Do I use the acces token in my app settings?


I have a console app which parses data from the streaming API. Currently I’m using Basic Auth and obviously need to change to oAuth.

Since it’s a console app, it’s not going to be calling websites to get access tokens.

I noticed there was an access token and an access token secret provided in my “app settings” page. Can I simply use that when making the call to the stream api?

I ask because I’m using those and keep getting a 401 and wanted to make sure if it’s the access tokens or something else.

I’ve compared my headers to the headers in oAuth tool and they look close enough. I’ve also compared the baseString and it looks the same.

Can I share these with you to help troubleshoot this?

These are the response headers I get from the 401:

Headers = {Connection: close Content-Length: 1285 Cache-Control: must-revalidate,no-cache,no-store Content-Type: text/html WWW-Authenticate: Basic realm="Firehose"


Yeah, you can use the access token and secret from your app page to connect to the public streaming endpoints (filter, sample) without needing to do the 3-legged flow. Just be careful about sharing those credentials - they give access to your account via the API.

Can you send some more information about the request you’re making (URL, sanitized headers)? The HTML response seems weird to me.


Here’s the headers. I removed the token from this post, not sure if anything else is sensitive.

Authorization OAuth
oauth_consumer_key=“zMNH25PFowKBtW5S3ZEJ4g”, oauth_nonce=“NjM1MDAwNzQwOTgxOTQzODk3”, oauth_signature=“8MuwZF2lxWgtiZnp%2F7nZAJ3DxhM%3D”,

Here is the Base String:


And this is the URL:


It looks like you’re missing an & between the URL and parameters list of your signature base string. I would expect to see:



Rather than missing, it’s encoded.


K. I updated, but still getting 401’s.

I noticed you’re using the URL: so I’ve updated to /1.1/ [I was using just /1/ but that doesn’t seem to fix my issue.



Seems correct now, but there’s still a bunch of reasons you could be having a problem. Spaces in query strings can cause issues, so maybe try tracking a single word first (your last signature base string seemed to be for the query “thank god god”, so if that wasn’t exactly the track value you sent, then that might be a problem).

Also make sure that the access token / secret belong to the consumer key / secret you’re using, and that you’re creating the signature using both secrets as the signing key and not just the consumer secret or access token secret.

If you’re able to fix the timestamp and nonce of your request I’d say generate a request using the oauth tool on this site and then try to generate the same exact request in your code and compare the values you see.


Fix my timestamp and nonce? Are they incorrect?


Sorry, I meant fix them to the values used by the oauth tool (as opposed to using a current timestamp / new nonce for each request). The idea would be to compare the same exact request as signed by the tool vs. the one generated by your library.


Thanks. I’ll give that a shot.

When is basic auth being completely removed? I know it’s “soon” but will you give a firm deadline prior to completely turning it off?


Yeah, we will announce a firm date for basic auth to be turned off.


I used the oauth tool. Copied the nonce and the timestamp. Put both into my code.

Still getting 401s. So does that rule out an issue with nonce and timestamp?

What else could be causing the 401? I’m using the access token and token secret from the app detail page and using the consumer key and secret as well.


This is how I’m creating signature:

var compositeKey = string.Concat(Uri.EscapeDataString(oauth_consumer_secret), "&", Uri.EscapeDataString(oauth_token_secret));

string oauth_signature;
using (HMACSHA1 hasher = new HMACSHA1(ASCIIEncoding.ASCII.GetBytes(compositeKey))) {
oauth_signature = Convert.ToBase64String(hasher.ComputeHash(ASCIIEncoding.ASCII.GetBytes(baseString)));


Does the signature generated from your code match the signature generated by the oauth tool when all the same parameters are used in both?

Does running the curl command from the tool produce a successful response?


Signatures are different:

Mine: FN%2FLXAebWcRvzpC1GqEX3y%2BnAnc%3D

Oauth Tool: SZPmGGx4IeB4arYF1kNGaHX077w%3D

I haven’t used the curl command yet as I’ve not really used curl before.

I did take the nonce, timestamp, and signature from the oAuth tool - used them in the call and still got a 401.


If the signatures are different, then something is wrong with your signing algorithm. My next step would be to do a character-by-character comparison of the signature base string generated by the tool vs. what your code generates. If anything is different at all it will be an error.

If the signature base strings are exactly the same, then you should look at the hashing code to make sure it generates the correct hmac signature.

Now that I see you’re using Java, I should also say that you should make sure that your Uri encoding follows the correct algorithm as documented here: - IIRC, Java would encode spaces as “+” which would break oauth signatures (although from your base string it seems to be doing the right thing and getting %20).

You may want to consider using an established Java OAuth library since there’s so much to get wrong. My experience is that there’s a lot of fussing until you’re able to get everything exactly correct. Twitter4j has a working implementation which would at least be worth reading:


Actually that’s C# (.NET) which is close enough. I was using AuthPack to generate the signatures, and the nonce and timestamp, but that wasn’t working at all either. Even with AuthPack, the signature is still not the same.

Not sure if you know anything about AuthPack, but you can see more here:


Given the nonce and timestamp from the oAuth tool, I am generating the signature correctly. However, I’m still getting 401 Unauthorized.

My clock seems to be in sync with Twitters. Although, I’m not sure how I can check that.