# C# JWT token invalid

**URL:** <https://devforum.zoom.us/t/c-jwt-token-invalid/5968>\
**Category:** API and Webhooks\
**Created:** [September 19, 2019, 10:15pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968 "2019-09-19T22:15:47Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![nvanderson](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/nvanderson/32/20082_2.png) [@nvanderson](https://devforum.zoom.us/u/nvanderson)\
**Post date:** [September 19, 2019, 10:15pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/1 "2019-09-19T22:15:47Z")

</div>

I am having an issue with token, the error is invalid token.  
Please help.

```
string key = "MY_Key";
             

                var securityKey = new Microsoft.IdentityModel.Tokens.SymmetricSecurityKey(Encoding.UTF8.GetBytes(key));
                var credentials = new Microsoft.IdentityModel.Tokens.SigningCredentials(securityKey, SecurityAlgorithms.HmacSha256);
                var header = new JwtHeader(credentials);
                var payload = new JwtPayload
                   {
                        { "iss", "my_API"},
                      { "iat", DateTimeOffset.Now.ToUnixTimeSeconds() },
                       { "exp", DateTimeOffset.Now.ToUnixTimeSeconds() + 1400 },
                   };
                        
                var secToken = new JwtSecurityToken(header, payload);
                var handler = new JwtSecurityTokenHandler();

                var tokenString = handler.WriteToken(secToken);

                Console.WriteLine(tokenString);
               
                var token = handler.ReadJwtToken(tokenString);

                Console.WriteLine(token.Payload.First().Value);
          
                RestClient client = new RestClient();
                client.BaseUrl = new Uri("https://api.zoom.us/v2");
           
                RestRequest request = new RestRequest("/users", Method.GET);
                request.AddHeader("Authorization", "Bearer " + tokenString.ToString());
               
                request.AddHeader("User-Agent", "Zoom-api-Jwt-Request");
                request.AddHeader("Content-Type", "application/json");
                var response = client.Execute(request);
                Console.Write(response.StatusCode);
```

---

<div class="post-metadata">

**Author:** ![ojus.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/ojus.zoom/32/734_2.png) [@ojus.zoom](https://devforum.zoom.us/u/ojus.zoom)\
**Post date:** [September 19, 2019, 10:31pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/2 "2019-09-19T22:31:14Z")

</div>

Hi @nvanderson,

Welcome to the Zoom Developer Forum. We are happy to help you.

- If you are using the windows SDK, then there are two types of Authentications that you need to do within your implementation:

1. SDK Authentication
2. JWT Authentication

To do the **SDK Authentication** , you would need the SDK API key and secret. To get the SDK key and secret, please visit [https://marketplace.zoom.us/docs/sdk/native-sdks/preface/sdk-keys-secrets](https://marketplace.zoom.us/docs/sdk/native-sdks/preface/sdk-keys-secrets). The SDK authentication is necessary for Zoom to allow you to use our SDKs.

**JWT Authentication:** If you need to do JWT authentication, please refer to the example mentioned here: [https://github.com/zoom/zoom-sdk-windows/blob/45f58efe46cab9af80e2d9a7f24a1893e75a34c9/demo/sdk\_demo\_v2/zoomHmacSHA256.cpp](https://github.com/zoom/zoom-sdk-windows/blob/45f58efe46cab9af80e2d9a7f24a1893e75a34c9/demo/sdk_demo_v2/zoomHmacSHA256.cpp). Even though this code is not written in C#, it is based on the same logic.  
The JWT token enables you to use our APIs. To find a list of all our APIs, please visit: [https://marketplace.zoom.us/docs/api-reference/introduction](https://marketplace.zoom.us/docs/api-reference/introduction)

- To generate a JWT token, please ensure that you are using the correct API key/secret, **not SDK key/secret**

- Please refer to this sample code for generating JWT tokens in our Windows demo app: [https://github.com/zoom/zoom-sdk-windows/blob/45f58efe46cab9af80e2d9a7f24a1893e75a34c9/demo/sdk\_demo\_v2/zoomHmacSHA256.cpp](https://github.com/zoom/zoom-sdk-windows/blob/45f58efe46cab9af80e2d9a7f24a1893e75a34c9/demo/sdk_demo_v2/zoomHmacSHA256.cpp)

I hope this helps.

