Enabling OAuth refresh-token login for Jabber and Webex App in Unified CM
Cisco Unified CM
Verified 2026-10-02 · 61 sources · tier 2
For Unified CM administrators who also administer or coordinate with the owners of IM and Presence, Unity Connection and Expressway MRA for the same users..
OAuth with Refresh Login Flow is a Unified CM enterprise parameter, set in Cisco Unified CM Administration at System > Enterprise Parameters in the SSO and OAuth Configuration section, and it defaults to Disabled 37 36. When it is Enabled, clients such as Cisco Jabber can use an OAuth-based Fast Login flow that does not require the user to sign in again, for example after a network change 14.
Before you start
- Cisco states that enabling OAuth with Refresh Login Flow requires support from other Unified Communications components such as Expressway and Unity Connection, running compatible versions with the refresh login flow enabled 34.
- The Jabber planning guide states that OAuth refresh tokens must be turned on across all deployed components (Unified CM, IM and Presence, Unity Connection, Expressway) for the feature to work 2.
- Jabber OAuth with refresh tokens requires Unified CM 11.5(SU3) or 12.0 and later, and the access-token and refresh-token expiry timers are Unified CM enterprise parameters 55.
- OAuth Refresh Logins for Cisco Jabber require Jabber Release 11.9 or later 30.
- With OAuth Refresh Logins, the default access-token lifespan is 60 minutes and the default refresh-token life is 60 days 12.
- Each time an access token reaches 75 percent of its lifespan, the client application requests a new access token from Unified CM 46.
- Unified CM access tokens are encrypted, signed and self-contained JWTs (RFC 7519), while refresh tokens are signed but not encrypted 53.
- For backward compatibility, older Jabber clients and supporting applications such as Cisco Unified RTMT can still authenticate with the implicit grant flow, which is enabled by default 25.
- Cisco Jabber OAuth can be set up with or without SSO, and if SSO is used, Cisco says it must be enabled for all services 35.
- SAML SSO itself is configured at System > SAML Single Sign On in Cisco Unified CM Administration, and the Cisco Tomcat service must be restarted both before and after SSO is enabled 56.
- Cisco warns that once OAuth Refresh Logins are enabled, disabling the feature requires resetting all Cisco Jabber clients 13.
See also Setting up SAML SSO for Unified CM.
See also Expressway and Mobile and Remote Access.
See also Cisco Unity Connection voicemail and migration.
What changes by situation
Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.
Five questions. One permanent page you can send to your manager.
Step 1 Inventory versions and the current key state
Do
Record the Unified CM release on every cluster, because Jabber OAuth with refresh tokens requires Unified CM 11.5(SU3) or 12.0 and later 55. Version 15 is the latest Unified CM major release listed on Cisco's support pages 57, and Version 12.5 reached end of support on 31 August 2025 58. The end of software maintenance releases for Unified CM Version 14 was 7 April 2026 59. WarmTransfer's reading of the sources is that 15SU4a is the newest build with published ReadMe and release notes, so new deployments and upgrades would normally target 15SU4a or later 60. Note whether each cluster is at 12.5(1)SU7, 14SU3 or later, because from those releases subscriber nodes as well as the publisher can update the refresh token, and the change replicates across the cluster 52. Confirm that Jabber is Release 11.9 or later 30. In standard deployments, confirm that IM and Presence runs a version matching Unified CM, because a version mismatch is not supported 61. Where clients use Mobile and Remote Access, record the Expressway version: Cisco recommends enabling OAuth with Refresh Login Flow only with an Expressway version that supports it, warning that an incompatible version may impact Jabber functionality 32.
Verify
Run show key authz signing and show key authz encryption on every Unified CM and IM and Presence node and compare the results, as Cisco TAC does to verify OAuth key consistency 49. Suggested check: record the outputs so later steps can compare against them.
Step 2 Set the token lifetimes
Keep Cisco's defaults (60 minutes / 60 days)
Do
Leave the access-token lifespan at its default of 60 minutes and the refresh-token life at its default of 60 days 12.
