# Token refresh problem

**URL:** <https://devforum.zoom.us/t/token-refresh-problem/52578>\
**Category:** API and Webhooks\
**Created:** [June 16, 2021, 1:55pm UTC](https://devforum.zoom.us/t/token-refresh-problem/52578 "2021-06-16T13:55:24Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![michal1](https://avatars.discourse-cdn.com/v4/letter/m/b77776/32.png) [@michal1](https://devforum.zoom.us/u/michal1)\
**Post date:** [June 16, 2021, 1:55pm UTC](https://devforum.zoom.us/t/token-refresh-problem/52578/1 "2021-06-16T13:55:24Z")

</div>

Hello

By the number of threads about it I believe it’s the most common issue with Zoom API :).

I’m building a WordPress website with a webinar registration form.  
You can see it here: [Hope Trust » Hope Trust: Creating a Comprehensive Special Needs Plan – It Takes a Village](http://hopetrust.tangosquared.com/webinar/hope-trust-creating-a-comprehensive-special-needs-plan-it-takes-a-village/)

The form uses Zoom API to add the participants through Zoom OAuth application. For the first hour after I install an application (and an auth token is created) the form works perfecly. Auth token and refresh token are saved in a database. During this first hour I can refresh the token with no problem (both tokens are being saved in a database). Refreshing the token also works through Postman.

The problem occurs after this first hour. When I try to register for a webinar I’m getting an exception 401, because auth token is no longer valid. So I’m sending a POST request to refresh the token but getting this error:  
{  
“reason”: “Invalid Token!”,  
“error”: “invalid\_request”  
}  
What’s interesting I’m getting the same error when trying through Postman. Remember - it was working fine during the first hour.

I think I tried everything. Reinstalling the application doesn’t help - after one hour the problem is back.  
I’m running out of ideas.

Here’s my PHP refresh token request:

```auto
$refresh_token = $db->get_refersh_token();

$client = new GuzzleHttp\Client(['base_uri' => 'https://zoom.us']);
$response = $client->request('POST', '/oauth/token', [
    "headers" => [
        "Authorization" => "Basic ". base64_encode(CLIENT_ID.':'.CLIENT_SECRET)
    ],
    'form_params' => [
        "grant_type" => "refresh_token",
        "refresh_token" => $refresh_token
    ],
]);

```

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [June 17, 2021, 7:44pm UTC](https://devforum.zoom.us/t/token-refresh-problem/52578/2 "2021-06-17T19:44:20Z")

</div>

Hi @michal1,

Thanks for reaching out about this, and happy to help look into it for you.

As a first step, can you review this post below, and let me know if you think any of these cases might apply in your scenario?

> [@Timeout when refreshing access tokens](https://devforum.zoom.us/t/timeout-when-refreshing-access-tokens/51049/2):
>
> Hi @bo.zhang, Thanks for reaching out about this. This can happen for a few different reasons. These are the most common: If a new access token is generated, both the previous access token and refresh token will become invalid. So you will need to update each of these tokens each time you request a new access token. Another situation that can arise is if multiple requests are sent using the same refresh token within a short amount of time, a race condition may prevent all requests from go…

Thanks,  
Will

---

<div class="post-metadata">

**Author:** ![michal1](https://avatars.discourse-cdn.com/v4/letter/m/b77776/32.png) [@michal1](https://devforum.zoom.us/u/michal1)\
**Post date:** [June 18, 2021, 10:42am UTC](https://devforum.zoom.us/t/token-refresh-problem/52578/3 "2021-06-18T10:42:27Z")

</div>

Hello @will.zoom

Thank you for your reply.  
Regarding the topic you attached.

1. Every time i reinstall the application both tokens are being saved in a database. Just in case I just tried again.

- I uninstalled the application.
- I removed all the data from the token table in my database, to be sure a new value will be saved.
- I installed the application again.
- New token was added to the database.
- I can register via the website form.
- 60 minutes later I try to register again, but I’m getting 401 response, because access token is no longer valid. Script tries to refresh the token and register again, but I’m getting a fatal error: Invalid token.

