# Generate OAuth authorization code

**URL:** <https://devforum.zoom.us/t/generate-oauth-authorization-code/14657>\
**Category:** API and Webhooks\
**Created:** [April 23, 2020, 7:19pm UTC](https://devforum.zoom.us/t/generate-oauth-authorization-code/14657 "2020-04-23T19:19:39Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![contactbymail01](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/contactbymail01/32/11049_2.png) [@contactbymail01](https://devforum.zoom.us/u/contactbymail01)\
**Post date:** [April 23, 2020, 7:19pm UTC](https://devforum.zoom.us/t/generate-oauth-authorization-code/14657/1 "2020-04-23T19:19:39Z")

</div>

Hi Tommy,

I am trying to use API via OAuth . Could you please help me with the below doubt.

1. Can we generate the OAuth authorization code using PostMan?  
Every time we generate the access token and refresh token, we have to save the refresh token to generate access token again. I don’t want to use refresh token every time and want to check whether we can generate the OAuth authorization code via code or we have to always generate it manually via local test or generate auth url.

Regards  
Mike

---

<div class="post-metadata">

**Author:** ![contactbymail01](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/contactbymail01/32/11049_2.png) [@contactbymail01](https://devforum.zoom.us/u/contactbymail01)\
**Post date:** [April 24, 2020, 5:21pm UTC](https://devforum.zoom.us/t/generate-oauth-authorization-code/14657/2 "2020-04-24T17:21:55Z")

</div>

Hi Guys,  
Could you please on above request ?

Regards  
Mike

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [April 28, 2020, 4:49pm UTC](https://devforum.zoom.us/t/generate-oauth-authorization-code/14657/3 "2020-04-28T16:49:06Z")

</div>

Hey @contactbymail01,

Yes you can generate the Authorization code using Postman. Follow these instructions:

[https://learning.postman.com/docs/postman/sending-api-requests/authorization/#oauth-20](https://learning.postman.com/docs/postman/sending-api-requests/authorization/#oauth-20)

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![contactbymail01](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/contactbymail01/32/11049_2.png) [@contactbymail01](https://devforum.zoom.us/u/contactbymail01)\
**Post date:** [April 28, 2020, 6:26pm UTC](https://devforum.zoom.us/t/generate-oauth-authorization-code/14657/4 "2020-04-28T18:26:38Z")

</div>

Hi Tommy,

Every time, when we try to generate auth code via Postman it goes to the login page always.

we are trying to implement in our paid zoom account but now to get auth code via the postman .

one I am able to Auth code I can generate token . but how to get auth code via postman in your link it shows how to get token via auth code

 ![image.png](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/d/d36ad1041a2878ce837a31b45a9509100bf62543.png)

Regards

Mike

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [May 4, 2020, 3:51am UTC](https://devforum.zoom.us/t/generate-oauth-authorization-code/14657/5 "2020-05-04T03:51:21Z")

</div>

Hey @contactbymail01,

[Sign-in is part of the OAuth flow.](https://marketplace.zoom.us/docs/guides/auth/oauth)

If you want to call the APIs without the Sign in OAuth2 flow, you can use [JWT Tokens](https://marketplace.zoom.us/docs/guides/auth/jwt) instead.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![nitin1](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/nitin1/32/1333_2.png) [@nitin1](https://devforum.zoom.us/u/nitin1)\
**Post date:** [May 21, 2020, 7:11am UTC](https://devforum.zoom.us/t/generate-oauth-authorization-code/14657/6 "2020-05-21T07:11:45Z")

</div>

Hi @tommy

I think the question being asked is that we would like to test user apps which need OAuth login. It appears that when we try to automate the Oauth request we get into a 302 redirect loop from the server. It appears to be a javascript dependency. Can you explain

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [May 27, 2020, 6:08pm UTC](https://devforum.zoom.us/t/generate-oauth-authorization-code/14657/7 "2020-05-27T18:08:59Z")

</div>

Hey @nitin1,

The [OAuth flow](https://marketplace.zoom.us/docs/guides/auth/oauth) requires user interaction for security purposes.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![nitin1](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/nitin1/32/1333_2.png) [@nitin1](https://devforum.zoom.us/u/nitin1)\
**Post date:** [June 6, 2020, 1:39am UTC](https://devforum.zoom.us/t/generate-oauth-authorization-code/14657/8 "2020-06-06T01:39:19Z")

</div>

For automation I was able to setup an automated process, which does not require user to interact continuously till the refresh token is valid.

For anyone else who is planning to do so, setup a temporary nodejs server and set the redirect uri for zoom auth as node. Now once the user authenticates, node can intercept the request and get a new access token.

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [June 11, 2020, 6:42pm UTC](https://devforum.zoom.us/t/generate-oauth-authorization-code/14657/9 "2020-06-11T18:42:14Z")

</div>

Hey @nitin1,

You can also use [JWT Tokens](https://marketplace.zoom.us/docs/guides/auth/jwt) which are designed for server to server (no user interaction) authentication. 🙂

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![nitin1](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/nitin1/32/1333_2.png) [@nitin1](https://devforum.zoom.us/u/nitin1)\
**Post date:** [June 11, 2020, 9:38pm UTC](https://devforum.zoom.us/t/generate-oauth-authorization-code/14657/10 "2020-06-11T21:38:42Z")

</div>

Thanks Tommy,

But I wanted to automate testing of user managed apps, where a user can add an app to their account. Will JWT work in that case as well ?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [June 16, 2020, 9:22pm UTC](https://devforum.zoom.us/t/generate-oauth-authorization-code/14657/11 "2020-06-16T21:22:26Z")

</div>

Hey @nitin1,

Ah gotcha! If you are setting up automated testing for OAuth apps then no, JWT should not be used.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![DeveloperBot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/developerbot/32/12632_2.png) [@DeveloperBot](https://devforum.zoom.us/u/DeveloperBot)\
**Post date:** [August 21, 2020, 10:04pm UTC](https://devforum.zoom.us/t/generate-oauth-authorization-code/14657/12 "2020-08-21T22:04:52Z")

</div>