Verify
In System > Enterprise Parameters, OAuth Access Token Expiry Timer (minutes) shows its default of 60 1 55. Suggested check: confirm that the refresh-token timer also still shows its default value.
Set custom values in the Unified CM enterprise parameters
Do
In System > Enterprise Parameters, set OAuth Access Token Expiry Timer (minutes) to a value from 1 to 1440 1 55. Set the refresh-token expiry timer, which is also a Unified CM enterprise parameter 55. We infer that a longer refresh-token lifetime means fewer sign-in prompts but a longer window in which a lost device keeps access, so revoking a leaver's refresh token with the revoke API matters more as the lifetime grows 26. Click Save 15.
Verify
Suggested check: re-open the enterprise parameters page and confirm both timers show the values you saved.
Rollback
Set the access-token timer back to 60 minutes and the refresh-token timer back to 60 days, the defaults 12 1.
Set the refresh-token lifetime from Control Hub (Cloud-Connected UC)
Do
Confirm the prerequisites: Cloud-Connected UC activated with on-premises devices communicating with Control Hub, Unified CM clusters at 11.5 or above, and Webex App 41.12 or later 5. In Control Hub, go to Services > Calling > Client Settings > Unified CM Settings and enter a value from 1 to 1825 days in Expiration timer for OAuth refresh token 7. Schedule the change, because it takes effect immediately and previously issued refresh tokens cease to be valid, forcing client applications that hold them to re-authenticate 6.
Verify
Check each cluster for a cluster-level value, because after the expiry is first set from Control Hub it can be changed at the individual cluster level, and the cluster-level setting always takes priority 4.
Rollback
Set Expiration timer for OAuth refresh token back to its default of 60 days 7. This change also takes effect immediately and invalidates previously issued refresh tokens 6.
Step 3 Decide on refresh-token auto-renewal (Release 15)
Keep Auto Renew Refresh Token enabled (the default)
Do
Leave the Auto Renew Refresh Token enterprise parameter enabled, which is its default from Release 15 3. From Release 15, for Webex clients only, Unified CM renews the refresh token automatically when renewal is enabled on Unified CM and the Webex client and the refresh token has reached 50 percent of its lifetime 54.
Verify
Suggested check: confirm the parameter reads Enabled on the enterprise parameters page.
Disable it so refresh tokens are not auto-extended
Do
Set Auto Renew Refresh Token to Disabled, after which Unified CM does not auto-extend refresh tokens 3. Click Save 15.
Verify
Suggested check: re-open the enterprise parameters page and confirm the parameter reads Disabled.
Rollback
Set Auto Renew Refresh Token back to Enabled, its default 3.
Step 4 Enable OAuth with Refresh Login Flow on Unified CM
Do
In Cisco Unified CM Administration, go to System > Enterprise Parameters, and in the SSO and OAuth Configuration section set OAuth with Refresh Login Flow to Enabled 37. In an IM and Presence centralized deployment, set it on each telephony cluster, which automatically enables the feature in the IM and Presence central cluster 21. Click Save; Cisco's generic enterprise-parameter procedure follows Save with Reset and OK to reset all devices 15. The 12.5(1) Configure Refresh Logins procedure ends by resetting all Cisco Jabber and Webex clients after the enterprise parameters are saved 47.
Verify
Suggested check: re-open the enterprise parameters page and confirm the parameter reads Enabled. Jabber detects the change at its configuration re-fetch interval 31.
Rollback
Set OAuth with Refresh Login Flow back to Disabled, its default 37 36. Disabling the feature after it has been enabled requires resetting all Cisco Jabber clients 13, and Jabber clears cached credentials and has the user sign out and sign in again 31.
Step 5 Bring IM and Presence in line
IM and Presence nodes are in the same cluster as Unified CM
Do
The Unified CM publisher replicates the OAuth keys to all Unified CM cluster nodes, including any local IM and Presence Service nodes 43.
Verify
Run show key authz signing and show key authz encryption on the IM and Presence nodes and compare the results with the Unified CM nodes 49.
