# {"reason":"Invalid Token!","error":"invalid\_request"}

**URL:** <https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567>\
**Category:** API and Webhooks\
**Created:** [August 19, 2020, 6:50am UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567 "2020-08-19T06:50:16Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![kristian](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/kristian/32/951_2.png) [@kristian](https://devforum.zoom.us/u/kristian)\
**Post date:** [August 19, 2020, 6:50am UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567/1 "2020-08-19T06:50:16Z")

</div>

**Description**  
I am unable to refresh access tokens

**Error**  
I constantly get this error:  
`{"reason":"Invalid Token!","error":"invalid_request"}`

**Which App Type (OAuth / Chatbot / JWT / Webhook)?**  
Oauth

**Which Endpoint/s?**  
[https://zoom.us/oauth/token](https://zoom.us/oauth/token)

**How To Reproduce (If applicable)**  
Steps to reproduce the behavior:

```auto
curl -X POST -H "Content-Type:application/x-www-form-urlencoded" \ --user {client-id}:{client-secret} \ --data 'grant\_type=refresh\_token&refresh\_token={refresh-token}' \ https://zoom.us/oauth/token

```

**Additional context**  
I am not sure why this isn’t working. When I get the initial access token, I can make requests just fine. I store the refresh token and when the access token expires after an hour, I try to refresh it and get this error.  
According to the docs ([https://marketplace.zoom.us/docs/guides/auth/oauth#refreshing](https://marketplace.zoom.us/docs/guides/auth/oauth#refreshing)), I should set `grant_type` and `refresh_token` as query params. However, someone notes ([REST API error on OAuth token refresh](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/6)) that it should really be form encoded. But neither seem to work for me. My app is listed on the marketplace.

I see that some people make the mistake of not storing the latest refresh token but that is not the case here, because I get this error on the first attempt. I also see that some have had issues when using the new access token immediately after receiving it but that is obviously also not the case as I never receive a new one 🙂. I am not sure what to do from here.

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [August 21, 2020, 8:44pm UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567/2 "2020-08-21T20:44:46Z")

</div>

Hey @kristian,

What is your app name?

Are you able to make the refresh request via Postman?

 ![Screen Shot 2020-08-21 at 2.44.36 PM](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/1/10f68648dac0301d7c1e87e2a8c42419a4539c3f.png)

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![kristian](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/kristian/32/951_2.png) [@kristian](https://devforum.zoom.us/u/kristian)\
**Post date:** [August 26, 2020, 6:35pm UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567/3 "2020-08-26T18:35:20Z")

</div>

Hi Tommy,

App name is Submotion. It doesn’t seem to work for me:

 ![billede](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/4/434f3952be624390f715a96bd6f197dde1c5cddb.png)

---

<div class="post-metadata">

**Author:** ![kristian](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/kristian/32/951_2.png) [@kristian](https://devforum.zoom.us/u/kristian)\
**Post date:** [August 27, 2020, 6:42am UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567/4 "2020-08-27T06:42:29Z")

</div>

@tommy I can send you the clientid and secret in a DM or something if you want

---

<div class="post-metadata">

**Author:** ![kristian](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/kristian/32/951_2.png) [@kristian](https://devforum.zoom.us/u/kristian)\
**Post date:** [August 31, 2020, 5:51am UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567/5 "2020-08-31T05:51:54Z")

</div>

Any hints on how to debug this would be greatly appreciated. It’s quite frustrating to work with because I have to re-authorize and wait for the token to expire to try something out and I don’t know what else to try at this point.

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [August 31, 2020, 3:59pm UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567/6 "2020-08-31T15:59:13Z")

</div>

Hey @kristian,

I have just DM’d you.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![nsaxena](https://avatars.discourse-cdn.com/v4/letter/n/73ab20/32.png) [@nsaxena](https://devforum.zoom.us/u/nsaxena)\
**Post date:** [August 31, 2020, 5:56pm UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567/7 "2020-08-31T17:56:53Z")

</div>

Hi Tommy,

We have business account, In SDK when joining meeting it is giving error. here is detail-

**localJsonpCallback({status: false, errorCode: 200, errorMessage: “The signature has expired.”})**  
**errorCode: 200**  
**errorMessage: "The signature has expired."**  
**status: false**

 ![image](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/4/477fe6dbd49be898a6798ab47262eb04ffa39c0c.png)

And when we click on ‘RETRY’ button zoom environment is loading. here is screenshot -

 ![image](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/a/a3e733447765dc65bd3f91f5ca21da74640afd40.png)

Signature I am creating through java version at server side which you are providing in below portal -

> **[Generate Signature - Essential Guides - Web - Native SDKs - Zoom Software...](https://marketplace.zoom.us/docs/sdk/native-sdks/web/essential/signature)**
>
> Generate Signature
> 
> Each request to Start or Join a Meeting / Webinar must be verified by an encrypted signature authorizing the user to enter.
> 
> The sig...

I tested different browser and also cleared cache, and added SetTimeOut on ZoomMtg.join() but did not helped.

Date format sample : 2020-08-31T16:49:18Z  
Type : 1

**SDK Version : 1.7.10**  
JWT App : DevTokenApp

Appreciate if you provide me a quick help. Let me know how can share you detail in private message if required. I am using JWT token?

Nikhil

---

<div class="post-metadata">

**Author:** ![kristian](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/kristian/32/951_2.png) [@kristian](https://devforum.zoom.us/u/kristian)\
**Post date:** [September 2, 2020, 10:38am UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567/8 "2020-09-02T10:38:43Z")

</div>

So for future visitors of this thread, it _seems_ to be resolved for me now. I didn’t change any code, so I am not sure what caused it. I did do one thing though, with Tommys help: I went to the “Test the App Locally” tab in the management UI, clicked “uninstall” and then “install”.

I have had one report of an invalid token after doing this, but I am currently unable to reproduce it so I am crossing my fingers that it’s now working.

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [September 4, 2020, 8:32pm UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567/9 "2020-09-04T20:32:54Z")

</div>

Hey @nsaxena,

Please create a topic here: #web-sdk 🙂

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [September 4, 2020, 8:34pm UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567/10 "2020-09-04T20:34:28Z")

</div>

Hey @kristian,

Thanks for sharing your solution! 🙂

Please let me know if you run into the issue again.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![hurle170](https://avatars.discourse-cdn.com/v4/letter/h/91b2a8/32.png) [@hurle170](https://devforum.zoom.us/u/hurle170)\
**Post date:** [September 12, 2020, 12:58am UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567/11 "2020-09-12T00:58:00Z")

</div>

I am having the same issue with my user managed app. All token refresh requests get the same invalid token error. I’ve ensured all the needed headers are present and that I am for sure sending the refresh token. The initial token works for all requests, but I can never refresh them. Any debugging suggestions?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [September 15, 2020, 12:43am UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567/12 "2020-09-15T00:43:08Z")

</div>

Hey @hurle170,

Are you able to reproduce the issue in Postman? Typically the issue relays in the logic within the code implementing the OAuth flow.

Please create a new topic since this one is solved. 🙂

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [October 15, 2020, 10:43am UTC](https://devforum.zoom.us/t/reason-invalid-token-error-invalid-request/27567/13 "2020-10-15T10:43:11Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
