Configuration · guide

Enabling OAuth refresh-token login for Jabber and Webex App in Unified CM

Cisco Unified CM

Verified 2026-10-02 · 61 sources · tier 2

For Unified CM administrators who also administer or coordinate with the owners of IM and Presence, Unity Connection and Expressway MRA for the same users..

OAuth with Refresh Login Flow is a Unified CM enterprise parameter, set in Cisco Unified CM Administration at System > Enterprise Parameters in the SSO and OAuth Configuration section, and it defaults to Disabled 37 36. When it is Enabled, clients such as Cisco Jabber can use an OAuth-based Fast Login flow that does not require the user to sign in again, for example after a network change 14.

Before you start

  • Cisco states that enabling OAuth with Refresh Login Flow requires support from other Unified Communications components such as Expressway and Unity Connection, running compatible versions with the refresh login flow enabled 34.
  • The Jabber planning guide states that OAuth refresh tokens must be turned on across all deployed components (Unified CM, IM and Presence, Unity Connection, Expressway) for the feature to work 2.
  • Jabber OAuth with refresh tokens requires Unified CM 11.5(SU3) or 12.0 and later, and the access-token and refresh-token expiry timers are Unified CM enterprise parameters 55.
  • OAuth Refresh Logins for Cisco Jabber require Jabber Release 11.9 or later 30.
  • With OAuth Refresh Logins, the default access-token lifespan is 60 minutes and the default refresh-token life is 60 days 12.
  • Each time an access token reaches 75 percent of its lifespan, the client application requests a new access token from Unified CM 46.
  • Unified CM access tokens are encrypted, signed and self-contained JWTs (RFC 7519), while refresh tokens are signed but not encrypted 53.
  • For backward compatibility, older Jabber clients and supporting applications such as Cisco Unified RTMT can still authenticate with the implicit grant flow, which is enabled by default 25.
  • Cisco Jabber OAuth can be set up with or without SSO, and if SSO is used, Cisco says it must be enabled for all services 35.
  • SAML SSO itself is configured at System > SAML Single Sign On in Cisco Unified CM Administration, and the Cisco Tomcat service must be restarted both before and after SSO is enabled 56.
  • Cisco warns that once OAuth Refresh Logins are enabled, disabling the feature requires resetting all Cisco Jabber clients 13.

See also Setting up SAML SSO for Unified CM.

See also Expressway and Mobile and Remote Access.

See also Cisco Unity Connection voicemail and migration.

What changes by situation

Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.

Where will you set the access-token and refresh-token lifetimes?
On Release 15 should Webex App refresh tokens renew automatically?
How is IM and Presence deployed for these users?
Do Jabber or Webex App users get voicemail from Unity Connection?
Do clients sign in over Mobile and Remote Access through Expressway?

Five questions. One permanent page you can send to your manager.

Step 1 Inventory versions and the current key state

Do

Record the Unified CM release on every cluster, because Jabber OAuth with refresh tokens requires Unified CM 11.5(SU3) or 12.0 and later 55. Version 15 is the latest Unified CM major release listed on Cisco's support pages 57, and Version 12.5 reached end of support on 31 August 2025 58. The end of software maintenance releases for Unified CM Version 14 was 7 April 2026 59. WarmTransfer's reading of the sources is that 15SU4a is the newest build with published ReadMe and release notes, so new deployments and upgrades would normally target 15SU4a or later 60. Note whether each cluster is at 12.5(1)SU7, 14SU3 or later, because from those releases subscriber nodes as well as the publisher can update the refresh token, and the change replicates across the cluster 52. Confirm that Jabber is Release 11.9 or later 30. In standard deployments, confirm that IM and Presence runs a version matching Unified CM, because a version mismatch is not supported 61. Where clients use Mobile and Remote Access, record the Expressway version: Cisco recommends enabling OAuth with Refresh Login Flow only with an Expressway version that supports it, warning that an incompatible version may impact Jabber functionality 32.

Verify

Run show key authz signing and show key authz encryption on every Unified CM and IM and Presence node and compare the results, as Cisco TAC does to verify OAuth key consistency 49. Suggested check: record the outputs so later steps can compare against them.

