Guide · in research
Enabling OAuth refresh-token login for Jabber and Webex App in Unified CM
Verified 2026-10-02 · 54 sources · tier 2
In research. This guide has not been written yet. It has 54 sources to build on.
See also
Configures
- Cisco unified cm — Cluster-wide enterprise parameter and token lifetimes on Unified CM.
Depends on
- Expressway and Mobile and Remote Access — MRA clients need Expressway Authorize by OAuth token with refresh and a Unified CM server refresh.
Related to
- Cisco Unity Connection voicemail and migration — Unity Connection needs the parameter enabled and an Authz server pointing at the Unified CM publisher.
- Setting up SAML SSO for Unified CM — OAuth refresh login works with or without SAML SSO; SSO setup is a separate guide.
- TLS certificates and secure SIP failures — SIP OAuth Mode builds on OAuth with Refresh Login Flow.
- Troubleshooting Jabber and Webex App sign-in on Unified CM on premisesstub — Repeated sign-in prompts and refresh-token failures.
Sources
- 1The OAuth Access Token Expiry Timer (minutes) enterprise parameter accepts 1 to 1440 minutes and defaults to 60.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins / OAuth parameter table, OAuth Access Token Expiry Timer (minutes) · Checked 2026-10-02
- 2The Jabber planning guide states that OAuth refresh tokens must be turned on across all deployed components (Unified CM, IM and Presence, Unity Connection, Expressway) for the feature to work.Planning Guide for Cisco Jabber 14.1 - User Management · User Management > OAuth · Checked 2026-10-02
- 3Release 15 adds the Auto Renew Refresh Token enterprise parameter, enabled by default; when it is disabled Unified CM does not auto-extend refresh tokens.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > Auto Renew Refresh Token · Checked 2026-10-02
- 4After the refresh-token expiry is first set from Control Hub it can be changed again at the individual cluster level, and the cluster-level setting always takes priority.Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Set Expiration Timer for OAuth Refresh Token · Checked 2026-10-02
- 5The Control Hub article's prerequisites are Cloud-Connected UC activated with on-premises devices communicating with Control Hub, Unified CM clusters at 11.5 or above, and Webex App 41.12 or later.Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Prerequisite · Checked 2026-10-02
- 6Changing the Control Hub refresh-token expiry takes effect immediately, and previously issued refresh tokens cease to be valid, forcing client applications that hold them to re-authenticate.Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Set Expiration Timer for OAuth Refresh Token · Checked 2026-10-02
- 7In Control Hub, Services > Calling > Client Settings > Unified CM Settings has an Expiration timer for OAuth refresh token field accepting 1 to 1825 days, default 60.Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Set Expiration Timer for OAuth Refresh Token · Checked 2026-10-02
- 8The username and password entered for a Unity Connection Authz server must be the same as the Unified CM system administrator credentials.System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server · Checked 2026-10-02
- 9Unity Connection uses the Unified CM publisher of the associated phone system as its Authz server, configured at System Settings > Authz Server > Add New; with Session Management Edition each leaf-cluster publisher can be added.System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server · Checked 2026-10-02
- 10The Unity Connection Authz server page has an Ignore Certificate Errors check box as an alternative to uploading valid Unified CM certificates to the Unity Connection Tomcat trust store.System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server, Ignore Certificate Errors field · Checked 2026-10-02
- 11OAuth flow is disabled by default on Unity Connection and is enabled in Cisco Unity Connection Administration at System Settings > Enterprise Parameters > SSO and OAuth Configuration by setting OAuth with Refresh Login Flow to Enabled.System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server, prerequisites · Checked 2026-10-02
- 12With OAuth Refresh Logins the default access-token lifespan is 60 minutes and the default refresh-token life is 60 days.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework · Checked 2026-10-02
- 13Cisco warns that once OAuth Refresh Logins are enabled, disabling the feature requires resetting all Cisco Jabber clients.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins, Note under OAuth with Refresh Login Flow · Checked 2026-10-02
- 14When OAuth with Refresh Login Flow is Enabled, clients such as Cisco Jabber can use an OAuth-based Fast Login flow that does not require the user to sign in again, for example after a network change.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Enabled bullet · Checked 2026-10-02
- 15Cisco's generic enterprise-parameter procedure is to edit the value, click Save, then click Reset and OK to reset all devices.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Configure Enterprise Parameters procedure · Checked 2026-10-02
- 16Expressway's Check for internal authentication availability setting defaults to No, and Cisco warns that Yes can allow rogue inbound requests from unauthenticated remote clients.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Check for internal authentication availability · Checked 2026-10-02
- 17Expressway's OAuth token with refresh option requires OAuth with refresh to be enabled on the Unified CM clusters and, where it is used, on Unity Connection.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh, requirements · Checked 2026-10-02
- 18Expressway's separate Authorize by OAuth token option (previously SSO mode) requires authentication through the IdP, defaults to Off, and is available only with SAML SSO authentication paths.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token (previously SSO mode) · Checked 2026-10-02
