# Question about OAuth refresh\_token

**URL:** <https://devforum.zoom.us/t/question-about-oauth-refresh-token/16830>\
**Category:** API and Webhooks\
**Created:** [May 8, 2020, 8:14pm UTC](https://devforum.zoom.us/t/question-about-oauth-refresh-token/16830 "2020-05-08T20:14:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kmwill23](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/kmwill23/32/6297_2.png) [@kmwill23](https://devforum.zoom.us/u/kmwill23)\
**Post date:** [May 8, 2020, 8:14pm UTC](https://devforum.zoom.us/t/question-about-oauth-refresh-token/16830/1 "2020-05-08T20:14:05Z")

</div>

**Description**  
I just want to be absolutely clear on how refresh\_token works for the OAuth API.

The initial token for a user expires in 1 hour. However, the refresh\_token lasts for 15 years.

Could I then just use that initial token, immediately generate a refresh\_token, and then not have to worry about web-based token generation ever again? (15 years).

I was originally going to ask if there was a method to use the OAuth API without using any kind of Token. This is because not all server operations are driven by a user, so there will be times where the web browser authorization process could not be done, but I’d still like to access information about Meetings without any user context.

But if I can at least generate user refresh\_tokens that last 15 years, I can just fake it. But is that going outside good OAuth design?

**Error**  
N/A

**Which App Type (OAuth / Chatbot / JWT / Webhook)?**  
OAuth

**Which Endpoint/s?**  
Kinda all of them.

**How To Reproduce (If applicable)**  
N/A

**Screenshots (If applicable)**  
N/A

**Additional context**  
N/A

---

<div class="post-metadata">

**Author:** ![samly](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@samly](https://devforum.zoom.us/u/samly)\
**Post date:** [May 8, 2020, 10:10pm UTC](https://devforum.zoom.us/t/question-about-oauth-refresh-token/16830/2 "2020-05-08T22:10:04Z")

</div>

Few things to consider:

1. A refresh\_token is only valid to get a new access\_token. It cannot be used to make API calls itself.
2. At the same time you recieve a new access\_token, the JSON response also includes a new refresh\_token.
3. The existing (now old) refresh\_token is invalidated when you use it to retrieve a new access\_token.

Ideally, you should store the latest access\_token, time it is granted, expiration, and refresh\_token every time you either do an OAuth from scratch or refresh\_token from the server. You can also combine the grant time + expiration time into one timestamp of when that access\_token expires.

The very first time you use OAuth in your application, the flow should look like this:  
(I have like an admin panel where I can re-start the Oauth process separate from the rest of the app)

1. Initial OAuth authorization
2. Get the “code” from the redirect back to your application
3. Complete the “token” step by posting to Zoom with the aforementioned code.
4. Store access\_token, expiration timestamp and refresh\_token somewhere.

On all requests to the API:

1. Check expiration time of current access\_token compared current time.
2. If expired,  
a. use the refresh\_token to get a new access\_token. (POST to [https://zoom.us.oauth/token](https://zoom.us.oauth/token) with refresh\_token)  
b. Store the new access\_token, expiration date and refresh token.
3. Use latest stored access\_token to make API call.
4. Repeat for all API requests.

---

<div class="post-metadata">

**Author:** ![kmwill23](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/kmwill23/32/6297_2.png) [@kmwill23](https://devforum.zoom.us/u/kmwill23)\
**Post date:** [May 8, 2020, 10:15pm UTC](https://devforum.zoom.us/t/question-about-oauth-refresh-token/16830/3 "2020-05-08T22:15:04Z")

</div>

oooo, powerful information. Though it did kill the fun of the 15 year access\_token idea. However, with the refresh\_token it appears the access\_token can be updated serverside without having to use the web auth all the time.

Thanks tons samly!

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [May 13, 2020, 10:37pm UTC](https://devforum.zoom.us/t/question-about-oauth-refresh-token/16830/4 "2020-05-13T22:37:29Z")

</div>

Hey @kmwill23,

Yep, you can [refresh the access\_token](https://marketplace.zoom.us/docs/guides/auth/oauth#refreshing) on server side whenever you choose.

Thanks @samly for your detailed solution!

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![DeveloperBot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/developerbot/32/12632_2.png) [@DeveloperBot](https://devforum.zoom.us/u/DeveloperBot)\
**Post date:** [August 21, 2020, 9:18pm UTC](https://devforum.zoom.us/t/question-about-oauth-refresh-token/16830/5 "2020-08-21T21:18:40Z")

</div>


