# Https://zoom.us/oauth/token

**URL:** <https://devforum.zoom.us/t/https-zoom-us-oauth-token/99772>\
**Category:** API and Webhooks\
**Created:** [December 8, 2023, 12:18am UTC](https://devforum.zoom.us/t/https-zoom-us-oauth-token/99772 "2023-12-08T00:18:47Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![horinouchi](https://avatars.discourse-cdn.com/v4/letter/h/b487fb/32.png) [@horinouchi](https://devforum.zoom.us/u/horinouchi)\
**Post date:** [December 8, 2023, 12:18am UTC](https://devforum.zoom.us/t/https-zoom-us-oauth-token/99772/1 "2023-12-08T00:18:47Z")

</div>

I am having trouble obtaining an access token, and I was hoping you could provide some assistance.

Specifically, I am following the steps below to retrieve the token:

Procedure:

Navigate to [Error - Zoom](https://zoom.us/oauth/authorize) to obtain the authorization code (code), and I have confirmed that the code is successfully acquired.

Go to [https://zoom.us/oauth/token](https://zoom.us/oauth/token) to request the access token. However, the result is a “500 Internal Server Error.”

Logs:

Request Timestamp: 2023-12-07 14:34:15

Request URL: [https://zoom.us/oauth/token?grant\_type=authorization\_code&code=\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*&redirect\_uri=https://\*\*\*\*\*\*\*\*\*\*\*\*\*\*.ne.jp/\*\*\*\*\*\*\*\*\*\*\*\*\*\*/](https://zoom.us/oauth/token?grant_type=authorization_code&code= *******************&redirect_uri=https://**************.ne.jp/ ************** /)  
Response Timestamp: 2023-12-07 14:34:16

Response Status:  
“status”: false,  
“errorCode”: -1,  
“errorMessage”: “500 Internal Server Error”  
I would appreciate it if you could provide guidance on resolving this issue.

Thank you.

Best regards,

---

<div class="post-metadata">

**Author:** ![ojus.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/ojus.zoom/32/734_2.png) [@ojus.zoom](https://devforum.zoom.us/u/ojus.zoom)\
**Post date:** [December 8, 2023, 7:30am UTC](https://devforum.zoom.us/t/https-zoom-us-oauth-token/99772/2 "2023-12-08T07:30:06Z")

</div>

Can you make sure you are following the correct guidelines to generate the access token?

Here are the steps that you may be missing:

### Request User Authorization

Direct users to the Zoom authorization page:

1. Construct a URL with the following format:

```auto
https://zoom.us/oauth/authorize?response_type=code&client_id=YOUR_CLIENT_ID&redirect_uri=YOUR_REDIRECT_URI

```

Replace `YOUR_CLIENT_ID` and `YOUR_REDIRECT_URI` with your actual client ID and redirect URI.

### Obtain an Authorization Code

Once a user authorizes your app, they will be redirected to your redirect URI with a code parameter in the URL. This is the **authorization code**.

Example URL: `https://yourredirecturi.com?code=AUTHORIZATION_CODE`

### Request an Access Token

Make a POST request to Zoom’s OAuth token URL:

1. The URL is `https://zoom.us/oauth/token`
2. Include the following parameters:

- `grant_type=authorization_code`
- `code=AUTHORIZATION_CODE` (the code you received)
- `redirect_uri=YOUR_REDIRECT_URI`

1. Authenticate this request with your Client ID and Client Secret. This is usually done using Basic HTTP authentication with the Client ID as the username and Client Secret as the password.

### Receive the Access Token

Zoom will respond with a JSON object containing your **access token** and **refresh token**.

```auto
{
  "access_token": "your_access_token",
  "token_type": "bearer",
  "expires_in": token_expiration_time,
  "refresh_token": "your_refresh_token",
  "scope": "user_profile"
}

```

### Use the Access Token

Use this access token to make authenticated requests to the Zoom API. It will usually be included in the HTTP header like so:

```auto
Authorization: Bearer your_access_token

```

---

<div class="post-metadata">

**Author:** ![horinouchi](https://avatars.discourse-cdn.com/v4/letter/h/b487fb/32.png) [@horinouchi](https://devforum.zoom.us/u/horinouchi)\
**Post date:** [December 8, 2023, 8:07am UTC](https://devforum.zoom.us/t/https-zoom-us-oauth-token/99772/3 "2023-12-08T08:07:19Z")

</div>

Thank you for contacting us.

I understand the contents.

There was a point I did not explain well enough.  
It was working fine until 1 or 2 months ago.  
The current situation is that we did not make any changes to the program, but when we ran the check in December, it resulted in an error.

I also checked again, and the program was built according to the specifications you gave us.  
(\*The information I provided looks like a GET, but it is being sent as a POST.)

Is there any possible cause for this?

