# Code 124 (Invalid access token) received for JWT API calls

**URL:** <https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815>\
**Category:** API and Webhooks\
**Created:** [December 19, 2020, 11:43pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815 "2020-12-19T23:43:28Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![eamonn](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/eamonn/32/20427_2.png) [@eamonn](https://devforum.zoom.us/u/eamonn)\
**Post date:** [December 19, 2020, 11:43pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/1 "2020-12-19T23:43:28Z")

</div>

**Description**  
When using either dynamically created JWT tokens, or even hard-copying the one provided from the App Marketplace for my app, my API requests always fail due to an ‘invalid access token’.

**Error**  
The response from the API is: { code: 124, message: “Invalid access token.” }

**Which App Type (OAuth / Chatbot / JWT / Webhook)?**  
JWT Credentials, Account-level app

**Which Endpoint/s?**  
I am currently working on the Meetings endpoint, specifically trying to create a meeting.

**How To Reproduce (If applicable)**

Request URL:  
[https://eu01api-www4local.zoom.us/v2/users/me/meetings](https://eu01api-www4local.zoom.us/v2/users/me/meetings)

Headers:

```
CURLOPT_HTTPHEADER => [
            "authorization: Bearer " . $this->generate_JWT(),
            "content-type: application/json"
]

```

where…

```
private function generate_JWT()
{
    $payload = [
        "iss" => self::ZOOM_API_SECRET,
        "exp" => time() + $this->timeout,
    ];
    return JWT::encode($payload, self::ZOOM_API_KEY, 'HS256');
}

```

using Firebase\JWT\JWT class per [jwt.io](http://jwt.io) reference

Am trying to connect from a project I am writing on localhost (so ‘CURLOPT\_SSL\_VERIFYPEER =\> false’). Any help you could give is appreciated.

---

<div class="post-metadata">

**Author:** ![DeveloperBot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/developerbot/32/12632_2.png) [@DeveloperBot](https://devforum.zoom.us/u/DeveloperBot)\
**Post date:** [December 19, 2020, 11:44pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/2 "2020-12-19T23:44:32Z")

</div>

Hey @eamonn

Thanks for posting on the Zoom Devforum! I am still learning, but I will try my best to help answer your question. 🙂

Checkout this related thread that may have the answer you are looking for:

> [@Invalid Access token for calls to /accounts endpoint](https://devforum.zoom.us/t/-/23675):
>
> Description We receive an “Invalid Access token” error when attempting to access the /accounts endpoint. The token appears to work for other endpoints. Error { code: 124, message: ‘Invalid access token.’ } Which App Type (OAuth / Chatbot / JWT / Webhook)? JWT Which Endpoint/s? /accounts Additional context We also receive the token error when testing access on the endpoint page [https://marketplace.zoom.us/docs/api-reference/zoom-api/accounts/accounts](https://marketplace.zoom.us/docs/api-reference/zoom-api/accounts/accounts) The token appears to work for s…

If this thread did not help, please let us know by replying back here and someone from the Developer Relations team will get back to you shortly.

Thanks,  
DeveloperBot

---

<div class="post-metadata">

**Author:** ![eamonn](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/eamonn/32/20427_2.png) [@eamonn](https://devforum.zoom.us/u/eamonn)\
**Post date:** [December 19, 2020, 11:45pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/3 "2020-12-19T23:45:59Z")

</div>

This solution is not suited to my query.

---

<div class="post-metadata">

**Author:** ![eamonn](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/eamonn/32/20427_2.png) [@eamonn](https://devforum.zoom.us/u/eamonn)\
**Post date:** [December 21, 2020, 4:21pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/4 "2020-12-21T16:21:43Z")

</div>

Is this the correct forum for my query - I can post it elsewhere if needs be…

---

<div class="post-metadata">

**Author:** ![MaxM](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/maxm/32/42303_2.png) [@MaxM](https://devforum.zoom.us/u/MaxM)\
**Post date:** [December 22, 2020, 10:17pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/5 "2020-12-22T22:17:13Z")

</div>

Hey @eamonn,

Thank you for reaching out to the Zoom Developer Forum. I just have a couple of questions to get us started. Does the token work if you replace `me` with the User ID? Do the tokens work for account-level APIs such as the dashboard? I’m thinking the issue here is that JWT tokens are account-level but the `me` route is specific to a user.

I hope that helps! Let me know if you have any questions.

Thanks,  
Max

---

<div class="post-metadata">

**Author:** ![eamonn](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/eamonn/32/20427_2.png) [@eamonn](https://devforum.zoom.us/u/eamonn)\
**Post date:** [December 23, 2020, 12:08am UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/6 "2020-12-23T00:08:40Z")

</div>

Hi Max,  
Thanks for your suggestions. I have tried using the user email instead of `me` in the URL. I have also tried basic GET requests for listing users and for listing existing meetings; neither to any avail. My assumption at this point is there is some scope issue with the JWT app?

