# Testing OAuth app on multiple environments

**URL:** <https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987>\
**Category:** App Marketplace\
**Created:** [November 26, 2020, 10:25am UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987 "2020-11-26T10:25:15Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![iwo.m](https://avatars.discourse-cdn.com/v4/letter/i/a183cd/32.png) [@iwo.m](https://devforum.zoom.us/u/iwo.m)\
**Post date:** [November 26, 2020, 10:25am UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/1 "2020-11-26T10:25:15Z")

</div>

Hello,

**Description**  
I’ve already published my app to Zoom marketplace. The app production redirect uri is pointing to my production environment (_[abc.example.com](http://abc.example.com)_) and it is working perfectly well. Now, I would like to add other features to my _abc_ webapp and be able to test the integration with Zoom on pre-production environments. The environments are: _[env1.abc.other-domain.com](http://env1.abc.other-domain.com), [env2.abc.other-domain.com](http://env2.abc.other-domain.com) and [env3.abc.yet-another-domain.com](http://env3.abc.yet-another-domain.com)_. I would also like to be able to connect multiple Zoom accounts on these environments (not only the account which created the app).

Since it is not possible to add multiple production redirect uris I can not authorize with the production app from pre-production environments. I also can not use `any` pattern in development redirect uri because my pre-production environments do not share the same domain.

How can I tackle this problem?

**Which App?**

> **[App Marketplace](https://marketplace.zoom.us/apps/Y1ax_BmBRpG4keAVMJa8YQ)**

---

<div class="post-metadata">

**Author:** ![iwo.m](https://avatars.discourse-cdn.com/v4/letter/i/a183cd/32.png) [@iwo.m](https://devforum.zoom.us/u/iwo.m)\
**Post date:** [November 30, 2020, 9:12am UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/2 "2020-11-30T09:12:33Z")

</div>

PS:  
I noticed that “redirect URL” validation is behaving different than it was before my app publication (Step 2 from [https://marketplace.zoom.us/docs/guides/auth/oauth](https://marketplace.zoom.us/docs/guides/auth/oauth)). My requests used to fail with 400 when redirect URL sent by my app did not match the redirect URL placed in Oauth App configuration. Now these requests are correct:

Redirect URL sent from my app in Step 2: [env1.abc.other-domain.com](http://env1.abc.other-domain.com)  
Redirect URL in Oauth App config: [abc.example.com](http://abc.example.com)

1. Is this behavior desired?
2. Is it safe to omit redirect URL parameter when performing Step 2?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [December 1, 2020, 7:23pm UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/3 "2020-12-01T19:23:35Z")

</div>

Hey @iwo.m,

Great questions! 🙂

> [@iwo.m](#):
>
> Redirect URL in Oauth App config: [abc.example.com](http://abc.example.com)

The redirect URL in the OAuth app config in the marketplace settings is the default one when someone clicks the “Install” button to install your app from the marketplace.

 ![Screen Shot 2020-12-01 at 12.24.28 PM](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/0/f/0f1e17254390187992206decd950bc4b8fe5e9cd.jpeg)

You can add multiple redirect urls, and set them dynamically by navigating the user to the authorize/install link yourself, like a button on your site. Checkout the dynamic redirect url docs here:

[https://marketplace.zoom.us/docs/guides/auth/oauth#using-multiple-environments](https://marketplace.zoom.us/docs/guides/auth/oauth#using-multiple-environments)

As long as the base domain is whitelisted, you will be able to set the redirect in [step 1 of the OAuth docs](https://marketplace.zoom.us/docs/guides/auth/oauth#step-1-request-user-authorization).

Due note, since your app is published, these changes will only take affect on the development environment. Once your app update is approved, the changes will take place on the production environment.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![iwo.m](https://avatars.discourse-cdn.com/v4/letter/i/a183cd/32.png) [@iwo.m](https://devforum.zoom.us/u/iwo.m)\
**Post date:** [December 2, 2020, 11:37am UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/4 "2020-12-02T11:37:58Z")

</div>

Hi @tommy, thanks for the response.

