# Always 401 from https://api.zoom.us/v2/users

**URL:** <https://devforum.zoom.us/t/always-401-from-https-api-zoom-us-v2-users/38728>\
**Category:** API and Webhooks\
**Created:** [December 18, 2020, 2:41pm UTC](https://devforum.zoom.us/t/always-401-from-https-api-zoom-us-v2-users/38728 "2020-12-18T14:41:53Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bgul](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/bgul/32/20347_2.png) [@bgul](https://devforum.zoom.us/u/bgul)\
**Post date:** [December 18, 2020, 2:41pm UTC](https://devforum.zoom.us/t/always-401-from-https-api-zoom-us-v2-users/38728/1 "2020-12-18T14:41:54Z")

</div>

**Description**  
[https://api.zoom.us/v2/users/{userid}/token](https://api.zoom.us/v2/users/%7Buserid%7D/token) always return 401.

**Error**  
it returns ,

`124` Invalid access token.

**Which App Type (OAuth / Chatbot / JWT / Webhook)?**  
api

**Which Endpoint/s?**  
[https://api.zoom.us/v2/users/{userid}/tokenhttps://api.zoom.us/v2/users/{userid}/token](https://api.zoom.us/v2/users/%7Buserid%7D/tokenhttps://api.zoom.us/v2/users/%7Buserid%7D/token)

When i create a jwt with credentials from developer console and try to send a get request it always returns 401 error. But with same credentials i am able to build simple app which creates and joins room.

this is my code :

```
private String getZoomToken() {
    try {
    URL zoomTokenEndpoint = new URL("https://api.zoom.us/v2/users/" + "bhdrgl06@gmail.com" + "/token?type=token&access_token=" + getJWT());
    HttpsURLConnection connection = (HttpsURLConnection) zoomTokenEndpoint.openConnection();
    if (connection.getResponseCode() == HttpURLConnection.HTTP_OK) {
        InputStream responseBody = connection.getInputStream();
        InputStreamReader responseBodyReader = new InputStreamReader(responseBody, "UTF-8");
        BufferedReader streamReader = new BufferedReader(responseBodyReader);
        StringBuilder responseStrBuilder = new StringBuilder();

        //get JSON String
        String inputStr;
        while ((inputStr = streamReader.readLine()) != null)
            responseStrBuilder.append(inputStr);

        connection.disconnect();
        JSONObject jsonObject = new JSONObject(responseStrBuilder.toString());
        return jsonObject.getString("token");
    } else {
        Log.d("dasdas", "error in connection");
        return null;
    }
    } catch (MalformedURLException e) {
        e.printStackTrace();
    } catch (UnsupportedEncodingException e) {
        e.printStackTrace();
    } catch (IOException e) {
        e.printStackTrace();
    } catch (JSONException e) {
        e.printStackTrace();
    }
    return "";
}

private String getJWT() {
    long time = System.currentTimeMillis()/1000 + 3600;

    String header = "{\"alg\": \"HS256\", \"typ\": \"JWT\"}";
    String payload = "{\"iss\": \"" + AppConstant.Zoom_Key + "\"" + ", \"exp\": " + String.valueOf(time) + "}";
    try {
        String headerBase64Str = Base64.encodeToString(header.getBytes("utf-8"), Base64.NO_WRAP| Base64.NO_PADDING | Base64.URL_SAFE);
        String payloadBase64Str = Base64.encodeToString(payload.getBytes("utf-8"), Base64.NO_WRAP| Base64.NO_PADDING | Base64.URL_SAFE);
        final Mac mac = Mac.getInstance("HmacSHA256");
        SecretKeySpec secretKeySpec = new SecretKeySpec(AppConstant.Zoom_Secret.getBytes(), "HmacSHA256");
        mac.init(secretKeySpec);

        byte[] digest = mac.doFinal((headerBase64Str + "." + payloadBase64Str).getBytes());

        return headerBase64Str + "." + payloadBase64Str + "." + Base64.encodeToString(digest, Base64.NO_WRAP| Base64.NO_PADDING | Base64.URL_SAFE);
    } catch (NoSuchAlgorithmException e) {
        e.printStackTrace();
    } catch (UnsupportedEncodingException e) {
        e.printStackTrace();
    } catch (InvalidKeyException e) {
        e.printStackTrace();
    }
    return "";
}
```

