# Invalid access token in Server-Server OAuth

**URL:** <https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041>\
**Category:** API and Webhooks\
**Tags:** api, s2s-oauth\
**Created:** [June 12, 2023, 11:58pm UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041 "2023-06-12T23:58:37Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![maksymhryhoriev](https://avatars.discourse-cdn.com/v4/letter/m/dfb087/32.png) [@maksymhryhoriev](https://devforum.zoom.us/u/maksymhryhoriev)\
**Post date:** [June 12, 2023, 11:58pm UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041/1 "2023-06-12T23:58:38Z")

</div>

We’re migrating from JWT to the Server-Server OAuth application. And we see the “invalid access token” error for some of our requests:  
Error response: `{"code":124,"message":"Invalid access token."}`

I can reproduce it:

Generate token:

```auto
curl --location --request POST 'https://zoom.us/oauth/token?grant_type=account_credentials&account_id=XXX' \
--header 'Authorization: Basic XXX' 

```

The answer is

```auto
{
"access_token": "XXXX",
"token_type": "bearer",
"expires_in": 3599,
"scope": "user:write:admin dashboard_zr:read:admin dashboard_im:read:admin user:read:admin information_barriers:write:admin zoom_events_basic:read:admin recording:write:admin dashboard_home:read:admin report:master report:read:admin dashboard_crc:read:admin zoom_events_sessions:read:admin zoom_events_reports:read:admin user:master meeting:master dashboard:master dashboard_webinars:read:admin meeting:read:admin zoom_events_basic:write:admin zoom_events_registrants:read:admin dashboard_meetings:read:admin recording:read:admin meeting:write:admin information_barriers:write:master"
}

```

Then I create a Zoom meeting:

```auto
curl --location 'https://api.zoom.us/v2/users/USER_XXX/meetings' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer XXXX' \
--data '{
"topic": "Meeting Dev #1",
"type": "2",
"settings": {
"auto_recording": "cloud"
}
}'

```

I received such answer:

```auto
{
"code": 124,
"message": "Invalid access token."
}

```

Headers:

```auto
x-zm-trackingid v=2.0;clid=aw1;rid=WEB_8d462191ab9544f49bc68bbbfe9af410
CF-RAY 7d6418332ff1ea4b-DFW

```

I can receive an access token, then create a meeting but when I try to remove the meeting I receive this error again. So there is no 100% when the access token doesn’t work at all.  
And all requests are done during the same couple of seconds so it’s an expiration issue.

We have many instances of our service and there are many requests on each instance. Each request generates a new access token. Can it be a problem?

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [June 14, 2023, 8:00pm UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041/2 "2023-06-14T20:00:55Z")

</div>

Hi @maksymhryhoriev  
Thanks for reaching out to the Zoom Developer Forum and welcome to our community, I am happy to help here!  
As of right now, the expected behavior when using Server to Server OAuth app, the creation of a new token will invalidate the previous one. So please make sure you are using the most recent token when making API calls so you dont run into this issue.

Cheers,  
Elisa

---

<div class="post-metadata">

**Author:** ![maksymhryhoriev](https://avatars.discourse-cdn.com/v4/letter/m/dfb087/32.png) [@maksymhryhoriev](https://devforum.zoom.us/u/maksymhryhoriev)\
**Post date:** [June 14, 2023, 8:15pm UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041/3 "2023-06-14T20:15:11Z")

</div>

We have many stateless instances of our service which owns Zoom integration. Now we have to add a common data store + distributive lock. Are there any other options to avoid it?

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [June 15, 2023, 2:15pm UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041/4 "2023-06-15T14:15:25Z")

</div>

@maksymhryhoriev  
We will be releasing a feature soon where you will be able to generate access tokens without invalidating the previous one…

---

<div class="post-metadata">

**Author:** ![maksymhryhoriev](https://avatars.discourse-cdn.com/v4/letter/m/dfb087/32.png) [@maksymhryhoriev](https://devforum.zoom.us/u/maksymhryhoriev)\
**Post date:** [June 15, 2023, 2:57pm UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041/5 "2023-06-15T14:57:21Z")

</div>

That’s great news. Do you have ETA for it?

