# Getting invalid access token with postman

**URL:** <https://devforum.zoom.us/t/getting-invalid-access-token-with-postman/24735>\
**Category:** API and Webhooks\
**Created:** [July 21, 2020, 11:32am UTC](https://devforum.zoom.us/t/getting-invalid-access-token-with-postman/24735 "2020-07-21T11:32:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![srinagachandrasekhar](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@srinagachandrasekhar](https://devforum.zoom.us/u/srinagachandrasekhar)\
**Post date:** [July 21, 2020, 11:32am UTC](https://devforum.zoom.us/t/getting-invalid-access-token-with-postman/24735/1 "2020-07-21T11:32:07Z")

</div>

**Description**  
Getting invalid access token when hitting the users url.

**Error**  
{  
“code”: 124,  
“message”: “Invalid access token.”  
}

**Which App Type (OAuth / Chatbot / JWT / Webhook)?**  
JWT

**Which Endpoint/s?**  
[https://oracle.zoom.us/v2/users/me](https://oracle.zoom.us/v2/users/me)

**How To Reproduce (If applicable)**  
Steps to reproduce the behavior:

1. use the end point url given above
2. Set the bearer token obtained from [https://jwt.io/#libraries-io](https://jwt.io/#libraries-io) by providing api\_key and secret  
under Authorization tab.
3. If the token is getting expired, we are getting an appropriate message that the token is expired.

**Screenshots (If applicable)**  
If applicable, add screenshots to help explain your problem.

**Additional context**  
Is it mandatory to have an APP created in the market place even if we have the key and secret?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [July 23, 2020, 9:57pm UTC](https://devforum.zoom.us/t/getting-invalid-access-token-with-postman/24735/3 "2020-07-23T21:57:59Z")

</div>

Hey @srinagachandrasekhar,

This should work fine, let me help you debug it. 🙂

Are you setting the authorization header as follows:

`"Authorization": "Bearer JWT_TOKEN_HERE"`

 ![Screen Shot 2020-07-23 at 3.57.47 PM](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/e/e50032f405a2187cf5deff6900246398d5ac9eaa.png)

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![srinagachandrasekhar](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@srinagachandrasekhar](https://devforum.zoom.us/u/srinagachandrasekhar)\
**Post date:** [July 24, 2020, 5:35am UTC](https://devforum.zoom.us/t/getting-invalid-access-token-with-postman/24735/4 "2020-07-24T05:35:35Z")

</div>

Hi Tommy,  
I am setting it under Authorization tab by selecting ‘Type’ as ‘Bearer Token’.  
Thanks  
Chandra

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [July 27, 2020, 8:49pm UTC](https://devforum.zoom.us/t/getting-invalid-access-token-with-postman/24735/5 "2020-07-27T20:49:31Z")

</div>

Hey @srinagachandrasekhar,

That should also work. Can you try using the JWT Token that is generated for you in your JWT App settings on the “App Credentials” page?

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![srinagachandrasekhar](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@srinagachandrasekhar](https://devforum.zoom.us/u/srinagachandrasekhar)\
**Post date:** [July 28, 2020, 5:46am UTC](https://devforum.zoom.us/t/getting-invalid-access-token-with-postman/24735/6 "2020-07-28T05:46:19Z")

</div>

Hi Tommy,  
We have generated the token using the key and secret obtained from profile settings page of my account. I am not sure if we have a JWT App in the marketplace. Is it mandatory to create one app there in order to use the API? This is one additional question I had asked when posting in forum.  
If it is mandatory to create an app, does it have an organization wide scope or application specific scope? In other words, if an organization has two different applications having their own implementation using zoom API, can both the applications use the same JWT App from the marketplace? Or there must be separate apps for each implementation?  
Thanks  
Chandra

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [July 29, 2020, 9:30pm UTC](https://devforum.zoom.us/t/getting-invalid-access-token-with-postman/24735/7 "2020-07-29T21:30:10Z")

</div>

Hey @srinagachandrasekhar,

> [@srinagachandrasekhar](#):
>
> We have generated the token using the key and secret obtained from profile settings page of my account.

Those are legacy credentials and will not work. To use a [JWT Token](https://marketplace.zoom.us/docs/guides/auth/jwt) to call the [Zoom APIs](https://marketplace.zoom.us/docs/api-reference/introduction), you have to create a [JWT App type](https://marketplace.zoom.us/docs/guides/build/jwt-app) here: [App Marketplace](https://marketplace.zoom.us/develop/create)

> [@srinagachandrasekhar](#):
>
> This is one additional question I had asked when posting in forum.  
> If it is mandatory to create an app, does it have an organization wide scope or application specific scope? In other words, if an organization has two different applications having their own implementation using zoom API, can both the applications use the same JWT App from the marketplace? Or there must be separate apps for each implementation?

A [JWT App](https://marketplace.zoom.us/docs/guides/build/jwt-app) is a single, account wide app that allows you to use the [Web SDK](https://marketplace.zoom.us/docs/sdk/native-sdks/web) or generate [JWT Tokens](https://marketplace.zoom.us/docs/guides/auth/jwt) for calling the [Zoom API](https://marketplace.zoom.us/docs/api-reference/introduction) for your account.

If you wan to have multiple apps with different levels of access, you can use [OAuth](https://marketplace.zoom.us/docs/guides/build/oauth-app) instead.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![srinagachandrasekhar](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@srinagachandrasekhar](https://devforum.zoom.us/u/srinagachandrasekhar)\
**Post date:** [August 4, 2020, 9:44am UTC](https://devforum.zoom.us/t/getting-invalid-access-token-with-postman/24735/8 "2020-08-04T09:44:22Z")

</div>

Hi Tommy,  
Thanks for the clarification so far. Got one more question in this regard. Can we generate the token in the market place for any ZOOM server url or only for the server provided by ZOOM forum.  
For ex. Can we generate token for [https://oracle.zoom.us/v2](https://oracle.zoom.us/v2) or only for [https://api.zoom.us/v2](https://api.zoom.us/v2)  
Thanks  
Chandra

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [August 5, 2020, 8:49pm UTC](https://devforum.zoom.us/t/getting-invalid-access-token-with-postman/24735/9 "2020-08-05T20:49:48Z")

</div>

Hey @srinagachandrasekhar,

Do you have an On Prem Zoom instance?

Thanks,  
Tommy
