# REST API error on OAuth token refresh

**URL:** <https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520>\
**Category:** API and Webhooks\
**Created:** [August 2, 2018, 10:58pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520 "2018-08-02T22:58:39Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Craig\_Soules](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@Craig\_Soules](https://devforum.zoom.us/u/Craig_Soules)\
**Post date:** [August 2, 2018, 10:58pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/1 "2018-08-02T22:58:39Z")

</div>

We are trying to implement OAuth token refresh for our API integration with Zoom and are getting the following error:

{“reason”:“Failed to find the refresh Token. The Token may be regenerated”,“error”:“invalid\_request”}

We can’t find any documentation on API errors.&nbsp; We also have tried re-authorizing the access and refresh tokens multiple times, but have never been able to perform a successful refresh.

Thanks,  
Craig

---

<div class="post-metadata">

**Author:** ![michael\_p.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/michael_p.zoom/32/18105_2.png) [@michael\_p.zoom](https://devforum.zoom.us/u/michael_p.zoom)\
**Post date:** [August 3, 2018, 6:26pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/2 "2018-08-03T18:26:38Z")

</div>

Hi Craig,&nbsp;

We will share this with our Engineering team and follow up with you as soon as we find a solution with refresh token.&nbsp;

Thanks

---

<div class="post-metadata">

**Author:** ![michael\_p.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/michael_p.zoom/32/18105_2.png) [@michael\_p.zoom](https://devforum.zoom.us/u/michael_p.zoom)\
**Post date:** [August 3, 2018, 6:54pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/3 "2018-08-03T18:54:48Z")

</div>

Hi Craig,&nbsp;

After you get the code and send a POST request to&nbsp;[https://zoom.us/oauth/token?grant\_type=authorization\_code](https://zoom.us/oauth/token?grant_type=authorization_code) similar to [Step 3 in our OAuth doc](https://developer.zoom.us/docs/oauth/). Are you receiving the the initial refresh token?

&nbsp;

Thanks

---

<div class="post-metadata">

**Author:** ![Craig\_Soules](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@Craig\_Soules](https://devforum.zoom.us/u/Craig_Soules)\
**Post date:** [August 3, 2018, 11:24pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/4 "2018-08-03T23:24:08Z")

</div>

Michael,

Yes, we are receiving the initial access and refresh tokens as expected.&nbsp; It is when we try to use that refresh token to perform the refresh that we are getting the error.

&nbsp;

It’s certainly possible we are doing something wrong on our side (although as I mentioned we’ve read the docs and tried several approaches), but it’s a strange error and we couldn’t find any documentation on the returned error codes that might help us debug… if there’s any additional details I can provide that might help you debug on your side, please just let me know.

&nbsp;

Thanks!

Craig

---

<div class="post-metadata">

**Author:** ![michael\_p.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/michael_p.zoom/32/18105_2.png) [@michael\_p.zoom](https://devforum.zoom.us/u/michael_p.zoom)\
**Post date:** [August 4, 2018, 12:03am UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/5 "2018-08-04T00:03:12Z")

</div>

Hi Craig,&nbsp;

Once you have the refresh token are you using it to generate a new access token, then you can call the APIs?

Here is an example&nbsp;

```
curl -X POST -H "Content-Type:application/x-www-form-urlencoded" \ --user {client-id}:{client-secret} \ --data 'grant\_type=refresh\_token&refresh\_token={refresh-token}' \ https://zoom.us/oauth/token

```

Thanks

---

<div class="post-metadata">

**Author:** ![Craig\_Soules](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@Craig\_Soules](https://devforum.zoom.us/u/Craig_Soules)\
**Post date:** [August 4, 2018, 7:36pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/6 "2018-08-04T19:36:48Z")

</div>

I notice you are using the header “Content-Type:application/x-www-form-urlencoded” which isn’t listed in the documentation around refresh listed on this page:

[https://devdocs.zoom.us/docs/oauth-with-zoom](https://devdocs.zoom.us/docs/oauth-with-zoom)

It appears to have solved our problem, so you may want to update the docs accordingly.&nbsp; Also on that page, the refresh token section makes reference to the revoke endpoint, which we noticed, but could be quite misleading for folks.

Thanks!  
Craig

---

<div class="post-metadata">

**Author:** ![Craig\_Soules](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@Craig\_Soules](https://devforum.zoom.us/u/Craig_Soules)\
**Post date:** [August 4, 2018, 7:38pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/7 "2018-08-04T19:38:03Z")

</div>

It would also be great if you guys could document the OAuth scopes somewhere since we couldn’t even find a list of them.

