# Deauthorization flow

**URL:** <https://devforum.zoom.us/t/deauthorization-flow/78491>\
**Category:** API and Webhooks\
**Created:** [November 8, 2022, 5:21pm UTC](https://devforum.zoom.us/t/deauthorization-flow/78491 "2022-11-08T17:21:26Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![rmjuarez12](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rmjuarez12/32/39802_2.png) [@rmjuarez12](https://devforum.zoom.us/u/rmjuarez12)\
**Post date:** [November 8, 2022, 5:21pm UTC](https://devforum.zoom.us/t/deauthorization-flow/78491/1 "2022-11-08T17:21:26Z")

</div>

Hello,

I am in the process of getting my app on the marketplace approved. One of the last things I have pending is a deauthorization flow. Currently, for authorizing, there is a URL I can use in which a user is able to accept or deny a request for authorization. Is there a way to do something similar with deauthorizing? I have been looking everywhere and I cannot find a single article on how to do a proper deauthorization flow, so here I am asking with hopes that I can get this resolved ASAP!

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![gianni.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/gianni.zoom/32/32523_2.png) [@gianni.zoom](https://devforum.zoom.us/u/gianni.zoom)\
**Post date:** [November 9, 2022, 4:53pm UTC](https://devforum.zoom.us/t/deauthorization-flow/78491/2 "2022-11-09T16:53:04Z")

</div>

Hi @rmjuarez12 ,

You will have the [deauthorization webhook](https://marketplace.zoom.us/docs/guides/auth/deauthorization/#deauthorization-event-notifications) sent to the [deauthorization notification endpoint](https://devforum.zoom.us/t/deauthorization-endpoint-user-identification/33047/2) that you provide. You can then [revoke the account/user’s access token](https://marketplace.zoom.us/docs/guides/auth/oauth/#revoking-an-access-token) prior to removing their data.

Let me know if the linked resources help to clarify things!

---

<div class="post-metadata">

**Author:** ![rmjuarez12](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rmjuarez12/32/39802_2.png) [@rmjuarez12](https://devforum.zoom.us/u/rmjuarez12)\
**Post date:** [November 9, 2022, 6:34pm UTC](https://devforum.zoom.us/t/deauthorization-flow/78491/3 "2022-11-09T18:34:18Z")

</div>

That part I do have done(except revoking access, that is pending). What I mean, is how do I go about the user removing the app. Do I have to just create a link from our webapp to Zoom to remove it from there? Or is there a way I can just call an API so that it is removed directly from my webapp?

---

<div class="post-metadata">

**Author:** ![gianni.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/gianni.zoom/32/32523_2.png) [@gianni.zoom](https://devforum.zoom.us/u/gianni.zoom)\
**Post date:** [November 9, 2022, 6:46pm UTC](https://devforum.zoom.us/t/deauthorization-flow/78491/4 "2022-11-09T18:46:41Z")

</div>

@rmjuarez12 the user will remove the app themselves causing the deauthorization webhook to send to your endpoint. At that point, you revoke the user’s access token. Does that make sense?

---

<div class="post-metadata">

**Author:** ![rmjuarez12](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rmjuarez12/32/39802_2.png) [@rmjuarez12](https://devforum.zoom.us/u/rmjuarez12)\
**Post date:** [November 9, 2022, 6:50pm UTC](https://devforum.zoom.us/t/deauthorization-flow/78491/5 "2022-11-09T18:50:44Z")

</div>

@gianni.zoom - Ah ok. So let me see if this flow is what I should follow:

- User goes to their settings page on my webapp dashboard
- User goes to their Zoom settings
- On the Zoom settings page, I provide a link to go to Zoom Marketplace, with a set of instructions on how to remove the app in there
- User removes app from Zoom Marketplace(NOT my webapp dashboard)
- My server receives a notifications to whichever endpoint I have specified
- That endpoint should remove any data from our DB in regards to their Zoom, as well as revoking the access token.

Let me know if the above is correct. I just want to make sure it is, since I want to send it for review ASAP.

---

<div class="post-metadata">

**Author:** ![gianni.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/gianni.zoom/32/32523_2.png) [@gianni.zoom](https://devforum.zoom.us/u/gianni.zoom)\
**Post date:** [November 28, 2022, 3:34am UTC](https://devforum.zoom.us/t/deauthorization-flow/78491/6 "2022-11-28T03:34:38Z")

</div>

Hi @rmjuarez12 ,

The endpoint itself cannot remove data from your DB. Once you receive the notification to the endpoint, you can programmatically [revoke the access token](https://marketplace.zoom.us/docs/guides/auth/oauth/#revoking-an-access-token) and remove their data 🙂

---

<div class="post-metadata">

**Author:** ![rmjuarez12](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rmjuarez12/32/39802_2.png) [@rmjuarez12](https://devforum.zoom.us/u/rmjuarez12)\
**Post date:** [November 29, 2022, 6:58pm UTC](https://devforum.zoom.us/t/deauthorization-flow/78491/7 "2022-11-29T18:58:20Z")

</div>

Hmmm how can I get the access token from the notification endpoint? According to the Deauthorization docs, the response I get does not contain the access token. How can I get the access token to be able to revoke it AFTER the user has removed the app?

---

<div class="post-metadata">

**Author:** ![gianni.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/gianni.zoom/32/32523_2.png) [@gianni.zoom](https://devforum.zoom.us/u/gianni.zoom)\
**Post date:** [November 29, 2022, 11:14pm UTC](https://devforum.zoom.us/t/deauthorization-flow/78491/8 "2022-11-29T23:14:57Z")

</div>

Hi @rmjuarez12 ,

Currently, best practice is to grab the access token during authorization. See below for outlined process:

> [@Deauthorization endpoint user identification](https://devforum.zoom.us/t/deauthorization-endpoint-user-identification/33047/6):
>
> Hey @dave2 , Thank you for clarifying, and my sincere apologies for not catching your concern from the onset. I understand now that you’re essentially looking to make this connection with a customer’s Account ID as soon as they authorize/install the app, so that you can then have this record on your end when they uninstall (but please correct me if I’m misunderstanding). While there’s not a completely straight forward way to track this, there is a suggestion I can make: When an account author…

---

<div class="post-metadata">

**Author:** ![rmjuarez12](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rmjuarez12/32/39802_2.png) [@rmjuarez12](https://devforum.zoom.us/u/rmjuarez12)\
**Post date:** [December 19, 2022, 6:18pm UTC](https://devforum.zoom.us/t/deauthorization-flow/78491/9 "2022-12-19T18:18:34Z")

</div>

Hello @gianni.zoom

Perfect, thank you so much, that is exactly what I was looking for. Sorry for the late reply!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/6/1/614bdd549b610bbaa46ff934617683a02bdaa03c.png) [@system](https://devforum.zoom.us/u/system)\
**Post date:** [December 23, 2023, 9:54am UTC](https://devforum.zoom.us/t/deauthorization-flow/78491/10 "2023-12-23T09:54:38Z")

</div>

This topic was automatically closed 368 days after the last reply. New replies are no longer allowed.