If I understood correctly, in Step 1 & 2 I can use multiple `redirect_uri` values as long as all the domains are listed here, in "Whitelist URL’:

 ![Screenshot from 2020-12-02 12-00-06](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/f/5/f56acad07498f3f00320f0c801a78041c3a28eb6.png)

It means that I could set up my production app with the following configuration and authorization flow would work fine on every environment on the list:

Redirect URL for OAuth: [https://abc.example.com/oauth/zoom](https://abc.example.com/oauth/zoom)  
Whitelist[0]: [https://env1.abc.other-domain.com/oauth/zoom](https://env1.abc.other-domain.com/oauth/zoom)  
Whitelist[1]: [https://env2.abc.other-domain.com/oauth/zoom](https://env2.abc.other-domain.com/oauth/zoom)  
Whitelist[2]: [https://env3.abc.yet-another-domain.com/oauth/zoom](https://env3.abc.yet-another-domain.com/oauth/zoom)  
Whitelist[3]: [https://abc.example.com/oauth/zoom](https://abc.example.com/oauth/zoom)

I am using “Direct landing URL” option to allow users to install the Oauth App, so it seems that “Redirect URL for Oauth” field is not really important for my use case (please correct me if I am mistaken anywhere here).

So coming back to the point I was trying to state - is it considered a good practise to integrate all non-production client environments with already published, live Zoom Oauth App. If not, then do you recommend any other pattern to achieve just that?

Thank you,  
Iwo

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [December 3, 2020, 7:45pm UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/5 "2020-12-03T19:45:04Z")

</div>

Hey @iwo.m,

> [@iwo.m](#):
>
> If I understood correctly, in Step 1 & 2 I can use multiple `redirect_uri` values as long as all the domains are listed here, in "Whitelist URL’:

Correct! Just make sure that you use the same redirect\_uri for Step 1. and Step 2.

For example, if for Step 1. one you use `https://env1.abc.other-domain.com/oauth/zoom` but then in Step 2. you use `https://env3.abc.yet-another-domain.com/oauth/zoom` it will fail. They need to be consistent throughout each instance of the OAuth process. Make sense?

> [@iwo.m](#):
>
> I am using “Direct landing URL” option to allow users to install the Oauth App, so it seems that “Redirect URL for Oauth” field is not really important for my use case (please correct me if I am mistaken anywhere here).

You nailed it! 🙂

> [@iwo.m](#):
>
> So coming back to the point I was trying to state - is it considered a good practise to integrate all non-production client environments with already published, live Zoom Oauth App. If not, then do you recommend any other pattern to achieve just that?

Yes, because you can use the Development Environment of your app to test them without affecting your Published Production Environment. I have seen some developers create two seperate apps, one for each environment, but to me that seems harder to manage. In the end, it is really up to you and what you prefer. 🙂

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![iwo.m](https://avatars.discourse-cdn.com/v4/letter/i/a183cd/32.png) [@iwo.m](https://devforum.zoom.us/u/iwo.m)\
**Post date:** [December 4, 2020, 9:36am UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/6 "2020-12-04T09:36:07Z")

</div>

Thanks @tommy, it’s getting much clearer.

> Yes, because you can use the Development Environment of your app to test them without affecting your Published Production Environment

Actually, it seems that my development `client_id` is not working from non-prod environemnt, even if I am logged in Zoom on app developer account:  
 ![Screenshot from 2020-12-04 09-55-51](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/f/b/fbf3270adb9e4a8e1b79ebfc82a1c4d0f76163c8.png)

I would expect that development credentials allow the owner to authorize. I whitelisted all my environments and production credentials work fine. What can be wrong here?

Moreover, even if I were able to authorize with development credentials, then the authorization would only be possible _inside_ the developer’s account, right? If yes, then how could I bypass this limitation so that every member of my QA team is able to test it freely on other accounts?

We have use cases where we need two or more distinct users (with distinct Zoom accounts) to interact, and these scenarios have to be performed on non-prod environments. I used to request for “sharing this app outside of the account” in “Submit” section but this option is no longer available after the publishing.

