# Server to Server Oauth

**URL:** <https://devforum.zoom.us/t/server-to-server-oauth/82901>\
**Category:** Meetings\
**Tags:** server-to-server, token-tolerance, s2s-oauth\
**Created:** [February 10, 2023, 1:24pm UTC](https://devforum.zoom.us/t/server-to-server-oauth/82901 "2023-02-10T13:24:24Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![EVant](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/evant/32/3511_2.png) [@EVant](https://devforum.zoom.us/u/EVant)\
**Post date:** [February 10, 2023, 1:24pm UTC](https://devforum.zoom.us/t/server-to-server-oauth/82901/1 "2023-02-10T13:24:24Z")

</div>

Hello

I have developed an app which is accessing meeting status within a loop.  
most of the time it works but sometimes I receive an error. `401 "Invalid access token."`

The process last a few minutes so I don’t reach the hour limit

Why is it occurring ?  
How can I check the validity of a recently generated token or avoid the problem ?

Thanks

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [February 14, 2023, 2:53pm UTC](https://devforum.zoom.us/t/server-to-server-oauth/82901/2 "2023-02-14T14:53:27Z")

</div>

Hi @EVant  
The access\_token generated with the Server to Server Oauth app has an expiration time of 1 hour and once you generate a new token, the previous one gets invalidated.  
It seems strange to me that you are getting this error if you are creating new tokens within minutes

---

<div class="post-metadata">

**Author:** ![EVant](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/evant/32/3511_2.png) [@EVant](https://devforum.zoom.us/u/EVant)\
**Post date:** [February 14, 2023, 3:15pm UTC](https://devforum.zoom.us/t/server-to-server-oauth/82901/3 "2023-02-14T15:15:03Z")

</div>

This happened 3 times.  
Each times and within a few minutes after the token generation and after several api calls

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [February 16, 2023, 9:18pm UTC](https://devforum.zoom.us/t/server-to-server-oauth/82901/4 "2023-02-16T21:18:30Z")

</div>

@EVant  
Interesting.  
Do you happen to have the API calls you made (endpoints) and the date and time when this issue happened?

---

<div class="post-metadata">

**Author:** ![EVant](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/evant/32/3511_2.png) [@EVant](https://devforum.zoom.us/u/EVant)\
**Post date:** [February 17, 2023, 7:09am UTC](https://devforum.zoom.us/t/server-to-server-oauth/82901/5 "2023-02-17T07:09:40Z")

</div>

Although the problem usually occurs in loop processing, this time there was only one call.

`2023-02-16 13:00:02,913 /meetings/89525337799/status`  
In this case, I generated the token, called the API, and received a 401 error message that was caught. I immediately requested another token and it worked

---

<div class="post-metadata">

**Author:** ![EVant](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/evant/32/3511_2.png) [@EVant](https://devforum.zoom.us/u/EVant)\
**Post date:** [February 17, 2023, 2:10pm UTC](https://devforum.zoom.us/t/server-to-server-oauth/82901/6 "2023-02-17T14:10:05Z")

</div>

here is an other example.  
end point: [https://api.zoom.us/v2/users/\*user\*/meetings](https://api.zoom.us/v2/users/*user*/meetings)  
In a loop  
Start at` 2023-02-17 14:49:24,256`  
97 success API calls  
`2023-02-17 14:50:02,006 **ERROR** `  
update header  
300 success API calls  
`2023-02-17 14:54:01,941 **ERROR** `  
update header  
305 success API calls

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [February 23, 2023, 7:47pm UTC](https://devforum.zoom.us/t/server-to-server-oauth/82901/7 "2023-02-23T19:47:16Z")

</div>

Hi @EVant  
I am really sorry for the late reply  
I will send you a private message to follow up

---

<div class="post-metadata">

**Author:** ![gianni.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/gianni.zoom/32/32523_2.png) [@gianni.zoom](https://devforum.zoom.us/u/gianni.zoom)\
**Post date:** [March 15, 2023, 6:12pm UTC](https://devforum.zoom.us/t/server-to-server-oauth/82901/8 "2023-03-15T18:12:42Z")

</div>

This behavior is similar to another developer. Linking the ticket here for reference:

> [@Issue migrating JWT to Server-to-Server OAuth](https://devforum.zoom.us/t/issue-migrating-jwt-to-server-to-server-oauth/82340/8):
>
> This is currently under escalation review. Sharing the ticket number here for other developer and Developer Advocates who may encounter someone experiencing the same behavior (ZSEE-85355).
