# I am getting 400 Bad Request while getting access token through auth code

**URL:** <https://devforum.zoom.us/t/i-am-getting-400-bad-request-while-getting-access-token-through-auth-code/126497>\
**Category:** Authentication\
**Created:** [February 11, 2025, 2:14pm UTC](https://devforum.zoom.us/t/i-am-getting-400-bad-request-while-getting-access-token-through-auth-code/126497 "2025-02-11T14:14:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bilal1](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/bilal1/32/67055_2.png) [@Bilal1](https://devforum.zoom.us/u/Bilal1)\
**Post date:** [February 11, 2025, 2:14pm UTC](https://devforum.zoom.us/t/i-am-getting-400-bad-request-while-getting-access-token-through-auth-code/126497/1 "2025-02-11T14:14:03Z")

</div>

const tokenResponse = await axios.post(“[https://zoom.us/oauth/token](https://zoom.us/oauth/token)”, null, {  
params: {  
code: code, // The authorization code you received  
grant\_type: “authorization\_code”, // The type of OAuth flow being used  
redirect\_uri: process.env.ZOOM\_REDIRECT\_URI, // The redirect URI registered in Zoom  
},  
headers: {  
“Authorization”: `Basic ${Buffer.from(`${process.env.ZOOM\_CLIENT\_ID}:${process.env.ZOOM\_CLIENT\_SECRET}`).toString("base64")}`,  
},  
});

Error

{  
“reason”: “Bad Request”,  
“error”: “invalid\_request”  
}

I tried in postman as well I also got the same error

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [February 12, 2025, 4:35pm UTC](https://devforum.zoom.us/t/i-am-getting-400-bad-request-while-getting-access-token-through-auth-code/126497/2 "2025-02-12T16:35:11Z")

</div>

Hi @Bilal1  
Could you please review the following post and let me know if that helps?

> [@Guide: Making a Zoom API Call with OAuth Credentials in Postman](https://devforum.zoom.us/t/guide-making-a-zoom-api-call-with-oauth-credentials-in-postman/64538):
>
> To publish an app on the Zoom Marketplace you must create an [OAuth app](https://marketplace.zoom.us/docs/guides/build/oauth-app/). When you’re ready to test making API calls, download the latest version of Postman and import the Zoom API collections following the steps outlined [here](https://marketplace.zoom.us/docs/guides/guides/postman/using-postman-to-test-zoom-apis/). There are Three Ways to Set up OAuth in Postman to Make API Requests We’re going to go through three ways to set up our OAuth application credentials to successfully authorize and access the Zoom API to make requests. The “Easy” Difficulty OAuth 2.0 Set Up in Postman We’…

---

<div class="post-metadata">

**Author:** ![Bilal1](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/bilal1/32/67055_2.png) [@Bilal1](https://devforum.zoom.us/u/Bilal1)\
**Post date:** [February 13, 2025, 7:12am UTC](https://devforum.zoom.us/t/i-am-getting-400-bad-request-while-getting-access-token-through-auth-code/126497/3 "2025-02-13T07:12:38Z")

</div>

I am sending auth code from react js side and at backend nodejs I try to get the access and refresh token through that auth code

const tokenUrl = ‘[https://zoom.us/oauth/token](https://zoom.us/oauth/token)’;  
const authHeader = Buffer.from(`${clientId}:${clientSecret}`).toString(‘base64’);  
const data = qs.stringify({  
grant\_type: ‘authorization\_code’,  
code: code,  
redirect\_uri: redirectUri  
});  
console.log(‘data’, data)  
console.log(‘authHeader’, authHeader)  
const response = await axios.post(tokenUrl, data, {  
headers: {  
‘Content-Type’: ‘application/x-www-form-urlencoded’,  
‘Authorization’: `Basic ${authHeader}`  
}  
});  
console.log(‘response’, response)

your message not helping me so please help me in this where I am doing wrong

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [February 14, 2025, 8:33pm UTC](https://devforum.zoom.us/t/i-am-getting-400-bad-request-while-getting-access-token-through-auth-code/126497/4 "2025-02-14T20:33:01Z")

</div>

Can you please take a look at that guide, to understand the proper way to generate the oauth token? Here is another useful link to our docs:

> **[OAuth for user authorized apps - Zoom Developers](https://developers.zoom.us/docs/integrations/oauth/)**
>
> The Zoom Developer Platform is an open platform that allows third-party developers to build applications and integrations upon Zoom’s video-first unified communications platform.

```auto
POST https://zoom.us/oauth/token
HTTP/1.1

# Header
Host: zoom.us
Authorization: Basic Q2xpZW50X0lEOkNsaWVudF9TZWNyZXQ=
Content-Type: application/x-www-form-urlencoded

# Request body
code: [CODE]
grant_type: authorization_code
redirect_uri: [REDIRECT URI]

```

Here is a sample app that could be helpful too

> <https://github.com/zoom/user-level-oauth-starter/blob/main/routes/api/zoomOauth.js>