This is PG now.

```auto
$basic = base64_encode(ZOOM_CLAIENT_ID.':'.ZOOM_CLAIENT_SECRET_KEY);
$return_zoom_url = " **********************************";
$zoom_url = "https://zoom.us/oauth/token?grant_type=authorization_code&code=" . $code . "&redirect_uri={$return_zoom_url}";

$ch = curl_init($zoom_url);

$headers = [
    'Content-Type: application/x-www-form-urlencoded',
    'Authorization: Basic ' . $basic,
];
$post = array(
    "grant_type" => "authorization_code",
    "code" => $code,
    "redirect_uri" => $return_zoom_url,

);
$options = array(
    CURLOPT_HTTPHEADER => $headers,
    CURLOPT_SSL_VERIFYHOST => false,
    CURLOPT_SSL_VERIFYPEER => false,
    CURLOPT_RETURNTRANSFER => true,  
    CURLOPT_CONNECTTIMEOUT => 15, 
    CURLOPT_TIMEOUT => 15, 
    CURLOPT_POST => 1,
    CURLOPT_POSTFIELDS => $post
);

curl_setopt_array( $ch, $options );
$result = curl_exec($ch);

```

---

<div class="post-metadata">

**Author:** ![ojus.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/ojus.zoom/32/734_2.png) [@ojus.zoom](https://devforum.zoom.us/u/ojus.zoom)\
**Post date:** [December 8, 2023, 8:24am UTC](https://devforum.zoom.us/t/https-zoom-us-oauth-token/99772/4 "2023-12-08T08:24:12Z")

</div>

Can you check the following:

1. The app and the user still exists and either havent been deactivated? Also can you confirm if the user building the app did not migrate between accounts?
2. You are using the correct app type (i.e. User authorized OAuth)
3. Can you create another app and check if it is able to generate an access token?

---

<div class="post-metadata">

**Author:** ![horinouchi](https://avatars.discourse-cdn.com/v4/letter/h/b487fb/32.png) [@horinouchi](https://devforum.zoom.us/u/horinouchi)\
**Post date:** [December 8, 2023, 12:50pm UTC](https://devforum.zoom.us/t/https-zoom-us-oauth-token/99772/5 "2023-12-08T12:50:19Z")

</div>

> 1.The app and the user still exists and either havent been deactivated? Also can you confirm if the user building the app did not migrate between accounts?  
> ⇒Both the app and the user used it

> 2.You are using the correct app type (i.e. User authorized OAuth)  
> ⇒Sorry, I couldn’t understand  
> Could you please tell me the details?

> 3.Can you create another app and check if it is able to generate an access token?  
> ⇒I will check

Is it possible to investigate from the log?  
Have the specifications changed in the last few months?

---

<div class="post-metadata">

**Author:** ![ojus.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/ojus.zoom/32/734_2.png) [@ojus.zoom](https://devforum.zoom.us/u/ojus.zoom)\
**Post date:** [December 12, 2023, 1:32am UTC](https://devforum.zoom.us/t/https-zoom-us-oauth-token/99772/6 "2023-12-12T01:32:53Z")

</div>

Hi,

nothing has changed to my knowledge. One of the reasons this could be occurring is if you are using credentials from a wrong app type.

Please make sure that you are using the correct app type.

> **[OAuth for user authorized apps](https://developers.zoom.us/docs/integrations/oauth/)**
>
> The Zoom Developer Platform is an open platform that allows third-party developers to build applications and integrations upon Zoom’s video-first unified communications platform.

---

<div class="post-metadata">

**Author:** ![zm.admin](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/zm.admin/32/58409_2.png) [@zm.admin](https://devforum.zoom.us/u/zm.admin)\
**Post date:** [April 6, 2024, 11:01pm UTC](https://devforum.zoom.us/t/https-zoom-us-oauth-token/99772/7 "2024-04-06T23:01:58Z")

</div>

I’m also having the same problem when send post reuqest after my program gets the code, here is my PHP code

```
$curl = curl_init();

curl_setopt_array($curl, array(
    CURLOPT_URL => "https://zoom.us/oauth/token?grant_type=authorization_code&code=" . urlencode($_GET["code"]) . "&redirect_uri=" . urlencode($redirect_uri),
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_ENCODING => "",
    CURLOPT_MAXREDIRS => 10,
    CURLOPT_TIMEOUT => 0,
    CURLOPT_FOLLOWLOCATION => true,
    CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
    CURLOPT_CUSTOMREQUEST => "POST",
    CURLOPT_HTTPHEADER => array(
        "Authorization: Basic " . base64_encode($client_id . ":" . $client_secret),
    ),
));

$response = curl_exec($curl);

curl_close($curl);
echo $response;

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [April 10, 2025, 2:38pm UTC](https://devforum.zoom.us/t/https-zoom-us-oauth-token/99772/8 "2025-04-10T14:38:55Z")

</div>

This topic was automatically closed 368 days after the last reply. New replies are no longer allowed.
