#!/usr/bin/env bash # ============================================================================= # WHost — Next-Gen Hosting Control Panel # # Copyright (c) 2026 WISECP LLC. All rights reserved. # # NOTICE: All information contained herein is, and remains the property of # WISECP LLC. The intellectual and technical concepts contained herein are # proprietary to WISECP LLC and may not be reproduced, disclosed, or used # without express written authorization. # # Website: https://wisecp.com # Contact: hello@wisecp.com # ============================================================================= # # HMAC-SHA256 v2 signing example for the WHost Agent API. # Signature payload: METHOD\nPATH\nTIMESTAMP\nNONCE\nBODY # # Usage: # export WHOST_BASE_URL='https://your-server:443' # export WHOST_API_KEY='...' # export WHOST_API_SECRET='...' # bash hmac-example.sh set -euo pipefail BASE_URL="${WHOST_BASE_URL:?WHOST_BASE_URL not set}" API_KEY="${WHOST_API_KEY:?WHOST_API_KEY not set}" API_SECRET="${WHOST_API_SECRET:?WHOST_API_SECRET not set}" METHOD="GET" PATH_="/api/v1/system/info" BODY="" TIMESTAMP="$(date +%s)" NONCE="$(openssl rand -hex 16)" # v2 payload: METHOD\nPATH\nTIMESTAMP\nNONCE\nBODY — every component newline-separated. # IMPORTANT: do NOT capture the payload with $() — bash command substitution # strips the trailing newline, which makes the signature mismatch the Python / # PHP / Go / Ruby implementations. Pipe printf directly into openssl instead. SIGNATURE="$(printf '%s\n%s\n%s\n%s\n%s' "$METHOD" "$PATH_" "$TIMESTAMP" "$NONCE" "$BODY" \ | openssl dgst -sha256 -hmac "$API_SECRET" \ | awk '{print $NF}')" curl -fsS -k \ -X "$METHOD" \ -H "X-WHost-Key: $API_KEY" \ -H "X-WHost-Timestamp: $TIMESTAMP" \ -H "X-WHost-Nonce: $NONCE" \ -H "X-WHost-Signature: $SIGNATURE" \ "$BASE_URL$PATH_"