# Always get "Invalid access token." using python and jwt

**URL:** <https://devforum.zoom.us/t/always-get-invalid-access-token-using-python-and-jwt/36741>\
**Category:** API and Webhooks\
**Created:** [November 23, 2020, 6:48pm UTC](https://devforum.zoom.us/t/always-get-invalid-access-token-using-python-and-jwt/36741 "2020-11-23T18:48:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![TomJerry](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tomjerry/32/19139_2.png) [@TomJerry](https://devforum.zoom.us/u/TomJerry)\
**Post date:** [November 23, 2020, 6:48pm UTC](https://devforum.zoom.us/t/always-get-invalid-access-token-using-python-and-jwt/36741/1 "2020-11-23T18:48:31Z")

</div>

**Description**  
The code is actually copied from zoom forum ([Zoom JWT Token Creation - Automate the Process](https://devforum.zoom.us/t/zoom-jwt-token-creation-automate-the-process/17708))

> import jwt  
> import requests  
> import json  
> from time import time
> 
> API\_KEY = ‘???’  
> API\_SEC = ‘???’

> #create a function to generate a token using the pyjwt library  
> def generateToken():  
> token = jwt.encode(  
> # Create a payload of the token containing API Key & expiration time  
> {“iss”: API\_KEY, “exp”: time() + 5000},  
> # Secret used to generate token signature  
> API\_SEC,  
> # Specify the hashing alg  
> algorithm=‘HS256’  
> # Convert token to utf-8  
> ).decode(‘utf-8’)
> 
> ```
> return token
> 
> ```
> 
> #send a request with headers including a token
> 
> def getUsers():  
> headers = {‘authorization’: ‘Bearer %s’ % generateToken(),  
> ‘content-type’: ‘application/json’}
> 
> ```
> r = requests.get('https://api.zoom.us/v2/users/', headers=headers)
> 
> print(r.text)
> 
> ```

**Error**  
When I run it, I always get  
{“code”:124,“message”:“Invalid access token.”}

**Which App Type (OAuth / Chatbot / JWT / Webhook)?**  
JWT

**How To Reproduce (If applicable)**  
Steps to reproduce the behavior:

1. create an test.py, paste the code above, change key and sec,  
python3 test.py
2. See error

---

<div class="post-metadata">

**Author:** ![TomJerry](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tomjerry/32/19139_2.png) [@TomJerry](https://devforum.zoom.us/u/TomJerry)\
**Post date:** [November 23, 2020, 9:07pm UTC](https://devforum.zoom.us/t/always-get-invalid-access-token-using-python-and-jwt/36741/2 "2020-11-23T21:07:47Z")

</div>

I find the issue. I have to create a JWT app. Then use the key and secret generate for JWT app.  
The previous one is a SDK app, that’s why it’s key and secret doesn’t work

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [November 24, 2020, 8:51pm UTC](https://devforum.zoom.us/t/always-get-invalid-access-token-using-python-and-jwt/36741/3 "2020-11-24T20:51:02Z")

</div>

Hey @TomJerry, glad you were able to figure this out! 💯

Best,  
Will

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [December 25, 2020, 6:51am UTC](https://devforum.zoom.us/t/always-get-invalid-access-token-using-python-and-jwt/36741/4 "2020-12-25T06:51:19Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