IM and Presence central cluster serving remote telephony clusters
Do
Confirm that every remote telephony cluster runs at least 11.5(1)SU4, the minimum for OAuth Refresh Logins in an IM and Presence centralized deployment 22. The setting made on the telephony clusters automatically enables the feature in the IM and Presence central cluster 21.
Verify
On the central cluster, each remote telephony cluster that supports the feature shows Synchronized for OAuth Refresh Logins, and earlier clusters may show Unsynchronized 23.
Rollback
Suggested rollback: disable the parameter on each telephony cluster as described in the Step 4 rollback.
No IM and Presence Service
Do
Run show key authz signing and show key authz encryption on every Unified CM node and compare the results 49.
Verify
Suggested check: confirm the outputs are identical on every node.
Step 6 Enable refresh login on Unity Connection
Yes from Unity Connection
Do
In Cisco Unity Connection Administration, go to System Settings > Enterprise Parameters > SSO and OAuth Configuration and set OAuth with Refresh Login Flow to Enabled, because OAuth flow is disabled by default on Unity Connection 11. Go to System Settings > Authz Server > Add New and add the Unified CM publisher of the associated phone system; with Session Management Edition, each leaf-cluster publisher can be added 9. Enter a username and password that are the same as the Unified CM system administrator credentials 8. The Ignore Certificate Errors check box is an alternative to uploading valid Unified CM certificates to the Unity Connection Tomcat trust store 10.
Verify
Suggested check: confirm the server entry saves without a certificate or credential error. Suggested check: after Step 9, confirm that a pilot user's visual voicemail works.
Rollback
Suggested rollback: delete the server entry you added. Set OAuth with Refresh Login Flow on Unity Connection back to Disabled, its default 11.
No Unity Connection integration for these clients
Do
Expressway's OAuth token with refresh option requires OAuth with refresh on Unity Connection only where Unity Connection is used 17.
Verify
Suggested check: confirm that the clients in scope are not configured with any voicemail server that would need this change.
Step 7 Authorize MRA by OAuth token with refresh
Yes for some or all users
Do
On Unified CM, tick Enable Mobile and Remote Access in the User Profile (User Management > User Settings > User Profile) used by each Jabber user, because it is mandatory for Cisco Jabber users who use OAuth Refresh Logins over MRA 33. On Expressway-C, go to Configuration > Unified Communications > Configuration > MRA Access Control and set Authorize by OAuth token with refresh to On; Cisco recommends it for all deployments that can support it, and its default is On 19. This option requires OAuth with refresh to be enabled on the Unified CM clusters and, where it is used, on Unity Connection 17. Refresh the Unified CM nodes defined on the Expressway, which fetches the keys the Expressway needs to decrypt the tokens 20. We infer that enabling the Unified CM parameter before refreshing Expressway avoids MRA clients being validated against missing keys 27. Leave Check for internal authentication availability at its default of No, because Cisco warns that Yes can allow rogue inbound requests from unauthenticated remote clients 16. The separate Authorize by OAuth token option (previously SSO mode) requires authentication through the IdP, defaults to Off, and is available only with SAML SSO authentication paths 18.
Verify
Suggested check: in Step 9, confirm that an off-network client signs in remotely and stays signed in past the access-token lifetime.
Rollback
Set Authorize by OAuth token with refresh to Off on Expressway-C 19. Suggested rollback: then reverse Step 4 if the whole change is being backed out.
No and on-premises sign-in only
Do
The Enable Mobile and Remote Access check box in the User Profile is mandatory only for Cisco Jabber users who use OAuth Refresh Logins over MRA 33.
Verify
Suggested check: confirm that the clients in scope sign in only from inside the network.
Step 8 Get clients onto the new flow
Do
Tell users to expect one sign-out and sign-in, because when OAuth is enabled or disabled on any of the servers, Jabber detects it at its configuration re-fetch interval, clears cached credentials and has the user sign out and sign in again 31. Reset all Cisco Jabber and Webex clients, as the 12.5(1) Configure Refresh Logins procedure directs 47.
Verify
Suggested check: confirm each pilot user signs in once and is not prompted again afterwards. Where SSO is used, Cisco says it must be enabled for all services 35.
