# Oauth invalid\_request

**URL:** <https://devforum.zoom.us/t/oauth-invalid-request/85291>\
**Category:** API and Webhooks\
**Tags:** webhooks, api, php, s2s-oauth\
**Created:** [March 24, 2023, 11:16am UTC](https://devforum.zoom.us/t/oauth-invalid-request/85291 "2023-03-24T11:16:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![p.gallo](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/p.gallo/32/46771_2.png) [@p.gallo](https://devforum.zoom.us/u/p.gallo)\
**Post date:** [March 24, 2023, 11:16am UTC](https://devforum.zoom.us/t/oauth-invalid-request/85291/1 "2023-03-24T11:16:12Z")

</div>

I’m migrating from JWT to oauth so I created Server-to-Server OAuth app with credentilas and scopes.  
Initially no problems but during the last days I had an issue with oauth token.  
With these credentials I create tokens in php

```auto
$url = 'https://zoom.us/oauth/token';
$data = array(
       'grant_type' => 'client_credentials'
    );
    
    $headers = array(
        'Authorization: Basic '. base64_encode(my_Client_ID:my_Client_secret)
    );
    
    $curl = curl_init();
        curl_setopt($curl, CURLOPT_URL, $url);
        curl_setopt($curl, CURLOPT_POST, 1);
        curl_setopt($curl, CURLOPT_POSTFIELDS, http_build_query($data));
        curl_setopt($curl, CURLOPT_HTTPHEADER, $headers);
        curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
    $response = curl_exec($curl);
    
    if(curl_errno($curl)) {
        echo 'Curl error: ' . curl_error($curl);
    }
    
    curl_close($curl);
    
    $data0=json_decode($response, true);

```

With this token I call some APIs, for example

```auto
$url = "https://api.zoom.us/v2/past_meetings/{$meeting_id}/participants";
$curl = curl_init($url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_HTTPHEADER, array(
    "Authorization: Bearer {$access_token}"
));
$response = curl_exec($curl);

```

or

```auto
$url = "https://api.zoom.us/oauth/check_token?access_token={$access_token}";
$ch = curl_init($url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$response = curl_exec($ch);
curl_close($ch);
$data = json_decode($response);
if (isset($data->error)) {
    print_r($data->error);    
}

```

The error I get is _ **invalid\_request** _.

I tried also creating a new token with shell but it’s the same.  
I tried also with different client ID and secret ID always the same error.  
Any ideas?  
Can you help me, please?

Thanks

---

<div class="post-metadata">

**Author:** ![p.gallo](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/p.gallo/32/46771_2.png) [@p.gallo](https://devforum.zoom.us/u/p.gallo)\
**Post date:** [March 28, 2023, 1:33pm UTC](https://devforum.zoom.us/t/oauth-invalid-request/85291/2 "2023-03-28T13:33:32Z")

</div>

Am I the only one experiencing this problem?

---

<div class="post-metadata">

**Author:** ![donte.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/donte.zoom/32/24412_2.png) [@donte.zoom](https://devforum.zoom.us/u/donte.zoom)\
**Post date:** [April 20, 2023, 9:38am UTC](https://devforum.zoom.us/t/oauth-invalid-request/85291/3 "2023-04-20T09:38:25Z")

</div>

@p.gallo,

Thank you for posting in the Zoom Developer Forum. Can you share screenshot of the message you are seeing ?

---

<div class="post-metadata">

**Author:** ![p.gallo](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/p.gallo/32/46771_2.png) [@p.gallo](https://devforum.zoom.us/u/p.gallo)\
**Post date:** [April 20, 2023, 10:30am UTC](https://devforum.zoom.us/t/oauth-invalid-request/85291/4 "2023-04-20T10:30:28Z")

</div>

> [@p.gallo](#):
>
> `print_r($data->error);`

Hi  
there’s no specific screenshot: the `print_r($data->error)` line prints out **invalid\_request**

print\_r($data); prints  
`stdClass Object`  
`(`  
` [reason] => Internal Error`  
` [error] => invalid_request`  
`)`

