Nonce", nonce) req.Header.Set("X-WHost-Signature", signature) // TLS verification ON by default (production-safe). Only disable // for local development against a self-signed cert by setting // WHOST_TLS_VERIFY=0 in the env. insecure := os.Getenv("WHOST_TLS_VERIFY") == "0" client := &http.Client{ Transport: &http.Transport{ TLSClientConfig: &tls.Config{InsecureSkipVerify: insecure}, }, Timeout: 10 * time.Second, } resp, err := client.Do(req) if err != nil { fail(err) } defer resp.Body.Close() respBody, err := io.ReadAll(resp.Body) if err != nil { fail(err) } fmt.Printf("HTTP %d\n%s\n", resp.StatusCode, respBody) } func mustEnv(name string) string { v := os.Getenv(name) if v == "" { fmt.Fprintf(os.Stderr, "%s not set\n", name) os.Exit(1) } return v } func fail(err error) { fmt.Fprintln(os.Stderr, err) os.Exit(1) }