Step 9 Test
Do
With a pilot user, sign in and leave the client running past the access-token lifetime, since the client requests a new access token each time the current one reaches 75 percent of its lifespan 46. Change networks and confirm no sign-in prompt appears, which is the Fast Login behaviour the enabled parameter provides 14.
Verify
A Jabber log line reading Failed to get valid access token from refresh token, maybe server issue indicates that a refresh-token exchange failed 29. If failures appear, check the Unified CM Tomcat ssosp log4j directory, where SSO application logs are in ssoApp.log and certificate operations are in certMgmt logs 51, and re-run the show key authz signing and show key authz encryption comparison 49. Suggested check: repeat the test from outside the network for users who sign in remotely.
Step 10 Put a leaver-revocation procedure in place
Do
Add a call to https://<UCMaddress>:8443/ssosp/token/revoke?user_id=<end_user>, made with administrator credentials, to the leaver process; it revokes the user's current refresh token 48.
Verify
After revocation, the user cannot obtain new access tokens 48. Suggested check: revoke a test user's token and confirm the client is prompted to sign in once its current access token expires.
Rollback
Suggested rollback: have the test user sign in again to obtain a new refresh token.
Step 11 Regenerate OAuth keys only if they are compromised
Do
Cisco TAC states the OAuth signing and encryption keys should be regenerated only if the administrator believes they have been compromised 41. Cisco recommends regenerating during off-hours, because current access and refresh tokens that use those keys become invalid 42. Regenerate the encryption key from the CLI with set key regen authz encryption, confirmed by yes, since it can be regenerated only from the CLI 40. Regenerate the signing key with set key regen authz signing, or in Cisco Unified OS Administration at Security > Certificate Management by selecting the AUTHZ certificate and clicking Regenerate 44. The publisher replicates the new keys to all Unified CM cluster nodes, including any local IM and Presence Service nodes 43. Where Expressway is used, refresh the Unified CM nodes defined on it so it fetches the keys it needs to decrypt the tokens 20. Restart the Cisco XCP Authentication Service on all IM and Presence nodes so that Jabber OAuth login works 24.
Verify
Run show key authz signing and show key authz encryption on every Unified CM and IM and Presence node and compare the results 49. Expect every user to sign in again, because existing access and refresh tokens that used the old keys are invalid 42.
Applicability
Applies to: Cisco Unified Communications Manager, Cisco Jabber, Cisco Webex Control Hub, Cisco Unity Connection, Cisco Expressway, and Cisco Unified CM IM. Deployments: on-premises and hybrid. Sources checked 2026-10-02. Auto Renew Refresh Token is a Release 15 addition 3. Subscriber-node refresh-token updates apply from Unified CM 12.5(1)SU7 and 14SU3 onwards 52. The Control Hub refresh-token timer requires Cloud-Connected UC with on-premises devices communicating with Control Hub, Unified CM clusters at 11.5 or above, and Webex App 41.12 or later 5.
What remains uncertain
- The allowed range for the Unified CM refresh-token expiry timer enterprise parameter, and how it differs by release, is not covered by the sources below.
- The minimum Expressway version for given Jabber and Webex App releases is not covered by the sources below.
- Whether changing the Unified CM refresh-token expiry enterprise parameter invalidates already-issued refresh tokens is not covered by the sources below.
- Whether a full device reset, rather than only a client reset, is required after saving this parameter is not covered by the sources below.
- The exact steps to bring a centralized IM and Presence cluster and Unity Connection in line after OAuth key regeneration are not covered by the sources below.
See also
Configures
- Cisco unified cm — Cluster-wide enterprise parameter and token lifetimes on Unified CM.
Depends on
- Expressway and Mobile and Remote Access — MRA clients need Expressway Authorize by OAuth token with refresh and a Unified CM server refresh.
Related to
- Cisco Unity Connection voicemail and migration — Unity Connection needs the parameter enabled and an Authz server pointing at the Unified CM publisher.