Step 2 Set the token lifetimes

Keep Cisco's defaults (60 minutes / 60 days)

Do

Leave the access-token lifespan at its default of 60 minutes and the refresh-token life at its default of 60 days 12.

Verify

In System > Enterprise Parameters, OAuth Access Token Expiry Timer (minutes) shows its default of 60 1 55. Suggested check: confirm that the refresh-token timer also still shows its default value.

Set custom values in the Unified CM enterprise parameters

Do

In System > Enterprise Parameters, set OAuth Access Token Expiry Timer (minutes) to a value from 1 to 1440 1 55. Set the refresh-token expiry timer, which is also a Unified CM enterprise parameter 55. We infer that a longer refresh-token lifetime means fewer sign-in prompts but a longer window in which a lost device keeps access, so revoking a leaver's refresh token with the revoke API matters more as the lifetime grows 26. Click Save 15.

Verify

Suggested check: re-open the enterprise parameters page and confirm both timers show the values you saved.

Rollback

Set the access-token timer back to 60 minutes and the refresh-token timer back to 60 days, the defaults 12 1.

Set the refresh-token lifetime from Control Hub (Cloud-Connected UC)

Do

Confirm the prerequisites: Cloud-Connected UC activated with on-premises devices communicating with Control Hub, Unified CM clusters at 11.5 or above, and Webex App 41.12 or later 5. In Control Hub, go to Services > Calling > Client Settings > Unified CM Settings and enter a value from 1 to 1825 days in Expiration timer for OAuth refresh token 7. Schedule the change, because it takes effect immediately and previously issued refresh tokens cease to be valid, forcing client applications that hold them to re-authenticate 6.

Verify

Check each cluster for a cluster-level value, because after the expiry is first set from Control Hub it can be changed at the individual cluster level, and the cluster-level setting always takes priority 4.

Rollback

Set Expiration timer for OAuth refresh token back to its default of 60 days 7. This change also takes effect immediately and invalidates previously issued refresh tokens 6.

Step 3 Decide on refresh-token auto-renewal (Release 15)

Keep Auto Renew Refresh Token enabled (the default)

Do

Leave the Auto Renew Refresh Token enterprise parameter enabled, which is its default from Release 15 3. From Release 15, for Webex clients only, Unified CM renews the refresh token automatically when renewal is enabled on Unified CM and the Webex client and the refresh token has reached 50 percent of its lifetime 54.

Verify

Suggested check: confirm the parameter reads Enabled on the enterprise parameters page.

Disable it so refresh tokens are not auto-extended

Do

Set Auto Renew Refresh Token to Disabled, after which Unified CM does not auto-extend refresh tokens 3. Click Save 15.

Verify

Suggested check: re-open the enterprise parameters page and confirm the parameter reads Disabled.

Rollback

Set Auto Renew Refresh Token back to Enabled, its default 3.

Step 4 Enable OAuth with Refresh Login Flow on Unified CM

Do

In Cisco Unified CM Administration, go to System > Enterprise Parameters, and in the SSO and OAuth Configuration section set OAuth with Refresh Login Flow to Enabled 37. In an IM and Presence centralized deployment, set it on each telephony cluster, which automatically enables the feature in the IM and Presence central cluster 21. Click Save; Cisco's generic enterprise-parameter procedure follows Save with Reset and OK to reset all devices 15. The 12.5(1) Configure Refresh Logins procedure ends by resetting all Cisco Jabber and Webex clients after the enterprise parameters are saved 47.

Verify

Suggested check: re-open the enterprise parameters page and confirm the parameter reads Enabled. Jabber detects the change at its configuration re-fetch interval 31.

Rollback

Set OAuth with Refresh Login Flow back to Disabled, its default 37 36. Disabling the feature after it has been enabled requires resetting all Cisco Jabber clients 13, and Jabber clears cached credentials and has the user sign out and sign in again 31.

Step 5 Bring IM and Presence in line

IM and Presence nodes are in the same cluster as Unified CM

Do

The Unified CM publisher replicates the OAuth keys to all Unified CM cluster nodes, including any local IM and Presence Service nodes 43.

