# Clarification regarding "client\_credentials" access\_token

**URL:** <https://devforum.zoom.us/t/clarification-regarding-client-credentials-access-token/135631>\
**Category:** Authentication\
**Created:** [July 24, 2025, 3:11pm UTC](https://devforum.zoom.us/t/clarification-regarding-client-credentials-access-token/135631 "2025-07-24T15:11:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ucczoomaruba](https://avatars.discourse-cdn.com/v4/letter/u/e56c9b/32.png) [@ucczoomaruba](https://devforum.zoom.us/u/ucczoomaruba)\
**Post date:** [July 24, 2025, 3:11pm UTC](https://devforum.zoom.us/t/clarification-regarding-client-credentials-access-token/135631/1 "2025-07-24T15:11:43Z")

</div>

**API Endpoint(s) and/or Zoom API Event(s)**

- oauth: [https://zoom.us/oauth/token?grant\_type=client\_credentials](https://zoom.us/oauth/token?grant_type=client_credentials) \*

**Description**  
I would like to get some clarification on the usage of client\_credentials type of access\_token which is used to subscribe for different events for an account.

Here are the steps used while testing:

1. A ‘General app’ type marketplace app, GEN\_APP, is created using an account ACT1. This is still in ‘Development’ and in ‘Production’ mode so is limited to this account ACT1. CLIENT\_ID & CLIENT\_SECRET from this app is stored.
2. The admin user of this account ACT1 tries to install this app GEN\_APP and calls: **MARKETPLACE/authorize?client\_id=\<CLIENT\_ID\>&response\_type=code&redirect\_uri=\<REDIRECT\_URL\>**
3. Code is received in the REDIRECT\_URL and then OAuth process is initiated using “grant\_type”:“authorization\_code” which results in getting access\_token (AUTH\_ACCESS\_TOKEN\_1). This access\_token is subsequently used for API resource calls.
4. Once the above step is complete, one more access\_token ( **CLIENT\_ACCESS\_TOKEN** ) is fetched using “grant\_type”:“ **client\_credentials** ”. Please note, there is no need of ‘code’ parameter here received in Step 3. This new access\_token is subsequently used to subscribe for different events using /v2/marketplace/app/event\_subscription for above ACT1 (payload consists of “events”:[“meeting.ended”], “event\_webhook\_url”:\<WEBHOOK\_CALLBACK\>, “subscription\_scope”: “account”, “account\_id”: ACT1). “event\_subscription\_id”: SUBS\_ID\_1 is received.

So once the above things are done, events are being received in the above WEBHOOK\_CALLBACK. This is all good so far.

But now, I am interested in getting one more account ACT2 to install this GEN\_APP.

This admin of **ACT2** would have to go through the same above steps. However, I have my concern related to the access\_token for grant\_type:client\_credentials for event subscription for this ACT2.

Can I use the same **CLIENT\_ACCESS\_TOKEN** received in above Step 4. to subscribe for events for this new account **ACT2** or yet another one needs to be created?

Since there is no ‘code’ dependency and this is kind of marketplace app specific, I assume the same CLIENT\_ACCESS\_TOKEN can be used for this new ACT2.

Since our marketplace GEN\_APP is still in ‘Development’ mode, I am unable to test this for the other account ACT2 in my setup.

@elisa.zoom Can you please check this & confirm.

---

<div class="post-metadata">

**Author:** ![expertswho](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/expertswho/32/60945_2.png) [@expertswho](https://devforum.zoom.us/u/expertswho)\
**Post date:** [July 24, 2025, 4:21pm UTC](https://devforum.zoom.us/t/clarification-regarding-client-credentials-access-token/135631/2 "2025-07-24T16:21:47Z")

</div>

hi @ucczoomaruba ,

When you go through the auth processes you have the client\_access and secret which allows the app to be initiated.  
Each user will get an access token back which is unique to that user on that account.  
This is how zoom, in most cases, will identify who has connected.

If another user goes through the oauth process, then they will get back a different access token.