- Setting up SAML SSO for Unified CM — OAuth refresh login works with or without SAML SSO; SSO setup is a separate guide.
- TLS certificates and secure SIP failures — SIP OAuth Mode builds on OAuth with Refresh Login Flow.
- Troubleshooting Jabber and Webex App sign-in on Unified CM on premises — Repeated sign-in prompts and refresh-token failures.
Referenced by
- Troubleshooting Jabber and Webex App sign-in on Unified CM on premises — Repeated sign-in prompts and refresh-token failures belong to that topic
Sources
- 1The OAuth Access Token Expiry Timer (minutes) enterprise parameter accepts 1 to 1440 minutes and defaults to 60.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins / OAuth parameter table, OAuth Access Token Expiry Timer (minutes) · Checked 2026-10-02
- 2The Jabber planning guide states that OAuth refresh tokens must be turned on across all deployed components (Unified CM, IM and Presence, Unity Connection, Expressway) for the feature to work.Planning Guide for Cisco Jabber 14.1 - User Management · User Management > OAuth · Checked 2026-10-02
- 3Release 15 adds the Auto Renew Refresh Token enterprise parameter, enabled by default; when it is disabled Unified CM does not auto-extend refresh tokens.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > Auto Renew Refresh Token · Checked 2026-10-02
- 4After the refresh-token expiry is first set from Control Hub it can be changed again at the individual cluster level, and the cluster-level setting always takes priority.Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Set Expiration Timer for OAuth Refresh Token · Checked 2026-10-02
- 5The Control Hub article's prerequisites are Cloud-Connected UC activated with on-premises devices communicating with Control Hub, Unified CM clusters at 11.5 or above, and Webex App 41.12 or later.Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Prerequisite · Checked 2026-10-02
- 6Changing the Control Hub refresh-token expiry takes effect immediately, and previously issued refresh tokens cease to be valid, forcing client applications that hold them to re-authenticate.Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Set Expiration Timer for OAuth Refresh Token · Checked 2026-10-02
- 7In Control Hub, Services > Calling > Client Settings > Unified CM Settings has an Expiration timer for OAuth refresh token field accepting 1 to 1825 days, default 60.Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Set Expiration Timer for OAuth Refresh Token · Checked 2026-10-02
- 8The username and password entered for a Unity Connection Authz server must be the same as the Unified CM system administrator credentials.System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server · Checked 2026-10-02
- 9Unity Connection uses the Unified CM publisher of the associated phone system as its Authz server, configured at System Settings > Authz Server > Add New; with Session Management Edition each leaf-cluster publisher can be added.System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server · Checked 2026-10-02
- 10The Unity Connection Authz server page has an Ignore Certificate Errors check box as an alternative to uploading valid Unified CM certificates to the Unity Connection Tomcat trust store.System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server, Ignore Certificate Errors field · Checked 2026-10-02
- 11OAuth flow is disabled by default on Unity Connection and is enabled in Cisco Unity Connection Administration at System Settings > Enterprise Parameters > SSO and OAuth Configuration by setting OAuth with Refresh Login Flow to Enabled.System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server, prerequisites · Checked 2026-10-02
- 12With OAuth Refresh Logins the default access-token lifespan is 60 minutes and the default refresh-token life is 60 days.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework · Checked 2026-10-02
- 13Cisco warns that once OAuth Refresh Logins are enabled, disabling the feature requires resetting all Cisco Jabber clients.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins, Note under OAuth with Refresh Login Flow · Checked 2026-10-02
- 14When OAuth with Refresh Login Flow is Enabled, clients such as Cisco Jabber can use an OAuth-based Fast Login flow that does not require the user to sign in again, for example after a network change.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Enabled bullet · Checked 2026-10-02
- 15Cisco's generic enterprise-parameter procedure is to edit the value, click Save, then click Reset and OK to reset all devices.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Configure Enterprise Parameters procedure · Checked 2026-10-02
- 16Expressway's Check for internal authentication availability setting defaults to No, and Cisco warns that Yes can allow rogue inbound requests from unauthenticated remote clients.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Check for internal authentication availability · Checked 2026-10-02