Thanks

---

<div class="post-metadata">

**Author:** ![nvanderson](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/nvanderson/32/20082_2.png) [@nvanderson](https://devforum.zoom.us/u/nvanderson)\
**Post date:** [September 20, 2019, 12:13am UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/3 "2019-09-20T00:13:42Z")

</div>

Yes I followed the links, unfortunately they did not solve my problem.

@michael_p.zoom can you take a look here?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [September 20, 2019, 5:25pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/4 "2019-09-20T17:25:55Z")

</div>

Hey @nvanderson,

Can you try hard coding the JWT token from your Zoom App Dashboard and see if the error goes away?

 ![19%20AM](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/c/c13bc61ad21b38049be4e284b409892f96336d61.png)

`request.AddHeader("Authorization", "Bearer JWTTOKEN");`

If it works, that would mean your JWT generation code is not working properly.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![nvanderson](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/nvanderson/32/20082_2.png) [@nvanderson](https://devforum.zoom.us/u/nvanderson)\
**Post date:** [September 20, 2019, 5:43pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/5 "2019-09-20T17:43:14Z")

</div>

Yes, the hard-coded value works. I am trying to figure our what is wrong the token generation…?!🤔

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [September 20, 2019, 7:30pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/6 "2019-09-20T19:30:33Z")

</div>

Hey @nvanderson,

I am no expert in C#. You can try using one of the .net libraries here to generate the JWT.

> **[JWT.IO](https://jwt.io/)**
>
> JSON Web Tokens are an open, industry standard RFC 7519 method for representing claims securely between two parties.

Also check out this stack overflow question about how to generate a JWT in C#

> <https://stackoverflow.com/questions/40281050/jwt-authentication-for-asp-net-web-api/40284152#40284152>

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![nvanderson](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/nvanderson/32/20082_2.png) [@nvanderson](https://devforum.zoom.us/u/nvanderson)\
**Post date:** [September 23, 2019, 7:03pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/8 "2019-09-23T19:03:11Z")

</div>

Finally figure it out…😆

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [September 23, 2019, 7:04pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/9 "2019-09-23T19:04:11Z")

</div>

Happy to hear @nvanderson 🙂

If you don’t mind, could you post the solution so if others have trouble they can see how you fixed it?

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![nvanderson](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/nvanderson/32/20082_2.png) [@nvanderson](https://devforum.zoom.us/u/nvanderson)\
**Post date:** [September 23, 2019, 7:24pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/10 "2019-09-23T19:24:05Z")

</div>

According to this [https://marketplace.zoom.us/docs/guides/authorization/jwt/jwt-with-zoom](https://marketplace.zoom.us/docs/guides/authorization/jwt/jwt-with-zoom)  
only 2 parameters are needed inside the playload.  
{ “iss”: “API\_KEY”,  
“exp”: 1496091964000  
}

However, 4 are needed  
string s =null;  
like this { aud = s, iss = Key, exp = secondsSinceEpoch, iat= NowsecondsSinceEpoch };

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [September 23, 2019, 7:27pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/11 "2019-09-23T19:27:38Z")

</div>

Thanks for posting this @nvanderson!

---

<div class="post-metadata">

**Author:** ![jtuschman](https://avatars.discourse-cdn.com/v4/letter/j/a587f6/32.png) [@jtuschman](https://devforum.zoom.us/u/jtuschman)\
**Post date:** [April 7, 2020, 2:16pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/12 "2020-04-07T14:16:13Z")

</div>

Hi Sr,

I was trying to reproduce the authorization process by testing with the JWT token and I got Unauthorized because an Invalid access token:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/c/c6515e7c281ce09f12e2fa853d1d84f9f2742e6a.png)

The token was taken from the test kwt on app info

Any help will be appreciatte.

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [April 7, 2020, 9:24pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/13 "2020-04-07T21:24:17Z")

</div>

Hey @jtuschman,

Please see my post here:

> [@JWT App is not working on multiple Zoom accounts](https://devforum.zoom.us/t/jwt-app-is-not-working-on-multiple-zoom-accounts/11672/4):
>
> Hey @hanson, Can you try activating and reactivating your JWT App and try again? Thanks, Tommy

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![jtuschman](https://avatars.discourse-cdn.com/v4/letter/j/a587f6/32.png) [@jtuschman](https://devforum.zoom.us/u/jtuschman)\
**Post date:** [April 7, 2020, 9:27pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/14 "2020-04-07T21:27:32Z")

</div>

I did that but it did not work., even tho, I re-generated a new key and it did not work as well

---

<div class="post-metadata">

**Author:** ![nvanderson](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/nvanderson/32/20082_2.png) [@nvanderson](https://devforum.zoom.us/u/nvanderson)\
**Post date:** [April 7, 2020, 9:39pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/15 "2020-04-07T21:39:05Z")

</div>

Did you include today’s date and token exp.date in Unix format?

