# Authentication

**URL:** https://devforum.zoom.us/c/api-and-webhooks/authentication/48.md

[Latest](https://devforum.zoom.us/latest.md) · [Categories](https://devforum.zoom.us/categories.md) · [Tags](https://devforum.zoom.us/tags.md)

---

## [About the Authentication category](https://devforum.zoom.us/t/about-the-authentication-category/64914)

<div class="topic-metadata">

**Author:** [@michael.zoom](https://devforum.zoom.us/u/michael.zoom)\
**Replies:** 0\
**Last updated:** [February 25, 2022, 10:12pm UTC](https://devforum.zoom.us/t/about-the-authentication-category/64914 "2022-02-25T22:12:10Z")

</div>

This category discusses OAuth and other authentication methods used for Zoom APIs and SDKs.

---

## [Domain validation is asking me to verify zoom.us for my app "Bosla Coach". I do not own zoom.us. The only domain I own and operate is boslacoach.com, which I can verify by TXT record. My app is added from my own site, and I have no zoom.us URL in my app c](https://devforum.zoom.us/t/domain-validation-is-asking-me-to-verify-zoom-us-for-my-app-bosla-coach-i-do-not-own-zoom-us-the-only-domain-i-own-and-operate-is-boslacoach-com-which-i-can-verify-by-txt-record-my-app-is-added-from-my-own-site-and-i-have-no-zoom-us-url-in-my-app-c/146714)

<div class="topic-metadata">

**Author:** [@Bassem](https://devforum.zoom.us/u/Bassem)\
**Replies:** 0\
**Last updated:** [September 24, 2026, 2:43am UTC](https://devforum.zoom.us/t/domain-validation-is-asking-me-to-verify-zoom-us-for-my-app-bosla-coach-i-do-not-own-zoom-us-the-only-domain-i-own-and-operate-is-boslacoach-com-which-i-can-verify-by-txt-record-my-app-is-added-from-my-own-site-and-i-have-no-zoom-us-url-in-my-app-c/146714 "2026-09-24T02:43:35Z")

</div>

Domain validation is asking me to verify zoom.us for my app “Bosla Coach”. I do not own zoom.us. The only domain I own and operate is boslacoach.com, which I can verify by TXT record. My app is added from my own site, a…

---

## [Configuration of Zoom / Slack MCP authentication](https://devforum.zoom.us/t/configuration-of-zoom-slack-mcp-authentication/146182)

<div class="topic-metadata">

**Author:** [@Jordan12](https://devforum.zoom.us/u/Jordan12)\
**Replies:** 1\
**Last updated:** [September 8, 2026, 5:54am UTC](https://devforum.zoom.us/t/configuration-of-zoom-slack-mcp-authentication/146182 "2026-09-08T05:54:11Z")

</div>

We have installed the standard official Zoom app in Slack to use the MCP integration with Slackbot (for pulling in meeting recaps, etc). A fresh install works for a little bit and then starts to give token refresh error…

---

## [Server-to-Server OAuth: Activated app returns 400 / invalid\_client although credentials are verified](https://devforum.zoom.us/t/server-to-server-oauth-activated-app-returns-400-invalid-client-although-credentials-are-verified/146092)

<div class="topic-metadata">

**Author:** [@Katarina1](https://devforum.zoom.us/u/Katarina1)\
**Replies:** 2\
**Last updated:** [September 1, 2026, 5:35pm UTC](https://devforum.zoom.us/t/server-to-server-oauth-activated-app-returns-400-invalid-client-although-credentials-are-verified/146092 "2026-09-01T17:35:48Z")

</div>

Hello Zoom Developer Support, I am currently setting up a private integration using a Zoom Server-to-Server OAuth app to register participants for Zoom meetings via API. Unfortunately, I am unable to obtain an access to…

---

## [Restrict meeting participants by source IP range - native client, external participants](https://devforum.zoom.us/t/restrict-meeting-participants-by-source-ip-range-native-client-external-participants/146033)