- 17Expressway's OAuth token with refresh option requires OAuth with refresh to be enabled on the Unified CM clusters and, where it is used, on Unity Connection.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh, requirements · Checked 2026-10-02
- 18Expressway's separate Authorize by OAuth token option (previously SSO mode) requires authentication through the IdP, defaults to Off, and is available only with SAML SSO authentication paths.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token (previously SSO mode) · Checked 2026-10-02
- 19On Expressway-C, Authorize by OAuth token with refresh is set under Configuration > Unified Communications > Configuration > MRA Access Control; Cisco recommends it for all deployments that can support it and its default is On.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh · Checked 2026-10-02
- 20After enabling OAuth token with refresh, the Unified CM nodes defined on the Expressway must be refreshed, which fetches the keys the Expressway needs to decrypt the tokens.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh · Checked 2026-10-02
- 21In an IM and Presence centralized deployment, OAuth with Refresh Login Flow is set on the telephony cluster, and that setting automatically enables the feature in the IM and Presence central cluster.Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment · Configure Centralized Deployment > Configure OAuth Refresh Logins · Checked 2026-10-02
- 22In an IM and Presence centralized deployment, the remote Unified CM telephony cluster must run at least 11.5(1)SU4 to support OAuth Refresh Logins.Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment · Configure Centralized Deployment > Configure OAuth Refresh Logins · Checked 2026-10-02
- 23In an IM and Presence centralized deployment, a remote Unified CM telephony cluster's status shows Synchronized for OAuth Refresh Logins when it supports the feature, and earlier clusters may show Unsynchronized.Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment · Configure Centralized Deployment > remote telephony cluster status · Checked 2026-10-02
- 24When OAuth keys are regenerated, the Cisco XCP Authentication Service must be restarted on all IM and Presence nodes for Jabber OAuth login to work.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework, Note on key regeneration · Checked 2026-10-02
- 25For backward compatibility, older Jabber clients and supporting applications such as Cisco Unified RTMT can still authenticate with the implicit grant flow, which is enabled by default.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · OAuth Refresh Logins overview · Checked 2026-10-02
- 26A longer refresh-token lifetime means fewer sign-in prompts but a longer window in which a lost device keeps access, so revoking a leaver's refresh token with the revoke API matters more as the lifetime grows.inferredSecurity Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework, token lifetimes and revoke API · Checked 2026-10-02
- 27Because Expressway fetches the Unified CM token keys only when its Unified CM nodes are refreshed and requires OAuth with refresh on Unified CM, enabling the Unified CM parameter before refreshing Expressway avoids MRA clients being validated against missing keys.inferredMobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh · Checked 2026-10-02
- 28Because Cisco documents different upper bounds for the refresh-token expiry (90 days for 12.0, 365 days for 12.5(1), 1825 days in Control Hub) and the Release 15 parameter text read here does not state one, the allowed range on a given cluster should be read from that cluster's own parameter help before choosing a value.inferredSystem Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · OAuth parameter table, compared with cisco-technote-212794-oauth-code-grant and webex-help-ki34wo-auto-provisioning-ucm · Checked 2026-10-02
- 29A Jabber log line reading Failed to get valid access token from refresh token, maybe server issue indicates that a refresh-token exchange failed.Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0 · Troubleshoot > Jabber logs · Checked 2026-10-02
- 30OAuth Refresh Logins for Cisco Jabber require Jabber Release 11.9 or later.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · OAuth Refresh Logins prerequisites · Checked 2026-10-02
- 31When OAuth is enabled or disabled on any of the servers, Jabber detects it at its configuration re-fetch interval, clears cached credentials and has the user sign out and sign in again.Planning Guide for Cisco Jabber 14.1 - User Management · User Management > OAuth · Checked 2026-10-02
- 32For Mobile and Remote Access deployments with Cisco Jabber, Cisco recommends enabling OAuth with Refresh Login Flow only with an Expressway version that supports it, warning that an incompatible version may impact Jabber functionality.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Note · Checked 2026-10-02