---

<div class="post-metadata">

**Author:** ![Craig\_Soules](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@Craig\_Soules](https://devforum.zoom.us/u/Craig_Soules)\
**Post date:** [August 4, 2018, 9:44pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/8 "2018-08-04T21:44:31Z")

</div>

Along these same lines, we are now getting an error:

“Invalid access token, does not contain scopes: [user:write:admin, user:read:admin]”

While trying to read the list of users from the endpoint:

[https://api.zoom.us/v2/users](https://api.zoom.us/v2/users)

We tried adding the following scope string to our initial OAuth token generation flow: “user:read:admin meeting:read user:read webinar:read” but got this error:

“Invalid scope: user:read:admin as current client hasn’t this approved scope! (4,700)”

Any suggestions here would be quite welcome.

Thanks!  
Craig

---

<div class="post-metadata">

**Author:** ![michael\_p.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/michael_p.zoom/32/18105_2.png) [@michael\_p.zoom](https://devforum.zoom.us/u/michael_p.zoom)\
**Post date:** [August 7, 2018, 4:45pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/9 "2018-08-07T16:45:47Z")

</div>

Hi Craig,&nbsp;

For your application OAuth flow, do you have it registered through our [developer.zoom.us](http://developer.zoom.us) site or using [marketplace.zoom.us](http://marketplace.zoom.us)?

&nbsp;

Thanks

---

<div class="post-metadata">

**Author:** ![Craig\_Soules](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@Craig\_Soules](https://devforum.zoom.us/u/Craig_Soules)\
**Post date:** [August 7, 2018, 5:14pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/10 "2018-08-07T17:14:51Z")

</div>

We set it up through the developer site.&nbsp; We’ll try going through the marketplace site.

Thanks!  
Craig

---

<div class="post-metadata">

**Author:** ![michael\_p.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/michael_p.zoom/32/18105_2.png) [@michael\_p.zoom](https://devforum.zoom.us/u/michael_p.zoom)\
**Post date:** [August 7, 2018, 5:17pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/11 "2018-08-07T17:17:42Z")

</div>

Hi Craig,&nbsp;

Great, you can set the scopes using marketplace as well, here is a list of the API method scopes -&nbsp;[https://devdocs.zoom.us/docs/permissions](https://devdocs.zoom.us/docs/permissions)

Thanks

---

<div class="post-metadata">

**Author:** ![Jared\_Morse](https://avatars.discourse-cdn.com/v4/letter/j/57b2e6/32.png) [@Jared\_Morse](https://devforum.zoom.us/u/Jared_Morse)\
**Post date:** [August 30, 2018, 5:42pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/12 "2018-08-30T17:42:19Z")

</div>

Also seeing this issue when trying to refresh an access token.&nbsp; The initial&nbsp;code/token exchange works, but after the access token expires we get this message when attempting a refresh.&nbsp; The docs&nbsp;are in a pretty bad state and contradict the OAuth2 spec in several ways.

&nbsp;

Craig, your example given also fails for us with the same message.

---

<div class="post-metadata">

**Author:** ![Craig\_Soules](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@Craig\_Soules](https://devforum.zoom.us/u/Craig_Soules)\
**Post date:** [August 30, 2018, 5:54pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/13 "2018-08-30T17:54:02Z")

</div>

Just to close the loop on this, apps created via the developer site seem to have very limited OAuth scopes that are not configurable.&nbsp; If you construct an app in their marketplace you can set your scopes which solves the problem.

Unfortunately the scopes are not documented anywhere, so it’s a bit trial and error to figure out which ones you need.&nbsp; For example, we found we had to request write access to users just to get a listing of users, which is both counter-intuitive and problematic from a security perspective –&nbsp;resulting in some questions from our customers.&nbsp; But at least it works now 😉

---

<div class="post-metadata">

**Author:** ![Jared\_Morse](https://avatars.discourse-cdn.com/v4/letter/j/57b2e6/32.png) [@Jared\_Morse](https://devforum.zoom.us/u/Jared_Morse)\
**Post date:** [August 30, 2018, 6:53pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/14 "2018-08-30T18:53:04Z")

</div>

Hey Craig, thanks for following up on that.&nbsp; My apologies, I meant to say that Michael’s example didn’t work.

We’ve created our app through the marketplace and still seeing this issue.&nbsp; We’re also having trouble with getting the scopes working in production, seeing errors like “Invalid scope: meeting:write as system can’t support! (4,700)”.