<div class="topic-metadata">

**Author:** [@pradeepkumarteel](https://devforum.zoom.us/u/pradeepkumarteel)\
**Replies:** 0\
**Last updated:** [August 30, 2026, 4:03pm UTC](https://devforum.zoom.us/t/restrict-meeting-participants-by-source-ip-range-native-client-external-participants/146033 "2026-08-30T16:03:16Z")

</div>

We run sessions for external participants (no accounts on our Zoom account) who attend from physical centres with known allowed public IP ranges. Compliance requires participants to only join from those IP ranges. We m…

---

## [Add Scopes to Legacy OAuth App](https://devforum.zoom.us/t/add-scopes-to-legacy-oauth-app/145070)

<div class="topic-metadata">

**Author:** [@amp23](https://devforum.zoom.us/u/amp23)\
**Replies:** 5\
**Last updated:** [August 19, 2026, 5:01pm UTC](https://devforum.zoom.us/t/add-scopes-to-legacy-oauth-app/145070 "2026-08-19T17:01:15Z")

</div>

API Endpoint(s) and/or Zoom API Event(s) Zoom OAuth Scopes Description We have an existing legacy OAuth app and would like to add additional scopes. While reviewing the documentation, we saw that existing customers wo…

---

## [Invalid redirect: http://localhost:3000/api/zoom/callback (4,700)](https://devforum.zoom.us/t/invalid-redirect-http-localhost-3000-api-zoom-callback-4-700/144664)

<div class="topic-metadata">

**Author:** [@Srinip](https://devforum.zoom.us/u/Srinip)\
**Replies:** 3\
**Last updated:** [August 19, 2026, 6:48am UTC](https://devforum.zoom.us/t/invalid-redirect-http-localhost-3000-api-zoom-callback-4-700/144664 "2026-08-19T06:48:34Z")

</div>

I have created a general app (General app 600) and completed the steps and made it localready. I have generated the below URL, which should take me to the login screen so that the user can authorize the app and receive …

---

## [Zoom Phone API: no working method to assign an existing device to a phone user (PATCH /phone/devices/{deviceId})](https://devforum.zoom.us/t/zoom-phone-api-no-working-method-to-assign-an-existing-device-to-a-phone-user-patch-phone-devices-deviceid/145499)

<div class="topic-metadata">

**Author:** [@kmarcy](https://devforum.zoom.us/u/kmarcy)\
**Replies:** 0\
**Last updated:** [August 12, 2026, 2:27am UTC](https://devforum.zoom.us/t/zoom-phone-api-no-working-method-to-assign-an-existing-device-to-a-phone-user-patch-phone-devices-deviceid/145499 "2026-08-12T02:27:55Z")

</div>

We’re a K-12 school district managing 1,000+ Zoom Phone devices and need to assign existing desk phone devices to phone users via the API for bulk/automated workflows. What we’re trying to do: Assign an already-created …

---

## [Security and user-level access limitations for Server-to-Server OAuth apps](https://devforum.zoom.us/t/security-and-user-level-access-limitations-for-server-to-server-oauth-apps/145462)

<div class="topic-metadata">

**Author:** [@Christian7](https://devforum.zoom.us/u/Christian7)\
**Replies:** 0\
**Last updated:** [August 10, 2026, 7:45pm UTC](https://devforum.zoom.us/t/security-and-user-level-access-limitations-for-server-to-server-oauth-apps/145462 "2026-08-10T19:45:21Z")

</div>

API Endpoint(s) and/or Zoom API Event(s) GET /scheduler/events GET /meetings/{meetingId} GET /past\_meetings/{meetingId} Description We are building an internal automation solution that uses Azure Functions to intera…

---

## [I'm unable to fetch email id of participants in zoom  meeting](https://devforum.zoom.us/t/im-unable-to-fetch-email-id-of-participants-in-zoom-meeting/145117)