Verify

Run show key authz signing and show key authz encryption on the IM and Presence nodes and compare the results with the Unified CM nodes 49.

IM and Presence central cluster serving remote telephony clusters

Do

Confirm that every remote telephony cluster runs at least 11.5(1)SU4, the minimum for OAuth Refresh Logins in an IM and Presence centralized deployment 22. The setting made on the telephony clusters automatically enables the feature in the IM and Presence central cluster 21.

Verify

On the central cluster, each remote telephony cluster that supports the feature shows Synchronized for OAuth Refresh Logins, and earlier clusters may show Unsynchronized 23.

Rollback

Suggested rollback: disable the parameter on each telephony cluster as described in the Step 4 rollback.

No IM and Presence Service

Do

Run show key authz signing and show key authz encryption on every Unified CM node and compare the results 49.

Verify

Suggested check: confirm the outputs are identical on every node.

Step 6 Enable refresh login on Unity Connection

Yes from Unity Connection

Do

In Cisco Unity Connection Administration, go to System Settings > Enterprise Parameters > SSO and OAuth Configuration and set OAuth with Refresh Login Flow to Enabled, because OAuth flow is disabled by default on Unity Connection 11. Go to System Settings > Authz Server > Add New and add the Unified CM publisher of the associated phone system; with Session Management Edition, each leaf-cluster publisher can be added 9. Enter a username and password that are the same as the Unified CM system administrator credentials 8. The Ignore Certificate Errors check box is an alternative to uploading valid Unified CM certificates to the Unity Connection Tomcat trust store 10.

Verify

Suggested check: confirm the server entry saves without a certificate or credential error. Suggested check: after Step 9, confirm that a pilot user's visual voicemail works.

Rollback

Suggested rollback: delete the server entry you added. Set OAuth with Refresh Login Flow on Unity Connection back to Disabled, its default 11.

No Unity Connection integration for these clients

Do

Expressway's OAuth token with refresh option requires OAuth with refresh on Unity Connection only where Unity Connection is used 17.

Verify

Suggested check: confirm that the clients in scope are not configured with any voicemail server that would need this change.

Step 7 Authorize MRA by OAuth token with refresh

Yes for some or all users

Do

On Unified CM, tick Enable Mobile and Remote Access in the User Profile (User Management > User Settings > User Profile) used by each Jabber user, because it is mandatory for Cisco Jabber users who use OAuth Refresh Logins over MRA 33. On Expressway-C, go to Configuration > Unified Communications > Configuration > MRA Access Control and set Authorize by OAuth token with refresh to On; Cisco recommends it for all deployments that can support it, and its default is On 19. This option requires OAuth with refresh to be enabled on the Unified CM clusters and, where it is used, on Unity Connection 17. Refresh the Unified CM nodes defined on the Expressway, which fetches the keys the Expressway needs to decrypt the tokens 20. We infer that enabling the Unified CM parameter before refreshing Expressway avoids MRA clients being validated against missing keys 27. Leave Check for internal authentication availability at its default of No, because Cisco warns that Yes can allow rogue inbound requests from unauthenticated remote clients 16. The separate Authorize by OAuth token option (previously SSO mode) requires authentication through the IdP, defaults to Off, and is available only with SAML SSO authentication paths 18.

Verify

Suggested check: in Step 9, confirm that an off-network client signs in remotely and stays signed in past the access-token lifetime.

Rollback

Set Authorize by OAuth token with refresh to Off on Expressway-C 19. Suggested rollback: then reverse Step 4 if the whole change is being backed out.

No and on-premises sign-in only

Do

The Enable Mobile and Remote Access check box in the User Profile is mandatory only for Cisco Jabber users who use OAuth Refresh Logins over MRA 33.

Verify

Suggested check: confirm that the clients in scope sign in only from inside the network.

Step 8 Get clients onto the new flow

Do

Tell users to expect one sign-out and sign-in, because when OAuth is enabled or disabled on any of the servers, Jabber detects it at its configuration re-fetch interval, clears cached credentials and has the user sign out and sign in again 31. Reset all Cisco Jabber and Webex clients, as the 12.5(1) Configure Refresh Logins procedure directs 47.

