# Unable to issue access tokens for existing users

**URL:** <https://community.sendbird.com/t/unable-to-issue-access-tokens-for-existing-users/420>\
**Category:** Sendbird Chat API/SDK\
**Tags:** chatsdk\
**Created:** [June 13, 2020, 6:12pm UTC](https://community.sendbird.com/t/unable-to-issue-access-tokens-for-existing-users/420 "2020-06-13T18:12:01Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Derek\_Quessenberry](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/derek_quessenberry/32/240_2.png) [@Derek\_Quessenberry](https://community.sendbird.com/u/Derek_Quessenberry)\
**Post date:** [June 13, 2020, 6:12pm UTC](https://community.sendbird.com/t/unable-to-issue-access-tokens-for-existing-users/420/1 "2020-06-13T18:12:01Z")

</div>

I have the SendBird Chat installed and working with my ReactNative app for months now. I am attempting to install and use SendBird Calls. Even though SB Chat supports authentication with only a user id (via `connect` method), apparently the SB Calls requires an access token. At this point I already have several users of my app, thus several users with SB accounts. None of those users have ever been issued an SB access token because up until this point I didn’t need to issue one. When I attempt to issue an access token for an existing user, via instructions found [here](https://docs.sendbird.com/platform/user#3_update_a_user), I am always getting a 400 server error, particularly a 400401 INVALID\_API\_TOKEN error. How can I issue a token for an existing user that never had a token issued if I am required to pass a token to issue a token? What am I missing here?

react-native: v0.62.2  
sendbird: v3.0.108  
sendbird-calls: v1.1.1

---

<div class="post-metadata">

**Author:** ![alex.orr](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/alex.orr/32/148_2.png) [@alex.orr](https://community.sendbird.com/u/alex.orr)\
**Post date:** [June 15, 2020, 9:56pm UTC](https://community.sendbird.com/t/unable-to-issue-access-tokens-for-existing-users/420/2 "2020-06-15T21:56:54Z")

</div>

That error likely means you don’t have the application level API token in the header when trying to issue an access token for a user. This API token can be your master API token or a secondary API token, but either way this is an application level token and not specific to any particular user. More information about the headers required to make a platform API call can be found [here](https://docs.sendbird.com/platform/quick_start#3_headers).

You can issue an access token for a user as seen [here](https://docs.sendbird.com/platform/user#3_update_a_user) or you can issue a token through the Sendbird Dashboard as seen in the attached screenshot.

 ![Screen Shot 2020-06-15 at 2.55.16 PM](https://us1.discourse-cdn.com/flex020/uploads/sendbird/original/1X/90b53ffc3fa2eb172ffcc02c98799174eb4aea8c.png)

---

<div class="post-metadata">

**Author:** ![fullStackChris](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/fullstackchris/32/1594_2.png) [@fullStackChris](https://community.sendbird.com/u/fullStackChris)\
**Post date:** [January 19, 2022, 5:23pm UTC](https://community.sendbird.com/t/unable-to-issue-access-tokens-for-existing-users/420/3 "2022-01-19T17:23:23Z")

</div>

This means that this type of action shouldn’t be done from clients (i.e. a mobile or web app), correct? Is there any way a logged in user on a client can authenticate themselves?

---

<div class="post-metadata">

**Author:** ![Tyler](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/tyler/32/810_2.png) [@Tyler](https://community.sendbird.com/u/Tyler)\
**Post date:** [January 19, 2022, 9:11pm UTC](https://community.sendbird.com/t/unable-to-issue-access-tokens-for-existing-users/420/4 "2022-01-19T21:11:19Z")

</div>

Hi @fullStackChris, from the SDK there is no way to the user to authenticate themselves. You would need to provide them with the Session Token or Access Token necessary for them to connect.

---

<div class="post-metadata">

**Author:** ![fullStackChris](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/fullstackchris/32/1594_2.png) [@fullStackChris](https://community.sendbird.com/u/fullStackChris)\
**Post date:** [January 19, 2022, 11:02pm UTC](https://community.sendbird.com/t/unable-to-issue-access-tokens-for-existing-users/420/5 "2022-01-19T23:02:35Z")

</div>

Alright, makes sense… I guess what I originally should have asked is if it is possible to get a user’s avatar / profile picture URL without any sort of authentication - that’s the use case I need. Is there a public endpoint somewhere to get that (given I have their Sendbird ID) or will I have to do it via an admin account from our server? If the question and/or answer is too complicated, I’m happy to open a new thread.

---

<div class="post-metadata">

**Author:** ![Tyler](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/tyler/32/810_2.png) [@Tyler](https://community.sendbird.com/u/Tyler)\
**Post date:** [January 19, 2022, 11:15pm UTC](https://community.sendbird.com/t/unable-to-issue-access-tokens-for-existing-users/420/6 "2022-01-19T23:15:26Z")

</div>

There is no unauthenticated API call that you can make to obtain a users profile\_url. You would either nee to connect the user to the SDK, or you would need to call a get request to the `/v3/users/{user_id}` endpoint ([User | Chat Platform API | Sendbird Docs](https://sendbird.com/docs/chat/v3/platform-api/guides/user#2-view-a-user)). Having a public URL that does not require any authentication to access could be considered a privacy issue.

---

<div class="post-metadata">

**Author:** ![fullStackChris](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/fullstackchris/32/1594_2.png) [@fullStackChris](https://community.sendbird.com/u/fullStackChris)\
**Post date:** [January 20, 2022, 7:21am UTC](https://community.sendbird.com/t/unable-to-issue-access-tokens-for-existing-users/420/7 "2022-01-20T07:21:59Z")

</div>

Sounds good. One final question then: does the profile picture URL also change when a user changes their profile picture? Or is the URL preserved and only the file replaced (assuming they have the same sendbird ID the whole time)

---

<div class="post-metadata">

**Author:** ![Tyler](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/tyler/32/810_2.png) [@Tyler](https://community.sendbird.com/u/Tyler)\
**Post date:** [January 20, 2022, 4:50pm UTC](https://community.sendbird.com/t/unable-to-issue-access-tokens-for-existing-users/420/8 "2022-01-20T16:50:21Z")

</div>

The `profile_url` will update each time the image is updated as it correlates to a specific resource in AWS. The url is not static.

---

<div class="post-metadata">

**Author:** ![fullStackChris](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/fullstackchris/32/1594_2.png) [@fullStackChris](https://community.sendbird.com/u/fullStackChris)\
**Post date:** [January 20, 2022, 6:09pm UTC](https://community.sendbird.com/t/unable-to-issue-access-tokens-for-existing-users/420/9 "2022-01-20T18:09:26Z")

</div>

Hmmm ok… do the older one(s) get invalidated after some time, or would they still work? 🙂