Below the code I use for creating and check the token

```auto
<?php

	$url = 'https://zoom.us/oauth/token';
	$data = array(
		'grant_type' => 'client_credentials'
	);
	
	$headers = array(
		'Authorization: Basic '. base64_encode('*my_Client_ID*:*my_Client_secret*')
	);
	
	$curl = curl_init();
		curl_setopt($curl, CURLOPT_URL, $url);
		curl_setopt($curl, CURLOPT_POST, 1);
		curl_setopt($curl, CURLOPT_POSTFIELDS, http_build_query($data));
		curl_setopt($curl, CURLOPT_HTTPHEADER, $headers);
		curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
	$response = curl_exec($curl);
	
	if(curl_errno($curl)) {
		echo 'Curl error: ' . curl_error($curl);
	}
	
	curl_close($curl);
	
	echo "<pre>";
	print_r($response);
	echo "</pre>";
	
	
	$data0=json_decode($response, true);
	
	
	
	
	$timestamp = time() + 3460;
	$expiration = date('YmdHi', $timestamp);

	$data0['creazione'] = date('YmdHi', time());
	$data0['expiration'] = $expiration;
	$generated_token=$data0['access_token'];
	
	echo "<pre>";
	print_r($data0);
	echo "</pre>";
	
	$generated_token=$data0['access_token'];
	
	echo "<pre>";
	print_r($generated_token);
	echo "</pre>";
	
	
$url = "https://api.zoom.us/oauth/check_token?access_token={$generated_token}";

	echo "<pre>";
	print_r($url);
	echo "</pre>";

$ch = curl_init($url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$response = curl_exec($ch);
curl_close($ch);

$data = json_decode($response);

if (isset($data->error)) {
    echo "Invalid or expired token.\n";
	echo "<h3>";
	print_r($data->error);
	echo "<pre>";
	
	print_r($data);
	echo "</pre></h3>";
	
	
} else {
    echo "Valid token.\n";
}
	

?>

```

Is there something else I can share with you?  
Thanks  
Pierpaolo

---

<div class="post-metadata">

**Author:** ![BetterMynd](https://avatars.discourse-cdn.com/v4/letter/b/278dde/32.png) [@BetterMynd](https://devforum.zoom.us/u/BetterMynd)\
**Post date:** [April 20, 2023, 11:23am UTC](https://devforum.zoom.us/t/oauth-invalid-request/85291/5 "2023-04-20T11:23:57Z")

</div>

Ran into this just this week as we swap over to OAuth.

Your query string needs the following:

- grant\_type = “account\_credentials”
- account\_id = “{Account Id in the OAuth App}”

You get an access token that lives for 1 hour, with no refresh token. When you need a new token, you call the endpoint again to fetch a new token.

[Server-to-Server OAuth (zoom.us)](https://developers.zoom.us/docs/internal-apps/s2s-oauth/)

---

<div class="post-metadata">

**Author:** ![p.gallo](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/p.gallo/32/46771_2.png) [@p.gallo](https://devforum.zoom.us/u/p.gallo)\
**Post date:** [April 20, 2023, 11:40am UTC](https://devforum.zoom.us/t/oauth-invalid-request/85291/6 "2023-04-20T11:40:21Z")

</div>

Thank you  
I’m pretty sure I still miss something because also with accout credentials I got the same error (altough the token is created)

Below the code

```auto
<?php

	$url = 'https://zoom.us/oauth/token';
	$data = array(
		'grant_type' => 'account_credentials',
		'account_id' => '*myAccount_id*'
	);
	
	$headers = array(
		'Authorization: Basic '. base64_encode('*my_Client_ID*:*my_Client_secret*')
	);
	
	$curl = curl_init();
		curl_setopt($curl, CURLOPT_URL, $url);
		curl_setopt($curl, CURLOPT_POST, 1);
		curl_setopt($curl, CURLOPT_POSTFIELDS, http_build_query($data));
		curl_setopt($curl, CURLOPT_HTTPHEADER, $headers);
		curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
	$response = curl_exec($curl);
	
	if(curl_errno($curl)) {
		echo 'Curl error: ' . curl_error($curl);
	}
	
	curl_close($curl);
	
	echo "<pre>";
	print_r($response);
	echo "</pre>";
	
	
	$data0=json_decode($response, true);
	
	
	
	
	$timestamp = time() + 3460;
	$expiration = date('YmdHi', $timestamp);

	$data0['creazione'] = date('YmdHi', time());
	$data0['expiration'] = $expiration;
	$generated_token=$data0['access_token'];
	
	echo "<pre>";
	print_r($data0);
	echo "</pre>";
	
	$generated_token=$data0['access_token'];
	
	echo "<pre>";
	print_r($generated_token);
	echo "</pre>";
	
	
$url = "https://api.zoom.us/oauth/check_token?access_token={$generated_token}";

	echo "<pre>";
	print_r($url);
	echo "</pre>";

$ch = curl_init($url);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$response = curl_exec($ch);
curl_close($ch);

$data = json_decode($response);

if (isset($data->error)) {
    echo "Invalid or expired token.\n";
	echo "<h3>";
	print_r($data->error);
	echo "<pre>";
	
	print_r($data);
	echo "</pre></h3>";
	
	
} else {
    echo "Valid token.\n";
}
	

?>

```

Thanks again

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [April 23, 2024, 3:17am UTC](https://devforum.zoom.us/t/oauth-invalid-request/85291/7 "2024-04-23T03:17:03Z")

</div>

This topic was automatically closed 368 days after the last reply. New replies are no longer allowed.
