# PHP Invalid Access Token

**URL:** <https://devforum.zoom.us/t/php-invalid-access-token/11776>\
**Category:** API and Webhooks\
**Created:** [April 7, 2020, 10:43am UTC](https://devforum.zoom.us/t/php-invalid-access-token/11776 "2020-04-07T10:43:41Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![TCADeveloper](https://avatars.discourse-cdn.com/v4/letter/t/a698b9/32.png) [@TCADeveloper](https://devforum.zoom.us/u/TCADeveloper)\
**Post date:** [April 7, 2020, 10:43am UTC](https://devforum.zoom.us/t/php-invalid-access-token/11776/1 "2020-04-07T10:43:41Z")

</div>

So I’m using the below code to firstly get an access token…

$clientID="**";  
$clientSecret="**";  
$content = “grant\_type=client\_credentials&client\_id=$clientID&client\_secret=$clientSecret”;  
$token\_url=“[https://zoom.us/oauth/token](https://zoom.us/oauth/token)”;

$ch = curl\_init($token\_url);  
curl\_setopt($ch, CURLOPT\_CUSTOMREQUEST, “POST”);  
curl\_setopt($ch, CURLOPT\_POSTFIELDS, $content);  
curl\_setopt($ch, CURLOPT\_RETURNTRANSFER, true);  
curl\_setopt($ch, CURLOPT\_TIMEOUT, 60);  
curl\_setopt($ch, CURLOPT\_CONNECTTIMEOUT, 60);  
curl\_setopt($ch, CURLOPT\_FOLLOWLOCATION, TRUE);  
curl\_setopt($ch, CURLOPT\_SSL\_VERIFYPEER, false);  
$result = curl\_exec($ch);  
$objJSON = json\_decode($result,false);

Which works fine and I get a token back…

$webinarID = “164712960”;  
$token\_url=“[https://api.zoom.us/v2/webinars/](https://api.zoom.us/v2/webinars/)”. $webinarID . “/registrants”;  
$content ="";  
$headers = array(  
‘authorization’ =\> 'Bearer ’ . $objJSON-\>access\_token,  
‘content-type’ =\> ‘application/json’  
);

$ch = curl\_init($token\_url);  
curl\_setopt($ch, CURLOPT\_CUSTOMREQUEST, “POST”);  
curl\_setopt($ch, CURLOPT\_POSTFIELDS, $content);  
curl\_setopt($ch, CURLOPT\_HTTPHEADER, $headers);  
curl\_setopt($ch, CURLOPT\_RETURNTRANSFER, true);  
curl\_setopt($ch, CURLOPT\_TIMEOUT, 60);  
curl\_setopt($ch, CURLOPT\_CONNECTTIMEOUT, 60);  
curl\_setopt($ch, CURLOPT\_FOLLOWLOCATION, TRUE);  
curl\_setopt($ch, CURLOPT\_SSL\_VERIFYPEER, false);  
$result = curl\_exec($ch);

However with the above that I am using to register a new attendee (aware I am not passing any content yet) I am getting a {“code”:124,“message”:“Invalid access token.”} response back.

What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [April 7, 2020, 10:46pm UTC](https://devforum.zoom.us/t/php-invalid-access-token/11776/2 "2020-04-07T22:46:20Z")

</div>

Hey @TCADeveloper,

Please try passing in a request body (content) and see if that fixes the issue.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![TCADeveloper](https://avatars.discourse-cdn.com/v4/letter/t/a698b9/32.png) [@TCADeveloper](https://devforum.zoom.us/u/TCADeveloper)\
**Post date:** [April 8, 2020, 8:07am UTC](https://devforum.zoom.us/t/php-invalid-access-token/11776/3 "2020-04-08T08:07:20Z")

</div>

Hi Tommy,

I’m now passing it the following JSON, and its still returning Invalid.

{“[email":"simon@simonhix.co.uk](mailto:email%22:%22simon@simonhix.co.uk)”,“first\_name”:“Simon”,“last\_name”:“Hix”,“address”:“dsfhkdjsfh st”,“city”:“jackson heights”,“country”:“US”,“zip”:“11371”,“state”:“NY”,“phone”:“00000000”,“industry”:“Food”,“org”:“Cooking Org”,“job\_title”:“Cooking Org”,“purchasing\_time\_frame”:“1-3 months”,“role\_in\_purchase\_process”:“Influencer”,“no\_of\_employees”:“10”,“comments”:“Looking forward to the Webinar”,“custom\_questions”:{“title”:“What do you hope to learn from this Webinar?”,“value”:“Look forward to learning how you come up with new recipes and what other services you offer.”}}

Simon

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [April 8, 2020, 7:24pm UTC](https://devforum.zoom.us/t/php-invalid-access-token/11776/4 "2020-04-08T19:24:33Z")

</div>

Hey @TCADeveloper,

Thanks, can you private message me your access token so I can take a look?

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![stanislav.furman](https://avatars.discourse-cdn.com/v4/letter/s/c77e96/32.png) [@stanislav.furman](https://devforum.zoom.us/u/stanislav.furman)\
**Post date:** [June 30, 2020, 5:52pm UTC](https://devforum.zoom.us/t/php-invalid-access-token/11776/5 "2020-06-30T17:52:20Z")

</div>

I am have similar problem with almost same code but I get “Invalid api key or secret.”  
Any idea what could cause this?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [July 1, 2020, 10:18pm UTC](https://devforum.zoom.us/t/php-invalid-access-token/11776/6 "2020-07-01T22:18:59Z")

</div>

Hey @stanislav.furman,

Which API are you calling?

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![stanislav.furman](https://avatars.discourse-cdn.com/v4/letter/s/c77e96/32.png) [@stanislav.furman](https://devforum.zoom.us/u/stanislav.furman)\
**Post date:** [July 2, 2020, 1:29pm UTC](https://devforum.zoom.us/t/php-invalid-access-token/11776/7 "2020-07-02T13:29:23Z")

</div>

Hi @tommy  
I am trying to implement a webform to add participants to a webinar.  
So, I am first trying to obtain an authorization token by calling `https://zoom.us/oauth/token?` just like in the original message of this topic. Then I try to add participants:  
`https://api.zoom.us/v2/webinars/{webinar_id}/registrants`  
… but I get {“code”:200,“message”:“Invalid api key or secret.”}.

I guess the token that I receive at my step 1 is not meant to be used to communicate with webinars methods.

I looked the [OAuth authorization steps](https://marketplace.zoom.us/docs/guides/auth/oauth) but I am not sure how step 1 can be implemented in my PHP code. It seems like I need to redirect the user to authorization page every time?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [July 6, 2020, 10:43pm UTC](https://devforum.zoom.us/t/php-invalid-access-token/11776/8 "2020-07-06T22:43:45Z")

</div>

Hey @stanislav.furman,

It sounds like you want to use [JWT Token auth](https://marketplace.zoom.us/docs/guides/auth/jwt) instead of OAuth since you aren’t needing to call the API on external Zoom users behalf.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![DeveloperBot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/developerbot/32/12632_2.png) [@DeveloperBot](https://devforum.zoom.us/u/DeveloperBot)\
**Post date:** [August 21, 2020, 10:35pm UTC](https://devforum.zoom.us/t/php-invalid-access-token/11776/9 "2020-08-21T22:35:21Z")

</div>


