# Developer set up for OAuth2

**URL:** <https://devforum.zoom.us/t/developer-set-up-for-oauth2/27030>\
**Category:** API and Webhooks\
**Created:** [August 13, 2020, 10:43am UTC](https://devforum.zoom.us/t/developer-set-up-for-oauth2/27030 "2020-08-13T10:43:13Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![blacknell](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/blacknell/32/13453_2.png) [@blacknell](https://devforum.zoom.us/u/blacknell)\
**Post date:** [August 13, 2020, 10:43am UTC](https://devforum.zoom.us/t/developer-set-up-for-oauth2/27030/1 "2020-08-13T10:43:13Z")

</div>

**Description**  
Confused as to how to manage redirect URL on local development system

**Error**  
When posting to the authorize endpoint i have to specify the redirect URL which has to match that in the app profile.

However, when developing I’m always using localhost:3000 as the website since this my IDE environment. I get the redirect URL back with the code in it (so I know it’s authorising ok) but of course, I can’t continue with the redirection since that’s on [www.mydomain.com](http://www.mydomain.com)

I have whitelisted [www.mydomain.com](http://www.mydomain.com) as well as localhost:3000

**Which App Type (OAuth / Chatbot / JWT / Webhook)?**  
OAuth2.

**Which Endpoint/s?**  
Authorize

**How To Reproduce (If applicable)**

**Screenshots (If applicable)**

**Additional context**

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [August 13, 2020, 7:21pm UTC](https://devforum.zoom.us/t/developer-set-up-for-oauth2/27030/2 "2020-08-13T19:21:14Z")

</div>

Hey @blacknell,

You can use [ngrok](https://ngrok.com/) to turn your localhost into a free server. Then use the ngrok url as your development redirect and whitelist.

Let me know if you have additional questions! 🙂

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![blacknell](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/blacknell/32/13453_2.png) [@blacknell](https://devforum.zoom.us/u/blacknell)\
**Post date:** [August 13, 2020, 7:59pm UTC](https://devforum.zoom.us/t/developer-set-up-for-oauth2/27030/3 "2020-08-13T19:59:03Z")

</div>

So are you suggesting I need to create another app with local host:3000 redirect & whitelist uri’s?

Regards  
Paul

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [August 13, 2020, 8:19pm UTC](https://devforum.zoom.us/t/developer-set-up-for-oauth2/27030/4 "2020-08-13T20:19:08Z")

</div>

Hey @blacknell,

No, just change your development redirect and whitelist urls to your ngrok url:

 ![Screen Shot 2020-08-13 at 2.18.44 PM](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/9/9aad0d4dfed2f0e17bd62ab478327fddb16cda27.png)

If I am misunderstanding your issue, can you explain more about why you need to use both localhost and [mydomain.com](http://mydomain.com) in the same OAuth flow?

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![blacknell](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/blacknell/32/13453_2.png) [@blacknell](https://devforum.zoom.us/u/blacknell)\
**Post date:** [August 16, 2020, 4:30pm UTC](https://devforum.zoom.us/t/developer-set-up-for-oauth2/27030/5 "2020-08-16T16:30:16Z")

</div>

Ok. I’m getting there but…

1. I got the code back after [https://zoom.us/oauth/authorize?client\_id=xxx&response\_type=code](https://zoom.us/oauth/authorize?client_id=xxx&response_type=code)
2. I then made the POST to [https://zoom.us/oauth/token?grant\_type=authorization\_code&code=yyy](https://zoom.us/oauth/token?grant_type=authorization_code&code=yyy) with encoded headers etc.

I’m getting a CORS error back

This is supposed to be a client side oauth process but it’s looking like your side doesn’t set Access-Control-Allow-Origin?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [August 18, 2020, 6:24pm UTC](https://devforum.zoom.us/t/developer-set-up-for-oauth2/27030/6 "2020-08-18T18:24:24Z")

</div>

Hey @blacknell,

It is a client side process until you land on your redirect url. You need to make the request to get an access token from the server side. A common flow is once you land on the redirect url, your client side makes a request to your server sending the auth code, and then your server [makes a request to get an access token from Zoom.](https://marketplace.zoom.us/docs/guides/auth/oauth#step-2-request-access-token)

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [September 18, 2020, 4:24am UTC](https://devforum.zoom.us/t/developer-set-up-for-oauth2/27030/7 "2020-09-18T04:24:31Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