- 33The Enable Mobile and Remote Access check box in the Unified CM User Profile (User Management > User Settings > User Profile) is mandatory for Cisco Jabber users who use OAuth Refresh Logins over MRA; non-Jabber users do not need it.Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Mobile and Remote Access · Configure Mobile and Remote Access Access Policy for Cisco Jabber Users, step 7 note · Checked 2026-10-02
- 34Cisco states that enabling OAuth with Refresh Login Flow requires support from other Unified Communications components such as Expressway and Unity Connection, running compatible versions with the refresh login flow enabled.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Enabled bullet · Checked 2026-10-02
- 35Cisco Jabber OAuth can be set up with or without SSO; if SSO is used, Cisco says it must be enabled for all services.Planning Guide for Cisco Jabber 14.1 - User Management · User Management > OAuth · Checked 2026-10-02
- 36The OAuth with Refresh Login Flow enterprise parameter defaults to Disabled.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow · Checked 2026-10-02
- 37The OAuth with Refresh Login Flow enterprise parameter is set in Cisco Unified CM Administration at System > Enterprise Parameters, in the SSO and OAuth Configuration section.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow · Checked 2026-10-02
- 38The 12.0 TAC tech note gives the refresh-token expiry range as 1 to 90 days with a default of 60 days.Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0 · Configure > OAuth token expiry parameters · Checked 2026-10-02
- 39In the Release 12.5(1) documentation, the OAuth Refresh Token Expiry Timer (days) enterprise parameter accepts 1 to 365 days and defaults to 60; after it expires the refresh token is invalid and the client must re-authenticate.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins / OAuth parameter table, OAuth Refresh Token Expiry Timer (days) · Checked 2026-10-02
- 40The OAuth encryption key can be regenerated only from the CLI, with set key regen authz encryption confirmed by yes.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Regenerate Keys for OAuth Refresh Logins · Checked 2026-10-02
- 41Cisco TAC states the OAuth signing and encryption keys should be regenerated only if the administrator believes they have been compromised.Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0 · Troubleshoot > key mismatch, Note · Checked 2026-10-02
- 42After the OAuth keys are regenerated, current access and refresh tokens that use those keys become invalid, and Cisco recommends doing it during off-hours.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Regenerate Keys for OAuth Refresh Logins · Checked 2026-10-02
- 43The Unified CM publisher regenerates the OAuth keys and replicates them to all Unified CM cluster nodes, including any local IM and Presence Service nodes.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Regenerate Keys for OAuth Refresh Logins · Checked 2026-10-02
- 44The OAuth signing key can be regenerated with the CLI command set key regen authz signing, or in Cisco Unified OS Administration at Security > Certificate Management by selecting the AUTHZ certificate and clicking Regenerate.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Regenerate Keys for OAuth Refresh Logins · Checked 2026-10-02
- 45After regenerating OAuth keys, the new keys must also be regenerated and synced on an IM and Presence central cluster and on Cisco Expressway or Cisco Unity Connection.Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Regenerate Keys for OAuth Refresh Logins, list of UC clusters · Checked 2026-10-02
- 46Each time an OAuth access token reaches 75 percent of its lifespan, the client application requests a new access token from Unified CM.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework · Checked 2026-10-02
- 47The 12.5(1) Configure Refresh Logins procedure ends by resetting all Cisco Jabber and Webex clients after the enterprise parameters are saved.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins, final step · Checked 2026-10-02
- 48Unified CM exposes a REST endpoint, https://<UCMaddress>:8443/ssosp/token/revoke?user_id=<end_user>, called with administrator credentials, that revokes a user's current refresh token so the user cannot obtain new access tokens.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework > revoke refresh tokens · Checked 2026-10-02
- 49Cisco TAC verifies OAuth key consistency by running show key authz signing and show key authz encryption on every Unified CM and IM and Presence node and comparing the results.Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0 · Verify / Troubleshoot > key mismatch · Checked 2026-10-02
