# Oauth - authorize API

**URL:** <https://devforum.zoom.us/t/oauth-authorize-api/19920>\
**Category:** API and Webhooks\
**Created:** [June 2, 2020, 6:00am UTC](https://devforum.zoom.us/t/oauth-authorize-api/19920 "2020-06-02T06:00:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![akashkulkarni796](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/akashkulkarni796/32/9210_2.png) [@akashkulkarni796](https://devforum.zoom.us/u/akashkulkarni796)\
**Post date:** [June 2, 2020, 6:00am UTC](https://devforum.zoom.us/t/oauth-authorize-api/19920/1 "2020-06-02T06:00:57Z")

</div>

**Description**  
I am trying to integrate zoom in our education website where multpile institutes will have their zoom account. We are using Oauth Authorisation. Here issues lies while generating auth-code with every request, Is there any way to follow the redirects in the backend and get auth code there which can be passed on to generate the token API

**Which App Type (OAuth / Chatbot / JWT / Webhook)?**  
Oauth

**Which Endpoint/s?**

`res.redirect('https://zoom.us/oauth/authorize?response_type=code&client_id=' + clientID + '&redirect_uri=' + redirectURL)`

---

<div class="post-metadata">

**Author:** ![michael.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/michael.zoom/32/37213_2.png) [@michael.zoom](https://devforum.zoom.us/u/michael.zoom)\
**Post date:** [June 5, 2020, 5:42pm UTC](https://devforum.zoom.us/t/oauth-authorize-api/19920/2 "2020-06-05T17:42:17Z")

</div>

Hi @akashkulkarni796, you do not need to generate an auth code with each request, but rather you need an access token. Access tokens expire in 1 hour, so you will also receive a refresh token which can be used to get a new access token.

Users will only need to authorize your application once, and thus will only need to be redirected once (unless they deauthorize). This URL can be something like `https://yourapp.com/callback/zoom/auth` which will receive a code query in the URL. Use this code to then [request an access token](https://marketplace.zoom.us/docs/guides/auth/oauth#step-2-request-access-token).

Reference our Sample OAuth app to see this flow:

> **[zoom/zoom-oauth-sample-app](https://github.com/zoom/zoom-oauth-sample-app)**
>
> Sample Zoom Oauth App NodeJS app to call Zoom's APIs - zoom/zoom-oauth-sample-app

---

<div class="post-metadata">

**Author:** ![akashkulkarni796](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/akashkulkarni796/32/9210_2.png) [@akashkulkarni796](https://devforum.zoom.us/u/akashkulkarni796)\
**Post date:** [June 6, 2020, 4:39am UTC](https://devforum.zoom.us/t/oauth-authorize-api/19920/3 "2020-06-06T04:39:56Z")

</div>

Thank you Michael,  
This helped me a lot. Now I am trying to generate code and then token, but if i provide different redirect\_uri to for auth and token api it says “ **invalid Redirect** ” , So is it necessary to give same redirect URI for both the requests ?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [June 11, 2020, 6:43pm UTC](https://devforum.zoom.us/t/oauth-authorize-api/19920/4 "2020-06-11T18:43:57Z")

</div>

Hey @akashkulkarni796,

Checkout my post here on dynamic redirect urls:

> [@Does zoom support more than two environments for oauth2?](https://devforum.zoom.us/t/does-zoom-support-more-than-two-environments-for-oauth2/11052/12):
>
> Hey @tuancode, @michael.solomon, This is totally possible! slight_smile Let me walk you through how to do this with the base domain of example.com For your whitelist, simply add your base domain: https://example.com Then in your dev/prod redirect url field, add a default redirect, https://any.example.com (this will be programmatically overridden to the correct sub domain, continue reading below) Now, with your install URL ([the url mentioned in Step 1. of the OAuth guide](https://marketplace.zoom.us/docs/guides/auth/oauth#getting-access-token)) in your code, dyna…

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![DeveloperBot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/developerbot/32/12632_2.png) [@DeveloperBot](https://devforum.zoom.us/u/DeveloperBot)\
**Post date:** [August 21, 2020, 10:00pm UTC](https://devforum.zoom.us/t/oauth-authorize-api/19920/5 "2020-08-21T22:00:10Z")

</div>