Thank you,  
Iwo

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [December 7, 2020, 8:52pm UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/7 "2020-12-07T20:52:13Z")

</div>

Hey @iwo.m,

> [@iwo.m](#):
>
> I would expect that development credentials allow the owner to authorize. I whitelisted all my environments and production credentials work fine. What can be wrong here?

This error is thrown when a user outside the account is trying to install a non Published App. Double check the user trying to install the app is logged into the correct account.

> [@iwo.m](#):
>
> Moreover, even if I were able to authorize with development credentials, then the authorization would only be possible _inside_ the developer’s account, right? If yes, then how could I bypass this limitation so that every member of my QA team is able to test it freely on other accounts?

Correct, however, if your QA team are users on your Zoom account, they will will be able to install and test the app. 🙂

[https://support.zoom.us/hc/en-us/articles/201363183-Managing-users](https://support.zoom.us/hc/en-us/articles/201363183-Managing-users)

> [@iwo.m](#):
>
> We have use cases where we need two or more distinct users (with distinct Zoom accounts) to interact, and these scenarios have to be performed on non-prod environments. I used to request for “sharing this app outside of the account” in “Submit” section but this option is no longer available after the publishing.

Great question, let me talk to the team about this.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![iwo.m](https://avatars.discourse-cdn.com/v4/letter/i/a183cd/32.png) [@iwo.m](https://devforum.zoom.us/u/iwo.m)\
**Post date:** [December 8, 2020, 9:13am UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/8 "2020-12-08T09:13:24Z")

</div>

Hi @tommy

> This error is thrown when a user outside the account is trying to install a non Published App. Double check the user trying to install the app is logged into the correct account.

I double checked that - when redirected to Zoom authorization page from my non-prod environment, I am logging in on Zoom app owner credentials. `client_id` in redirect query param is equal to my “development” `client_id` from Zoom Oauth app configuration. The error is still displayed and I can not authorize.

However, when I take the “Publishable URL” (with “production” `client_id` embedded in it) I see the expected authorization prompt, my logo and scopes.

> Correct, however, if your QA team are users on your Zoom account, they will will be able to install and test the app. 🙂

Unfortunately, “User Management” section is not displayed in my account settings. The type of the account is “Enterprise”, and it’s role is “Developer”. It seems that this account is a part of our enterprise program.

The issue is blocking further integration with Zoom. Do I have any options other than using “production” Oauth credentials for non-prod environments? It seems that it is the only way now to satisfy all the requirements stated above.

Thank you,  
Iwo

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [December 10, 2020, 1:36am UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/9 "2020-12-10T01:36:10Z")

</div>

Hey @iwo.m,

This will be easier to resolve over a Zoom meeting. I will send you the meeting details.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [December 11, 2020, 4:59pm UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/10 "2020-12-11T16:59:10Z")

</div>

Hey @iwo.m,

Our engineering team is investigating the root cause of this. (ZOOM-226260)

I will get back to you with an update as soon as possible.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![iwo.m](https://avatars.discourse-cdn.com/v4/letter/i/a183cd/32.png) [@iwo.m](https://devforum.zoom.us/u/iwo.m)\
**Post date:** [December 14, 2020, 8:27am UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/11 "2020-12-14T08:27:45Z")

</div>

Thank you @tommy, waiting to hear back from you

Iwo

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [December 14, 2020, 5:52pm UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/12 "2020-12-14T17:52:35Z")

</div>

Hey @iwo.m,

We found the issue. It looks like the app was built on a personal/different Zoom account, and then that account was moved onto your company Zoom account. We will update the account for the app so it is fully configured. 🙂 That will fix the issue.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [December 15, 2020, 5:27pm UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/13 "2020-12-15T17:27:58Z")

</div>

Hey @iwo.m,

You should be able to install the app now. 🙂

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [January 15, 2021, 3:28am UTC](https://devforum.zoom.us/t/testing-oauth-app-on-multiple-environments/36987/14 "2021-01-15T03:28:02Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
