# User's refresh token keeps expiring

**URL:** <https://devforum.zoom.us/t/users-refresh-token-keeps-expiring/41872>\
**Category:** API and Webhooks\
**Created:** [January 28, 2021, 11:09pm UTC](https://devforum.zoom.us/t/users-refresh-token-keeps-expiring/41872 "2021-01-28T23:09:24Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![mike8](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/mike8/32/18771_2.png) [@mike8](https://devforum.zoom.us/u/mike8)\
**Post date:** [January 28, 2021, 11:09pm UTC](https://devforum.zoom.us/t/users-refresh-token-keeps-expiring/41872/1 "2021-01-28T23:09:24Z")

</div>

I have an app that uses OAuth named Donut.  
[https://marketplace.zoom.us/apps/7PBvwbgER6atU2rbdmznDQ](https://marketplace.zoom.us/apps/7PBvwbgER6atU2rbdmznDQ)

The refresh token for one of my users regularly expires. This doesn’t happen to most of our users. I have no idea why this happens.

The user confirmed that the reason described here isn’t relevant to them:

> [@Anything that would cause all Refresh tokens for a user-level app to go bad?](https://devforum.zoom.us/t/anything-that-would-cause-all-refresh-tokens-for-a-user-level-app-to-go-bad/24186/2):
>
> I am not sure if Zoom tracks anything on their side, but I can speak on my experience here. When two users log in using the same Zoom credentials, the old refresh\_token is then invalidated and will not work. Thinking in this way, it is possible that multiple users are sharing a single Zoom login to authenticate. That’s the scenario we bumped in to. Maybe it helps!

Any ideas?

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [January 29, 2021, 2:48pm UTC](https://devforum.zoom.us/t/users-refresh-token-keeps-expiring/41872/2 "2021-01-29T14:48:57Z")

</div>

Hey @mike8 ,

Thanks for reaching out about this. Refresh token errors in regards to expiration can occur for a few different reasons. If the user isn’t accessing your app from multiple devices like in that other thread, here are a few other things to check on your end:

1. If a new access token is generated, both the previous access token and refresh token will become invalid. Make sure you’re updating each of these tokens each time you request a new access token.

2. Another situation that can arise is if multiple requests are sent using the same refresh token within a short amount of time, a race condition may prevent all requests from going through successfully. In this case, if you are not able to update the refresh token at your end (this generally happens when you make multiple requests in a short amount of time), a recommended workaround would be to reauthorize the app.

3. If a user uninstalls the app by [revoking the authentication](https://marketplace.zoom.us/docs/guides/auth/oauth#revoking), the refresh token will become invalid. This may not be a scenario in your case.

Let me know if you think any of these could be the case.

Thanks,  
Will

---

<div class="post-metadata">

**Author:** ![mike8](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/mike8/32/18771_2.png) [@mike8](https://devforum.zoom.us/u/mike8)\
**Post date:** [February 3, 2021, 6:48pm UTC](https://devforum.zoom.us/t/users-refresh-token-keeps-expiring/41872/3 "2021-02-03T18:48:27Z")

</div>

Thanks! I looked into these possibilities, but I don’t think these any of these scenarios are the answer in this case.

#1: the user’s token is valid for a while (\<1 day to several days) before it fails, and they’re not attempting to reauth on the day it stops working.  
#2: I don’t think it’s this because we don’t make multiple quick requests with one token like you’re describing. Also, if you’re saying that it would fail temporarily but the refresh token would stay valid, I can confirm that after the event that makes the refresh\_token invalid, it stays invalid indefinitely for future requests.  
#3: I’m not sure how to match the info we’re receiving in the deauthorization events to the data we have for the user (would the client id be their team? is something in the jwt-decoded data of their token useful? I didn’t see anything that seemed to match), but the timestamps of the deauthorization events we’ve received don’t line up with the user’s timeline of issues and reauthorizations. The only scopes we have are to create and read meetings, so I don’t know how to see the Zoom team’s id (don’t see that in the meeting data).

A new clue? I’ve found since last writing in that whatever event is happening makes ALL the tokens on their Zoom team invalid. Seems like a useful clue, though I’m not sure what possibilities that opens up.

