# Bug with http:// redirect

**URL:** <https://devforum.zoom.us/t/bug-with-http-redirect/6706>\
**Category:** API and Webhooks\
**Created:** [November 18, 2019, 5:05pm UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706 "2019-11-18T17:05:36Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![ryan](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/ryan/32/37137_2.png) [@ryan](https://devforum.zoom.us/u/ryan)\
**Post date:** [November 18, 2019, 5:05pm UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/1 "2019-11-18T17:05:36Z")

</div>

**Description/Error**  
When using an http (NOT https) redirect url, Zoom will change the `redirect_uri` param to https and then fail to redirect.

**How To Reproduce**  
Steps to reproduce the behavior:

1. Setup an application with an http redirect e.g. `http://localhost:3000/_/zoom_redirect`
2. Make sure the user is logged out from Zoom
3. Start the Zoom Oauth Flow by redirecting the user to `https://zoom.us/oauth/authorize?client_id=XXX&redirect_uri=http%3A%2F%2Flocalhost%3A3000%2F_%2Fzoom_redirect&response_type=code&state=YYY`
4. Login to Zoom with Google.
5. Get an Zoom error page (NB https):

> Invalid redirect: [https://localhost:3000/\_/zoom\_redirect](https://localhost:3000/_/zoom_redirect) (4,700)

This is hopefully only an issue for local development but is still pretty annoying!

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [November 18, 2019, 11:00pm UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/2 "2019-11-18T23:00:34Z")

</div>

Hey @ryan,

Can you try this to resolve the issue:

> [@Zoom Application Wrong redirect](https://devforum.zoom.us/t/zoom-application-wrong-redirect/4402/5):
>
> Hey @subhan, This issue only happens with localhost urls. To solve this you could use [https://ngrok.com/](https://ngrok.com/) to turn your localhost server into a free server with a url, and replace the localhost redirect url with the ngrok url. Instead of [http://localhost:8080/api/v1/zoom/complete-oauth](http://localhost:8080/api/v1/zoom/complete-oauth) it would be [https://d4c4477b.ngrok.io/api/v1/zoom/complete-oauth](https://d4c4477b.ngrok.io/api/v1/zoom/complete-oauth) This way you can still develop and test locally and have your redirect url work! Let me know if this helps!

Let me know if this works!

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![ryan](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/ryan/32/37137_2.png) [@ryan](https://devforum.zoom.us/u/ryan)\
**Post date:** [November 18, 2019, 11:15pm UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/3 "2019-11-18T23:15:44Z")

</div>

It definitely does work, but we’ve had some issues running all of our traffic over ngrok so we’re reserving it just for webhooks. Self-signed certs would also be a solution but a bit of a hassle to set up…

For the time being we’ll put up with the minor annoyance and we’ll look forward to a bug fix.

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [November 19, 2019, 1:57am UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/4 "2019-11-19T01:57:45Z")

</div>

Hey @ryan,

I was able to reproduce the error. This only happens when signing in with Google. Like you said, it changes http to https.

We will work on fixing this. Thanks again for posting. JIRA: ZOOM-121664

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![edward](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/edward/32/1829_2.png) [@edward](https://devforum.zoom.us/u/edward)\
**Post date:** [January 15, 2020, 10:20pm UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/5 "2020-01-15T22:20:12Z")

</div>

Hey @tommy,  
This still seems to be an issue. Our redirect url is being changed from `http://localhost` to `https://localhost`. Any updates on this?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [January 15, 2020, 11:30pm UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/6 "2020-01-15T23:30:29Z")

</div>

Hey @edward,

No updates, I would suggest using [Ngrok](https://ngrok.io).

> [@Zoom Application Wrong redirect](https://devforum.zoom.us/t/zoom-application-wrong-redirect/4402/5):
>
> Hey @subhan, This issue only happens with localhost urls. To solve this you could use [https://ngrok.com/](https://ngrok.com/) to turn your localhost server into a free server with a url, and replace the localhost redirect url with the ngrok url. Instead of [http://localhost:8080/api/v1/zoom/complete-oauth](http://localhost:8080/api/v1/zoom/complete-oauth) it would be [https://d4c4477b.ngrok.io/api/v1/zoom/complete-oauth](https://d4c4477b.ngrok.io/api/v1/zoom/complete-oauth) This way you can still develop and test locally and have your redirect url work! Let me know if this helps!

