zendesk oauth unauthorized_client error
For developers and agents building Zendesk integrations. Use when OAuth fails with unauthorized_client. Not for user-denied or API permission errors.
Fix Zendesk OAuth failing with unauthorized_client
TL;DR
unauthorized_client means the Zendesk OAuth client is not allowed to use the grant type or the app is not authorized for that Zendesk subdomain. Check the OAuth client settings in Zendesk Admin and confirm the app is allow-listed for the subdomain. The client exists but lacks permission.
The error
Zendesk OAuth failed
{"error":"unauthorized_client","error_description":"The client is not authorized"}Use this skill
Agent? Search Vectle for this error:
curl -s "https://vectle.com/api/v1/search?q=zendesk oauth unauthorized_client error"Fix it
Step 1: Open the OAuth client in Zendesk Admin
Zendesk Admin Center -> Apps and integrations -> APIs -> OAuth Clients -> [client].Expected: The client exists and shows its configured grant types.
Step 2: Confirm the grant type is enabled
Check that the client allows the grant type your flow uses (authorization code for user flows).Expected: The grant type your app needs is enabled on the client.
Step 3: Verify the client identifier matches
Compare the client id your app sends with the one in Admin Center.Expected: They match exactly.
Step 4: Check subdomain authorization
Confirm the OAuth client is authorized for the Zendesk subdomain the user logs into.Expected: The subdomain is covered by the client's configuration.
Step 5: Retry the OAuth flow
Run the authorization flow again from the app.Expected: The flow completes and tokens are issued.
When this applies
- Zendesk OAuth fails with unauthorized_client
- The OAuth client exists but the flow never gets past authorization
- You are setting up a new Zendesk integration
When it doesn't
- The error is invalid_client (check the client id and secret)
- The error is access_denied (the user declined or lacks permission)
- Tokens work but API calls fail (check API permissions)
Compatibility
Zendesk OAuth 2.0 API clients. Admin Center as of 2026.
Variant phrasings
zendesk oauth client not authorized
Same error. The client is known to Zendesk but not permitted for this flow or subdomain.
zendesk unauthorized_client authorization code
The authorization code grant must be explicitly enabled on the client.
zendesk oauth fails new integration
New integrations hit this when the client was created with default settings that do not include the needed grant.
Why it happens
Zendesk gates OAuth clients by grant type and by subdomain. unauthorized_client is the gate saying no: the client is registered, but the specific thing it tried is not allowed. It is a permissions problem on the client record, not a user problem.
Edge cases
- Clients created via the API sometimes miss grant settings that the UI sets by default
- Multi-subdomain setups need the client authorized per subdomain
- Deactivating and recreating a client changes its id; update the app config to match
If it still fails
- Reproduce with one API call in isolation, outside the agent, to separate platform issues from agent issues.
- Check the platform status page and changelog; OAuth and webhook behaviors change without warning.
- Capture the full request and response with timestamps for the vendor ticket, redacting credentials.
- Test in a second workspace or sandbox to rule out workspace-specific policy blocks.
- If the integration is business-critical, build the fallback now: cached data, a manual trigger, or a second provider.
Prevention
- Store OAuth credentials in a secrets manager with rotation reminders.
- Build the reconnect flow before you need it; every integration gets revoked eventually.
- Log token ages so expiring grants are visible ahead of time.
- Keep a sandbox integration for testing config changes.
- Document the required scopes per integration so reinstalls request the right ones.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstOleDM16Ix3dFnxlwSz23A
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.