JWT apps to be deprecated in favor of Server-to-Server OAuth

hey @beirne feel free to follow along with this guide:

Hi,
When will Server-to-Server OAuth be available for zoomgov.com ?
Thanks,

Hi @ksks
Thanks for reaching out to the Zoom Developer Forum.
It will be available.
I do not have a specific Date for you but allow me ask to my team and will come back to you with an update shortly.

Best,
Elisa

Hi @elisa.zoom

We are using this below API to join the call using JWT

With the JWT app deprecation/ switching to access token, what is the required scope to invoke this API?

Hi @djoy
Thanks for reaching out to the Zoom Developer Forum, I am happy to help here!
As far as I know, all the Zoom Room endpoints will eventually be available using our Server to Server.
Let me confirm the estimated timeline with the team.
Best,
Elisa

Another thing to note, that isn’t obvious and not in the documentation (yet), is that you may need to build an access token rotation system. Each time you request an access token for a particular token index (by default, you only get one), it invalidates the previous access token.

Thanks @david5 for bringing this into my attention. I am going to test this behavior.

1 Like

Thanks for you sharing your insight and contributing to the Zoom Developer Forum, @david5 !

Hi,
Following up on this:
When will Server-to-Server OAuth be available for zoomgov.com ?
Thanks,

Hi @ksks
I just reached out to some of my team members and will come back to you with an update shortly.
Best,
Elisa

I am working with a customer who has created the server-to-server oauth app for his account, but his credentials get a 400 response

Is server-to-server oauth still not functional? Or is this because our fed moderate solution is considered a 3rd party app and that is not allowed yet?

Hi @michael.curran
Could you please open up a new topic describing your issue with details and we will take it from there!
Best,
Elisa

Opened it here. Thank you!

1 Like

Will this server to server Oauth change effect how my organization uses SAML2.0 to authenticate with our IDP?

Hi,
Is only JWT App type have been deprecated? In our case, we are using Meeting SDK for building mobile apps, but we are using JWT to initialise zoom SDK. Do we also need to migrate to Server-to-Server OAuth?
Thanks

Hi @htec
Thanks for reaching out to us and welcome to our community!
The only app that is going to be deprecated will be the JWT app type.
You will also need to change the credentials you use to initialize the zoom SDK if you are using the API key and secret from JWT

Hi Elisa,

Thank you for your welcome!
We are passing JWT token to Zoom Meeting SDK method inside ZoomSDKInitParams which is wrapped inside SDK

ZoomSDK sdk = ZoomSDK.getInstance();
sdk.initialize(Context, ZoomSDKInitializeListener, ZoomSDKInitParams)

Does it mean that we need to migrate?

Thank you!

@htec,

To confirm, are you passing the JWT token from your JWT Marketplace App? If yes, then you will need to migrate. The JWT app type will be deprecated June 1, 2023.

Here are migration resources for reference :

JWT App Type Deprecation FAQ

https://marketplace.zoom.us/docs/guides/build/jwt-app/jwt-faq/

JWT app type migration guide

https://marketplace.zoom.us/docs/guides/build/jwt-app/jwt-app-migration/


Or are you passing an SDK JWT token ? If yes, then you will NOT need to migrate.

Create a Meeting SDK App

https://marketplace.zoom.us/docs/guides/build/sdk-app/

Generate a Meeting SDK JWT

https://marketplace.zoom.us/docs/sdk/native-sdks/auth/#generate-a-meeting-sdk-jwt

Feel free to let me know if you have any questions about this.

1 Like

Hello Donte,

We have both JWT and Meeting SDK app. We don’t see the warning message “This app type will be deprecated on 6/1/2023” on our JWT app. But we see the following on our “Meeting SDK” app.

image

When I click the “Update” link, I got the following popup:

My question is: will our existing app stop working immediately after we update the app to server-to-server OAuth?

Thank you

Thank you for your question, @rjd ! No, your existing app will not stop working immediately after we update the app to server-to-server OAuth. The JWT Marketplace App will not stop Deprecation until June 1, 2023.

Also, I would like to let you know that the Meeting SDK Marketplace update adds OAuth functionality to an SDK App type. However, it is not required to use the OAuth functionality, and the existing SDK functionality will not break. To learn more, check out this doc for an explanation:

https://marketplace.zoom.us/docs/guides/build/sdk-app#update-app

Feel free to let me know if you have any additional questions about this.