# This API does not support client credentials for authorization

**URL:** <https://devforum.zoom.us/t/this-api-does-not-support-client-credentials-for-authorization/94848>\
**Category:** Authentication\
**Created:** [September 11, 2023, 5:13pm UTC](https://devforum.zoom.us/t/this-api-does-not-support-client-credentials-for-authorization/94848 "2023-09-11T17:13:47Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![marketing2](https://avatars.discourse-cdn.com/v4/letter/m/34f0e0/32.png) [@marketing2](https://devforum.zoom.us/u/marketing2)\
**Post date:** [September 11, 2023, 5:13pm UTC](https://devforum.zoom.us/t/this-api-does-not-support-client-credentials-for-authorization/94848/1 "2023-09-11T17:13:47Z")

</div>

Hello, I am attempting to update to the OAuth from the JWT and ran into a problem. I have created a server-to-server-oauth app and have the keys. I can retrieve a token but when I try to use the token, it returns the error, “This API does not support client credentials for authorization.”

From what I can find in the forums, I need to change the grant type from “client\_credentials” to “account\_credentials”. However, that returns “invalid request”

This is in PHP, and I am using the package “league/oauth2-client” to get the token.

I am attempting to salvage the existing code base which uses Guzzle, and get a token and attach that to the Guzzle requests.

The code is rather simple,

$provider = new \League\OAuth2\Client\Provider\GenericProvider(  
[  
‘clientId’ =\> ‘…’, // The client ID assigned to you by the provider  
‘clientSecret’ =\> ‘…’, // The client password assigned to you by the provider  
‘redirectUri’ =\> ‘’,  
‘urlAccessToken’ =\> ‘[https://zoom.us/oauth/token](https://zoom.us/oauth/token)’,  
]);

```
$accessToken = $provider->getAccessToken('client_credentials');

```

This does work as I do receive a token, but I can’t seem to access the endpoints with it.

An example endpoint, users/[email]/webinars, to just receive a list of webinars.

Am I missing something?

---

<div class="post-metadata">

**Author:** ![ojus.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/ojus.zoom/32/734_2.png) [@ojus.zoom](https://devforum.zoom.us/u/ojus.zoom)\
**Post date:** [September 11, 2023, 8:57pm UTC](https://devforum.zoom.us/t/this-api-does-not-support-client-credentials-for-authorization/94848/2 "2023-09-11T20:57:04Z")

</div>

1. Please make sure that you are using a server to server Oauth app and not a user authorized oauth app
2. Please remove the redirect\_url query parameter

---

<div class="post-metadata">

**Author:** ![marketing2](https://avatars.discourse-cdn.com/v4/letter/m/34f0e0/32.png) [@marketing2](https://devforum.zoom.us/u/marketing2)\
**Post date:** [September 11, 2023, 9:02pm UTC](https://devforum.zoom.us/t/this-api-does-not-support-client-credentials-for-authorization/94848/3 "2023-09-11T21:02:41Z")

</div>

1. I created the app in the marketplace and it said server to server oauth. I don’t see anything about this being a user oauth app.
2. ah ok. Still doesn’t give me a valid token

---

<div class="post-metadata">

**Author:** ![ojus.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/ojus.zoom/32/734_2.png) [@ojus.zoom](https://devforum.zoom.us/u/ojus.zoom)\
**Post date:** [September 11, 2023, 9:05pm UTC](https://devforum.zoom.us/t/this-api-does-not-support-client-credentials-for-authorization/94848/4 "2023-09-11T21:05:18Z")

</div>

Can you try using a tool like postman to see if you are able to receive a token with the same credentials?

---

<div class="post-metadata">

**Author:** ![marketing2](https://avatars.discourse-cdn.com/v4/letter/m/34f0e0/32.png) [@marketing2](https://devforum.zoom.us/u/marketing2)\
**Post date:** [September 11, 2023, 9:07pm UTC](https://devforum.zoom.us/t/this-api-does-not-support-client-credentials-for-authorization/94848/5 "2023-09-11T21:07:16Z")

</div>

I wasn’t able to get postman to make a successful token request. It just keeps giving an error, "Invalid redirect: [https://oauth.pstmn.io/v1/callback](https://oauth.pstmn.io/v1/callback) (4,700) " that I was not able to find a solution for.

