Guide · in research

Enabling OAuth refresh-token login for Jabber and Webex App in Unified CM

Verified 2026-10-02 · 54 sources · tier 2

In research. This guide has not been written yet. It has 54 sources to build on.

See also

Configures

  • Cisco unified cm — Cluster-wide enterprise parameter and token lifetimes on Unified CM.

Depends on

Related to

Sources

  1. 1
    The OAuth Access Token Expiry Timer (minutes) enterprise parameter accepts 1 to 1440 minutes and defaults to 60.
    System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins / OAuth parameter table, OAuth Access Token Expiry Timer (minutes) · Checked 2026-10-02
  2. 2
    The Jabber planning guide states that OAuth refresh tokens must be turned on across all deployed components (Unified CM, IM and Presence, Unity Connection, Expressway) for the feature to work.
    Planning Guide for Cisco Jabber 14.1 - User Management · User Management > OAuth · Checked 2026-10-02
  3. 3
    Release 15 adds the Auto Renew Refresh Token enterprise parameter, enabled by default; when it is disabled Unified CM does not auto-extend refresh tokens.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > Auto Renew Refresh Token · Checked 2026-10-02
  4. 4
    After the refresh-token expiry is first set from Control Hub it can be changed again at the individual cluster level, and the cluster-level setting always takes priority.
    Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Set Expiration Timer for OAuth Refresh Token · Checked 2026-10-02
  5. 5
    The Control Hub article's prerequisites are Cloud-Connected UC activated with on-premises devices communicating with Control Hub, Unified CM clusters at 11.5 or above, and Webex App 41.12 or later.
  6. 6
    Changing the Control Hub refresh-token expiry takes effect immediately, and previously issued refresh tokens cease to be valid, forcing client applications that hold them to re-authenticate.
    Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Set Expiration Timer for OAuth Refresh Token · Checked 2026-10-02
  7. 7
    In Control Hub, Services > Calling > Client Settings > Unified CM Settings has an Expiration timer for OAuth refresh token field accepting 1 to 1825 days, default 60.
    Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Set Expiration Timer for OAuth Refresh Token · Checked 2026-10-02
  8. 8
    The username and password entered for a Unity Connection Authz server must be the same as the Unified CM system administrator credentials.
    System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server · Checked 2026-10-02
  9. 9
    Unity Connection uses the Unified CM publisher of the associated phone system as its Authz server, configured at System Settings > Authz Server > Add New; with Session Management Edition each leaf-cluster publisher can be added.
    System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server · Checked 2026-10-02
  10. 10
    The Unity Connection Authz server page has an Ignore Certificate Errors check box as an alternative to uploading valid Unified CM certificates to the Unity Connection Tomcat trust store.
    System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server, Ignore Certificate Errors field · Checked 2026-10-02
  11. 11
    OAuth flow is disabled by default on Unity Connection and is enabled in Cisco Unity Connection Administration at System Settings > Enterprise Parameters > SSO and OAuth Configuration by setting OAuth with Refresh Login Flow to Enabled.
    System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server, prerequisites · Checked 2026-10-02
  12. 12
    With OAuth Refresh Logins the default access-token lifespan is 60 minutes and the default refresh-token life is 60 days.
  13. 13
    Cisco warns that once OAuth Refresh Logins are enabled, disabling the feature requires resetting all Cisco Jabber clients.
    System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins, Note under OAuth with Refresh Login Flow · Checked 2026-10-02
  14. 14
    When OAuth with Refresh Login Flow is Enabled, clients such as Cisco Jabber can use an OAuth-based Fast Login flow that does not require the user to sign in again, for example after a network change.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Enabled bullet · Checked 2026-10-02
  15. 15
    Cisco's generic enterprise-parameter procedure is to edit the value, click Save, then click Reset and OK to reset all devices.
  16. 16
    Expressway's Check for internal authentication availability setting defaults to No, and Cisco warns that Yes can allow rogue inbound requests from unauthenticated remote clients.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Check for internal authentication availability · Checked 2026-10-02
  17. 17
    Expressway's OAuth token with refresh option requires OAuth with refresh to be enabled on the Unified CM clusters and, where it is used, on Unity Connection.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh, requirements · Checked 2026-10-02
  18. 18
    Expressway's separate Authorize by OAuth token option (previously SSO mode) requires authentication through the IdP, defaults to Off, and is available only with SAML SSO authentication paths.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token (previously SSO mode) · Checked 2026-10-02
  19. 19
    On Expressway-C, Authorize by OAuth token with refresh is set under Configuration > Unified Communications > Configuration > MRA Access Control; Cisco recommends it for all deployments that can support it and its default is On.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh · Checked 2026-10-02
  20. 20
    After enabling OAuth token with refresh, the Unified CM nodes defined on the Expressway must be refreshed, which fetches the keys the Expressway needs to decrypt the tokens.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh · Checked 2026-10-02
  21. 21
    In an IM and Presence centralized deployment, OAuth with Refresh Login Flow is set on the telephony cluster, and that setting automatically enables the feature in the IM and Presence central cluster.
    Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment · Configure Centralized Deployment > Configure OAuth Refresh Logins · Checked 2026-10-02
  22. 22
    In an IM and Presence centralized deployment, the remote Unified CM telephony cluster must run at least 11.5(1)SU4 to support OAuth Refresh Logins.
    Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment · Configure Centralized Deployment > Configure OAuth Refresh Logins · Checked 2026-10-02
  23. 23
    In an IM and Presence centralized deployment, a remote Unified CM telephony cluster's status shows Synchronized for OAuth Refresh Logins when it supports the feature, and earlier clusters may show Unsynchronized.
    Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment · Configure Centralized Deployment > remote telephony cluster status · Checked 2026-10-02
  24. 24
    When OAuth keys are regenerated, the Cisco XCP Authentication Service must be restarted on all IM and Presence nodes for Jabber OAuth login to work.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework, Note on key regeneration · Checked 2026-10-02
  25. 25
    For backward compatibility, older Jabber clients and supporting applications such as Cisco Unified RTMT can still authenticate with the implicit grant flow, which is enabled by default.
