# Domain Validation Explanation

**URL:** <https://devforum.zoom.us/t/domain-validation-explanation/87699>\
**Category:** App Marketplace\
**Tags:** guide, app-submission, domainvalidation\
**Created:** [May 2, 2023, 12:09pm UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699 "2023-05-02T12:09:12Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![kwaku.nyante](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/kwaku.nyante/32/23475_2.png) [@kwaku.nyante](https://devforum.zoom.us/u/kwaku.nyante)\
**Post date:** [May 2, 2023, 12:09pm UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/1 "2023-05-02T12:09:12Z")

</div>

**What is Domain Validation?**

Every App that is to be [‘Published’](https://developers.zoom.us/docs/distribute/) or ‘Submitted for Review’ on the Zoom App Marketplace _ **must go** _ through domain validation. With this, Zoom ensures that all the listed App Endpoints and URLs are owned by the respective App/Company.

Please note that this is a one-time verification process.

**Why do we employ it?**

Security. Zoom needs to make sure that the domains where the App is expected to receive Zoom callbacks are owned by the respective App/Company.

**Which App have Domain Validation restrictions?**

Every Published App, even Zoom’s First Party Apps.

**Which URLs are verified against this check?**

1. Privacy Policy URL
2. Terms of Use URL
3. Support URL
4. Documentation URL
5. Configure URL
6. Redirect URL for OAuth
7. Bot Url
8. Webhook Callback URL

**When do App Developers encounter this request?**

When third-party developers are preparing to Submit their App for Review to Marketplace, they are required to pass Domain Validation to be able to Submit the App successfully.

**Note: The SUBMIT button is click-activated once domains are validated. If not validated, it will remain unclickable.**

![Screenshot 2023-05-03 at 1.17.18 PM](https://us1.discourse-cdn.com/flex016/uploads/zoomdeveloper/original/3X/3/b/3b2d30a62f5be02ef86893a79f087ff6754f12e5.png)

**Manual Domain Validation**

If you are unable to validate your domain using the HTML method listed on the Submission Page, please create a [devforum](https://devforum.zoom.us/) post and our team should help you resolve the issue within 48hrs. 😃

Note: We will reach out to you via DM after the request is made so detailed information is not viewable Publicly.

---

<div class="post-metadata">

**Author:** ![tiffanytip23](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tiffanytip23/32/51441_2.png) [@tiffanytip23](https://devforum.zoom.us/u/tiffanytip23)\
**Post date:** [August 25, 2023, 12:12pm UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/2 "2023-08-25T12:12:31Z")

</div>

I have followed each step carefully and my domain is still not validated. The error code says my verification codes do not match. I have deleted and reinstalled 3 times.

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [August 25, 2023, 4:43pm UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/3 "2023-08-25T16:43:47Z")

</div>

Hi @tiffanytip23

If you are unable to validate your domain using the HTML method listed on the Submission Page, please create a [devforum](https://devforum.zoom.us/) post and our team should help you resolve the issue within 48hrs. 😃

Note: We will reach out to you via DM after the request is made so detailed information is not viewable Publicly.

---

<div class="post-metadata">

**Author:** ![daniel.eigler-hardin](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@daniel.eigler-hardin](https://devforum.zoom.us/u/daniel.eigler-hardin)\
**Post date:** [September 28, 2023, 9:05pm UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/4 "2023-09-28T21:05:26Z")

</div>

How do I validate multiple domains? I only validate one url but my website and endpoints are hosted by two different domains (I can validate both of them).

---

<div class="post-metadata">

**Author:** ![rakyk](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rakyk/32/52852_2.png) [@rakyk](https://devforum.zoom.us/u/rakyk)\
**Post date:** [October 9, 2023, 9:40am UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/5 "2023-10-09T09:40:04Z")

</div>

Hi !  
I need to create connector from Zoom to Snow software. I need create application with secret key but without App publication.  
which type of Application I need to create?  
I dont pass through the validation .

