# ============================================================================= # WHost — Next-Gen Hosting Control Panel # # Copyright (c) 2026 WISECP LLC. All rights reserved. # # NOTICE: All information contained herein is, and remains the property of # WISECP LLC. The intellectual and technical concepts contained herein are # proprietary to WISECP LLC and may not be reproduced, disclosed, or used # without express written authorization. # # Website: https://wisecp.com # Contact: hello@wisecp.com # ============================================================================= # # HMAC-SHA256 v2 signing example for the WHost Agent API. # Signature payload: METHOD\nPATH\nTIMESTAMP\nNONCE\nBODY # # Usage: # WHOST_BASE_URL=https://... WHOST_API_KEY=... WHOST_API_SECRET=... ruby hmac-example.rb require 'net/http' require 'openssl' require 'securerandom' require 'uri' base_url = ENV.fetch('WHOST_BASE_URL') api_key = ENV.fetch('WHOST_API_KEY') api_secret = ENV.fetch('WHOST_API_SECRET') method = 'GET' path = '/api/v1/system/info' body = '' timestamp = Time.now.to_i.to_s nonce = SecureRandom.hex(16) # v2 payload: METHOD\nPATH\nTIMESTAMP\nNONCE\nBODY payload = "#{method}\n#{path}\n#{timestamp}\n#{nonce}\n#{body}" signature = OpenSSL::HMAC.hexdigest('sha256', api_secret, payload) uri = URI.join(base_url, path) http = Net::HTTP.new(uri.host, uri.port) http.use_ssl = uri.scheme == 'https' # TLS verification ON by default (production-safe). Only disable for # local development against a self-signed cert by setting # WHOST_TLS_VERIFY=0 in the env. http.verify_mode = (ENV['WHOST_TLS_VERIFY'] == '0') ? OpenSSL::SSL::VERIFY_NONE : OpenSSL::SSL::VERIFY_PEER request_class = case method when 'GET' then Net::HTTP::Get when 'POST' then Net::HTTP::Post when 'PUT' then Net::HTTP::Put when 'PATCH' then Net::HTTP::Patch when 'DELETE' then Net::HTTP::Delete else raise "Unsupported method: #{method}" end req = request_class.new(uri.request_uri) req['X-WHost-Key'] = api_key req['X-WHost-Timestamp'] = timestamp req['X-WHost-Nonce'] = nonce req['X-WHost-Signature'] = signature req.body = body if !body.empty? && %w[POST PUT PATCH DELETE].include?(method) response = http.request(req) puts "HTTP #{response.code}" puts response.body