# Bad request on In-client OAuth server side token request

**URL:** <https://devforum.zoom.us/t/bad-request-on-in-client-oauth-server-side-token-request/71650>\
**Category:** Zoom Apps\
**Tags:** oauth, pkce-flow, pkce\
**Created:** [July 5, 2022, 6:29am UTC](https://devforum.zoom.us/t/bad-request-on-in-client-oauth-server-side-token-request/71650 "2022-07-05T06:29:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![auke.vanscheltinga](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@auke.vanscheltinga](https://devforum.zoom.us/u/auke.vanscheltinga)\
**Post date:** [July 5, 2022, 6:29am UTC](https://devforum.zoom.us/t/bad-request-on-in-client-oauth-server-side-token-request/71650/1 "2022-07-05T06:29:37Z")

</div>

1. I generate the 32 bit code verifier client side

```auto
function generateRandomString(length) {
  var text = "";
  var possible = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789";

  for (var i = 0; i < length; i++) {
    text += possible.charAt(Math.floor(Math.random() * possible.length));
  }

  return text;
}

```

1. I listen for the onAuthorized event.

```auto
zoomSdk.addEventListener("onAuthorized", function(event){
        event.verifier = codeVerifier
      jsonRequest(api_url + "/client_authorize" , event, 'POST', async function (json) {
        if (json != null) {
          console.log(json)
        }
      })
    console.log(event)
  })

```

1. I sent a random state and codeChallenge to the zoom api (using the codeVerifier as codeChallenge as it is PKCE plain)

```auto
const result = await zoomSdk.callZoomApi("authorize", {
              "state": state,
              "codeChallenge": codeVerifier
            })

```

1. at the server side I send a tokenRequest using the unchanged code form the zoomapps-sample-js on github, (it works when I use the tranditional OAuth flow)
2. Getting 400 bad request, does anyone know why this is a bad request?

Thank you,  
Auke van Scheltinga

---

<div class="post-metadata">

**Author:** ![auke.vanscheltinga](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@auke.vanscheltinga](https://devforum.zoom.us/u/auke.vanscheltinga)\
**Post date:** [July 5, 2022, 7:37am UTC](https://devforum.zoom.us/t/bad-request-on-in-client-oauth-server-side-token-request/71650/2 "2022-07-05T07:37:22Z")

</div>

Tried to implement using the [GitHub - zoom/zoomapps-advancedsample-react: This repository contains an Advanced Zoom Apps Sample. It should serve as a starting point for you to build and test your own Zoom App in development.](https://github.com/zoom/zoomapps-advancedsample-react.git) (generate the challenge server side):

```auto
crypto.randomBytes(64).toString('hex')

```

Getting the same result, 400 bad request.

Kind regards,  
Auke van Scheltinga

---

<div class="post-metadata">

**Author:** ![auke.vanscheltinga](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@auke.vanscheltinga](https://devforum.zoom.us/u/auke.vanscheltinga)\
**Post date:** [July 5, 2022, 8:19am UTC](https://devforum.zoom.us/t/bad-request-on-in-client-oauth-server-side-token-request/71650/3 "2022-07-05T08:19:58Z")

</div>

It wasn’t the crypto, it turned out to be the **redirectUrl**. If you use the In client OAuth flow the Zoom api takes the redirectUrl to be the **current url**. Make sure to update your serverside tokenRequest method to use this current url as redirectUrl . In my case I was reusing the tokenRequest from the zoom app sample which uses a fixed redirect url set by an environment variable on application boot.

---

<div class="post-metadata">

**Author:** ![MaxM](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/maxm/32/42303_2.png) [@MaxM](https://devforum.zoom.us/u/MaxM)\
**Post date:** [July 5, 2022, 11:32pm UTC](https://devforum.zoom.us/t/bad-request-on-in-client-oauth-server-side-token-request/71650/4 "2022-07-05T23:32:18Z")

</div>

@auke.vanscheltinga I’m glad to hear that you were able to get this sorted out! Thanks for sharing your solution.