  26. 26
    A longer refresh-token lifetime means fewer sign-in prompts but a longer window in which a lost device keeps access, so revoking a leaver's refresh token with the revoke API matters more as the lifetime grows.inferred
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework, token lifetimes and revoke API · Checked 2026-10-02
  27. 27
    Because Expressway fetches the Unified CM token keys only when its Unified CM nodes are refreshed and requires OAuth with refresh on Unified CM, enabling the Unified CM parameter before refreshing Expressway avoids MRA clients being validated against missing keys.inferred
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh · Checked 2026-10-02
  28. 28
    Because Cisco documents different upper bounds for the refresh-token expiry (90 days for 12.0, 365 days for 12.5(1), 1825 days in Control Hub) and the Release 15 parameter text read here does not state one, the allowed range on a given cluster should be read from that cluster's own parameter help before choosing a value.inferred
    System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · OAuth parameter table, compared with cisco-technote-212794-oauth-code-grant and webex-help-ki34wo-auto-provisioning-ucm · Checked 2026-10-02
  29. 29
    A Jabber log line reading Failed to get valid access token from refresh token, maybe server issue indicates that a refresh-token exchange failed.
  30. 30
    OAuth Refresh Logins for Cisco Jabber require Jabber Release 11.9 or later.
  31. 31
    When OAuth is enabled or disabled on any of the servers, Jabber detects it at its configuration re-fetch interval, clears cached credentials and has the user sign out and sign in again.
    Planning Guide for Cisco Jabber 14.1 - User Management · User Management > OAuth · Checked 2026-10-02
  32. 32
    For Mobile and Remote Access deployments with Cisco Jabber, Cisco recommends enabling OAuth with Refresh Login Flow only with an Expressway version that supports it, warning that an incompatible version may impact Jabber functionality.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Note · Checked 2026-10-02
  33. 33
    The Enable Mobile and Remote Access check box in the Unified CM User Profile (User Management > User Settings > User Profile) is mandatory for Cisco Jabber users who use OAuth Refresh Logins over MRA; non-Jabber users do not need it.
    Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Mobile and Remote Access · Configure Mobile and Remote Access Access Policy for Cisco Jabber Users, step 7 note · Checked 2026-10-02
  34. 34
    Cisco states that enabling OAuth with Refresh Login Flow requires support from other Unified Communications components such as Expressway and Unity Connection, running compatible versions with the refresh login flow enabled.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Enabled bullet · Checked 2026-10-02
  35. 35
    Cisco Jabber OAuth can be set up with or without SSO; if SSO is used, Cisco says it must be enabled for all services.
    Planning Guide for Cisco Jabber 14.1 - User Management · User Management > OAuth · Checked 2026-10-02
  36. 36
    The OAuth with Refresh Login Flow enterprise parameter defaults to Disabled.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow · Checked 2026-10-02
  37. 37
    The OAuth with Refresh Login Flow enterprise parameter is set in Cisco Unified CM Administration at System > Enterprise Parameters, in the SSO and OAuth Configuration section.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow · Checked 2026-10-02
  38. 38
    The 12.0 TAC tech note gives the refresh-token expiry range as 1 to 90 days with a default of 60 days.
  39. 39
    In the Release 12.5(1) documentation, the OAuth Refresh Token Expiry Timer (days) enterprise parameter accepts 1 to 365 days and defaults to 60; after it expires the refresh token is invalid and the client must re-authenticate.
    System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins / OAuth parameter table, OAuth Refresh Token Expiry Timer (days) · Checked 2026-10-02
  40. 40
    The OAuth encryption key can be regenerated only from the CLI, with set key regen authz encryption confirmed by yes.
  41. 41
    Cisco TAC states the OAuth signing and encryption keys should be regenerated only if the administrator believes they have been compromised.
  42. 42
    After the OAuth keys are regenerated, current access and refresh tokens that use those keys become invalid, and Cisco recommends doing it during off-hours.
  43. 43
    The Unified CM publisher regenerates the OAuth keys and replicates them to all Unified CM cluster nodes, including any local IM and Presence Service nodes.
  44. 44
    The OAuth signing key can be regenerated with the CLI command set key regen authz signing, or in Cisco Unified OS Administration at Security > Certificate Management by selecting the AUTHZ certificate and clicking Regenerate.
  45. 45
    After regenerating OAuth keys, the new keys must also be regenerated and synced on an IM and Presence central cluster and on Cisco Expressway or Cisco Unity Connection.
    Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Regenerate Keys for OAuth Refresh Logins, list of UC clusters · Checked 2026-10-02
  46. 46
    Each time an OAuth access token reaches 75 percent of its lifespan, the client application requests a new access token from Unified CM.
  47. 47
    The 12.5(1) Configure Refresh Logins procedure ends by resetting all Cisco Jabber and Webex clients after the enterprise parameters are saved.
  48. 48
    Unified CM exposes a REST endpoint, https://<UCMaddress>:8443/ssosp/token/revoke?user_id=<end_user>, called with administrator credentials, that revokes a user's current refresh token so the user cannot obtain new access tokens.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework > revoke refresh tokens · Checked 2026-10-02
  49. 49
    Cisco TAC verifies OAuth key consistency by running show key authz signing and show key authz encryption on every Unified CM and IM and Presence node and comparing the results.
  50. 50
    SIP OAuth Mode, supported for Cisco Jabber from Unified CM 12.5 onwards, includes setting OAuth with Refresh Login Flow to Enabled as part of its configuration.
  51. 51
    OAuth and SSO operations on Unified CM are logged under the Tomcat ssosp log4j directory, with SSO application logs in ssoApp.log and certificate operations in certMgmt logs.
  52. 52
    From Unified CM 12.5(1)SU7 and 14SU3 onwards, subscriber nodes as well as the publisher can update the refresh token in the requesting node's database, and the change replicates across the cluster.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Important · Checked 2026-10-02
  53. 53
    Unified CM OAuth access tokens are encrypted, signed and self-contained JWTs (RFC 7519), while refresh tokens are signed but not encrypted.
  54. 54
    From Release 15, for Webex clients only, Unified CM renews the refresh token automatically when renewal is enabled on Unified CM and the Webex client and the refresh token has reached 50 percent of its lifetime.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework, refresh token renewal paragraph · Checked 2026-10-02