---

<div class="post-metadata">

**Author:** ![bgul](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/bgul/32/20347_2.png) [@bgul](https://devforum.zoom.us/u/bgul)\
**Post date:** [December 18, 2020, 4:20pm UTC](https://devforum.zoom.us/t/always-401-from-https-api-zoom-us-v2-users/38728/2 "2020-12-18T16:20:40Z")

</div>

it caused most stupid mistake ever. About crentials. Now i am able to do make request. Bu it returns empty not token

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [December 18, 2020, 9:27pm UTC](https://devforum.zoom.us/t/always-401-from-https-api-zoom-us-v2-users/38728/3 "2020-12-18T21:27:51Z")

</div>

Hey @bgul,

Are you still having an issue with this request? Can you share an example of the latest request where you’re getting an empty token? We’re happy to take a closer look.

Thanks,  
Will

---

<div class="post-metadata">

**Author:** ![bgul](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/bgul/32/20347_2.png) [@bgul](https://devforum.zoom.us/u/bgul)\
**Post date:** [December 18, 2020, 9:46pm UTC](https://devforum.zoom.us/t/always-401-from-https-api-zoom-us-v2-users/38728/4 "2020-12-18T21:46:25Z")

</div>

Hi @will.zoom,

Thank you for your response,  
Below request returns as success but has empty json response

[https://api.zoom.us/v2/users/ValidUserMail/token?type=token&access\_token=e](https://api.zoom.us/v2/users/ValidUserMail/token?type=token&access_token=e)

I also called same method with id of same user instead email from below service

String url = “[https://api.zoom.us/v2/users?access\_token=](https://api.zoom.us/v2/users?access_token=)” + token

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [December 21, 2020, 10:08pm UTC](https://devforum.zoom.us/t/always-401-from-https-api-zoom-us-v2-users/38728/5 "2020-12-21T22:08:06Z")

</div>

Hey @bgul,

Please try passing in the access token via the **header** instead of a query param in the request url.

Example:

```auto
"Authorization": "Basic ACCESS_TOKEN_HERE"

```

Docs here:

> **[OAuth 2.0 - Authorization - Documentation](https://marketplace.zoom.us/docs/guides/auth/oauth#using-access-token)**
>
> OAuth with Zoom
> 
> The Zoom API uses OAuth 2.0 to authenticate and authorize users to make requests. To setup access credentials and request scopes for yo...

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![bgul](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/bgul/32/20347_2.png) [@bgul](https://devforum.zoom.us/u/bgul)\
**Post date:** [December 22, 2020, 11:34am UTC](https://devforum.zoom.us/t/always-401-from-https-api-zoom-us-v2-users/38728/6 "2020-12-22T11:34:13Z")

</div>

actually both of them was working. Problem was i signed in google. When i sign-up from different accout it was all fine. After that to add user and get zak i needed to upgrade my account to pro.

---

<div class="post-metadata">

**Author:** ![MaxM](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/maxm/32/42303_2.png) [@MaxM](https://devforum.zoom.us/u/MaxM)\
**Post date:** [December 23, 2020, 8:41pm UTC](https://devforum.zoom.us/t/always-401-from-https-api-zoom-us-v2-users/38728/7 "2020-12-23T20:41:02Z")

</div>

Hey @bgul,

Thank you for the update. I’m glad to hear that you resolved your issues! If you encounter any further issues or questions, please don’t hesitate to reach out.

Thanks,  
Max

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [January 23, 2021, 6:41am UTC](https://devforum.zoom.us/t/always-401-from-https-api-zoom-us-v2-users/38728/8 "2021-01-23T06:41:06Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