Verify

Suggested check: confirm each pilot user signs in once and is not prompted again afterwards. Where SSO is used, Cisco says it must be enabled for all services 35.

Step 9 Test

Do

With a pilot user, sign in and leave the client running past the access-token lifetime, since the client requests a new access token each time the current one reaches 75 percent of its lifespan 46. Change networks and confirm no sign-in prompt appears, which is the Fast Login behaviour the enabled parameter provides 14.

Verify

A Jabber log line reading Failed to get valid access token from refresh token, maybe server issue indicates that a refresh-token exchange failed 29. If failures appear, check the Unified CM Tomcat ssosp log4j directory, where SSO application logs are in ssoApp.log and certificate operations are in certMgmt logs 51, and re-run the show key authz signing and show key authz encryption comparison 49. Suggested check: repeat the test from outside the network for users who sign in remotely.

Step 10 Put a leaver-revocation procedure in place

Do

Add a call to https://<UCMaddress>:8443/ssosp/token/revoke?user_id=<end_user>, made with administrator credentials, to the leaver process; it revokes the user's current refresh token 48.

Verify

After revocation, the user cannot obtain new access tokens 48. Suggested check: revoke a test user's token and confirm the client is prompted to sign in once its current access token expires.

Rollback

Suggested rollback: have the test user sign in again to obtain a new refresh token.

Step 11 Regenerate OAuth keys only if they are compromised

Do

Cisco TAC states the OAuth signing and encryption keys should be regenerated only if the administrator believes they have been compromised 41. Cisco recommends regenerating during off-hours, because current access and refresh tokens that use those keys become invalid 42. Regenerate the encryption key from the CLI with set key regen authz encryption, confirmed by yes, since it can be regenerated only from the CLI 40. Regenerate the signing key with set key regen authz signing, or in Cisco Unified OS Administration at Security > Certificate Management by selecting the AUTHZ certificate and clicking Regenerate 44. The publisher replicates the new keys to all Unified CM cluster nodes, including any local IM and Presence Service nodes 43. Where Expressway is used, refresh the Unified CM nodes defined on it so it fetches the keys it needs to decrypt the tokens 20. Restart the Cisco XCP Authentication Service on all IM and Presence nodes so that Jabber OAuth login works 24.

Verify

Run show key authz signing and show key authz encryption on every Unified CM and IM and Presence node and compare the results 49. Expect every user to sign in again, because existing access and refresh tokens that used the old keys are invalid 42.

Applicability

Applies to: Cisco Unified Communications Manager, Cisco Jabber, Cisco Webex Control Hub, Cisco Unity Connection, Cisco Expressway, and Cisco Unified CM IM. Deployments: on-premises and hybrid. Sources checked 2026-10-02. Auto Renew Refresh Token is a Release 15 addition 3. Subscriber-node refresh-token updates apply from Unified CM 12.5(1)SU7 and 14SU3 onwards 52. The Control Hub refresh-token timer requires Cloud-Connected UC with on-premises devices communicating with Control Hub, Unified CM clusters at 11.5 or above, and Webex App 41.12 or later 5.

What remains uncertain

  • The allowed range for the Unified CM refresh-token expiry timer enterprise parameter, and how it differs by release, is not covered by the sources below.
  • The minimum Expressway version for given Jabber and Webex App releases is not covered by the sources below.
  • Whether changing the Unified CM refresh-token expiry enterprise parameter invalidates already-issued refresh tokens is not covered by the sources below.
  • Whether a full device reset, rather than only a client reset, is required after saving this parameter is not covered by the sources below.
  • The exact steps to bring a centralized IM and Presence cluster and Unity Connection in line after OAuth key regeneration are not covered by the sources below.

See also

Configures

  • Cisco unified cm — Cluster-wide enterprise parameter and token lifetimes on Unified CM.