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [June 20, 2023, 4:59pm UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041/6 "2023-06-20T16:59:09Z")

</div>

Hi @maksymhryhoriev  
It is live now.  
You should be able to request multiple tokens and the request of a new one won’t invalidate the previous one

---

<div class="post-metadata">

**Author:** ![maksymhryhoriev](https://avatars.discourse-cdn.com/v4/letter/m/dfb087/32.png) [@maksymhryhoriev](https://devforum.zoom.us/u/maksymhryhoriev)\
**Post date:** [June 20, 2023, 5:11pm UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041/7 "2023-06-20T17:11:09Z")

</div>

Wow, that was quick. Thank you 🙂  
I have one more question. Can we generate a new token for each request? Or it should be one token per service instance?

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [June 20, 2023, 9:25pm UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041/8 "2023-06-20T21:25:11Z")

</div>

@maksymhryhoriev  
Hi ! yes this feature was released over the weekend 🙂  
you can generate as many tokens as you want, so it would be up to what works best for you. I think I would do it per service instance so you are not generating tokens per request

---

<div class="post-metadata">

**Author:** ![bartosz.blimke](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/bartosz.blimke/32/5780_2.png) [@bartosz.blimke](https://devforum.zoom.us/u/bartosz.blimke)\
**Post date:** [July 10, 2023, 8:42pm UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041/9 "2023-07-10T20:42:47Z")

</div>

Hi @elisa.zoom

Do I need to pass some special parameter to /oauth/token endpoint to make sure other tokens are not invalidated? I can see that change was released 20 days ago and yet I have been experiencing that issue last week.

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [July 11, 2023, 1:24pm UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041/10 "2023-07-11T13:24:55Z")

</div>

Hi @bartosz.blimke  
You do not need to pass any special parameter when making the request.

---

<div class="post-metadata">

**Author:** ![niceperson404](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/niceperson404/32/49132_2.png) [@niceperson404](https://devforum.zoom.us/u/niceperson404)\
**Post date:** [July 17, 2023, 3:03am UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041/11 "2023-07-17T03:03:51Z")

</div>

Hi Elisa,  
I would like to know if there’s any link related to this feature release?

Obviously this multiple access\_token is already functioning, but i need to provide some kind of official release note or something to my superior.

Did Zoom mentioned anywhere regarding this ‘live’ announcement?

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [July 17, 2023, 2:23pm UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041/12 "2023-07-17T14:23:46Z")

</div>

Hi @niceperson404

You can see it is documented right now

> **[Server-to-Server OAuth](https://developers.zoom.us/docs/internal-apps/s2s-oauth/#zoom-account-credentials-grant-type)**
>
> The Zoom Developer Platform is an open platform that allows third-party developers to build applications and integrations upon Zoom’s video-first unified communications platform.

And there was also an announcement in the Dev Forum

> [@Multi Access tokens launched for S2S apps](https://devforum.zoom.us/t/multi-access-tokens-launched-for-s2s-apps/90527):
>
> We’re thrilled to announce a significant new feature that many of you have been eagerly anticipating: Multiple Access Tokens are now available in the Server-to-server App! As we continuously strive to improve our developer platform based on your feedback, we understand that the ability to generate and manage multiple access tokens is a crucial aspect for many of our users. Whether you are managing multiple projects, or you need different tokens for your team, this new feature will enhance your …

Hope this helps  
Cheers,  
Elisa

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [July 20, 2024, 5:59am UTC](https://devforum.zoom.us/t/invalid-access-token-in-server-server-oauth/90041/13 "2024-07-20T05:59:51Z")

</div>

This topic was automatically closed 368 days after the last reply. New replies are no longer allowed.