- 19On Expressway-C, Authorize by OAuth token with refresh is set under Configuration > Unified Communications > Configuration > MRA Access Control; Cisco recommends it for all deployments that can support it and its default is On.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh · Checked 2026-10-02
- 20After enabling OAuth token with refresh, the Unified CM nodes defined on the Expressway must be refreshed, which fetches the keys the Expressway needs to decrypt the tokens.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh · Checked 2026-10-02
- 21In an IM and Presence centralized deployment, OAuth with Refresh Login Flow is set on the telephony cluster, and that setting automatically enables the feature in the IM and Presence central cluster.Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment · Configure Centralized Deployment > Configure OAuth Refresh Logins · Checked 2026-10-02
- 22In an IM and Presence centralized deployment, the remote Unified CM telephony cluster must run at least 11.5(1)SU4 to support OAuth Refresh Logins.Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment · Configure Centralized Deployment > Configure OAuth Refresh Logins · Checked 2026-10-02
- 23In an IM and Presence centralized deployment, a remote Unified CM telephony cluster's status shows Synchronized for OAuth Refresh Logins when it supports the feature, and earlier clusters may show Unsynchronized.Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment · Configure Centralized Deployment > remote telephony cluster status · Checked 2026-10-02
- 24When OAuth keys are regenerated, the Cisco XCP Authentication Service must be restarted on all IM and Presence nodes for Jabber OAuth login to work.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework, Note on key regeneration · Checked 2026-10-02
- 25For backward compatibility, older Jabber clients and supporting applications such as Cisco Unified RTMT can still authenticate with the implicit grant flow, which is enabled by default.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · OAuth Refresh Logins overview · Checked 2026-10-02
- 26A longer refresh-token lifetime means fewer sign-in prompts but a longer window in which a lost device keeps access, so revoking a leaver's refresh token with the revoke API matters more as the lifetime grows.inferredSecurity Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework, token lifetimes and revoke API · Checked 2026-10-02
- 27Because Expressway fetches the Unified CM token keys only when its Unified CM nodes are refreshed and requires OAuth with refresh on Unified CM, enabling the Unified CM parameter before refreshing Expressway avoids MRA clients being validated against missing keys.inferredMobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh · Checked 2026-10-02
- 28Because Cisco documents different upper bounds for the refresh-token expiry (90 days for 12.0, 365 days for 12.5(1), 1825 days in Control Hub) and the Release 15 parameter text read here does not state one, the allowed range on a given cluster should be read from that cluster's own parameter help before choosing a value.inferredSystem Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · OAuth parameter table, compared with cisco-technote-212794-oauth-code-grant and webex-help-ki34wo-auto-provisioning-ucm · Checked 2026-10-02
- 29A Jabber log line reading Failed to get valid access token from refresh token, maybe server issue indicates that a refresh-token exchange failed.Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0 · Troubleshoot > Jabber logs · Checked 2026-10-02
- 30OAuth Refresh Logins for Cisco Jabber require Jabber Release 11.9 or later.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · OAuth Refresh Logins prerequisites · Checked 2026-10-02
- 31When OAuth is enabled or disabled on any of the servers, Jabber detects it at its configuration re-fetch interval, clears cached credentials and has the user sign out and sign in again.Planning Guide for Cisco Jabber 14.1 - User Management · User Management > OAuth · Checked 2026-10-02
- 32For Mobile and Remote Access deployments with Cisco Jabber, Cisco recommends enabling OAuth with Refresh Login Flow only with an Expressway version that supports it, warning that an incompatible version may impact Jabber functionality.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Note · Checked 2026-10-02
- 33The Enable Mobile and Remote Access check box in the Unified CM User Profile (User Management > User Settings > User Profile) is mandatory for Cisco Jabber users who use OAuth Refresh Logins over MRA; non-Jabber users do not need it.Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Mobile and Remote Access · Configure Mobile and Remote Access Access Policy for Cisco Jabber Users, step 7 note · Checked 2026-10-02
- 34Cisco states that enabling OAuth with Refresh Login Flow requires support from other Unified Communications components such as Expressway and Unity Connection, running compatible versions with the refresh login flow enabled.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Enabled bullet · Checked 2026-10-02
- 35Cisco Jabber OAuth can be set up with or without SSO; if SSO is used, Cisco says it must be enabled for all services.Planning Guide for Cisco Jabber 14.1 - User Management · User Management > OAuth · Checked 2026-10-02
- 36The OAuth with Refresh Login Flow enterprise parameter defaults to Disabled.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow · Checked 2026-10-02
- 37The OAuth with Refresh Login Flow enterprise parameter is set in Cisco Unified CM Administration at System > Enterprise Parameters, in the SSO and OAuth Configuration section.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow · Checked 2026-10-02
- 38The 12.0 TAC tech note gives the refresh-token expiry range as 1 to 90 days with a default of 60 days.Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0 · Configure > OAuth token expiry parameters · Checked 2026-10-02
