# App Deauthorization

**URL:** <https://devforum.zoom.us/t/app-deauthorization/34543>\
**Category:** API and Webhooks\
**Created:** [October 28, 2020, 5:55pm UTC](https://devforum.zoom.us/t/app-deauthorization/34543 "2020-10-28T17:55:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![demo2Thalamus](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/demo2thalamus/32/14548_2.png) [@demo2Thalamus](https://devforum.zoom.us/u/demo2Thalamus)\
**Post date:** [October 28, 2020, 5:55pm UTC](https://devforum.zoom.us/t/app-deauthorization/34543/1 "2020-10-28T17:55:08Z")

</div>

**Description**  
If you have a web integration but you aren’t capturing user data, other than the token and refresh token, is there a need to notify for deauthorization?

**Which App Type (OAuth / Chatbot / JWT / Webhook)?**  
OAuth

**Which Endpoint/s?**  
Deauthorization

**Additional context**  
This is in the context of submitting an app to the marketplace

---

<div class="post-metadata">

**Author:** ![DeveloperBot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/developerbot/32/12632_2.png) [@DeveloperBot](https://devforum.zoom.us/u/DeveloperBot)\
**Post date:** [October 28, 2020, 5:55pm UTC](https://devforum.zoom.us/t/app-deauthorization/34543/2 "2020-10-28T17:55:52Z")

</div>

Hey @demo2Thalamus

Thanks for posting on the Zoom Devforum! I am still learning, but I will try my best to help answer your question. 🙂

Checkout this related thread that may have the answer you are looking for:

> [@Deauthorization API - not webhook](https://devforum.zoom.us/t/-/9177):
>
> Hi, When a user requests to disconnect my app, or for example, my app would like to disconnect inactive users (to avoid extraneous webhooks) - I need some deauthorization API call for Zoom. Is there a app deauthorization API? (i.e: not the webhook callback when the user deauthorizes on Zoom end) Thanks, Alon

If this thread did not help, please let us know by replying back here and someone from the Developer Relations team will get back to you shortly.

Thanks,  
DeveloperBot

---

<div class="post-metadata">

**Author:** ![demo2Thalamus](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/demo2thalamus/32/14548_2.png) [@demo2Thalamus](https://devforum.zoom.us/u/demo2Thalamus)\
**Post date:** [October 28, 2020, 5:57pm UTC](https://devforum.zoom.us/t/app-deauthorization/34543/3 "2020-10-28T17:57:08Z")

</div>

Thanks DevBot, but that answer did not help

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [October 29, 2020, 7:01pm UTC](https://devforum.zoom.us/t/app-deauthorization/34543/4 "2020-10-29T19:01:39Z")

</div>

Hi @demo2Thalamus,

Good question— If a user uninstalls your app from their account and does not want you to keep the data, then you should remove **all the data related to the user** , in order to be compliant. This would include not only the User ID, but the token, names, meeting history and any other data that you might have which belonged to the user.

Calling the Data compliance API is a way of letting Zoom know and record your app’s compliance. It lets us know that you have honored users’ data retention preferences on all fronts, and that you do not have any Zoom Customer Data stored on your servers, without the user’s consent (expressed via the de-authorization)—so making this call lets us know you’ve done your due diligence regardless of your servers’ storage.

I hope this helps to clarify!  
Will

---

<div class="post-metadata">

**Author:** ![demo2Thalamus](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/demo2thalamus/32/14548_2.png) [@demo2Thalamus](https://devforum.zoom.us/u/demo2Thalamus)\
**Post date:** [November 5, 2020, 4:33pm UTC](https://devforum.zoom.us/t/app-deauthorization/34543/5 "2020-11-05T16:33:51Z")

</div>

> [@will.zoom](#):
>
> This would include not only the User ID, but the token, names, meeting history and any other data that you might have which belonged to the user.

But what if we **only** have the tokens? Those expire automatically after 14 days.

---

<div class="post-metadata">

**Author:** ![will.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/will.zoom/32/14417_2.png) [@will.zoom](https://devforum.zoom.us/u/will.zoom)\
**Post date:** [November 5, 2020, 9:42pm UTC](https://devforum.zoom.us/t/app-deauthorization/34543/6 "2020-11-05T21:42:18Z")

</div>

Hi @demo2Thalamus,

Even if you only retain tokens, it is still required to call our Data Compliance endpoint.

Thanks,  
Will

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [December 6, 2020, 7:42am UTC](https://devforum.zoom.us/t/app-deauthorization/34543/7 "2020-12-06T07:42:25Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
