# Client ID not being recognised

**URL:** <https://devforum.zoom.us/t/client-id-not-being-recognised/5704>\
**Category:** API and Webhooks\
**Created:** [August 28, 2019, 8:31am UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704 "2019-08-28T08:31:48Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![rich](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rich/32/1029_2.png) [@rich](https://devforum.zoom.us/u/rich)\
**Post date:** [August 28, 2019, 8:31am UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/1 "2019-08-28T08:31:48Z")

</div>

Having added an App to the system and retrieved the Auth code, I can’t get a token to use as the system is returning a client ID error.

**Which Endpoint/s?**

> **[Video Conferencing, Web Conferencing, Webinars, Screen Sharing](https://zoom.us/oauth/signin?_rnd=1566981340502&client_id&redirect_uri&response_type)**
>
> Zoom is the leader in modern enterprise video communications, with an easy, reliable cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems. Zoom Rooms is the original software-based conference...

  
oauth/token  
grant\_type=authorization\_code  
code=54iFI8I27C\_XXXMxyKRRhOz1obX4Z0I6g  
redirect\_uri=https://dev.thetherapy.space/\_ajax/?ajax\_response=oauth&model=zoom&componentID=external\_connections

The client ID and Secret are base64 hashed (client\_id . ‘:’ . client\_secret) and the only header is “Authorization”:Basic . $hash

This is using cURL in PHP if it makes a difference

returns  
HTTP/1.1 100 Continue

HTTP/1.1 401 Unauthorized  
Date: Wed, 28 Aug 2019 08:21:55 GMT  
Content-Type: application/json;charset=UTF-8  
Transfer-Encoding: chunked  
Connection: keep-alive  
Server: ZOOM  
x-zm-trackingid: WEB\_d5f3aafe93b2fc784b1061ed8c18b559  
X-Content-Type-Options: nosniff  
Set-Cookie: cred=0E89C2B4CDE5B873E544ED233290AB56; Path=/; Secure; HttpOnly  
Set-Cookie: \_zm\_page\_auth=aw1\_c\_sueHhOatS-Gu\_B-DqBelEw; [Domain=.zoom.us](http://Domain=.zoom.us); Path=/; Secure; HttpOnly  
p3p: CP=“NOI ADM DEV PSAi COM NAV OUR OTR STP IND DEM”  
Set-Cookie: \_zm\_ssid=aw1\_c\_gWn3D1hhRW6ApD6HmLx6Ig; [Domain=.zoom.us](http://Domain=.zoom.us); Path=/; Secure; HttpOnly  
Cache-Control: no-store  
Pragma: no-cache

{“reason”:“Invalid client\_id or client\_secret”,“error”:“invalid\_client”}’

Clearly something is wrong but I can’t see what

---

<div class="post-metadata">

**Author:** ![michael\_p.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/michael_p.zoom/32/18105_2.png) [@michael\_p.zoom](https://devforum.zoom.us/u/michael_p.zoom)\
**Post date:** [August 28, 2019, 5:04pm UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/2 "2019-08-28T17:04:05Z")

</div>

Hi @Rich,

Are you using your development or production OAuth credentials when trying to generate an OAuth access token? Have you followed our OAuth guide within our docs[1]?  
Also, once your get your access code you can use Postman to generate an access token, just in case there is something wrong with your code.

1- [https://marketplace.zoom.us/docs/guides/authorization/oauth/oauth-with-zoom](https://marketplace.zoom.us/docs/guides/authorization/oauth/oauth-with-zoom)

---

<div class="post-metadata">

**Author:** ![rich](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rich/32/1029_2.png) [@rich](https://devforum.zoom.us/u/rich)\
**Post date:** [August 30, 2019, 7:00am UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/3 "2019-08-30T07:00:28Z")

</div>

We’re using the dev credentials. But have tried the production ones too with the same result  
Postman doesn’t appear to be of use as it’s using JWT and we want to use OAUTH

---

<div class="post-metadata">

**Author:** ![michael\_p.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/michael_p.zoom/32/18105_2.png) [@michael\_p.zoom](https://devforum.zoom.us/u/michael_p.zoom)\
**Post date:** [August 30, 2019, 3:55pm UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/4 "2019-08-30T15:55:41Z")