Depends on

Related to

Referenced by

Sources

  1. 1
    The OAuth Access Token Expiry Timer (minutes) enterprise parameter accepts 1 to 1440 minutes and defaults to 60.
    System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins / OAuth parameter table, OAuth Access Token Expiry Timer (minutes) · Checked 2026-10-02
  2. 2
    The Jabber planning guide states that OAuth refresh tokens must be turned on across all deployed components (Unified CM, IM and Presence, Unity Connection, Expressway) for the feature to work.
    Planning Guide for Cisco Jabber 14.1 - User Management · User Management > OAuth · Checked 2026-10-02
  3. 3
    Release 15 adds the Auto Renew Refresh Token enterprise parameter, enabled by default; when it is disabled Unified CM does not auto-extend refresh tokens.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > Auto Renew Refresh Token · Checked 2026-10-02
  4. 4
    After the refresh-token expiry is first set from Control Hub it can be changed again at the individual cluster level, and the cluster-level setting always takes priority.
    Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Set Expiration Timer for OAuth Refresh Token · Checked 2026-10-02
  5. 5
    The Control Hub article's prerequisites are Cloud-Connected UC activated with on-premises devices communicating with Control Hub, Unified CM clusters at 11.5 or above, and Webex App 41.12 or later.
  6. 6
    Changing the Control Hub refresh-token expiry takes effect immediately, and previously issued refresh tokens cease to be valid, forcing client applications that hold them to re-authenticate.
    Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Set Expiration Timer for OAuth Refresh Token · Checked 2026-10-02
  7. 7
    In Control Hub, Services > Calling > Client Settings > Unified CM Settings has an Expiration timer for OAuth refresh token field accepting 1 to 1825 days, default 60.
    Auto-Provisioning of Webex App for Calling in Webex (Unified CM) · Set Expiration Timer for OAuth Refresh Token · Checked 2026-10-02
  8. 8
    The username and password entered for a Unity Connection Authz server must be the same as the Unified CM system administrator credentials.
    System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server · Checked 2026-10-02
  9. 9
    Unity Connection uses the Unified CM publisher of the associated phone system as its Authz server, configured at System Settings > Authz Server > Add New; with Session Management Edition each leaf-cluster publisher can be added.
    System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server · Checked 2026-10-02
  10. 10
    The Unity Connection Authz server page has an Ignore Certificate Errors check box as an alternative to uploading valid Unified CM certificates to the Unity Connection Tomcat trust store.
    System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server, Ignore Certificate Errors field · Checked 2026-10-02
  11. 11
    OAuth flow is disabled by default on Unity Connection and is enabled in Cisco Unity Connection Administration at System Settings > Enterprise Parameters > SSO and OAuth Configuration by setting OAuth with Refresh Login Flow to Enabled.
    System Administration Guide for Cisco Unity Connection Release 15 - System Settings · System Settings > Authz Server, prerequisites · Checked 2026-10-02
  12. 12
    With OAuth Refresh Logins the default access-token lifespan is 60 minutes and the default refresh-token life is 60 days.
  13. 13
    Cisco warns that once OAuth Refresh Logins are enabled, disabling the feature requires resetting all Cisco Jabber clients.
    System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins, Note under OAuth with Refresh Login Flow · Checked 2026-10-02
  14. 14
    When OAuth with Refresh Login Flow is Enabled, clients such as Cisco Jabber can use an OAuth-based Fast Login flow that does not require the user to sign in again, for example after a network change.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Enabled bullet · Checked 2026-10-02
  15. 15
    Cisco's generic enterprise-parameter procedure is to edit the value, click Save, then click Reset and OK to reset all devices.
  16. 16
    Expressway's Check for internal authentication availability setting defaults to No, and Cisco warns that Yes can allow rogue inbound requests from unauthenticated remote clients.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Check for internal authentication availability · Checked 2026-10-02
  17. 17
    Expressway's OAuth token with refresh option requires OAuth with refresh to be enabled on the Unified CM clusters and, where it is used, on Unity Connection.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh, requirements · Checked 2026-10-02
  18. 18
    Expressway's separate Authorize by OAuth token option (previously SSO mode) requires authentication through the IdP, defaults to Off, and is available only with SAML SSO authentication paths.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token (previously SSO mode) · Checked 2026-10-02
  19. 19
    On Expressway-C, Authorize by OAuth token with refresh is set under Configuration > Unified Communications > Configuration > MRA Access Control; Cisco recommends it for all deployments that can support it and its default is On.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh · Checked 2026-10-02
  20. 20