---

<div class="post-metadata">

**Author:** ![ojus.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/ojus.zoom/32/734_2.png) [@ojus.zoom](https://devforum.zoom.us/u/ojus.zoom)\
**Post date:** [September 11, 2023, 9:09pm UTC](https://devforum.zoom.us/t/this-api-does-not-support-client-credentials-for-authorization/94848/6 "2023-09-11T21:09:27Z")

</div>

whats the base url that you are using?

it should be something like:  
[api.zoom.us/oauth/token](http://api.zoom.us/oauth/token)

---

<div class="post-metadata">

**Author:** ![marketing2](https://avatars.discourse-cdn.com/v4/letter/m/34f0e0/32.png) [@marketing2](https://devforum.zoom.us/u/marketing2)\
**Post date:** [September 11, 2023, 9:12pm UTC](https://devforum.zoom.us/t/this-api-does-not-support-client-credentials-for-authorization/94848/7 "2023-09-11T21:12:56Z")

</div>

To request the token, ‘[https://zoom.us/oauth/token](https://zoom.us/oauth/token)’, then, ‘[https://api.zoom.us/v2/](https://api.zoom.us/v2/)’ as the base for the client request.

I just tried postman with the bearer token I got and I received the same error message about not being authorized.

Is [https://api.zoom.us/v2/users/me/webinars](https://api.zoom.us/v2/users/me/webinars) a valid API path?

---

<div class="post-metadata">

**Author:** ![marketing2](https://avatars.discourse-cdn.com/v4/letter/m/34f0e0/32.png) [@marketing2](https://devforum.zoom.us/u/marketing2)\
**Post date:** [September 11, 2023, 9:14pm UTC](https://devforum.zoom.us/t/this-api-does-not-support-client-credentials-for-authorization/94848/8 "2023-09-11T21:14:02Z")

</div>

the link you provided returns a error, " Invalid response received from Authorization Server."

---

<div class="post-metadata">

**Author:** ![marketing2](https://avatars.discourse-cdn.com/v4/letter/m/34f0e0/32.png) [@marketing2](https://devforum.zoom.us/u/marketing2)\
**Post date:** [September 12, 2023, 3:03pm UTC](https://devforum.zoom.us/t/this-api-does-not-support-client-credentials-for-authorization/94848/9 "2023-09-12T15:03:38Z")

</div>

I was not able to get it to work with Guzzle, because of some kind of header bug.

I used this command as a basis for this request.

```auto
curl -X POST https://zoom.us/oauth/token -d 'grant_type=account_credentials' -d 'account_id=#ID#' -H 'Host: zoom.us' -H 'Authorization: Basic ##base64_string##'

```

taken from, [Server-to-Server OAuth](https://developers.zoom.us/docs/internal-apps/s2s-oauth/#terminal-command-line-curl-method)

Once I had the correct keys in that command, I was able to get a token and then use Postman to test a request. Everything worked.

I posted a bug report on Guzzle, [Host Header · Issue #3176 · guzzle/guzzle · GitHub](https://github.com/guzzle/guzzle/issues/3176) if you want to see the Guzzle code.

I was able to make it work using Curl,

```auto
$curl = curl_init();

    curl_setopt($curl, CURLOPT_URL, 'https://zoom.us/oauth/token');
    curl_setopt($curl, CURLOPT_POST, true);

    $data = array(
        'grant_type' => 'account_credentials',
        'account_id' => $account_id
    );
    curl_setopt($curl, CURLOPT_POSTFIELDS, $data);

// $r is base_64encode string... I was not able to make it work If I actually put an array for the 
    authorization header it would fail but if it did it like this it worked

    $headers = array(
        'Host' => 'zoom.us',
        "Authorization: Basic $r"
    );
    curl_setopt($curl, CURLOPT_HTTPHEADER, $headers);

    $response = curl_exec($curl);

    var_dump($response);

    curl_close($curl);

```

Anyway, hope this helps someone in the future.

---

<div class="post-metadata">

**Author:** ![murungatim](https://avatars.discourse-cdn.com/v4/letter/m/ccd318/32.png) [@murungatim](https://devforum.zoom.us/u/murungatim)\
**Post date:** [April 13, 2024, 9:19am UTC](https://devforum.zoom.us/t/this-api-does-not-support-client-credentials-for-authorization/94848/10 "2024-04-13T09:19:50Z")

</div>

This is giving me an error php curl  
{“reason”:“Invalid client\_id or client\_secret”,“error”:“invalid\_client”}bool(true)
