# Invalid api key or secret error

**URL:** <https://devforum.zoom.us/t/invalid-api-key-or-secret-error/5227>\
**Category:** API and Webhooks\
**Created:** [July 29, 2019, 6:27am UTC](https://devforum.zoom.us/t/invalid-api-key-or-secret-error/5227 "2019-07-29T06:27:36Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![umarraza2200](https://avatars.discourse-cdn.com/v4/letter/u/34f0e0/32.png) [@umarraza2200](https://devforum.zoom.us/u/umarraza2200)\
**Post date:** [July 29, 2019, 6:27am UTC](https://devforum.zoom.us/t/invalid-api-key-or-secret-error/5227/1 "2019-07-29T06:27:37Z")

</div>

I have been working on a Laravel project that provides online education to students. I wanted to use ZOOM services of video conferencing so that teacher can connect with his students through video conference. Following the API reference documentation, I have registered an app with zoom. I got API key and API secret along with an access token by following the documentation.

I am sending subsequent requests to post/fetch data from zoom, but I have been getting an error message like this.

Client error: `POST https://api.zoom.us/v2/accounts` resulted in a `400 Bad Request` response: {“code”:200,“message”:“Invalid api key or secret.”}

I am sending API key and API secret in header but still getting the same error. Probably I am doing something wrong with the requesting process or may be something else, I don’t know. I have searched on internet how to integrate zoom with Laravel app but couldn’t found any helpful information.

Can anybody please help me to figure out what I am doing wrong? Can someone provide me some helpful resources about zoom API integration with Laravel?

My code:

```auto
    $client_id = env('CLIENT_ID');
    $client_secret = env('CLIENT_SECRET');

    $content = "grant_type=client_credentials&client_id=$client_id&client_secret=$client_secret";
    $token_url="https://zoom.us/oauth/token";

    $curl = curl_init();

    curl_setopt_array($curl, array(

        CURLOPT_URL => $token_url,
        CURLOPT_SSL_VERIFYPEER => true,
        CURLOPT_RETURNTRANSFER => true,
        CURLOPT_POST => true,
        CURLOPT_POSTFIELDS => $content

    ));

    $data = curl_exec($curl);
    curl_close($curl);
    $result = json_decode($data);

    $access_token = $result->access_token;
    $client = new \GuzzleHttp\Client();

    $api_key = env('API_KEY');
    $api_secret = env('API_SECRET');

    $response = $client->request('POST', 'https://api.zoom.us/v2/accounts', [
        'headers' => [
            'apikey' => $api_key,
            'apisecret' => $api_secret,
            'Accept' => 'application/json',
            'Content-Type' => 'application/json',
            'Authorization' => 'Bearer '. $access_token
        ],
        'form_params' => [
            'first_name' => $request->first_name,
            'last_name' => $request->last_name,
            'email' => $request->email,
            'password' => $request->password,
        ],
    ]);
    $response = $response->getBody()->getContents();
    dd($response);
}

```

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [July 29, 2019, 4:59pm UTC](https://devforum.zoom.us/t/invalid-api-key-or-secret-error/5227/2 "2019-07-29T16:59:18Z")

</div>

Hey @umarraza2200 thanks for using the Zoom API!

I noticed you are trying to use: `grant_type=client_credentials` to get an `access_token`. The `grant_type=client_credentials` is only for [getting Chatbot tokens](https://marketplace.zoom.us/docs/guides/chatbots/authorization#access-tokens).

To [call the Zoom APIs via the OAuth App Type](https://marketplace.zoom.us/docs/guides/authorization/oauth/oauth-with-zoom#request-access-token) you must use: `grant_type=code` to get an `access_token`.

OR

For server to server integration, you can use a [JWT App Type](https://marketplace.zoom.us/docs/guides/authorization/jwt/jwt-with-zoom) to call the Zoom APIs.

More details on [Zoom App Types here](https://marketplace.zoom.us/docs/guides/getting-started/app-types).

Let me know if this works for you!

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![umarraza2200](https://avatars.discourse-cdn.com/v4/letter/u/34f0e0/32.png) [@umarraza2200](https://devforum.zoom.us/u/umarraza2200)\
**Post date:** [August 1, 2019, 4:39am UTC](https://devforum.zoom.us/t/invalid-api-key-or-secret-error/5227/3 "2019-08-01T04:39:36Z")

</div>

Hi Tommy,

Thanks for reaching me out. Let me know that what type, either JWT App type or OAuth type i have to use in my application. The scenario of the application is that on this web application,

teachers can take online virtual classes and can deliver lectures to students of this application. What type of app i have to integrate in my application? JWT for server to server integration or OAuth

for end-user?

I will be grateful if you guide me about that.

Regards,

Umar Raza

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [August 1, 2019, 4:06pm UTC](https://devforum.zoom.us/t/invalid-api-key-or-secret-error/5227/4 "2019-08-01T16:06:08Z")

</div>

Hey @umarraza2200,

For your use case, I would suggest an [OAuth App](https://marketplace.zoom.us/docs/guides/getting-started/app-types/create-oauth-app) because you will have many end-users using your application.

By creating an [OAuth App](https://marketplace.zoom.us/docs/guides/getting-started/app-types/create-oauth-app) on the [Zoom App Marketplace](https://marketplace.zoom.us/develop/create), you can securely integrate with Zoom APIs and access users’ authorized data using a user-based authentication approach. This app can either be installed and managed across an account by account admins (account-level app) or by users individually (user-managed app).

