# Deauthorisation api

**URL:** <https://devforum.zoom.us/t/deauthorisation-api/20055>\
**Category:** API and Webhooks\
**Created:** [June 3, 2020, 2:23am UTC](https://devforum.zoom.us/t/deauthorisation-api/20055 "2020-06-03T02:23:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![laura1](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/laura1/32/3992_2.png) [@laura1](https://devforum.zoom.us/u/laura1)\
**Post date:** [June 3, 2020, 2:23am UTC](https://devforum.zoom.us/t/deauthorisation-api/20055/1 "2020-06-03T02:23:17Z")

</div>

**Description**  
We read that we need to create a **deauthorisation api end point as per** [https://marketplace.zoom.us/docs/guides/auth/deauthorization](https://marketplace.zoom.us/docs/guides/auth/deauthorization) in order to fulfil the requirements to publish our app.

However, we need to understand what Zoom expects us to do on our side when deauthorizing.  
For example, we will assume that we need to remove data associated with the user that connects them to zoom, but do we also need to delete all the info with regards to meetings already created, past and future? Or is it sufficient to give the user the option to do this manually?

---

<div class="post-metadata">

**Author:** ![michael.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/michael.zoom/32/37213_2.png) [@michael.zoom](https://devforum.zoom.us/u/michael.zoom)\
**Post date:** [June 5, 2020, 10:08pm UTC](https://devforum.zoom.us/t/deauthorisation-api/20055/2 "2020-06-05T22:08:33Z")

</div>

Hi @laura1, the Deauthorization Endpoint URL is a URL to which Zoom will notify you that a user has deauthorized your app.

When you receive a notification at this location, your app will need to respect the user’s preferences to keep or delete their data **within your app/database**. If a user requests you to delete their data, you should delete it from your records but not delete the meetings themselves.

---

<div class="post-metadata">

**Author:** ![nassoft](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/nassoft/32/11153_2.png) [@nassoft](https://devforum.zoom.us/u/nassoft)\
**Post date:** [June 29, 2020, 7:27pm UTC](https://devforum.zoom.us/t/deauthorisation-api/20055/3 "2020-06-29T19:27:17Z")

</div>

Hello Michael, we are also breaking our heads on this deauthorisation routine, is there any sample code to understand how we can come about this function? It is not clear how we receive this information from zoom since there is no way to test it.  
I tryed to use the production URL to authorize and then whent to marketplce to deauthorize but did’t get any response, only a message that its been deauthorized.  
regards,

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [July 1, 2020, 12:25am UTC](https://devforum.zoom.us/t/deauthorisation-api/20055/4 "2020-07-01T00:25:48Z")

</div>

Hey @nassoft,

Here is an example of the deauth flow in Node.js:

> <https://github.com/zoom/unsplash-chatbot/blob/master/index.js#L179>

Here are the docs (I will work improve them as soon as I can):

> **[Data Compliance - Publishing an App - Documentation](https://marketplace.zoom.us/docs/guides/publishing/data-compliance)**
>
> Data Compliance
> 
> All Marketplace app developers must comply with users’ preferences on how their data should be handled. 
> 
> The Zoom Data Compliance requ...

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![nassoft](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/nassoft/32/11153_2.png) [@nassoft](https://devforum.zoom.us/u/nassoft)\
**Post date:** [July 1, 2020, 7:02am UTC](https://devforum.zoom.us/t/deauthorisation-api/20055/5 "2020-07-01T07:02:58Z")

</div>

Hi Tommy,

Thanks so much for your quick reply. I wonder if you have any similar code in PHP .

Regards

Nas

![image001.jpg](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/c/cb6477d7486e12f28258ffdc8751d356bee647a8.jpeg)

![image002.jpg](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/9/9b2564405377fb4d0b91226454963e8ac87ed534.jpeg)

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [July 6, 2020, 5:45pm UTC](https://devforum.zoom.us/t/deauthorisation-api/20055/6 "2020-07-06T17:45:22Z")

</div>

Hey @nassoft,

Not for the [webhook part](https://stackoverflow.com/a/45844612/6592510), but for making the deauth request we do here:

 ![Screen Shot 2020-07-06 at 11.43.49 AM](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/2X/e/ef6166a45030e3d3175b9d36c7a2eec6ad8e756b.png)

> **[Data Compliance - Data Compliance - Data Compliance API - API Reference](https://marketplace.zoom.us/docs/api-reference/data-compliance/data-compliance/compliance)**
>
> Notify Zoom that you comply with the Data Compliance policy which requires you to handle user's data in accordance to the user's preference after the us...

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![DeveloperBot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/developerbot/32/12632_2.png) [@DeveloperBot](https://devforum.zoom.us/u/DeveloperBot)\
**Post date:** [August 21, 2020, 10:34pm UTC](https://devforum.zoom.us/t/deauthorisation-api/20055/7 "2020-08-21T22:34:20Z")

</div>