Documents

tier 2 current vendor documentation

Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates

Cisco Systems · 2026-08-31 · accessed 2026-09-25

tier 2 current vendor documentation

Auto-Provisioning of Webex App for Calling in Webex (Unified CM)

Cisco · 2025-10-29 · accessed 2026-09-30

tier 2 current vendor documentation

Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment

Cisco Systems · 2026-01-07 · accessed 2026-10-02

tier 2 current vendor documentation

Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0

Cisco Systems · 2022-03-18 · accessed 2026-10-02

tier 2 current vendor documentation

Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Mobile and Remote Access

Cisco Systems · 2026-09-16 · accessed 2026-10-02

tier 2 current vendor documentation

Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - SIP OAuth Mode

Cisco Systems · 2026-10-02 · accessed 2026-10-02

tier 2 current vendor documentation

Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration

Cisco Systems · 2024-01-07 · accessed 2026-10-02

tier 2 current vendor documentation

Planning Guide for Cisco Jabber 14.1 - User Management

Cisco Systems · 2024-04-02 · accessed 2026-10-02

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management

Cisco Systems · 2026-09-22 · accessed 2026-10-02

tier 2 current vendor documentation

System Administration Guide for Cisco Unity Connection Release 15 - System Settings

Cisco Systems · 2025-12-12 · accessed 2026-10-02

tier 2 current vendor documentation

System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber

Cisco Systems · 2026-10-02 · accessed 2026-10-02

Cite this page

APA

WarmTransfer. (2026, October 2). Enabling OAuth refresh-token login for Jabber and Webex App in Unified CM. WarmTransfer. https://warmtransfer.net/guides/cucm-oauth-refresh-login-setup

BibTeX

@misc{warmtransfer-cucm-oauth-refresh-login-setup,
  title  = {Enabling OAuth refresh-token login for Jabber and Webex App in Unified CM},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/guides/cucm-oauth-refresh-login-setup},
  note   = {Verified 2026-10-02}
}