Zoom CC API - 403 Forbidden on Queue Member Update via n8n

The PATCH /v2/contact_center/queues/{queueId}/members endpoint is throwing a 403 Forbidden when trying to update member roles through an n8n HTTP Request node. It’s weird because the same clientId and clientSecret work fine for GET requests on the same resource.

Environment is n8n v1.22.1 self-hosted on Docker. The OAuth2 credential is valid and the scope contact_center:write:admin is assigned. Logic flow is simple: a trigger hits the HTTP Request node, it pulls the memberId from the JSON body, and attempts the update.

The response body is consistently:
{"status": "failure", "code": "forbidden", "message": "Insufficient permissions to perform this action"}

Tried rotating the accessToken and verified the queueId variable isn’t null. The request headers are standard. Not 100% sure but it feels like a scope mismatch despite the admin flag.

{
 "member": {
 "role": "manager"
 }
}
2 Likes

The 403 error usually means the OAuth app doesn’t have the right scope for the write action. Since GET works, the credentials are fine. But PATCH needs different permissions in the Zoom App Marketplace.

Check the scopes for the app. You need contact_center:queue_member:write or similar. If the scope is missing, the API will block the request even if the user role is an admin.

In n8n, the HTTP Request node sometimes sends the wrong content-type. Try forcing it to application/json. Here is how the body should look for a member update:

{
 "role": "supervisor",
 "status": "active"
}

I tried something like this in a connector and it failed until I fixed the scope. Also, check if the queueId is correct. If it’s a wrong ID, sometimes the error is confusing.

The log I have is a bit cut off, but it looks like this:
{"code": 403, "message": "Forbidden", "details": "Insufficient...

If the scope is already there, try to refresh the OAuth token. Sometimes the old token doesn’t have the new permissions.

Confirmed contact_center:write:admin is enabled in the Marketplace. The access_token is definitely current, but the 403 Forbidden persists specifically on the PATCH method while GET returns 200 OK.

1 Like