# Android SDK JWT Token

**URL:** <https://devforum.zoom.us/t/android-sdk-jwt-token/19355>\
**Category:** Android\
**Created:** [May 28, 2020, 8:41am UTC](https://devforum.zoom.us/t/android-sdk-jwt-token/19355 "2020-05-28T08:41:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![emre](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/emre/32/4132_2.png) [@emre](https://devforum.zoom.us/u/emre)\
**Post date:** [May 28, 2020, 8:41am UTC](https://devforum.zoom.us/t/android-sdk-jwt-token/19355/1 "2020-05-28T08:41:58Z")

</div>

**Description**  
Initialize SDK with JWT Error Code 1

**Which version?**  
v4.6.21666.0429

**Additional context**  
Hi,  
when I try to initialize sdk with jwt token getting errorCode=1  
if I try to initialize with sdk\_key and secret it works  
Followed the steps below

1-builded app with type sdks

2-generated jwt with code below:

String getJWTToken(){  
long time = System.currentTimeMillis()/1000 + 60\*1000;

```
    String header = "{\"alg\": \"HS256\", \"typ\": \"JWT\"}";
    String payload = "{\"appKey\": \"" + Constants.SDK_KEY + "\""
            + ", \"iat\": " + String.valueOf(time)
            + ", \"exp\": " + String.valueOf(time)
            + ", \"tokenExp\": " + String.valueOf(time)
            + "}";
    try {
        String headerBase64Str = Base64.encodeToString(header.getBytes("utf-8"), Base64.NO_WRAP| Base64.NO_PADDING | Base64.URL_SAFE);
        String payloadBase64Str = Base64.encodeToString(payload.getBytes("utf-8"), Base64.NO_WRAP| Base64.NO_PADDING | Base64.URL_SAFE);
        final Mac mac = Mac.getInstance("HmacSHA256");
        SecretKeySpec secretKeySpec = new SecretKeySpec(Constants.SDK_SECRET.getBytes(), "HmacSHA256");
        mac.init(secretKeySpec);

        byte[] digest = mac.doFinal((headerBase64Str + "." + payloadBase64Str).getBytes());

        return headerBase64Str + "." + payloadBase64Str + "." + Base64.encodeToString(digest, Base64.NO_WRAP| Base64.NO_PADDING | Base64.URL_SAFE);
    } catch (NoSuchAlgorithmException e) {
        e.printStackTrace();
    } catch (UnsupportedEncodingException e) {
        e.printStackTrace();
    } catch (InvalidKeyException e) {
        e.printStackTrace();
    }
    return null;
}

```

3-passed jwt to init params

could you help me ? 🙂

---

<div class="post-metadata">

**Author:** ![carson.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/carson.zoom/32/785_2.png) [@carson.zoom](https://devforum.zoom.us/u/carson.zoom)\
**Post date:** [May 29, 2020, 7:34am UTC](https://devforum.zoom.us/t/android-sdk-jwt-token/19355/2 "2020-05-29T07:34:38Z")

</div>

Hi @emre,

Thanks for using Zoom SDK. Here is the payload of the JWT token(As mentioned in [https://marketplace.zoom.us/docs/sdk/native-sdks/iOS/mastering-zoom-sdk/sdk-initialization](https://marketplace.zoom.us/docs/sdk/native-sdks/iOS/mastering-zoom-sdk/sdk-initialization)):

```auto
{
  	"appKey": "string", // Your SDK key
        "iat": long, // access token issue timestamp
        "exp": long, // access token expire timestamp, iat + a time less than 48 hours
	"tokenExp": long // token expire timestamp, MIN:1800 seconds
}

```

Based on the code snippet, it seems like your `iat` and `exp` are the same, and the `tokenExp` should be a timestamp that is at least iat + 1800 seconds.

Hope this helps. Thanks!

---

<div class="post-metadata">

**Author:** ![emre](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/emre/32/4132_2.png) [@emre](https://devforum.zoom.us/u/emre)\
**Post date:** [June 1, 2020, 10:17am UTC](https://devforum.zoom.us/t/android-sdk-jwt-token/19355/3 "2020-06-01T10:17:19Z")

</div>

thanks for the reply,  
can you explain what is iat and exp?  
If could you give me an example with right values for iat, exp and tokenExp it would be perfect 🙂  
should I use seconds or milliseconds?

If I get and pass valid JWT can I use it for SSO login?[SSO Login](https://marketplace.zoom.us/docs/sdk/native-sdks/android/mastering-zoom-sdk/start-join-meeting/sso-login-user/authentication)  
Do I need another token for that?

Thank you

---

<div class="post-metadata">

**Author:** ![carson.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/carson.zoom/32/785_2.png) [@carson.zoom](https://devforum.zoom.us/u/carson.zoom)\
**Post date:** [June 3, 2020, 11:38am UTC](https://devforum.zoom.us/t/android-sdk-jwt-token/19355/4 "2020-06-03T11:38:12Z")

</div>

Hi @emre,

`iat` is the access token issue timestamp and `exp` is the access token expire timestamp. The `exp` should be `iat + a time less than 48 hours`.

An example would be:

```auto
{
"appKey": "SDK key",
"iat": 1591184085,
"exp": 1591228800,
"tokenExp": 1591226800
}

```

This JWT token is for SKD initialization. SSO login will expect a SSO token returned from the IdP.

Thanks!

---

<div class="post-metadata">

**Author:** ![DeveloperBot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/developerbot/32/12632_2.png) [@DeveloperBot](https://devforum.zoom.us/u/DeveloperBot)\
**Post date:** [August 21, 2020, 9:49pm UTC](https://devforum.zoom.us/t/android-sdk-jwt-token/19355/5 "2020-08-21T21:49:34Z")

</div>


