# Code 124: Invalid access token

**URL:** <https://devforum.zoom.us/t/code-124-invalid-access-token/52737>\
**Category:** API and Webhooks\
**Created:** [June 18, 2021, 4:36pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token/52737 "2021-06-18T16:36:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bud.gressett](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/bud.gressett/32/28281_2.png) [@bud.gressett](https://devforum.zoom.us/u/bud.gressett)\
**Post date:** [June 18, 2021, 4:36pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token/52737/1 "2021-06-18T16:36:32Z")

</div>

**Description**  
I am using OAuth to acquire an Access Token and Refresh Token successfully. But when I attempt to create a new Webinar with an API ReST call, I am getting “Invalid access token” for a response.

**Error**  
{“code”:124,“message”:“Invalid access token.”}

**How I process**  
Using [https://api.zoom.com/v2/users/{user}/webinars](https://api.zoom.com/v2/users/%7Buser%7D/webinars) as my ENDPOINT where {user} is the same id I used in OAuth to successfully acquire a token.

Request data is:  
{   
“topic”: “Buds Zoom Test1”,   
“type”: 5,   
“start\_time”: “2021-12-01T13:00:00Z”,   
“duration”: “60”,   
“timezone”: “”,   
“agenda”: “”,   
“settings”: "   
{   
“host\_video”: “true”,   
“panelists\_video”: “true”,   
“practice\_session”: “false”,   
“hd\_video”: “true”,   
“approval\_type”: 0,   
“registration\_type”: 2,   
“audio”: “both”,   
“auto\_recording”: “none”,   
“enforce\_login”: “false”,   
“close\_registration”: “true”,   
“show\_share\_button”: “true”,   
“allow\_multiple\_devices”: “true”,   
“registrants\_email\_notification”: “true”   
}  
}

Making the following calls:  
HttpReq.open “POST”, “[https://api.zoom.com/v2/users/{user}/webinars](https://api.zoom.com/v2/users/%7Buser%7D/webinars)”, False  
(where {user} is the same ID I used to call OAuth)

HttpReq.setRequestHeader “Content-Type” , “application/json”  
HttpReq.setRequestHeader “Authorization”, "Bearer " & csMaster\_AccessToken  
HttpReq.send sReqBody

sReqBody = the request string above  
csMaster\_AccessToken = the Access Token

I verified that the AccessToken is the same one returned from calling a Refresh.

I don’t know why this is happening and could use some guidance.

Could it be that the scope is set to “scope”:“webinar:master webinar:read:admin webinar:write:admin”? Or perhaps that I’m using this to test and have not yet setup a Webinar feature for my account? If the answer is yes to either of the former, shouldn’t I be getting a different error message?

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [June 22, 2021, 3:46pm UTC](https://devforum.zoom.us/t/code-124-invalid-access-token/52737/2 "2021-06-22T15:46:34Z")

</div>

Hi @bud.gressett,

Thanks for reaching out about this.

> Or perhaps that I’m using this to test and have not yet setup a Webinar feature for my account?

If you do not have a Webinar package on your account and a webinar license applied to the user you’re attempting to create a webinar under, this would likely be the issue.

Once you add a webinar license, I believe this should address the error.

Thanks,  
Will

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [July 23, 2021, 1:47am UTC](https://devforum.zoom.us/t/code-124-invalid-access-token/52737/3 "2021-07-23T01:47:19Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
