# Access token invalided

**URL:** <https://devforum.zoom.us/t/access-token-invalided/83910>\
**Category:** Meetings\
**Created:** [March 1, 2023, 5:09am UTC](https://devforum.zoom.us/t/access-token-invalided/83910 "2023-03-01T05:09:13Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![hbetancur](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/hbetancur/32/29586_2.png) [@hbetancur](https://devforum.zoom.us/u/hbetancur)\
**Post date:** [March 1, 2023, 5:09am UTC](https://devforum.zoom.us/t/access-token-invalided/83910/1 "2023-03-01T05:09:13Z")

</div>

If i create a meeting using API ,then showing error {“code”:124,“message”:“invalid access token, this access token is not supported as query parameter string”}

So i couldn’t create meeting . Please help me .

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [March 1, 2023, 8:59pm UTC](https://devforum.zoom.us/t/access-token-invalided/83910/2 "2023-03-01T20:59:49Z")

</div>

Hi @hbetancur  
It looks like you are passing the access token as a query parameter.  
We recently made some security enhancements to the way we manage access tokens, learn more about that here:

> [@\[Security Update\] No token values in URL query parameters](https://devforum.zoom.us/t/security-update-no-token-values-in-url-query-parameters/78782/4):
>
> Yes it does. You would need to put the access\_token in the ‘Authorization’ header for the request. In the curl example, you would have to use the output flag, i.e, --output /path/to/download.file.

[https://marketplace.zoom.us/docs/guides/auth/oauth/#step-2-request-access-token](https://marketplace.zoom.us/docs/guides/auth/oauth/#step-2-request-access-token)

Hope this helps,  
Elisa

---

<div class="post-metadata">

**Author:** ![hbetancur](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/hbetancur/32/29586_2.png) [@hbetancur](https://devforum.zoom.us/u/hbetancur)\
**Post date:** [March 2, 2023, 1:45pm UTC](https://devforum.zoom.us/t/access-token-invalided/83910/3 "2023-03-02T13:45:56Z")

</div>

const clientId = ‘xxxxxxxxxxxxxxxxxxxxxxxxxx’;  
const redirectUri = ‘[https://xxxxxxxxxxxxxxx/](https://xxxxxxxxxxxxxxx/)’;  
const responseType = ‘code’;

```
	const authEndpoint = 'https://zoom.us/oauth/authorize';
	const authUrl = `${authEndpoint}?response_type=${responseType}&client_id=${clientId}&redirect_uri=${redirectUri}`;

	axios.get(authUrl, {
	  headers: {
		'Access-Control-Allow-Origin': '*'
	  }
	})
	  .then(response => {
		alert(response.data);
	  })
	  .catch(error => {
		alert(error);
	  });

```

Showing this error

Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at [https://zoom.us/oauth/authorize?response\_type=code&client\_id=q0zpHuuMSwuGujMbHNiKqQ&redirect\_uri=http://127.0.0.1:8000](https://zoom.us/oauth/authorize?response_type=code&client_id=q0zpHuuMSwuGujMbHNiKqQ&redirect_uri=http://127.0.0.1:8000). (Reason: CORS header ‘Access-Control-Allow-Origin’ missing). Status code: 403.

How to fix this error. Please help me .

---

<div class="post-metadata">

**Author:** ![hbetancur](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/hbetancur/32/29586_2.png) [@hbetancur](https://devforum.zoom.us/u/hbetancur)\
**Post date:** [March 2, 2023, 4:07pm UTC](https://devforum.zoom.us/t/access-token-invalided/83910/4 "2023-03-02T16:07:56Z")

</div>

$CURL\_URL = ‘[https://api.zoom.us/v2/users/useremail/token?type=zak](https://api.zoom.us/v2/users/useremail/token?type=zak)’;

```
	$curl = curl_init();

	curl_setopt_array($curl, array(
	  CURLOPT_URL => $CURL_URL,
	  CURLOPT_RETURNTRANSFER => true,
	  CURLOPT_ENCODING => '',
	  CURLOPT_MAXREDIRS => 10,
	  CURLOPT_TIMEOUT => 0,
	  CURLOPT_FOLLOWLOCATION => true,
	  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
	  CURLOPT_CUSTOMREQUEST => 'GET',
	  CURLOPT_HTTPHEADER => array(
		'Authorization: <token>'
	  ),
	));

	$response = curl_exec($curl);

	curl_close($curl);
	echo $response;

```

showing error {“code”:124,“message”:“invalid access token”}  
How to fix this error. Please help me .  
I couldn’t generator access token. Please help me how to generator access token ?

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [March 2, 2023, 9:15pm UTC](https://devforum.zoom.us/t/access-token-invalided/83910/5 "2023-03-02T21:15:17Z")

</div>

Hi @hbetancur  
Could you please specify what app type you are using to generate the access token?

---

<div class="post-metadata">

**Author:** ![hbetancur](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/hbetancur/32/29586_2.png) [@hbetancur](https://devforum.zoom.us/u/hbetancur)\
**Post date:** [March 3, 2023, 5:01am UTC](https://devforum.zoom.us/t/access-token-invalided/83910/6 "2023-03-03T05:01:09Z")

</div>

// create a payload with the issuer and expiration time  
const payload = {  
iss: process.env.MIX\_ZOOM\_API\_KEY,  
exp: new Date().getTime() + 5000,  
};

// sign the token using your API Secret  
const acc\_token = jwt.sign(payload, process.env.MIX\_ZOOM\_API\_SECRET\_KEY);

I am using JWT app type. Before using this code to generator access token and create zoom meeting successfully.  
Now generator access token successfully, but if create zoom meeting api call then showing {“code”:124,“message”:“invalid access token, this access token is not supported as query parameter string”} error message.So how to fix this error and create zoom meeting. Please help us.

which type of app using for this issue to solve ?

 ![zoom](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/e/a/eadee91512eafb530446ac9aab04ae0d4e19c726.png)

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [March 3, 2023, 4:09pm UTC](https://devforum.zoom.us/t/access-token-invalided/83910/7 "2023-03-03T16:09:37Z")

</div>

Hi @hbetancur  
As I mentioned in my previous post, the error you are getting is because of the way you are passing the access token when creating a meeting

Here is the documentation about how to use access token:

[https://marketplace.zoom.us/docs/guides/auth/oauth/#using-an-access-token](https://marketplace.zoom.us/docs/guides/auth/oauth/#using-an-access-token)

Best,  
Elisa

---

<div class="post-metadata">

**Author:** ![hbetancur](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/hbetancur/32/29586_2.png) [@hbetancur](https://devforum.zoom.us/u/hbetancur)\
**Post date:** [March 6, 2023, 7:14am UTC](https://devforum.zoom.us/t/access-token-invalided/83910/8 "2023-03-06T07:14:47Z")

</div>

which type of app using for this issue to solve ?  
Please reply me

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [March 6, 2023, 3:01pm UTC](https://devforum.zoom.us/t/access-token-invalided/83910/9 "2023-03-06T15:01:27Z")

</div>

Hi @hbetancur  
Can you please share with me the request URL and request body that you are sending when creating the meeting so I can point you in the right direction?  
The error you are seeing it’s not about the app type, it is because of the way you are passing your access token

Cheers,  
elisa