Thanks for your continued help,  
Mike

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [February 4, 2021, 3:10pm UTC](https://devforum.zoom.us/t/users-refresh-token-keeps-expiring/41872/4 "2021-02-04T15:10:55Z")

</div>

Hey @mike8,

Can you share a recent refresh token that you’ve encountered this issue on for the user? You can send this to our team at [developersupport@zoom.us](mailto:developersupport@zoom.us) and this will help us to take a closer look.

Thanks!  
Will

---

<div class="post-metadata">

**Author:** ![fahad.beehive](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/fahad.beehive/32/17024_2.png) [@fahad.beehive](https://devforum.zoom.us/u/fahad.beehive)\
**Post date:** [February 28, 2021, 9:15pm UTC](https://devforum.zoom.us/t/users-refresh-token-keeps-expiring/41872/5 "2021-02-28T21:15:04Z")

</div>

I have the same issue it seems! [Frequently receiving invalid\_request / token revocation from Zoom - #5 by will.zoom](https://devforum.zoom.us/t/frequently-receiving-invalid-request-token-revocation-from-zoom/44220/5)

Again - this is not happening with all of our users, but with some it’s happening every day. I have a feeling it’s because they’re using our apps on multiple machines? Maybe Zoom is internally not keeping track of unique devices?

---

<div class="post-metadata">

**Author:** ![fahad.beehive](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/fahad.beehive/32/17024_2.png) [@fahad.beehive](https://devforum.zoom.us/u/fahad.beehive)\
**Post date:** [February 28, 2021, 9:17pm UTC](https://devforum.zoom.us/t/users-refresh-token-keeps-expiring/41872/6 "2021-02-28T21:17:16Z")

</div>

I think that is it!! Users that are using the same account on two macs. Zoom incorrectly expires the refresh token of the other mac.

Damnit. I’ve pulled my hair out for 2 weeks over this. Zoom - FIX THIS - PLEASE.

This is absolutely unacceptable, no matter the reason. Users these days have multiple machines / devices they use our apps on. They expect these to work. This needlessly increases our support around an issue Zoom needs to fix. This not only is disruptive, it also ruins the overall seamless experience users expect from our apps.

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [March 1, 2021, 5:21pm UTC](https://devforum.zoom.us/t/users-refresh-token-keeps-expiring/41872/7 "2021-03-01T17:21:13Z")

</div>

Hi @fahad.beehive,

I can see that we’ve connected over email and I will continue the conversation there.

Thanks,  
Will

---

<div class="post-metadata">

**Author:** ![morgs.dovetail](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/morgs.dovetail/32/24913_2.png) [@morgs.dovetail](https://devforum.zoom.us/u/morgs.dovetail)\
**Post date:** [March 23, 2021, 12:23am UTC](https://devforum.zoom.us/t/users-refresh-token-keeps-expiring/41872/8 "2021-03-23T00:23:07Z")

</div>

Any update on this? Our users are experiencing the same pain.

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [March 23, 2021, 4:17pm UTC](https://devforum.zoom.us/t/users-refresh-token-keeps-expiring/41872/9 "2021-03-23T16:17:34Z")

</div>

Hey @morgs.dovetail,

Currently, if a user simultaneously accesses the app from a second device such as another computer, phone, etc., any other access\_tokens will be invalidated. At the moment, this is expected behavior.

However, in the future, we hope to support multiple active OAuth tokens per user to enhance the flow where the user needs to OAuth authenticate on multiple devices.

Thanks,  
Will

---

<div class="post-metadata">

**Author:** ![fahad.beehive](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/fahad.beehive/32/17024_2.png) [@fahad.beehive](https://devforum.zoom.us/u/fahad.beehive)\
**Post date:** [March 24, 2021, 10:37am UTC](https://devforum.zoom.us/t/users-refresh-token-keeps-expiring/41872/10 "2021-03-24T10:37:20Z")

</div>

Also see this: [Frequently receiving invalid\_request / token revocation from Zoom - #15 by fahad.beehive](https://devforum.zoom.us/t/frequently-receiving-invalid-request-token-revocation-from-zoom/44220/15)

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [March 24, 2021, 9:45pm UTC](https://devforum.zoom.us/t/users-refresh-token-keeps-expiring/41872/12 "2021-03-24T21:45:43Z")

</div>