<div class="topic-metadata">

**Author:** [@subhashini1](https://devforum.zoom.us/u/subhashini1)\
**Replies:** 0\
**Last updated:** [July 29, 2026, 5:12am UTC](https://devforum.zoom.us/t/im-unable-to-fetch-email-id-of-participants-in-zoom-meeting/145117 "2026-07-29T05:12:52Z")

</div>

I need to fetch email address of the meeting participants to implement a logic in my business. Can anyone have the idea about that

---

## [Requesting a manual domain bypass for supabase.co](https://devforum.zoom.us/t/requesting-a-manual-domain-bypass-for-supabase-co/144837)

<div class="topic-metadata">

**Author:** [@Linda6](https://devforum.zoom.us/u/Linda6)\
**Replies:** 0\
**Last updated:** [July 17, 2026, 6:15pm UTC](https://devforum.zoom.us/t/requesting-a-manual-domain-bypass-for-supabase-co/144837 "2026-07-17T18:15:51Z")

</div>

Hello Zoom Marketplace Team, I am requesting manual domain verification or bypass for a Supabase OAuth callback URL used by our production Zoom OAuth app. Our primary application domain is verified: globalcfoclientpor…

---

## [Zoom API Invalid Access Token Behavior Change](https://devforum.zoom.us/t/zoom-api-invalid-access-token-behavior-change/114327)

<div class="topic-metadata">

**Author:** [@reese](https://devforum.zoom.us/u/reese)\
**Replies:** 3\
**Last updated:** [July 2, 2026, 10:57am UTC](https://devforum.zoom.us/t/zoom-api-invalid-access-token-behavior-change/114327 "2026-07-02T10:57:33Z")

</div>

API Endpoint(s) and/or Zoom API Event(s) /v2/contact\_center/users Description Starting July 19, 2024, we have noticed a change in the way this endpoint responds when an invalid token (i.e. expired) is used. Our Zoom…

---

## [Zoom API – Is per-user scoped access to recordings possible?](https://devforum.zoom.us/t/zoom-api-is-per-user-scoped-access-to-recordings-possible/143898)

<div class="topic-metadata">

**Author:** [@SamDevForum](https://devforum.zoom.us/u/SamDevForum)\
**Replies:** 0\
**Last updated:** [May 28, 2026, 9:25am UTC](https://devforum.zoom.us/t/zoom-api-is-per-user-scoped-access-to-recordings-possible/143898 "2026-05-28T09:25:58Z")

</div>

Hi all, We are exploring using the Zoom API for integrations/workflows involving user recordings in our org. Current issue From what we’ve seen: Zoom roles define permissions Groups are used for scoping When p…

---

## [Where to enter redirect URL / whitelist URL for Server-to-Server OAuth app?](https://devforum.zoom.us/t/where-to-enter-redirect-url-whitelist-url-for-server-to-server-oauth-app/143829)

<div class="topic-metadata">

**Author:** [@AnkitaWhats](https://devforum.zoom.us/u/AnkitaWhats)\
**Replies:** 5\
**Last updated:** [May 25, 2026, 5:53pm UTC](https://devforum.zoom.us/t/where-to-enter-redirect-url-whitelist-url-for-server-to-server-oauth-app/143829 "2026-05-25T17:53:08Z")

</div>

Hello, I am creating a Server-to-Server OAuth APP and would like to know how to configure the Redirect URL or Whitelist URL for this app type. I am unable to find these options in the app settings. Could you please gu…

---

## [Connection timed out after 30000 milliseconds (ERROR 28)](https://devforum.zoom.us/t/connection-timed-out-after-30000-milliseconds-error-28/143843)

<div class="topic-metadata">

**Author:** [@tomkl](https://devforum.zoom.us/u/tomkl)\
**Replies:** 1\
**Last updated:** [May 25, 2026, 2:48am UTC](https://devforum.zoom.us/t/connection-timed-out-after-30000-milliseconds-error-28/143843 "2026-05-25T02:48:52Z")