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![umarraza2200](https://avatars.discourse-cdn.com/v4/letter/u/34f0e0/32.png) [@umarraza2200](https://devforum.zoom.us/u/umarraza2200)\
**Post date:** [August 2, 2019, 4:58am UTC](https://devforum.zoom.us/t/invalid-api-key-or-secret-error/5227/5 "2019-08-02T04:58:00Z")

</div>

Hey Tommy,

Just last question, Is there any certain type of role of JWT to integrate my app with OAuth? Do we need JWT token or JWT credentials to enable Oauth in my application? I am asking this because I have tried integrating Oauth and I was getting an

error related to JWT credentials “Invalid api key or secret”. What is the relationship between JWT and Oauth in this case.

[![](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/c/ce885f4cfadc009ecaf10fdc45bf39ef6f6bc236.png)](http://www.avg.com/email-signature?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail)  
Virus-free. [www.avg.com](http://www.avg.com/email-signature?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail)

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [August 2, 2019, 5:14pm UTC](https://devforum.zoom.us/t/invalid-api-key-or-secret-error/5227/6 "2019-08-02T17:14:15Z")

</div>

Hey @umarraza2200,

If you use OAuth, in most cases you would not want to use JWT as well.

The steps to authenticate OAuth to call our API’s are a little different then JWT.

[Here are instructions](https://marketplace.zoom.us/docs/guides/authorization/oauth/oauth-with-zoom) on how to get an `access_token` to call the Zoom API endpoints.

1. [Get an Authorization Code](https://marketplace.zoom.us/docs/guides/authorization/oauth/oauth-with-zoom#authorization-code)
2. [Use Authorization Code to get an Access Token](https://marketplace.zoom.us/docs/guides/authorization/oauth/oauth-with-zoom#request-access-token)
3. [Use the Access Token to call Zoom APIs](https://marketplace.zoom.us/docs/api-reference/zoom-api/users/users). For example,

GET `https://api.zoom.us/v2/users`

Headers:  
`"Authorization": "Bearer {{ Access Token }}"`

Let me know if this helps!

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![umarraza2200](https://avatars.discourse-cdn.com/v4/letter/u/34f0e0/32.png) [@umarraza2200](https://devforum.zoom.us/u/umarraza2200)\
**Post date:** [August 3, 2019, 6:58am UTC](https://devforum.zoom.us/t/invalid-api-key-or-secret-error/5227/7 "2019-08-03T06:58:29Z")

</div>

Hi tommy,

I’ve followed the guide you mentioned. Zoom gives an example to get an access token in Node js. I am using Laravel so I have to make request in Laravel. This is the code

```php
$client_id = env('CLIENT_ID');
$client_secret = env('CLIENT_SECRET');
$redirect_uri = "http://localhost/alkhizra/get-autorization-code";
$content = "https://zoom.us/oauth/authorize?response_type=code&client_id=.'$client_id'.&redirect_uri=.$redirect_uri";

$client = new \GuzzleHttp\Client();
$request = $client->get("https://zoom.us/oauth/authorize?response_type=code&client_id=.'$client_id'.&redirect_uri=.$redirect_uri");
$response = $request->getBody()->getContents();
print_r($response);
die();

```

Now I am getting an error of invalid client\_id although the client\_id is correct.  
Invalid client\_id: .‘7zYVrnETtq5iqpuWXr5lA’. (4,702)

---

<div class="post-metadata">

**Author:** ![umarraza2200](https://avatars.discourse-cdn.com/v4/letter/u/34f0e0/32.png) [@umarraza2200](https://devforum.zoom.us/u/umarraza2200)\
**Post date:** [August 3, 2019, 6:59am UTC](https://devforum.zoom.us/t/invalid-api-key-or-secret-error/5227/8 "2019-08-03T06:59:27Z")

</div>

Can we make API requests to zoom if we are working on localhost or there are any helpful resource about integrating Zoom with Laravel application?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [August 5, 2019, 6:47pm UTC](https://devforum.zoom.us/t/invalid-api-key-or-secret-error/5227/9 "2019-08-05T18:47:50Z")

</div>

Hey @umarraza2200,

Can you try turning your localhost into a [web server](https://ngrok.com/)?

Example here:

> [@Zoom Application Wrong redirect](https://devforum.zoom.us/t/zoom-application-wrong-redirect/4402/5):
>
> Hey @subhan, This issue only happens with localhost urls. To solve this you could use [https://ngrok.com/](https://ngrok.com/) to turn your localhost server into a free server with a url, and replace the localhost redirect url with the ngrok url. Instead of [http://localhost:8080/api/v1/zoom/complete-oauth](http://localhost:8080/api/v1/zoom/complete-oauth) it would be [https://d4c4477b.ngrok.io/api/v1/zoom/complete-oauth](https://d4c4477b.ngrok.io/api/v1/zoom/complete-oauth) This way you can still develop and test locally and have your redirect url work! Let me know if this helps!

Let me know if this works!

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![DeveloperBot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/developerbot/32/12632_2.png) [@DeveloperBot](https://devforum.zoom.us/u/DeveloperBot)\
**Post date:** [August 21, 2020, 6:36pm UTC](https://devforum.zoom.us/t/invalid-api-key-or-secret-error/5227/10 "2020-08-21T18:36:22Z")

</div>