I will keep you updated on when we are releasing a fix.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![edward](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/edward/32/1829_2.png) [@edward](https://devforum.zoom.us/u/edward)\
**Post date:** [January 22, 2020, 10:02pm UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/7 "2020-01-22T22:02:01Z")

</div>

Hey @tommy,

Yes, I saw that suggestion. Unfortunately, we deal with a large amount of traffic, and therefore using ngrok is not an ideal solution for us.

Edward

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [January 22, 2020, 10:10pm UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/8 "2020-01-22T22:10:29Z")

</div>

Hey @edward, we are working to make localhost redirect urls work.

Although, I was able to install the app successfully using `http://localhost` installing via the “Local Test” page and not using Google SSO.

Are you signing in with Google?

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![edward](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/edward/32/1829_2.png) [@edward](https://devforum.zoom.us/u/edward)\
**Post date:** [January 24, 2020, 12:10am UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/9 "2020-01-24T00:10:46Z")

</div>

Hey @tommy,

What do you mean by “Local Test”?  
Re: using Google SSO- I am observing this as an issue for both Google SSO and for Zoom account logins.

Thanks,  
Edward

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [January 24, 2020, 12:12am UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/10 "2020-01-24T00:12:58Z")

</div>

Hey @edward,

“Local Test” as in:

![Screen Shot 2020-01-23 at 5.11.51 PM](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/5/5acc4336d393140bd1e767c6bb20ff0017de5e1c.png)

Oh I see. The issue does not happen if you are already logged in to Zoom.

In the meantime, we are working on fixing the issue.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![martin](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/martin/32/3273_2.png) [@martin](https://devforum.zoom.us/u/martin)\
**Post date:** [February 20, 2020, 2:58pm UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/11 "2020-02-20T14:58:32Z")

</div>

Hi, I’m getting the same issue on my side. Do you have any update ?

Also, if my redirect url has 2 parameters, the last one is always deleted :  
[http://localhost/example.html?param1=blabla&param2=toto](http://localhost/example.html?param1=blabla&param2=toto)  
becomes  
[https://localhost/example.html?param1=blabla&code=zoom\_code](https://localhost/example.html?param1=blabla&code=zoom_code)

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [February 20, 2020, 6:05pm UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/12 "2020-02-20T18:05:46Z")

</div>

Hey @martin, thanks for posting and using Zoom!

No updates on this, we are still working on the issue.

As for the query params, that is intended functionality. Here is the proper way to add query params:

> [@Client ID not being recognised](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/8):
>
> Hey @rich, Here is whats happening, in your app dashboard you have https://dev.thetherapy.space/\_ajax/?ajax\_response=oauth&model=zoom&componentID=external\_connections as your redirect url. Then when you go to authorize your app: https://zoom.us/oauth/token?grant\_type=authorization\_code&code=6Y6x0lVGDt\_XXXMxyKRRhOz1obX4Z0I6g&redirect\_uri=https://dev.thetherapy.space/\_ajax/?ajax\_response=oauth&model=zoom&componentID=external\_connections Zoom handles your &model=zoom&componentID=external\_conn…

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![aurena](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/aurena/32/9770_2.png) [@aurena](https://devforum.zoom.us/u/aurena)\
**Post date:** [June 3, 2020, 3:05pm UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/13 "2020-06-03T15:05:40Z")

</div>

I am having the same issue. Installing required certificates to use https seems quite tedious on a local development environment. Is there a way to redirect locally with out using https? Ngrock seems like a proprietary solution- is there an external solution that is not proprietary.

---

<div class="post-metadata">

**Author:** ![michael.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/michael.zoom/32/37213_2.png) [@michael.zoom](https://devforum.zoom.us/u/michael.zoom)\
**Post date:** [June 5, 2020, 11:35pm UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/14 "2020-06-05T23:35:23Z")

</div>

Hi @aurena, without the creation of your own redirect to localhost, using ngrok is our suggested local testing solution. We require all redirect URLs to be HTTPS.

---

<div class="post-metadata">

**Author:** ![DeveloperBot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/developerbot/32/12632_2.png) [@DeveloperBot](https://devforum.zoom.us/u/DeveloperBot)\
**Post date:** [August 21, 2020, 9:54pm UTC](https://devforum.zoom.us/t/bug-with-http-redirect/6706/15 "2020-08-21T21:54:23Z")

</div>


