documentation /api provider

Zoom Three-Legged

API provider

Three-legged Zoom OAuth 2.0. Each end-user logs in with their Zoom account; the app acts on their behalf with the scopes they grant. Use these settings: authorizationUrl = https://api.zoom.us/oauth/authorize, tokenUrl = https://api.zoom.us/oauth/token.

  • API category: Zoom
  • Needs login: Yes, three-legged: each end-user must complete an OAuth-style login flow

Configuration parameters

Required

  • title : string; required
    Human-readable label for this OAuth provider (shown to end-users during login).
  • authorizationUrl : string; required
    Provider’s OAuth2 authorization endpoint URL (where users are redirected to log in). $ENV_VAR references anywhere in the value are resolved from the app’s environment at request time.
  • tokenUrl : string; required
    Provider’s OAuth2 token endpoint URL (where authorization codes are exchanged for access tokens). $ENV_VAR references anywhere in the value are resolved from the app’s environment at request time.
  • clientId : string; required
    OAuth client ID issued by the provider when the app was registered. Use $ENV_VAR (the whole value) to load it from an environment variable.
  • clientSecret : string; required
    OAuth client secret issued by the provider when the app was registered. Use $ENV_VAR (the whole value) to load it from an environment variable.
  • webhook_token : string; required
    Verification token for incoming Zoom event webhooks (from the Feature > Event Subscriptions page of the Zoom app).

Optional

  • bonusAccessArgs : string; optional
    Extra query-string arguments appended to the authorization URL (e.g. &access_type=offline&prompt=consent for Google refresh tokens).
  • hosted_domain : string; optional
    If set, restricts logins to accounts in this domain (e.g. for Google Workspace SSO). Where the app also accepts bearer tokens, it restricts those callers too, matched against the token’s hd claim.
  • defaultExpiration : string; optional
    Token expiration in seconds, used as a fallback when the provider does not return one (e.g. 1800 for Salesforce and QuickBooks).
  • nameForScopeParameter : string; optional
    Override the scope-parameter name in the authorization URL (some providers use scopes instead of scope).
  • tokenMetadata : string; optional
    Provider-specific metadata appended to access tokens, carrying an instance/tenant identifier where the integration needs one (the instance id for Salesforce and ServiceNow, the company Realm ID for QuickBooks). Leave blank for providers that do not need it.
  • resource : string; optional
    RFC 8707 resource indicator: the URL of the resource these tokens are for, such as an MCP server’s endpoint. Sent on the authorization request, the code exchange and the refresh grant, so the provider can issue a token audienced to that resource alone. Leave blank unless the provider asks for it; this names a resource this app calls, never an endpoint this app serves.
  • disablePkce : true/false; optional
    Set to true to turn off PKCE (RFC 7636) for this connection, which is otherwise always on. Only for an authorization server that rejects the code_challenge parameter instead of ignoring it, as RFC 6749 requires of parameters it does not recognize; turning PKCE off gives up the protection against a stolen authorization code, so leave this unset unless logins fail without it.

What components can use this API

Concepts:

Ingredients: