oAuth signature creation issue with PHP (posting photoset to Tumblr)
Asked Answered



I've made a simple script that posts images on tumblr. everything is fine, but I've noticed some performance issues right after I've changed the host provider (my new host is limited and cheaper).

now, after debugging the script and after contacting the tumblr api helpdesk, I'm stuck on a problem:

there are 3 functions:

function oauth_gen($method, $url, $iparams, &$headers) {

    $iparams['oauth_consumer_key'] = CONSUMER_KEY;
    $iparams['oauth_nonce'] = strval(time());
    $iparams['oauth_signature_method'] = 'HMAC-SHA1';
    $iparams['oauth_timestamp'] = strval(time());
    $iparams['oauth_token'] = OAUTH_TOKEN;
    $iparams['oauth_version'] = '1.0';
    $iparams['oauth_signature'] = oauth_sig($method, $url, $iparams);    
    $oauth_header = array();
    foreach($iparams as $key => $value) {
        if (strpos($key, "oauth") !== false) { 
           $oauth_header []= $key ."=".$value;

    $str = print_r($iparams, true);
    file_put_contents('data1-1.txt', $str); 
    $oauth_header = "OAuth ". implode(",", $oauth_header);
    $headers["Authorization"] = $oauth_header;

function oauth_sig($method, $uri, $params) {

    $parts []= $method;
    $parts []= rawurlencode($uri);   
    $iparams = array();
    foreach($params as $key => $data) {
            if(is_array($data)) {
                $count = 0;
                foreach($data as $val) {
                    $n = $key . "[". $count . "]";
                    $iparams []= $n . "=" . rawurlencode($val);
                    //$iparams []= $n . "=" . $val;
            } else {
                $iparams[]= rawurlencode($key) . "=" .rawurlencode($data);
    $str = print_r($iparams, true);
    file_put_contents('data-1.txt', $str);
    //$size = filesize('data.txt');

    $parts []= rawurlencode(implode("&", $iparams));
    $sig = implode("&", $parts);
    return base64_encode(hash_hmac('sha1', $sig, CONSUMER_SECRET."&". OAUTH_SECRET, true));

these 2 functions above comes from an online functional example, they have always worked fine.

this is the function I use to call the APIs and the oAuth:

function posta_array($files,$queue,$tags,$caption,$link,$blog){
    $datArr = array();
    $photoset_layout = "";
    foreach ($files as $sing_file){
        $dataArr [] = file_get_contents($sing_file);
        $photoset_layout .= "1";

    $headers = array("Host" => "http://api.tumblr.com/", "Content-type" => "application/x-www-form-urlencoded", "Expect" => "");

    $params = array(
        "data" => $dataArr,
        "type" => "photo",
        "state" => $queue,
        "photoset_layout" => $photoset_layout,
    oauth_gen("POST", "http://api.tumblr.com/v2/blog/$blog/post", $params, $headers);
    debug($headers,"head 2");
    $ch = curl_init();
    curl_setopt($ch, CURLOPT_USERAGENT, "Tumblr v1.0");
    curl_setopt($ch, CURLOPT_URL, "http://api.tumblr.com/v2/blog/$blog/post");
    curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1 );
    curl_setopt($ch, CURLOPT_HTTPHEADER, array(
        "Authorization: " . $headers['Authorization'],
        "Content-type: " . $headers["Content-type"],
        "Expect: ")
    $params = http_build_query($params);
    $str = print_r($params, true);
    file_put_contents('data_curl1.txt', $str);

    curl_setopt($ch, CURLOPT_POST, 1);
    curl_setopt($ch, CURLOPT_POSTFIELDS, $params);
    $response = curl_exec($ch);
    return $response;


this is the function with some problems, I try to explain:

I called the oauth_gen passing the parameters array to it, the oauth_gen creates the oauth header that I later used here: "Authorization: " . $headers['Authorization'],.

As I stated, everything is working smoothly, until I have tried to post a gif photoset of 6 files for a total of 6Mb (tumblr permit 2Mb each file and 10Mb total).

PHP runs out of memory and return an error, here it starts my debugging, after a while I contacted the tumblr api helpdesk, and they answer in this way:

You shouldn't need to include the files in the parameters used for generating the oauth signature. For an example of how this is done, checkout one of our official API clients.

This changes everything. Untill now, I passed the entire parameters array to the oauth_gen, which, calling the oauth_sig, will rawencode everything into the array (binary strings of gif files inlcuded), with a result of a binary file of about 1Mb becomes at least 3Mb of rawurlencoded string.

and that's why I had memory issues. Nice, so, as the helpdesk say, I've changed the call to the oauth_gen in this way:

$new_array = array();
oauth_gen("POST", "http://api.tumblr.com/v2/blog/$blog/post", $new_array, $headers); 

seams legit to me, I passed a new array to the function, the function then generate the oAuth, the headers are passed back and I can use them into the posting call, the result was:


asking more to tumblr api helpdesk leads only to more links to their documentation and their "tumblr php client" which I can't use, so it isn't a option.

Does anyone has experience with oAuth and can explain me what I'm doing wrong? as far as I understand, the trick is into the encrypted data the oauth_sig create, but I can't figure out how to proceed.

I really want to understand the oauth, but more I read about it and more the tumblr helpdsek seams right to me, but... the solution doesn't work, and works only if I let the oauth function to encrypt the entire data array (with the images and everything) but I can understand that this is wrong... help me.

UPDATE 1 I've tried a new thing today, first I created the empty array, then passed by reference to the oauth_genand only after generating the signature, I've added to the same array all the other fields about the post itself, but the result is the same.

UPDATE 2 reading here: http://oauth.net/core/1.0a/#signing_process seems that the parameters of the request must all be used for the signature, but this is not totally clear (if someone could explain it better, I really appreciate). this is weird, because if it's true, it go against the words of the Tumblr help desk, while if it's not true, there is a little confusion in the whole process. by the way, at this time, I'm stile struck in the same point.

Abdication answered 20/4, 2016 at 14:56 Comment(0)

After digging couple of hours into the issue, debugging, reviewing tumblr api and api client, registering a test account and trying to post some images. The good news is finally I come up with a solution. It is not using a native CURL only, you need guzzle and an OAuth library to sign the requests.

Tumblr guys are correct about signing the request. You don't need to pass image data to sign the request. If you check their official library you can see; https://github.com/tumblr/tumblr.php/blob/master/lib/Tumblr/API/RequestHandler.php#L85

I tried to fix the issue with native CURL library but unfortunately I was not successful, either I was signing the request in a wrong way or missing something in the request header, data etc. I don't know actually, Tumblr api is really bad at informing you what you are doing wrong.

So I cheated a little bit and start to read Tumblr api client code, and I come up with a solution.

Here we go, first you need two packages.

$ composer require "eher/oauth:1.0.*"
$ composer require "guzzle/guzzle:>=3.1.0,<4"

And then the PHP code, just define your keys, tokens, secrets etc. Then it should be good to go.

Since the signing request does not include picture data, it is not exceeding memory limit. After signing the request actually we are not getting the contents of the files into our post data array. We are using addPostFiles method of guzzle, which takes care of file addition to POST request, does the dirty work for you. And here is the result for me;

string(70) "{"meta":{"status":201,"msg":"Created"},"response":{"id":143679527674}}" And here is the url; http://blog-transparentcoffeebouquet.tumblr.com/

ini_set('memory_limit', '64M');

define("CONSUMER_KEY", "");
define("CONSUMER_SECRET", "");
define("OAUTH_TOKEN", "");
define("OAUTH_SECRET", "");

function request($options,$blog) {

    // Take off the data param, we'll add it back after signing
    $files = isset($options['data']) ? $options['data'] : false;

    $url = "https://api.tumblr.com/v2/blog/$blog/post";

    $client =  new \Guzzle\Http\Client(null, array(
        'redirect.disable' => true

    $consumer = new \Eher\OAuth\Consumer(CONSUMER_KEY, CONSUMER_SECRET);
    $token = new \Eher\OAuth\Token(OAUTH_TOKEN, OAUTH_SECRET);

    $oauth = \Eher\OAuth\Request::from_consumer_and_token(
    $oauth->sign_request(new \Eher\OAuth\HmacSha1(), $consumer, $token);
    $authHeader = $oauth->to_header();
    $pieces = explode(' ', $authHeader, 2);
    $authString = $pieces[1];

    // POST requests get the params in the body, with the files added
    // and as multipart if appropriate
    /** @var \Guzzle\Http\Message\RequestInterface $request */
    $request = $client->post($url, null, $options);
    $request->addHeader('Authorization', $authString);
    if ($files) {
        if (is_array($files)) {
            $collection = array();
            foreach ($files as $idx => $f) {
                $collection["data[$idx]"] = $f;
        } else {
            $request->addPostFiles(array('data' => $files));

    $request->setHeader('User-Agent', 'tumblr.php/0.1.2');

    // Guzzle throws errors, but we collapse them and just grab the
    // response, since we deal with this at the \Tumblr\Client level
    try {
        $response = $request->send();
    } catch (\Guzzle\Http\Exception\BadResponseException $e) {
        $response = $request->getResponse();

    // Construct the object that the Client expects to see, and return it
    $obj = new \stdClass;
    $obj->status = $response->getStatusCode();
    $obj->body = $response->getBody();
    $obj->headers = $response->getHeaders()->toArray();

    return $obj;

$files = [

$params = array(
    "type" => "photo",
    "state" => "published",
    "tags"=> [],
    "data" => $files,

$response = request($params, "blog-transparentcoffeebouquet.tumblr.com");
Spathose answered 1/5, 2016 at 12:23 Comment(8)
Hi Ugur, thanks for the answer, I've stepped in your path too before trying to handle the whole process with curl, actualy I'm talking about this issue in the tumblr dev group on google, at the end I have understand that it is all a matter on "how you send the params to tumblr", using multipart form data, you must not include the parameters in the signature, while using application/x-www-form-urlencoded like I do, the signature must include every parameter, I'll vote your question but I'll write the whole process once I solve the issue.Foreknowledge
Hi Matteo, Thank you for the comment and vote. To be more descriptive I am not going with the whole native curl approach, Guzzle is taking care of whether you have to send "application/x-www-form-urlencoded " or "multipart/form-data". I don't know what you're discussing in Tumblr Google group but if your aim to send posts to Tumblr I believe my approach is able to solve the issue. I didn't get why you are sticking with only "application/x-www-form-urlencoded"? Do you have some kind of restrictions? Also I believe using packages like Guzzle, Eher/OAuth helps to develop stable software.Spathose
Hey Ugur, yes, your approach is actually good, the issue I have is that I can't put any code I didn't write or totally read on the server, so using libraries and premades is a little difficult because I have to document all the functions, classes and methods, that's why I liked the more easy approach of manually made the curl. actually you are right, I'll accept your answer and I'll write my solution directly into the question, so that could be cover all future cases.Foreknowledge
Hi Matteo, I am glad to help to you and to any potential readers. Dealing with legacy code/unmaintainable code is a whole another topic I guess. To be able to include packages/libraries/gems etc. is a must and needs less effort rather than writing the code yourself. I would be glad to see your approaches to the problem if you come up with a different approach in google groups. Best of luck.Spathose
@Spathose Hey I'm trying to use your implementation, but I'm confused, at what point do you assign the OAUTH_TOKEN and OAUTH_TOKEN_SECRET constants? I followed your code but I'm still getting {"meta":{"status":401,"msg":"Unauthorized"},"response":[]} :(Bloch
@Bloch Hello! Everything about the token and oAuth is starting with lines; ´$consumer = new \Eher\OAuth\Consumer(CONSUMER_KEY, CONSUMER_SECRET); $token = new \Eher\OAuth\Token(OAUTH_TOKEN, OAUTH_SECRET);´ and ending with line, ´$request->addHeader('Authorization', $authString);´ Eher\OAuth library is taking care of the tokens and generating a Authorization header for the service. You may be misplacing the tokens maybe, that was a common pitfall for me when answering this question.Spathose
Where to place photo folder? i tried placing it where i placed above php file but its not working. Fatal error: Uncaught exception 'Guzzle\Common\Exception\InvalidArgumentException' with message 'Unable to open /photo/1.jpg for reading' inHottentot
@Hottentot If i am not misreading my own code, I placed the files at the root of my file system. I think you can use an absolute path to locate your files while defining $files array.Spathose

© 2022 - 2024 — McMap. All rights reserved.