# Create Meeting Unauthorized

**URL:** <https://devforum.zoom.us/t/create-meeting-unauthorized/38162>\
**Category:** API and Webhooks\
**Created:** [December 10, 2020, 11:49pm UTC](https://devforum.zoom.us/t/create-meeting-unauthorized/38162 "2020-12-10T23:49:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![matt-clickinon](https://avatars.discourse-cdn.com/v4/letter/m/0ea827/32.png) [@matt-clickinon](https://devforum.zoom.us/u/matt-clickinon)\
**Post date:** [December 10, 2020, 11:49pm UTC](https://devforum.zoom.us/t/create-meeting-unauthorized/38162/1 "2020-12-10T23:49:04Z")

</div>

**Description**  
I am trying to create a meeting using C# / RestSharp, but I keep receiving an ‘Unauthorized’ response, with content of ‘"{“code”:124,“message”:“Invalid access token.”}"’. However, if I run the same code to retrieve a list of users, the response comes back without any problems?!

**Error**  
Unauthorized, Code 124, Message “Invalid Access Token”

**Which App Type (OAuth / Chatbot / JWT / Webhook)?**  
JWT

**Which Endpoint/s?**  
Create Meeting

**How To Reproduce (If applicable)**  
Steps to reproduce the behavior:  
This doesn’t work:

var tokenHandler = new JwtSecurityTokenHandler();  
DateTime expiry = DateTime.UtcNow.AddMinutes(5);  
string apiSecret = “API\_SECRET”;  
string apiKey = “API\_KEY”;  
int ts = (int)(expiry - new DateTime(1970, 1, 1)).TotalSeconds;

var securityKey = new Microsoft.IdentityModel.Tokens.SymmetricSecurityKey(Encoding.UTF8.GetBytes(apiSecret));

var credentials = new SigningCredentials(securityKey, SecurityAlgorithms.HmacSha256);  
var header = new JwtHeader(credentials);

var payload = new JwtPayload  
{  
{ “iss”, apiKey},  
{ “exp”, ts },  
};

var securityToken = new JwtSecurityToken(header, payload);  
var handler = new JwtSecurityTokenHandler();  
var tokenString = handler.WriteToken(securityToken);

RestClient client = new RestClient();  
client.BaseUrl = new Uri(“[http://api.zoom.us/v2/users/me/meetings](http://api.zoom.us/v2/users/me/meetings)”);  
RestRequest request = new RestRequest(Method.POST);

request.AddHeader(“content-type”, “application/json”);  
request.AddHeader(“authorization”, String.Format(“Bearer {0}”, tokenString));

var data = “{“topic”: “Test Meeting”,“type”: 2,“start\_time”: “2020-12-11T10:00”,“duration”: 60,“timezone”: “Europe/London”,“password”: “abcd”,“agenda”: “Testing Meeting”}”;

request.AddParameter(“application/json”, data, ParameterType.RequestBody);

IRestResponse response = client.Execute(request);

This does:

var tokenHandler = new JwtSecurityTokenHandler();  
DateTime expiry = DateTime.UtcNow.AddMinutes(5);  
string apiSecret = “API\_SECRET”;  
string apiKey = “API\_KEY”;  
int ts = (int)(expiry - new DateTime(1970, 1, 1)).TotalSeconds;

var securityKey = new Microsoft.IdentityModel.Tokens.SymmetricSecurityKey(Encoding.UTF8.GetBytes(apiSecret));

var credentials = new SigningCredentials(securityKey, SecurityAlgorithms.HmacSha256);  
var header = new JwtHeader(credentials);

var payload = new JwtPayload  
{  
{ “iss”, apiKey},  
{ “exp”, ts },  
};

var securityToken = new JwtSecurityToken(header, payload);  
var handler = new JwtSecurityTokenHandler();

var tokenString = handler.WriteToken(securityToken);

RestClient client = new RestClient();  
client.BaseUrl = new Uri(“[https://api.zoom.us/v2/users?status=active&page\_size=30&page\_number=1](https://api.zoom.us/v2/users?status=active&page_size=30&page_number=1)”);  
RestRequest request = new RestRequest(Method.GET);

request.AddHeader(“content-type”, “application/json”);  
request.AddHeader(“authorization”, String.Format(“Bearer {0}”, tokenString));

IRestResponse response = client.Execute(request);

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [December 11, 2020, 6:18pm UTC](https://devforum.zoom.us/t/create-meeting-unauthorized/38162/2 "2020-12-11T18:18:31Z")

</div>

Hi @matt-clickinon,

In your request URL, can you replace `me` with the user (userId or email) who you’re creating the meeting for? Our Create Meeting endpoint doesn’t support the `me` context as it’s a user-level endpoint.

Try making this change and let me know if this resolves the error.

Thanks,  
Will

---

<div class="post-metadata">

**Author:** ![matt-clickinon](https://avatars.discourse-cdn.com/v4/letter/m/0ea827/32.png) [@matt-clickinon](https://devforum.zoom.us/u/matt-clickinon)\
**Post date:** [December 11, 2020, 9:09pm UTC](https://devforum.zoom.us/t/create-meeting-unauthorized/38162/3 "2020-12-11T21:09:40Z")

</div>

Hi @will.zoom ,

I tried it both with “me” and with both the user email addresses registered in our account.

Thanks

Matt

---

<div class="post-metadata">

**Author:** ![MaxM](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/maxm/32/42303_2.png) [@MaxM](https://devforum.zoom.us/u/MaxM)\
**Post date:** [December 11, 2020, 10:28pm UTC](https://devforum.zoom.us/t/create-meeting-unauthorized/38162/4 "2020-12-11T22:28:08Z")

</div>

Hey @matt-clickinon,

Thank you for providing additional information. Are you able to provide a log of the endpoint, request body, and you are using when you encounter an Unauthorized response?

Thanks,  
Max

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [January 11, 2021, 8:28am UTC](https://devforum.zoom.us/t/create-meeting-unauthorized/38162/5 "2021-01-11T08:28:29Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