---

<div class="post-metadata">

**Author:** ![MaxM](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/maxm/32/42303_2.png) [@MaxM](https://devforum.zoom.us/u/MaxM)\
**Post date:** [December 23, 2020, 11:27pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/7 "2020-12-23T23:27:31Z")

</div>

Hey @eamonn,

Thank you for reaching out to the Zoom Developer Forum. After looking at this a bit closer, I’m thinking this may be related to the URL that you’re using. Please try using the URL listed in the documentation to see if that resolves your issues: [https://api.zoom.us/v2/](https://api.zoom.us/v2/)

I hope that helps!

Thanks,  
Max

---

<div class="post-metadata">

**Author:** ![eamonn](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/eamonn/32/20427_2.png) [@eamonn](https://devforum.zoom.us/u/eamonn)\
**Post date:** [December 24, 2020, 2:32am UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/8 "2020-12-24T02:32:15Z")

</div>

Hi Max.  
That worked. That’s actually pretty frustrating - the API documentation states:  
`To support GDPR requirements of EU customers, you may use https://eu01api-www4local.zoom.us as the base URL for all API requests associated with EU accounts.`  
We’re registering with .ie accounts and domains, and there is nothing in Account Settings or Profile to suggest that we are _not_ an EU customer, or how to become one if not. I would suggest that a little more clarity on this in the documentation would have saved me a lot of bother, and may do likewise for others in the future.

Nonetheless, thanks for you help - well spotted!

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [December 28, 2020, 9:11pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/9 "2020-12-28T21:11:25Z")

</div>

Hey @eamonn,

Sorry for the frustration here. Can you point to us where the documentation says that so we can clear up any confusion?

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![eamonn](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/eamonn/32/20427_2.png) [@eamonn](https://devforum.zoom.us/u/eamonn)\
**Post date:** [January 2, 2021, 12:10pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/10 "2021-01-02T12:10:39Z")

</div>

Hi @tommy,

API docs, page 1, paragraph 3:

> **[Introduction - API Reference](https://marketplace.zoom.us/docs/api-reference/introduction)**
>
> Introduction to Zoom API
> 
> 
> 
> The Zoom API is the primary means for developers to access a collection of resources from Zoom. Apps can read and write to t...

Also, upon reflection, the returned error ‘invalid access token’ does not accurately describe the issue either, but I can understand how that’s a circular problem to solve.

---

<div class="post-metadata">

**Author:** ![MaxM](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/maxm/32/42303_2.png) [@MaxM](https://devforum.zoom.us/u/MaxM)\
**Post date:** [January 4, 2021, 8:24pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/11 "2021-01-04T20:24:03Z")

</div>

Hey @eamonn,

Thank you for pointing out where that is documented. From here I can have our documentation team address that or have our engineering team determine why that isn’t working. First, I want to confirm if you are able to use that API base URL if you remove the `/v2` route from the URL?

Thanks,  
Max

---

<div class="post-metadata">

**Author:** ![eamonn](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/eamonn/32/20427_2.png) [@eamonn](https://devforum.zoom.us/u/eamonn)\
**Post date:** [January 5, 2021, 9:23am UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/12 "2021-01-05T09:23:24Z")

</div>

Hi Max,

When sending to:

- [https://api.zoom.us/v2](https://api.zoom.us/v2) - response OK
- [https://eu01api-www4local.zoom.us/v2](https://eu01api-www4local.zoom.us/v2) - response invalid token
- [https://eu01api-www4local.zoom.us](https://eu01api-www4local.zoom.us) - empty/no response

---

<div class="post-metadata">

**Author:** ![MaxM](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/maxm/32/42303_2.png) [@MaxM](https://devforum.zoom.us/u/MaxM)\
**Post date:** [January 5, 2021, 9:17pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/13 "2021-01-05T21:17:38Z")

</div>

Hey @eamonn,

Thank you for testing that! I’ve since reached out to our engineering team to confirm how the EU base URL should be used and how our documentation should be updated. I’ll keep you posted with any new developments. (ZOOM-232544)

Thanks,  
Max

---

<div class="post-metadata">

**Author:** ![MaxM](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/maxm/32/42303_2.png) [@MaxM](https://devforum.zoom.us/u/MaxM)\
**Post date:** [January 6, 2021, 12:55am UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/14 "2021-01-06T00:55:47Z")

</div>

Hey @eamonn,

Thank you for your patience. I sent you a DM requesting the account owner email as our internal team indicated this could be caused by your account not being located in our EU Cluster. With the Account Owner email or even an email of a user on that account, I can check if this is the case.

Thanks,  
Max

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [February 5, 2021, 10:55am UTC](https://devforum.zoom.us/t/code-124-invalid-access-token-received-for-jwt-api-calls/38815/15 "2021-02-05T10:55:48Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
