# Fix Zendesk OAuth failing with unauthorized_client

## TL;DR
unauthorized_client means the Zendesk OAuth client is not allowed to use the grant type or the app is not authorized for that Zendesk subdomain. Check the OAuth client settings in Zendesk Admin and confirm the app is allow-listed for the subdomain. The client exists but lacks permission.

## The error
```text
Zendesk OAuth failed
{"error":"unauthorized_client","error_description":"The client is not authorized"}
```

## Use this skill
Agent? Search Vectle for this error:
```bash
curl -s "https://vectle.com/api/v1/search?q=zendesk oauth unauthorized_client error"
```

## Fix it

### Step 1: Open the OAuth client in Zendesk Admin

```bash
Zendesk Admin Center -> Apps and integrations -> APIs -> OAuth Clients -> [client].
```

Expected: The client exists and shows its configured grant types.

### Step 2: Confirm the grant type is enabled

```bash
Check that the client allows the grant type your flow uses (authorization code for user flows).
```

Expected: The grant type your app needs is enabled on the client.

### Step 3: Verify the client identifier matches

```bash
Compare the client id your app sends with the one in Admin Center.
```

Expected: They match exactly.

### Step 4: Check subdomain authorization

```bash
Confirm the OAuth client is authorized for the Zendesk subdomain the user logs into.
```

Expected: The subdomain is covered by the client's configuration.

### Step 5: Retry the OAuth flow

```bash
Run the authorization flow again from the app.
```

Expected: The flow completes and tokens are issued.

## When this applies

- Zendesk OAuth fails with unauthorized_client
- The OAuth client exists but the flow never gets past authorization
- You are setting up a new Zendesk integration

## When it doesn't

- The error is invalid_client (check the client id and secret)
- The error is access_denied (the user declined or lacks permission)
- Tokens work but API calls fail (check API permissions)

## Compatibility

Zendesk OAuth 2.0 API clients. Admin Center as of 2026.

## Variant phrasings

### zendesk oauth client not authorized

Same error. The client is known to Zendesk but not permitted for this flow or subdomain.

### zendesk unauthorized_client authorization code

The authorization code grant must be explicitly enabled on the client.

### zendesk oauth fails new integration

New integrations hit this when the client was created with default settings that do not include the needed grant.

## Why it happens

Zendesk gates OAuth clients by grant type and by subdomain. unauthorized_client is the gate saying no: the client is registered, but the specific thing it tried is not allowed. It is a permissions problem on the client record, not a user problem.

## Edge cases

- Clients created via the API sometimes miss grant settings that the UI sets by default
- Multi-subdomain setups need the client authorized per subdomain
- Deactivating and recreating a client changes its id; update the app config to match

## If it still fails

- Reproduce with one API call in isolation, outside the agent, to separate platform issues from agent issues.
- Check the platform status page and changelog; OAuth and webhook behaviors change without warning.
- Capture the full request and response with timestamps for the vendor ticket, redacting credentials.
- Test in a second workspace or sandbox to rule out workspace-specific policy blocks.
- If the integration is business-critical, build the fallback now: cached data, a manual trigger, or a second provider.

## Prevention

- Store OAuth credentials in a secrets manager with rotation reminders.
- Build the reconnect flow before you need it; every integration gets revoked eventually.
- Log token ages so expiring grants are visible ahead of time.
- Keep a sandbox integration for testing config changes.
- Document the required scopes per integration so reinstalls request the right ones.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_OleDM16Ix3dFnxlw_Sz23A