    After enabling OAuth token with refresh, the Unified CM nodes defined on the Expressway must be refreshed, which fetches the keys the Expressway needs to decrypt the tokens.
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh · Checked 2026-10-02
  21. 21
    In an IM and Presence centralized deployment, OAuth with Refresh Login Flow is set on the telephony cluster, and that setting automatically enables the feature in the IM and Presence central cluster.
    Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment · Configure Centralized Deployment > Configure OAuth Refresh Logins · Checked 2026-10-02
  22. 22
    In an IM and Presence centralized deployment, the remote Unified CM telephony cluster must run at least 11.5(1)SU4 to support OAuth Refresh Logins.
    Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment · Configure Centralized Deployment > Configure OAuth Refresh Logins · Checked 2026-10-02
  23. 23
    In an IM and Presence centralized deployment, a remote Unified CM telephony cluster's status shows Synchronized for OAuth Refresh Logins when it supports the feature, and earlier clusters may show Unsynchronized.
    Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment · Configure Centralized Deployment > remote telephony cluster status · Checked 2026-10-02
  24. 24
    When OAuth keys are regenerated, the Cisco XCP Authentication Service must be restarted on all IM and Presence nodes for Jabber OAuth login to work.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework, Note on key regeneration · Checked 2026-10-02
  25. 25
    For backward compatibility, older Jabber clients and supporting applications such as Cisco Unified RTMT can still authenticate with the implicit grant flow, which is enabled by default.
  26. 26
    A longer refresh-token lifetime means fewer sign-in prompts but a longer window in which a lost device keeps access, so revoking a leaver's refresh token with the revoke API matters more as the lifetime grows.inferred
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework, token lifetimes and revoke API · Checked 2026-10-02
  27. 27
    Because Expressway fetches the Unified CM token keys only when its Unified CM nodes are refreshed and requires OAuth with refresh on Unified CM, enabling the Unified CM parameter before refreshing Expressway avoids MRA clients being validated against missing keys.inferred
    Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration · MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh · Checked 2026-10-02
  28. 28
    Because Cisco documents different upper bounds for the refresh-token expiry (90 days for 12.0, 365 days for 12.5(1), 1825 days in Control Hub) and the Release 15 parameter text read here does not state one, the allowed range on a given cluster should be read from that cluster's own parameter help before choosing a value.inferred
    System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · OAuth parameter table, compared with cisco-technote-212794-oauth-code-grant and webex-help-ki34wo-auto-provisioning-ucm · Checked 2026-10-02
  29. 29
    A Jabber log line reading Failed to get valid access token from refresh token, maybe server issue indicates that a refresh-token exchange failed.
  30. 30
    OAuth Refresh Logins for Cisco Jabber require Jabber Release 11.9 or later.
  31. 31
    When OAuth is enabled or disabled on any of the servers, Jabber detects it at its configuration re-fetch interval, clears cached credentials and has the user sign out and sign in again.
    Planning Guide for Cisco Jabber 14.1 - User Management · User Management > OAuth · Checked 2026-10-02
  32. 32
    For Mobile and Remote Access deployments with Cisco Jabber, Cisco recommends enabling OAuth with Refresh Login Flow only with an Expressway version that supports it, warning that an incompatible version may impact Jabber functionality.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Note · Checked 2026-10-02
  33. 33
    The Enable Mobile and Remote Access check box in the Unified CM User Profile (User Management > User Settings > User Profile) is mandatory for Cisco Jabber users who use OAuth Refresh Logins over MRA; non-Jabber users do not need it.
    Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Mobile and Remote Access · Configure Mobile and Remote Access Access Policy for Cisco Jabber Users, step 7 note · Checked 2026-10-02
  34. 34
    Cisco states that enabling OAuth with Refresh Login Flow requires support from other Unified Communications components such as Expressway and Unity Connection, running compatible versions with the refresh login flow enabled.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Enabled bullet · Checked 2026-10-02
  35. 35
    Cisco Jabber OAuth can be set up with or without SSO; if SSO is used, Cisco says it must be enabled for all services.
    Planning Guide for Cisco Jabber 14.1 - User Management · User Management > OAuth · Checked 2026-10-02
  36. 36
    The OAuth with Refresh Login Flow enterprise parameter defaults to Disabled.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow · Checked 2026-10-02
  37. 37
    The OAuth with Refresh Login Flow enterprise parameter is set in Cisco Unified CM Administration at System > Enterprise Parameters, in the SSO and OAuth Configuration section.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow · Checked 2026-10-02
  38. 38
    The 12.0 TAC tech note gives the refresh-token expiry range as 1 to 90 days with a default of 60 days.