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [October 9, 2023, 3:13pm UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/6 "2023-10-09T15:13:03Z")

</div>

Hi @rakyk  
You can always create an Oauth app with intend to publish No, if it is an internal application  
If you want your app to make api calls on behalf of third party users you would have to submit your app for review with our marketplace

---

<div class="post-metadata">

**Author:** ![rakyk](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rakyk/32/52852_2.png) [@rakyk](https://devforum.zoom.us/u/rakyk)\
**Post date:** [October 10, 2023, 3:18am UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/7 "2023-10-10T03:18:53Z")

</div>

Can somebody help me with that ? 😇  
Ruslana

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [October 10, 2023, 1:38pm UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/8 "2023-10-10T13:38:40Z")

</div>

Sure thing @rakyk  
If this integration is meant to be for internal use (ex generate internal report, create meetings for users under the same account, get recordings from users under the account) then you could benefit from using our Server to Server OAuth integration

> **[Internal apps (Server-to-server)](https://developers.zoom.us/docs/internal-apps/)**
>
> The Zoom Developer Platform is an open platform that allows third-party developers to build applications and integrations upon Zoom’s video-first unified communications platform.

> [@How to user Server-to-Sever OAuth app with Postman](https://devforum.zoom.us/t/how-to-user-server-to-sever-oauth-app-with-postman/70848):
>
> How to use our Server-to-Server OAuth with Postman? As some of you might be aware of, our JWT app is being deprecated by June 2023 and we encourage you to migrate to the newly introduced [Server-to-Server OAuth App](https://marketplace.zoom.us/docs/guides/build/server-to-server-oauth-app) That being said, here is a quick and simple guide on how to use or new app with Postman As stated in our documentation here: This new app type facilitates OAuth-authenticated requests between servers without end-user involvement. And this grant type enable your private server a…

---

<div class="post-metadata">

**Author:** ![shanon](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@shanon](https://devforum.zoom.us/u/shanon)\
**Post date:** [October 12, 2023, 8:48am UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/9 "2023-10-12T08:48:45Z")

</div>

I only validate one URL, but two domains host my website and endpoints.  
I would like to know how to do “Manual Domain Validation.”

---

<div class="post-metadata">

**Author:** ![rakyk](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/rakyk/32/52852_2.png) [@rakyk](https://devforum.zoom.us/u/rakyk)\
**Post date:** [October 27, 2023, 8:08am UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/10 "2023-10-27T08:08:54Z")

</div>

Hi Elisa!  
in which section I can find created application . I want to use it like an axample . Server to Server OAuth application

---

<div class="post-metadata">

**Author:** ![ibrahimzalareih](https://avatars.discourse-cdn.com/v4/letter/i/6a8cbe/32.png) [@ibrahimzalareih](https://devforum.zoom.us/u/ibrahimzalareih)\
**Post date:** [October 27, 2023, 1:26pm UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/11 "2023-10-27T13:26:57Z")

</div>

Hi Ruslanaits  
It’s good i find applications about Apls

---

<div class="post-metadata">

**Author:** ![Anonymous2](https://avatars.discourse-cdn.com/v4/letter/a/5f9b8f/32.png) [@Anonymous2](https://devforum.zoom.us/u/Anonymous2)\
**Post date:** [October 31, 2023, 8:40am UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/12 "2023-10-31T08:40:36Z")

</div>

@elisa.zoom you guys haven’t replied to this message yet.

Am facing the same issue, urgent attention is needed here please @elisa.zoom

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [October 31, 2023, 8:44pm UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/13 "2023-10-31T20:44:31Z")

</div>

Hi @rakyk@Anonymous2  
Do you still need assistance here?  
Could you please open up a new thread and make sure to tag me to get a notification?  
This is not related with Domain Validation

---

<div class="post-metadata">

**Author:** ![elisa.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/elisa.zoom/32/47836_2.png) [@elisa.zoom](https://devforum.zoom.us/u/elisa.zoom)\
**Post date:** [October 31, 2023, 8:44pm UTC](https://devforum.zoom.us/t/domain-validation-explanation/87699/14 "2023-10-31T20:44:38Z")

</div>