</div>

Hi @rich,

1. For using development credentials, make sure to local test url. From there you should see the authorization screen.  

2. After you click **Authorize** , you will be redirected to your redirect url where you can use the **OAuth Code**.  
 ![34%20AM](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/1/1848724eda724635099f9f91adb3e6173f5c34ac.png)

3. Once you get OAuth code, you can go to Postman to request your Access token. To do so, here is an example url, make sure to replace code with your OAuth code and your redirect url with what you have listed in your marketplace app. Also, for username enter in your development **client ID** and for password, enter in your developer **Client Secret**.  
[https://zoom.us/oauth/token?grant\_type=authorization\_code&code=](https://zoom.us/oauth/token?grant_type=authorization_code&code=) **m-eQMGSPM-wGA3ANg** &redirect\_uri=**[https://zoom.us](https://zoom.us)**

 ![38%20AM](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/1/13a95af268f9cab2094c9da97fb9d7f79bfe6316.png)

Let me know if that helps!

Thanks

---

<div class="post-metadata">

**Author:** ![rich](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rich/32/1029_2.png) [@rich](https://devforum.zoom.us/u/rich)\
**Post date:** [September 2, 2019, 9:16am UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/5 "2019-09-02T09:16:18Z")

</div>

Thanks for the help

Using Postman I am getting the following response:  
{  
“reason”: “Invalid request : Redirect URI mismatch.”,  
“error”: “invalid\_request”  
}

Even though the redirecturl works for the auth code and is copied directly out of the app config?  
Config redirect uri  
[https://dev.thetherapy.space/\_ajax/?ajax\_response=oauth&model=zoom&componentID=external\_connections](https://dev.thetherapy.space/_ajax/?ajax_response=oauth&model=zoom&componentID=external_connections)

URL is now : [https://zoom.us/oauth/token?grant\_type=authorization\_code&code=6Y6x0lVGDt\_XXXMxyKRRhOz1obX4Z0I6g&redirect\_uri=https://dev.thetherapy.space/\_ajax/?ajax\_response=oauth&model=zoom&componentID=external\_connections](https://zoom.us/oauth/token?grant_type=authorization_code&code=6Y6x0lVGDt_XXXMxyKRRhOz1obX4Z0I6g&redirect_uri=https://dev.thetherapy.space/_ajax/?ajax_response=oauth&model=zoom&componentID=external_connections)

Username AB\_0J0tQA2pe5altgs7Ww  
Pwd aaViFxDnrRC4PMjaNZEwo68iar7Axkq0  
Auth header is : Authorization : Basic QUJfMEowdFFBMnBlNWFsdGdzN1d3OmFhVmlGeERuclJDNFBNamFOWkV3bzY4aWFyN0F4a3Ew

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [September 3, 2019, 3:59pm UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/6 "2019-09-03T15:59:48Z")

</div>

Hey @rich,

I just tested and was able to reproduce your issue.

I believe the issue is having query params in the redirect url. Can you try removing them so your redirect url becomes `https://dev.thetherapy.space/_ajax`

`https://zoom.us/oauth/token?grant_type=authorization_code&code=6Y6x0lVGDt_XXXMxyKRRhOz1obX4Z0I6g&redirect_uri=https://dev.thetherapy.space/_ajax`

Let me know if that works!

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![rich](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rich/32/1029_2.png) [@rich](https://devforum.zoom.us/u/rich)\
**Post date:** [September 4, 2019, 1:42pm UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/7 "2019-09-04T13:42:06Z")

</div>

Thanks.

No. We can’t remove the query params, that’s how our system accepts call backs, otherwise you are probably behind a secure login.

However if the token request is only using the URI as validation we can give that a try, providing that we will never need to refresh the authorization code?

It seem odd that the URI works for supplying the auth code in the first place, and then fails when it is used again. We can’t be the first people to have query params in their redirect uri.

I will not be able to get to this until tommororw though, so will respond then.

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [September 4, 2019, 8:35pm UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/8 "2019-09-04T20:35:41Z")

</div>

Hey @rich,

Here is whats happening, in your app dashboard you have  
`https://dev.thetherapy.space/_ajax/?ajax_response=oauth&model=zoom&componentID=external_connections`  
as your redirect url.