1. Multiple request - I don’t think so. I’m testing manually - two request during one hour.

2. Application uninstalled - no, I’m the only one working on this, but just in case I checked the logs - the application is installed.

Maybe there’s something wrong with my script?

It’s a simple PHP function:

1. Try to register user:

- POST [https://api.zoom.us/v2/webinars/$zoomID/registrants](https://api.zoom.us/v2/webinars/%24zoomID/registrants)
- authenticate with access token
- provide json variables.

1. If access token is no longer valid:

- POST [https://zoom.us/oauth/token](https://zoom.us/oauth/token)
- authenticate with Client ID and Client Secret
- provide refresh token
- get new tokens and upgrade the database
- try to register again (go back to step 1 above).

See the code below.  
I’m sure it’s some stupid mistake I make, but after a few hours and a lot of attempts to make it work I just can’t see it.

```auto
<?php
    require_once 'config.php';
     
    function register_user() {
        $client = new GuzzleHttp\Client(['base_uri' => 'https://api.zoom.us']);
     
        $db = new DB();
        $arr_token = $db->get_access_token();
        $accessToken = $arr_token->access_token;

        parse_str($_POST['data'], $variables);
        $zoomID = intval($variables['zoomID']);
        $email = $variables['email'];
        $firstname = $variables['firstname'];
        $lastname = $variables['lastname'];
        $phone = $variables['phone'];
     
        try {
            $response = $client->request('POST', '/v2/webinars/'.$zoomID.'/registrants', [
                "headers" => [
                    "Authorization" => "Bearer $accessToken"
                ],
                'json' => [
                    "email" => $email,
                    "first_name" => $firstname,                              
                    "last_name" => $lastname, 
                    "phone" => $phone
                ],
            ]);
     
            $data = json_decode($response->getBody());
            
            $response = array( 'status' => 'success' );
            echo(json_encode($response));
     
        } catch(Exception $e) {
            if( 401 == $e->getCode() ) {
                $refresh_token = $db->get_refersh_token();
 
                $client = new GuzzleHttp\Client(['base_uri' => 'https://zoom.us']);
                $response = $client->request('POST', '/oauth/token', [
                    "headers" => [
                        "Authorization" => "Basic ". base64_encode(CLIENT_ID.':'.CLIENT_SECRET)
                    ],
                    'form_params' => [
                        "grant_type" => "refresh_token",
                        "refresh_token" => $refresh_token
                    ],
                ]);
                $db->update_access_token($response->getBody());
     
                register_user();
            } else {
                echo $e->getMessage();
            }
        }
    }
     
    register_user();
?>

```

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [June 22, 2021, 2:42pm UTC](https://devforum.zoom.us/t/token-refresh-problem/52578/4 "2021-06-22T14:42:38Z")

</div>

Hi @michal1,

Thank you for confirming these details.

In order to further investigate, can I kindly ask that you share a recent example (within the last 7 days) of one of the refresh tokens that failed? You can share this with me directly at [developersupport@zoom.us](mailto:developersupport@zoom.us). Please reference this thread in your email, and I will be happy to check our logs and further investigate for you.

Thanks,  
Will

---

<div class="post-metadata">

**Author:** ![michal1](https://avatars.discourse-cdn.com/v4/letter/m/b77776/32.png) [@michal1](https://devforum.zoom.us/u/michal1)\
**Post date:** [June 28, 2021, 10:07am UTC](https://devforum.zoom.us/t/token-refresh-problem/52578/5 "2021-06-28T10:07:23Z")

</div>

Hello @will.zoom

Thank you, I just emailed you the tokens.

Best,  
Michal

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [June 29, 2021, 2:02pm UTC](https://devforum.zoom.us/t/token-refresh-problem/52578/6 "2021-06-29T14:02:41Z")

</div>

Hi @michal1,

Thank you—we will be in touch with you directly.

Thanks!  
Will

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [July 30, 2021, 12:02am UTC](https://devforum.zoom.us/t/token-refresh-problem/52578/7 "2021-07-30T00:02:41Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