- 50SIP OAuth Mode, supported for Cisco Jabber from Unified CM 12.5 onwards, includes setting OAuth with Refresh Login Flow to Enabled as part of its configuration.Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - SIP OAuth Mode · SIP OAuth Mode > Configure Refresh Logins · Checked 2026-10-02
- 51OAuth and SSO operations on Unified CM are logged under the Tomcat ssosp log4j directory, with SSO application logs in ssoApp.log and certificate operations in certMgmt logs.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · OAuth troubleshooting log locations · Checked 2026-10-02
- 52From Unified CM 12.5(1)SU7 and 14SU3 onwards, subscriber nodes as well as the publisher can update the refresh token in the requesting node's database, and the change replicates across the cluster.System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Important · Checked 2026-10-02
- 53Unified CM OAuth access tokens are encrypted, signed and self-contained JWTs (RFC 7519), while refresh tokens are signed but not encrypted.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · OAuth Refresh Logins overview · Checked 2026-10-02
- 54From Release 15, for Webex clients only, Unified CM renews the refresh token automatically when renewal is enabled on Unified CM and the Webex client and the refresh token has reached 50 percent of its lifetime.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework, refresh token renewal paragraph · Checked 2026-10-02
- 55Jabber OAuth with refresh tokens requires Unified CM 11.5(SU3) or 12.0 and later, and the access and refresh token expiry timers are Unified CM enterprise parameters.Planning Guide for Cisco Jabber 14.0 - User Management · User Management > OAuth · Checked 2026-09-25
- 57Version 15 is the latest Cisco Unified Communications Manager major release listed on Cisco's support pages; it was released on 16 October 2023 and its status is Available.Cisco Unified Communications Manager (CallManager) - Support · Product status and Latest release fields; Supported versions list · Checked 2026-09-30
- 58Cisco Unified CM Version 12.5 reached end of support on 31 August 2025.Cisco Unified Communications Manager (CallManager) - Support · Supported versions list, Version 12.5 entry (End-of-Support Date) · Checked 2026-09-30
- 59The end of software maintenance releases for Unified CM Version 14 was 7 April 2026.End-of-Sale and End-of-Life Announcement for the Cisco Version 14 of On-premises Calling applications (including Cisco Unified Communications Manager) — Perpetual · Table 1 End-of-life milestones, row End of SW Maintenance Releases Date · Checked 2026-09-30
- 60As of 2026-09-30, the newest Unified CM build with published ReadMe and release notes is 15SU4a, and Version 14 has passed its end of software maintenance, so new deployments and upgrades would normally target 15SU4a or later.inferredReadMe for Cisco Unified Communications Manager Release 15SU4a · Document header (Last Updated July 29 2026); combined with cisco-eol-v14-onprem-calling-apps Table 1 · Checked 2026-09-30
- 61In standard deployments, Unified CM and the IM and Presence Service must run supported, matching versions; a version mismatch is not supported.Installation Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Planning the Installation · Version compatibility section · Checked 2026-09-30
Documents
Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates
Auto-Provisioning of Webex App for Calling in Webex (Unified CM)
Cisco Unified Communications Manager (CallManager) - Support
Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment
Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0
End-of-Sale and End-of-Life Announcement for the Cisco Version 14 of On-premises Calling applications (including Cisco Unified Communications Manager) — Perpetual
Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Mobile and Remote Access
Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - SIP OAuth Mode
Installation Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Planning the Installation
Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration
Planning Guide for Cisco Jabber 14.0 - User Management
Planning Guide for Cisco Jabber 14.1 - User Management
ReadMe for Cisco Unified Communications Manager Release 15SU4a
SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration
Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management
System Administration Guide for Cisco Unity Connection Release 15 - System Settings
System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber
System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services
Cite this page
APA
WarmTransfer. (2026, October 2). Enabling OAuth refresh-token login for Jabber and Webex App in Unified CM. WarmTransfer. https://warmtransfer.net/guides/cucm-oauth-refresh-login-setup
BibTeX
@misc{warmtransfer-cucm-oauth-refresh-login-setup,
title = {Enabling OAuth refresh-token login for Jabber and Webex App in Unified CM},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/guides/cucm-oauth-refresh-login-setup},
note = {Verified 2026-10-02}
}