- 39In the Release 12.5(1) documentation, the OAuth Refresh Token Expiry Timer (days) enterprise parameter accepts 1 to 365 days and defaults to 60; after it expires the refresh token is invalid and the client must re-authenticate.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins / OAuth parameter table, OAuth Refresh Token Expiry Timer (days) · Checked 2026-10-02
- 40The OAuth encryption key can be regenerated only from the CLI, with set key regen authz encryption confirmed by yes.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Regenerate Keys for OAuth Refresh Logins · Checked 2026-10-02
- 41Cisco TAC states the OAuth signing and encryption keys should be regenerated only if the administrator believes they have been compromised.Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0 · Troubleshoot > key mismatch, Note · Checked 2026-10-02
- 42After the OAuth keys are regenerated, current access and refresh tokens that use those keys become invalid, and Cisco recommends doing it during off-hours.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Regenerate Keys for OAuth Refresh Logins · Checked 2026-10-02
- 43The Unified CM publisher regenerates the OAuth keys and replicates them to all Unified CM cluster nodes, including any local IM and Presence Service nodes.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Regenerate Keys for OAuth Refresh Logins · Checked 2026-10-02
- 44The OAuth signing key can be regenerated with the CLI command set key regen authz signing, or in Cisco Unified OS Administration at Security > Certificate Management by selecting the AUTHZ certificate and clicking Regenerate.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Regenerate Keys for OAuth Refresh Logins · Checked 2026-10-02
- 45After regenerating OAuth keys, the new keys must also be regenerated and synced on an IM and Presence central cluster and on Cisco Expressway or Cisco Unity Connection.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Regenerate Keys for OAuth Refresh Logins, list of UC clusters · Checked 2026-10-02
- 46Each time an OAuth access token reaches 75 percent of its lifespan, the client application requests a new access token from Unified CM.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework · Checked 2026-10-02
- 47The 12.5(1) Configure Refresh Logins procedure ends by resetting all Cisco Jabber and Webex clients after the enterprise parameters are saved.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins, final step · Checked 2026-10-02
- 48Unified CM exposes a REST endpoint, https://<UCMaddress>:8443/ssosp/token/revoke?user_id=<end_user>, called with administrator credentials, that revokes a user's current refresh token so the user cannot obtain new access tokens.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework > revoke refresh tokens · Checked 2026-10-02
- 49Cisco TAC verifies OAuth key consistency by running show key authz signing and show key authz encryption on every Unified CM and IM and Presence node and comparing the results.Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0 · Verify / Troubleshoot > key mismatch · Checked 2026-10-02
- 50SIP OAuth Mode, supported for Cisco Jabber from Unified CM 12.5 onwards, includes setting OAuth with Refresh Login Flow to Enabled as part of its configuration.Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - SIP OAuth Mode · SIP OAuth Mode > Configure Refresh Logins · Checked 2026-10-02
- 51OAuth and SSO operations on Unified CM are logged under the Tomcat ssosp log4j directory, with SSO application logs in ssoApp.log and certificate operations in certMgmt logs.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · OAuth troubleshooting log locations · Checked 2026-10-02
- 52From Unified CM 12.5(1)SU7 and 14SU3 onwards, subscriber nodes as well as the publisher can update the refresh token in the requesting node's database, and the change replicates across the cluster.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Important · Checked 2026-10-02
- 53Unified CM OAuth access tokens are encrypted, signed and self-contained JWTs (RFC 7519), while refresh tokens are signed but not encrypted.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · OAuth Refresh Logins overview · Checked 2026-10-02
- 54From Release 15, for Webex clients only, Unified CM renews the refresh token automatically when renewal is enabled on Unified CM and the Webex client and the refresh token has reached 50 percent of its lifetime.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework, refresh token renewal paragraph · Checked 2026-10-02
Documents
tier 2 current vendor documentation
Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates
tier 2 current vendor documentation
Auto-Provisioning of Webex App for Calling in Webex (Unified CM)
tier 2 current vendor documentation
Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment
tier 2 current vendor documentation
Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0
tier 2 current vendor documentation
Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Mobile and Remote Access
tier 2 current vendor documentation
Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - SIP OAuth Mode
tier 2 current vendor documentation
Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration
tier 2 current vendor documentation
Planning Guide for Cisco Jabber 14.1 - User Management
tier 2 current vendor documentation
Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management
tier 2 current vendor documentation
System Administration Guide for Cisco Unity Connection Release 15 - System Settings
tier 2 current vendor documentation
System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber
tier 2 current vendor documentation
System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services
Cite this page
APA
WarmTransfer. (2026, October 2). Enabling OAuth refresh-token login for Jabber and Webex App in Unified CM. WarmTransfer. https://warmtransfer.net/guides/cucm-oauth-refresh-login-setup
BibTeX
@misc{warmtransfer-cucm-oauth-refresh-login-setup,
title = {Enabling OAuth refresh-token login for Jabber and Webex App in Unified CM},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/guides/cucm-oauth-refresh-login-setup},
note = {Verified 2026-10-02}
}