Then when you go to authorize your app:

`https://zoom.us/oauth/token?grant_type=authorization_code&code=6Y6x0lVGDt_XXXMxyKRRhOz1obX4Z0I6g&redirect_uri=https://dev.thetherapy.space/_ajax/?ajax_response=oauth&model=zoom&componentID=external_connections`

Zoom handles your `&model=zoom&componentID=external_connections` as the base URL’s query param, so Zoom is comparing

`https://dev.thetherapy.space/_ajax/?ajax_response=oauth&model=zoom&componentID=external_connections`

with

`https://dev.thetherapy.space/_ajax/?ajax_response=oauth`

hence you getting the error:

```json
{
“reason”: “Invalid request : Redirect URI mismatch.”,
“error”: “invalid_request”
}

```

(I tested having the first query param of `?ajax_response=oauth` works, but when you add another one with `&` it breaks.)

This is the case for most OAuth flows including Googles API. ([Referencing this stack overflow answer](https://stackoverflow.com/a/7722099/6592510))

**That being said,**

The correct way to do this, is to add a query param to the end of the authorization url itself, instead of the redirect url.

For example in my App Dashboard I have `https://zoom.us` as my redirect url, and then I added a `&state=data` query param to the auth url:

`https://zoom.us/oauth/authorize?response_type=code&client_id={{ clientID }}&redirect_uri=https://zoom.us&state=somedata`

This will take you to `https://zoom.us/?code=zoiAoSEm98_KdYKjnimT4KPd8KKdQt9FQ&state=data`.

Then when requesting an access\_token, pass I pass in `https://zoom.us` as the `redirect_url` and it works.

`https://zoom.us/oauth/token?code=zoiAoSEm98_KdYKjnimT4KPd8KKdQt9FQ&grant_type=authorization_code&redirect_uri=https://zoom.us`

Let me know if this helps!

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![rich](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rich/32/1029_2.png) [@rich](https://devforum.zoom.us/u/rich)\
**Post date:** [September 5, 2019, 8:47am UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/9 "2019-09-05T08:47:37Z")

</div>

> [@tommy](#):
>
> [https://dev.thetherapy.space/\_ajax/?ajax\_response=oauth](https://dev.thetherapy.space/_ajax/?ajax_response=oauth)

HI  
Tried the suggest redirect uri.  
and  
[https://dev.thetherapy.space/\_ajax](https://dev.thetherapy.space/_ajax)

And did finally get a valid response from Postman.

On second run got  
{  
“reason”: “Invalid request : token created error: Save Access token into Database error”,  
“error”: “invalid\_request”  
}

I assume as I have a token and refresh token I can now use those to access the API.

---

<div class="post-metadata">

**Author:** ![rich](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rich/32/1029_2.png) [@rich](https://devforum.zoom.us/u/rich)\
**Post date:** [September 5, 2019, 9:52am UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/10 "2019-09-05T09:52:15Z")

</div>

OK

So some progress. Using the retrieved refresh token a request to

> **[Video Conferencing, Web Conferencing, Webinars, Screen Sharing](https://zoom.us/oauth/signin?_rnd=1567677050852&client_id&redirect_uri=https%3A%2F%2Fdev.thetherapy.space%2F_ajax&response_type)**
>
> Zoom is the leader in modern enterprise video communications, with an easy, reliable cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems. Zoom Rooms is the original software-based conference...

Gives  
“reason”: “Invalid Token!”, “error”: “invalid\_request”

in code and in Postman?

Is this config on the zoom end?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [September 5, 2019, 4:38pm UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/11 "2019-09-05T16:38:07Z")

</div>

Hey @rich,

> [@rich](#):
>
> On second run got  
> {  
> “reason”: “Invalid request : token created error: Save Access token into Database error”,  
> “error”: “invalid\_request”  
> }
> 
> I assume as I have a token and refresh token I can now use those to access the API.

What do you mean “On second run”? Which endpoint are you calling?