</div>

API Endpoint(s) and/or Zoom API Event(s) POST \[https://zoom.us/oauth/token\](https://zoom.us/oauth/token) GET \[https://api.zoom.us/v2/users\](https://api.zoom.us/v2/users) Description We are a high-volume user of t…

---

## [oAuth app scopes missing(i am the only admin with full access)](https://devforum.zoom.us/t/oauth-app-scopes-missing-i-am-the-only-admin-with-full-access/143247)

<div class="topic-metadata">

**Author:** [@Sorin](https://devforum.zoom.us/u/Sorin)\
**Replies:** 1\
**Last updated:** [May 19, 2026, 5:58pm UTC](https://devforum.zoom.us/t/oauth-app-scopes-missing-i-am-the-only-admin-with-full-access/143247 "2026-05-19T17:58:08Z")

</div>

I want to send text messages through zoom API using openclaw so it looks like i need to do that through a oAuth app. I created the oAuth app but i don’t see the required scopes (phone:write:admin,phone:write,phone\_sms:wr…

---

## [Users provisioning via Identity-Zoom connector](https://devforum.zoom.us/t/users-provisioning-via-identity-zoom-connector/143729)

<div class="topic-metadata">

**Author:** [@AmolSA](https://devforum.zoom.us/u/AmolSA)\
**Replies:** 0\
**Last updated:** [May 19, 2026, 7:52am UTC](https://devforum.zoom.us/t/users-provisioning-via-identity-zoom-connector/143729 "2026-05-19T07:52:41Z")

</div>

Hi Zoom Dev Forum, We (University of SanDiego) are working on user provisioning through API calls via our Identity connector, and we’re hoping to get some guidance or best practices. Current Setup: We use two provis…

---

## [How can I use RTMS streams for and admin-managed app where the admin can assign licenses?](https://devforum.zoom.us/t/how-can-i-use-rtms-streams-for-and-admin-managed-app-where-the-admin-can-assign-licenses/143662)

<div class="topic-metadata">

**Author:** [@Canary\_Speech](https://devforum.zoom.us/u/Canary_Speech)\
**Replies:** 1\
**Last updated:** [May 18, 2026, 10:41pm UTC](https://devforum.zoom.us/t/how-can-i-use-rtms-streams-for-and-admin-managed-app-where-the-admin-can-assign-licenses/143662 "2026-05-18T22:41:48Z")

</div>

I see the answer given for the following question, “Is there a way for an account-managed app to subscribe to RTMS started/stopped in Meeting events, or to programmatically install a user-managed component on behalf of l…

---

## [POST /v2/contact\_center/outbound\_campaign/contact\_lists/{id}/contacts — correct field names for request body?](https://devforum.zoom.us/t/post-v2-contact-center-outbound-campaign-contact-lists-id-contacts-correct-field-names-for-request-body/143630)

<div class="topic-metadata">

**Author:** [@Eric14](https://devforum.zoom.us/u/Eric14)\
**Replies:** 0\
**Last updated:** [May 14, 2026, 3:07pm UTC](https://devforum.zoom.us/t/post-v2-contact-center-outbound-campaign-contact-lists-id-contacts-correct-field-names-for-request-body/143630 "2026-05-14T15:07:15Z")

</div>

Trying to add contacts to an outbound campaign contact list via S2S OAuth. The endpoint returns error 300 “Validation Failed” with contact\_phones and contact\_display\_name listed as missing, even when present in the paylo…

---

## [How the expiration time for refresh tokens is calculated](https://devforum.zoom.us/t/how-the-expiration-time-for-refresh-tokens-is-calculated/143290)

<div class="topic-metadata">

**Author:** [@suzunosuke.miyahara](https://devforum.zoom.us/u/suzunosuke.miyahara)\
**Replies:** 4\
**Last updated:** [May 11, 2026, 1:12am UTC](https://devforum.zoom.us/t/how-the-expiration-time-for-refresh-tokens-is-calculated/143290 "2026-05-11T01:12:56Z")