This is how Zoom can tell who is who.  
I said most, becusae if you use the appsdk in a Zoom app, then those calls are authorised becasue you are in the Zoom App and authorsed by it. However you would still need the token if you did an API call back to Zoom.

I hope that explains it better

John

---

<div class="post-metadata">

**Author:** ![ucczoomaruba](https://avatars.discourse-cdn.com/v4/letter/u/e56c9b/32.png) [@ucczoomaruba](https://devforum.zoom.us/u/ucczoomaruba)\
**Post date:** [July 24, 2025, 4:36pm UTC](https://devforum.zoom.us/t/clarification-regarding-client-credentials-access-token/135631/3 "2025-07-24T16:36:51Z")

</div>

Hi @expertswho  
I think I wasn’t clear enough when I said:  
“This admin of ACT2 would have to go through the same above steps. However, I have my concern related to the access\_token for grant\_type:client\_credentials for event subscription for this ACT2.”

Yes, I am aware that each user will have to fetch unique access\_token in order to use for API calls. And this access\_token is for grant\_type: **authorization\_code**. This case is clear, as mentioned before.

However, I am talking about the other type of access\_token used for event subscription i.e. grant\_type: **client\_credentials**. This is obtained using client\_id & client\_secret of the marketplace app ONLY and does NOT have the ‘code’ dependency during 0Auth process.

Please check my above details again.

---

<div class="post-metadata">

**Author:** ![ucczoomaruba](https://avatars.discourse-cdn.com/v4/letter/u/e56c9b/32.png) [@ucczoomaruba](https://devforum.zoom.us/u/ucczoomaruba)\
**Post date:** [July 29, 2025, 4:29am UTC](https://devforum.zoom.us/t/clarification-regarding-client-credentials-access-token/135631/4 "2025-07-29T04:29:08Z")

</div>

Hi @expertswho  
Can you please check this and provide me the info required?

Well, I just want to know if the **same** ‘Client authorization’ access\_token be used to subscribe events for 2 different accounts/customers?

Please note, this access\_token is obtained using:  
POST [https://zoom.us/oauth/token?grant\_type=\*\*client\_credentials](https://zoom.us/oauth/token?grant_type=**client_credentials)\*\*

And events are subscribed using:  
POST /marketplace/app/event\_subscription  
Payload:

```auto
{
  "events": [
    "meeting.created"
  ],
  "event_subscription_name": "Example Event Subscription",
  "event_webhook_url": "https://www.example.com",
  "user_ids": [],
  "subscription_scope": "account",
  "account_id": "pvg3UAgpRlyTDW-9sIpKcw"
}

```

---

<div class="post-metadata">

**Author:** ![expertswho](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/expertswho/32/60945_2.png) [@expertswho](https://devforum.zoom.us/u/expertswho)\
**Post date:** [July 29, 2025, 12:48pm UTC](https://devforum.zoom.us/t/clarification-regarding-client-credentials-access-token/135631/5 "2025-07-29T12:48:24Z")

</div>

hi @ucczoomaruba ,  
The OAuth secret process returns a copy that is unique for that user using your app.  
It DOES not return the same code for every OAuth.

Each customer/user must have done the OAuth to get their secret key and their refresh key.

For each api, you will then be passing back that code and an encoded string, which gives you the authority to request the api.

Zoom will then check that API call against the scopes you have requested, and will then return the data if it is a valid request  
.  
There are so many examples from Zoom

> **[Zoom](https://github.com/zoom)**
>
> Power Up Your Apps with Video, Phone, and Chat. Zoom has 113 repositories available. Follow their code on GitHub.

All the best

John

---

<div class="post-metadata">

**Author:** ![ucczoomaruba](https://avatars.discourse-cdn.com/v4/letter/u/e56c9b/32.png) [@ucczoomaruba](https://devforum.zoom.us/u/ucczoomaruba)\
**Post date:** [July 29, 2025, 3:03pm UTC](https://devforum.zoom.us/t/clarification-regarding-client-credentials-access-token/135631/6 "2025-07-29T15:03:18Z")

</div>

Hi @expertswho  
I am sorry to say that my concern is not understood again.

Let me try to explain it again:

1. First step for each user/account is to initiate below authorize call to get ‘code’:  
oauth/authorize?response\_type=code&client\_id=ZOOM\_CLIENT\_ID&redirect\_uri=ZOOM\_REDIRECT\_URL
2. I am aware of OAuth process where using ‘code’ param received during redirect URL, each user/account will request for access\_token & refresh\_token to access/call API resources. And this is done using:  
POST [https://zoom.us/oauth/token?grant\_type=authorization\_code](https://zoom.us/oauth/token?grant_type=authorization_code)
3. Please note, above grant\_type is **authorization\_code** and this access\_token obtained is for subsequent API calls such as for:  
/v2/metrics/meetings/\<MEETING\_ID\>/participants?type=past.
4. And I am also aware this access\_token is unique to each user/account. So each user/account/customer would have to get a different one using the client\_id & client\_secret & **code** params to get this.
5. So this is all clear so far. No confusion here.
6. Now, there is another access\_token that a user/account can obtain using grant\_type **client\_credentials** i.e.:  
POST [https://zoom.us/oauth/token?grant\_type=client\_credentials](https://zoom.us/oauth/token?grant_type=client_credentials)
7. The access\_token obtained using grant\_type: client\_credentials, is used to subscribe to events such as “meeting.started” using below APIs dynamically:  
POST /marketplace/app/event\_subscription
8. For this access\_token, only the client\_id & client\_secret of the marketplace app is required and no ‘code’ param, due to which it seems to be NOT a unique for each user/account. However, the subscriptions in step. 6 are for each user/account based on the payload for the event\_subscription API. Also note, there is no refresh\_token for this type. This token expires after 3599 and the same process has to followed to get a new token without refresh\_token.  
And I did NOT have to call below authorize call for redirection to get ‘code’ for this, as it’s not required here:  
oauth/authorize?response\_type=code&client\_id=ZOOM\_CLIENT\_ID&redirect\_uri=ZOOM\_REDIRECT\_URL
9. This above step is also fine. It’s working all fine so far i.e. obtaining access\_token (grant\_type:client\_crendentials) & subscribing events. I am even getting the event notifications to my webhook URL registered once the meeting starts.

So now coming to my concern.  
I just want to confirm whether the access\_token that is obtained using grant\_type: client\_credentials, i.e. in above step. 5, remains same for each marketplace app, and whether the same one can be used to subscribe for events for different users/accounts (with different payloads consisting of “account\_id” & others mentioned in my previous comment)?

(As I mentioned before, I could have tested this myself but there is a limitation with **unpublished** marketplace apps where other users/accounts cannot install it, so I am unable to test this currently)

It would be great if some extra eyes can be added to this issue, perhaps from your team. @elisa.zoom can you please help in this?

I hope my above details will help this time to understand my actual issue.

And I seriously hope that I am not missing anything here or not understanding what you have replied so far.

Feel free to ask for more info, if required.  
Thanks

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [July 30, 2025, 8:14pm UTC](https://devforum.zoom.us/t/clarification-regarding-client-credentials-access-token/135631/7 "2025-07-30T20:14:11Z")

</div>

Hi @ucczoomaruba thanks for reaching out to us and thanks @expertswho for jumping in and sharing your experience!

You are spot on! You can generate access tokens using grant\_type=client\_credentials to create event subscriptions for a specific app. This token can only be used with that set of endpoints, and it will only work for the specific app it was generated for.

So yes, you should be able to use it with different payloads but always against the same app.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![ucczoomaruba](https://avatars.discourse-cdn.com/v4/letter/u/e56c9b/32.png) [@ucczoomaruba](https://devforum.zoom.us/u/ucczoomaruba)\
**Post date:** [July 31, 2025, 4:14am UTC](https://devforum.zoom.us/t/clarification-regarding-client-credentials-access-token/135631/8 "2025-07-31T04:14:27Z")

</div>

Thanks @elisa.zoom for confirming this.