And Yes once you have an access\_token you can call the [Zoom API’s](https://marketplace.zoom.us/docs/api-reference/introduction). [The access\_token only lasts for an hour so once it expires, to get a new access\_token, use your refresh token to do so.](https://marketplace.zoom.us/docs/guides/authorization/oauth/oauth-with-zoom#refresh-access-token)

POST `https://zoom.us/oauth/token?grant_type=refresh_token&refresh_token={ REFRESH TOKEN }&redirect_uri={ REDIRECT URL }`

Headers:

```json
{
    "Authorization": "Basic base64Encoded({ ClientID }:{ ClientSecret })"
}

```

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![tnv.9119](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tnv.9119/32/4489_2.png) [@tnv.9119](https://devforum.zoom.us/u/tnv.9119)\
**Post date:** [March 30, 2020, 2:01pm UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/12 "2020-03-30T14:01:17Z")

</div>

Hi, I still error  
i’m using develop credentials

 ![Capture](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/f/f271fc3b6576677a86edc6e980d6dd2f4fc9a08d.png)

---

<div class="post-metadata">

**Author:** ![tnv.9119](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tnv.9119/32/4489_2.png) [@tnv.9119](https://devforum.zoom.us/u/tnv.9119)\
**Post date:** [March 30, 2020, 2:16pm UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/13 "2020-03-30T14:16:06Z")

</div>

And I use oauth2 of postman, it return token

 ![image](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/9/9cf1fffd408080d796964a0552f5c77db3d61d17.png)

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [March 30, 2020, 11:45pm UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/14 "2020-03-30T23:45:17Z")

</div>

Hey @tnv.9119,

Please follow the OAuth guide here:

[https://marketplace.zoom.us/docs/guides/auth/oauth](https://marketplace.zoom.us/docs/guides/auth/oauth)

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![rania.mohamed](https://avatars.discourse-cdn.com/v4/letter/r/71c47a/32.png) [@rania.mohamed](https://devforum.zoom.us/u/rania.mohamed)\
**Post date:** [April 4, 2020, 2:13pm UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/15 "2020-04-04T14:13:11Z")

</div>

please I made all these steps but getting this error

Invalid client\_id: (4,702)

my App Intent to publish option is false , I don’t want it to be in the marketplace , is it related to this error ?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [April 6, 2020, 5:02pm UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/16 "2020-04-06T17:02:34Z")

</div>

Hey @rania.mohamed,

Please share more details like what step in OAuth you are seeing this error.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![rania.mohamed](https://avatars.discourse-cdn.com/v4/letter/r/71c47a/32.png) [@rania.mohamed](https://devforum.zoom.us/u/rania.mohamed)\
**Post date:** [April 8, 2020, 3:55pm UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/17 "2020-04-08T15:55:19Z")

</div>

hey @tommy  
this happens when get Access token second step, this is my request with the generated code  
[https://zoom.us/oauth/token?redirect\_uri=http%3A%2F%2Fsaharaschools.com&grant\_type=authorization\_code&code=niKEHgBGTx\_XvIOzQwMQNW1r1UqIeUgGQ](https://zoom.us/oauth/token?redirect_uri=http%3A%2F%2Fsaharaschools.com&grant_type=authorization_code&code=niKEHgBGTx_XvIOzQwMQNW1r1UqIeUgGQ)

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [April 8, 2020, 11:57pm UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/18 "2020-04-08T23:57:28Z")

</div>

Hey @rania.mohamed,

[Make sure to pass in the Basic Authorization header.](https://marketplace.zoom.us/docs/guides/auth/oauth#step-2-request-access-token)

| Authorization Header | Description |
| --- | --- |
| Authorization | The string “Basic” with your Client ID and Client Secret with a colon : in between, Base64 Encoded. For example, Client\_ID:Client\_Secret [base64 encoded](https://www.base64encode.org/) is Q2xpZW50X0lEOkNsaWVudF9TZWNyZXQ= |

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![rania.mohamed](https://avatars.discourse-cdn.com/v4/letter/r/71c47a/32.png) [@rania.mohamed](https://devforum.zoom.us/u/rania.mohamed)\
**Post date:** [April 9, 2020, 8:03am UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/19 "2020-04-09T08:03:47Z")

</div>

hey @tommy,

yes I’m doing this , and this is my curl

–header 'Authorization: Basic

is anything related to the application itself?  
settings or something I should do?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [April 10, 2020, 6:54am UTC](https://devforum.zoom.us/t/client-id-not-being-recognised/5704/20 "2020-04-10T06:54:52Z")

</div>

Hey @rania.mohamed,

Please double check you are using the correct client secret, it does not look right.

Thanks,  
Tommy

[Next page](https://devforum.zoom.us/t/client-id-not-being-recognised/5704.md?page=2)