</div>

■Prerequisites One of the Zoom API’s restrictions is the expiration of refresh tokens. ◇Zoom API Restrictions ・The refresh token used to call the Zoom API expires 90 days after its last use. If this period is exceede…

---

## [Unable to get imchat:bot scope — getting error 7010 when calling /v2/im/chat/messages](https://devforum.zoom.us/t/unable-to-get-imchat-bot-scope-getting-error-7010-when-calling-v2-im-chat-messages/142803)

<div class="topic-metadata">

**Author:** [@WayneYang](https://devforum.zoom.us/u/WayneYang)\
**Replies:** 2\
**Last updated:** [April 7, 2026, 11:46pm UTC](https://devforum.zoom.us/t/unable-to-get-imchat-bot-scope-getting-error-7010-when-calling-v2-im-chat-messages/142803 "2026-04-07T23:46:26Z")

</div>

Hi everyone, I followed the documentation at Get credentials - Chat - Zoom Developer Docs to create a Chatbot app and enabled Team Chat Subscription. The app is working — I can receive webhook events (bot\_notification)…

---

## [Bad Request Creating Connector for Zoom calls](https://devforum.zoom.us/t/bad-request-creating-connector-for-zoom-calls/142658)

<div class="topic-metadata">

**Author:** [@Anita3](https://devforum.zoom.us/u/Anita3)\
**Replies:** 1\
**Last updated:** [April 1, 2026, 4:27pm UTC](https://devforum.zoom.us/t/bad-request-creating-connector-for-zoom-calls/142658 "2026-04-01T16:27:16Z")

</div>

Bad Request result Adding Connector for iTimekeep Passive Time Assistant: API Endpoint(s) and/or Zoom API Event(s) Link Zoom calls to Aderant iTimekeep Passive Time Assistant. Description Hi, I’m not a Zoom developer …

---

## [Educational platform](https://devforum.zoom.us/t/educational-platform/142547)

<div class="topic-metadata">

**Author:** [@Mona](https://devforum.zoom.us/u/Mona)\
**Replies:** 1\
**Last updated:** [April 1, 2026, 7:17am UTC](https://devforum.zoom.us/t/educational-platform/142547 "2026-04-01T07:17:28Z")

</div>

Hello, I am working with an online academy that has more than 700 students. We are planning to build a custom learning platform, and we are considering integrating Zoom into our system. I would like to understand the …

---

## [\[OAuth App\] Deauthorization webhook requests missing verification headers (Authorization / x-zm-signature)](https://devforum.zoom.us/t/oauth-app-deauthorization-webhook-requests-missing-verification-headers-authorization-x-zm-signature/142352)

<div class="topic-metadata">

**Author:** [@masaki.hori](https://devforum.zoom.us/u/masaki.hori)\
**Replies:** 3\
**Last updated:** [March 16, 2026, 2:00pm UTC](https://devforum.zoom.us/t/oauth-app-deauthorization-webhook-requests-missing-verification-headers-authorization-x-zm-signature/142352 "2026-03-16T14:00:30Z")

</div>

Dear Zoom Developer Support, We have an OAuth app published on the Zoom App Marketplace and receive app deauthorization notifications at our Deauthorization URL. We are unable to verify these requests because the webhoo…

---

## [Issue with Channel API Scope Permissions](https://devforum.zoom.us/t/issue-with-channel-api-scope-permissions/125341)

<div class="topic-metadata">

**Author:** [@rambabu.rachamalla](https://devforum.zoom.us/u/rambabu.rachamalla)\
**Replies:** 6\
**Last updated:** [March 10, 2026, 1:17am UTC](https://devforum.zoom.us/t/issue-with-channel-api-scope-permissions/125341 "2026-03-10T01:17:25Z")