---

<div class="post-metadata">

**Author:** ![michael\_p.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/michael_p.zoom/32/18105_2.png) [@michael\_p.zoom](https://devforum.zoom.us/u/michael_p.zoom)\
**Post date:** [August 30, 2018, 7:13pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/15 "2018-08-30T19:13:29Z")

</div>

Hi Jared,&nbsp;

Can you share the curl command that you used when trying to get the refresh token? Below is the one that I just used and it worked on our end. Keep in mind that the clientID and client secret was for --user was from [marketplace](http://marketplace.zoom.us).&nbsp;

curl -X POST -H “Content-Type:application/x-www-form-urlencoded” \

**–user clientID:clientSecret** &nbsp;&nbsp;\

–data ‘grant\_type=refresh\_token&refresh\_token= **refreshToken** ’ \

[https://zoom.us/oauth/token](https://zoom.us/oauth/token)

Thanks

---

<div class="post-metadata">

**Author:** ![michael\_p.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/michael_p.zoom/32/18105_2.png) [@michael\_p.zoom](https://devforum.zoom.us/u/michael_p.zoom)\
**Post date:** [August 30, 2018, 7:22pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/16 "2018-08-30T19:22:01Z")

</div>

Hi Jared,&nbsp;

We would love to hear your feedback in regards to our documentation. Feel free to let us know or you can click the suggest edits button.&nbsp;

![](https://support.zoom.us/hc/user_images/i0A5fJQ3MeatxvkKatRXLw.png)

Thanks

---

<div class="post-metadata">

**Author:** ![Jared\_Morse](https://avatars.discourse-cdn.com/v4/letter/j/57b2e6/32.png) [@Jared\_Morse](https://devforum.zoom.us/u/Jared_Morse)\
**Post date:** [August 30, 2018, 8:57pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/17 "2018-08-30T20:57:25Z")

</div>

Hey Michael, thanks for&nbsp;jumping in.&nbsp; Playing around with this some more I was able to successfully refresh a token, so I’m going to assume I was doing something wrong before.&nbsp; I’ll&nbsp;suggest a few edits to the docs, but I would highly recommend having a developer look at them closely as there are simply a large number of typos and fat-finger bugs (e.g. grant\_type=refresh instead of grant\_type=refresh\_token).

In regards to another issue we’re having, for our production client we are seeing “Invalid scope: meeting:write as system can’t support! (4,700)” when we redirect the agent to the authorization page.&nbsp; It’s the same URL as the dev equivalent (client ID and redirect URI being different), which does work.&nbsp; The only thing I can think of is that we haven’t actually been published on the marketplace.&nbsp; I&nbsp;sent the exact authorization URL I have been using to&nbsp;[marketplace-support@zoom.us](mailto:marketplace-support@zoom.us).

---

<div class="post-metadata">

**Author:** ![michael\_p.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/michael_p.zoom/32/18105_2.png) [@michael\_p.zoom](https://devforum.zoom.us/u/michael_p.zoom)\
**Post date:** [August 30, 2018, 10:44pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/18 "2018-08-30T22:44:37Z")

</div>

Hi Jared,&nbsp;

Thanks for letting us know about the error. We took a look and it’s happening because your production credentials are not live yet. You will need to create your publishable url in the marketplace before your app credentials and scopes to be valid.

On our end, we’ll make sure to update our marketplace site and documentation to explicitly state that production credentials and scopes cannot be used until there is a publishable url.&nbsp;&nbsp;

Thanks

---

<div class="post-metadata">

**Author:** ![Jared\_Morse](https://avatars.discourse-cdn.com/v4/letter/j/57b2e6/32.png) [@Jared\_Morse](https://devforum.zoom.us/u/Jared_Morse)\
**Post date:** [August 31, 2018, 4:00pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/19 "2018-08-31T16:00:22Z")

</div>

Thank you Michael!&nbsp; I really appreciate&nbsp;the quick replies.

---

<div class="post-metadata">

**Author:** ![Dmitry\_Pashkevich](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/dmitry_pashkevich/32/53_2.png) [@Dmitry\_Pashkevich](https://devforum.zoom.us/u/Dmitry_Pashkevich)\
**Post date:** [September 7, 2018, 1:42pm UTC](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520/20 "2018-09-07T13:42:05Z")

</div>

Please document ths token refresh request correctly on these pages!

[https://developer.zoom.us/docs/oauth/](https://developer.zoom.us/docs/oauth/)

[https://devdocs.zoom.us/docs/oauth-with-zoom](https://devdocs.zoom.us/docs/oauth-with-zoom)

&nbsp;

I had to do a bit of googling to find the correct request posted here:

```
curl -X POST -H "Content-Type:application/x-www-form-urlencoded" \ --user {client-id}:{client-secret} \ --data 'grant\_type=refresh\_token&refresh\_token={refresh-token}' \ https://zoom.us/oauth/token

```

This page ([https://devdocs.zoom.us/docs/oauth-with-zoom](https://devdocs.zoom.us/docs/oauth-with-zoom)) does have an “example refresh request” but it’s&nbsp; **incorrect** as it uses authorization code as a parameter, not the refresh token, and it also specifies&nbsp;grant\_type=refresh instead of&nbsp;grant\_type=refresh\_token.

[Next page](https://devforum.zoom.us/t/rest-api-error-on-oauth-token-refresh/1520.md?page=2)