  39. 39
    In the Release 12.5(1) documentation, the OAuth Refresh Token Expiry Timer (days) enterprise parameter accepts 1 to 365 days and defaults to 60; after it expires the refresh token is invalid and the client must re-authenticate.
    System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber · Configure Refresh Logins / OAuth parameter table, OAuth Refresh Token Expiry Timer (days) · Checked 2026-10-02
  40. 40
    The OAuth encryption key can be regenerated only from the CLI, with set key regen authz encryption confirmed by yes.
  41. 41
    Cisco TAC states the OAuth signing and encryption keys should be regenerated only if the administrator believes they have been compromised.
  42. 42
    After the OAuth keys are regenerated, current access and refresh tokens that use those keys become invalid, and Cisco recommends doing it during off-hours.
  43. 43
    The Unified CM publisher regenerates the OAuth keys and replicates them to all Unified CM cluster nodes, including any local IM and Presence Service nodes.
  44. 44
    The OAuth signing key can be regenerated with the CLI command set key regen authz signing, or in Cisco Unified OS Administration at Security > Certificate Management by selecting the AUTHZ certificate and clicking Regenerate.
  45. 45
    After regenerating OAuth keys, the new keys must also be regenerated and synced on an IM and Presence central cluster and on Cisco Expressway or Cisco Unity Connection.
    Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates · Regenerate Keys for OAuth Refresh Logins, list of UC clusters · Checked 2026-10-02
  46. 46
    Each time an OAuth access token reaches 75 percent of its lifespan, the client application requests a new access token from Unified CM.
  47. 47
    The 12.5(1) Configure Refresh Logins procedure ends by resetting all Cisco Jabber and Webex clients after the enterprise parameters are saved.
  48. 48
    Unified CM exposes a REST endpoint, https://<UCMaddress>:8443/ssosp/token/revoke?user_id=<end_user>, called with administrator credentials, that revokes a user's current refresh token so the user cannot obtain new access tokens.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework > revoke refresh tokens · Checked 2026-10-02
  49. 49
    Cisco TAC verifies OAuth key consistency by running show key authz signing and show key authz encryption on every Unified CM and IM and Presence node and comparing the results.
  50. 50
    SIP OAuth Mode, supported for Cisco Jabber from Unified CM 12.5 onwards, includes setting OAuth with Refresh Login Flow to Enabled as part of its configuration.
  51. 51
    OAuth and SSO operations on Unified CM are logged under the Tomcat ssosp log4j directory, with SSO application logs in ssoApp.log and certificate operations in certMgmt logs.
  52. 52
    From Unified CM 12.5(1)SU7 and 14SU3 onwards, subscriber nodes as well as the publisher can update the refresh token in the requesting node's database, and the change replicates across the cluster.
    System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services · Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Important · Checked 2026-10-02
  53. 53
    Unified CM OAuth access tokens are encrypted, signed and self-contained JWTs (RFC 7519), while refresh tokens are signed but not encrypted.
  54. 54
    From Release 15, for Webex clients only, Unified CM renews the refresh token automatically when renewal is enabled on Unified CM and the Webex client and the refresh token has reached 50 percent of its lifetime.
    Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management · Identity Management > OAuth Framework, refresh token renewal paragraph · Checked 2026-10-02
  55. 55
    Jabber OAuth with refresh tokens requires Unified CM 11.5(SU3) or 12.0 and later, and the access and refresh token expiry timers are Unified CM enterprise parameters.
    Planning Guide for Cisco Jabber 14.0 - User Management · User Management > OAuth · Checked 2026-09-25
  56. 56
    SAML SSO is configured at System > SAML Single Sign On in Cisco Unified CM Administration, and the Cisco Tomcat service must be restarted both before and after SSO is enabled.
  57. 57
    Version 15 is the latest Cisco Unified Communications Manager major release listed on Cisco's support pages; it was released on 16 October 2023 and its status is Available.
    Cisco Unified Communications Manager (CallManager) - Support · Product status and Latest release fields; Supported versions list · Checked 2026-09-30
  58. 58
    Cisco Unified CM Version 12.5 reached end of support on 31 August 2025.
    Cisco Unified Communications Manager (CallManager) - Support · Supported versions list, Version 12.5 entry (End-of-Support Date) · Checked 2026-09-30
  59. 59
    The end of software maintenance releases for Unified CM Version 14 was 7 April 2026.
  60. 60
    As of 2026-09-30, the newest Unified CM build with published ReadMe and release notes is 15SU4a, and Version 14 has passed its end of software maintenance, so new deployments and upgrades would normally target 15SU4a or later.inferred
    ReadMe for Cisco Unified Communications Manager Release 15SU4a · Document header (Last Updated July 29 2026); combined with cisco-eol-v14-onprem-calling-apps Table 1 · Checked 2026-09-30
  61. 61
    In standard deployments, Unified CM and the IM and Presence Service must run supported, matching versions; a version mismatch is not supported.