</div>

Hi Zoom Support Team, We are using the Channel API (https://api.zoom.us/v2/chat/channels) in our integration, and it was working perfectly until last week. However, we are now encountering an issue where the API fails w…

---

## [Request for manual domain verification on clientID](https://devforum.zoom.us/t/request-for-manual-domain-verification-on-clientid/142301)

<div class="topic-metadata">

**Author:** [@josharcher](https://devforum.zoom.us/u/josharcher)\
**Replies:** 0\
**Last updated:** [March 4, 2026, 8:54pm UTC](https://devforum.zoom.us/t/request-for-manual-domain-verification-on-clientid/142301 "2026-03-04T20:54:09Z")

</div>

client Id 6Fzs9SWxQ9KskE2gala4ww

---

## [Meeting.rtms\_started webhook missing WebSocket URL / Stream ID](https://devforum.zoom.us/t/meeting-rtms-started-webhook-missing-websocket-url-stream-id/141905)

<div class="topic-metadata">

**Author:** [@harkunal](https://devforum.zoom.us/u/harkunal)\
**Replies:** 2\
**Last updated:** [February 17, 2026, 5:23pm UTC](https://devforum.zoom.us/t/meeting-rtms-started-webhook-missing-websocket-url-stream-id/141905 "2026-02-17T17:23:29Z")

</div>

Hi Team, Our RTMS-enabled Zoom App previously received full RTMS session details in the meeting.rtms\_started webhook, including: server\_urls rtms\_stream\_id signature / access token Recently, the webhook only…

---

## [onAuthorized event not firing on custom domain - works on ngrok](https://devforum.zoom.us/t/onauthorized-event-not-firing-on-custom-domain-works-on-ngrok/141478)

<div class="topic-metadata">

**Author:** [@EricChong](https://devforum.zoom.us/u/EricChong)\
**Replies:** 1\
**Last updated:** [January 24, 2026, 8:51pm UTC](https://devforum.zoom.us/t/onauthorized-event-not-firing-on-custom-domain-works-on-ngrok/141478 "2026-01-24T20:51:38Z")

</div>

Issue The onAuthorized event from the Zoom Apps SDK is not firing after a user clicks “Allow” on the consent dialog when my app is hosted on a custom domain. The same code works correctly on ngrok. Environment SDK Vers…

---

## [How to Prevent Zoom Access Token Expired (124) Error in Salesforce?](https://devforum.zoom.us/t/how-to-prevent-zoom-access-token-expired-124-error-in-salesforce/137652)

<div class="topic-metadata">

**Author:** [@cafer](https://devforum.zoom.us/u/cafer)\
**Replies:** 3\
**Last updated:** [December 1, 2025, 3:50pm UTC](https://devforum.zoom.us/t/how-to-prevent-zoom-access-token-expired-124-error-in-salesforce/137652 "2025-12-01T15:50:23Z")

</div>

Integration Overview We have built a custom Salesforce integration with Zoom for Meetings and Phone Calls. The app is created as a General App (Account Level) in Zoom Marketplace. From Salesforce, we can success…

---

## [Not Receiving Deauthorization Notifications at Webhook Endpoint for App Integration](https://devforum.zoom.us/t/not-receiving-deauthorization-notifications-at-webhook-endpoint-for-app-integration/138349)

<div class="topic-metadata">

**Author:** [@Rainbow1](https://devforum.zoom.us/u/Rainbow1)\
**Replies:** 2\
**Last updated:** [November 3, 2025, 9:11am UTC](https://devforum.zoom.us/t/not-receiving-deauthorization-notifications-at-webhook-endpoint-for-app-integration/138349 "2025-11-03T09:11:18Z")

</div>

Hello Zoom Developer Team, I am experiencing an issue with deauthorization notifications for our Zoom integration, specifically related to the Dotdigital app. Background: Our application was previously receiving deaut…

[Next page](https://devforum.zoom.us/c/api-and-webhooks/authentication/48.md?page=1)