---

<div class="post-metadata">

**Author:** ![jtuschman](https://avatars.discourse-cdn.com/v4/letter/j/a587f6/32.png) [@jtuschman](https://devforum.zoom.us/u/jtuschman)\
**Post date:** [April 7, 2020, 9:48pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/16 "2020-04-07T21:48:06Z")

</div>

Actually I’m testing with the JWT token that you provided me on my app JWT dashboard, this JWT token need to be necessary to know if the authorization is granted. And this one did not work either

Best,  
Jason

---

<div class="post-metadata">

**Author:** ![jtuschman](https://avatars.discourse-cdn.com/v4/letter/j/a587f6/32.png) [@jtuschman](https://devforum.zoom.us/u/jtuschman)\
**Post date:** [April 7, 2020, 9:50pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/17 "2020-04-07T21:50:03Z")

</div>

Actually I read another post:

> [@JTW app - "Invalid access token." error on API calls](https://devforum.zoom.us/t/jtw-app-invalid-access-token-error-on-api-calls/11591/9):
>
> Even tho, I used the JWT token for testing purposes after deactivate and reactivate again and I’m still getting the same issue. Any suggestions here @tkrevh

where this issue is occurring since last days… so maybe is related to my concern, I’m just want to validate and check where it could be solved

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [April 8, 2020, 7:47am UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/18 "2020-04-08T07:47:10Z")

</div>

Hey @jtuschman,

Yes, this is a caching issue, can you please try again tomorrow?

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![Fitpass](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/fitpass/32/6007_2.png) [@Fitpass](https://devforum.zoom.us/u/Fitpass)\
**Post date:** [April 13, 2020, 8:30pm UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/19 "2020-04-13T20:30:00Z")

</div>

I’m using the JWT as provided by the Zoom page “credentials” for my Marketplace app.

I am trying the token using the Curl code as provided by the Zoom page at [https://marketplace.zoom.us/docs/guides/auth/jwt](https://marketplace.zoom.us/docs/guides/auth/jwt) :

```auto
curl --request GET \
  --url 'https://api.zoom.us/v2/users?status=active&page_size=30&page_number=1' \
  --header 'authorization: Bearer 39ug3j309t8unvmlmslmlkfw853u8' \
  --header 'content-type: application/json

```

(I simply replace “39ug3j309t8unvmlmslmlkfw853u8” with my JWT token as provided by the Zoom web page “credentials” for my app)

**I receive the error message "Invalid access token."**

Please help.

---

<div class="post-metadata">

**Author:** ![nvanderson](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/nvanderson/32/20082_2.png) [@nvanderson](https://devforum.zoom.us/u/nvanderson)\
**Post date:** [April 14, 2020, 1:00am UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/20 "2020-04-14T01:00:05Z")

</div>

I think you need to include exp.date and todays date, so

4 total parameters are needed

string s =null;

like this { aud = s, iss = Key, exp = secondsSinceEpoch, iat= NowsecondsSinceEpoch };

---

<div class="post-metadata">

**Author:** ![Fitpass](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/fitpass/32/6007_2.png) [@Fitpass](https://devforum.zoom.us/u/Fitpass)\
**Post date:** [April 14, 2020, 2:50am UTC](https://devforum.zoom.us/t/c-jwt-token-invalid/5968/21 "2020-04-14T02:50:05Z")

</div>

Thanks - I’ll give it a go, and I really do appreciate your reply.

But I’m using the JWT as created by the Zoom page, so surely Zoom will include any params that Zoom requires? I’m not creating the JWT using my own code (yet).

If my own JWT code works, I’ll update you here.

Either:

1. the Zoom page is giving me a bad JWT token, or…
2. the Zoom API is incorrectly rejecting my JWT token

[Next page](https://devforum.zoom.us/t/c-jwt-token-invalid/5968.md?page=2)