Documents

tier 2 current vendor documentation

Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates

Cisco Systems · 2026-08-31 · accessed 2026-09-25

tier 2 current vendor documentation

Auto-Provisioning of Webex App for Calling in Webex (Unified CM)

Cisco · 2025-10-29 · accessed 2026-09-30

tier 2 current vendor documentation

Cisco Unified Communications Manager (CallManager) - Support

Cisco Systems · accessed 2026-09-30

tier 2 current vendor documentation

Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment

Cisco Systems · 2026-01-07 · accessed 2026-10-02

tier 2 current vendor documentation

Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0

Cisco Systems · 2022-03-18 · accessed 2026-10-02

tier 2 current vendor documentation

Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Mobile and Remote Access

Cisco Systems · 2026-09-16 · accessed 2026-10-02

tier 2 current vendor documentation

Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - SIP OAuth Mode

Cisco Systems · 2026-10-02 · accessed 2026-10-02

tier 2 current vendor documentation

Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration

Cisco Systems · 2024-01-07 · accessed 2026-10-02

tier 2 current vendor documentation

Planning Guide for Cisco Jabber 14.0 - User Management

Cisco · accessed 2026-09-25

tier 2 current vendor documentation

Planning Guide for Cisco Jabber 14.1 - User Management

Cisco Systems · 2024-04-02 · accessed 2026-10-02

tier 2 current vendor documentation

ReadMe for Cisco Unified Communications Manager Release 15SU4a

Cisco Systems · 2026-07-29 · accessed 2026-09-30

tier 2 current vendor documentation

Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management

Cisco Systems · 2026-09-22 · accessed 2026-10-02

tier 2 current vendor documentation

System Administration Guide for Cisco Unity Connection Release 15 - System Settings

Cisco Systems · 2025-12-12 · accessed 2026-10-02

tier 2 current vendor documentation

System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber

Cisco Systems · 2026-10-02 · accessed 2026-10-02

Cite this page

APA

WarmTransfer. (2026, October 2). Enabling OAuth refresh-token login for Jabber and Webex App in Unified CM. WarmTransfer. https://warmtransfer.net/guides/cucm-oauth-refresh-login-setup

BibTeX

@misc{warmtransfer-cucm-oauth-refresh-login-setup,
  title  = {Enabling OAuth refresh-token login for Jabber and Webex App in Unified CM},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/guides/cucm-oauth-refresh-login-setup},
  note   = {Verified 2026-10-02}
}