[Security Update] No token values in URL query parameters

What the heck, Zoom Team?! Your API Security change theoretically hit on February 14th per other forum posts, etc, but for some reason our app today (Feb 22nd) was affected. But here’s the thing - regardless, we shouldn’t be subject to this change because it stated clearly that it was for OAuth. We are using JWT!

Now I know we have to change from JWT to OAuth this summer. I get it, and we will, but you did not indicate anywhere that this query string change would apply to BOTH types of integrations - only OAuth. Why the switch?

Also, why were no other announcements / notifications sent to developers / partners?! You can’t just let this sit for months and then do it - there should be countdown announcements, etc when you change critical aspects of your API.

This is a REALLY poor way to handle your developer community. Do better, please.

John,

I am sorry that there was confusion around this change. We started sending notifications to developers around Christmas until the deadline. We sent these emails to the account owners, admins, and the developer contact that we have on file for the app. In the emails, we linked the FAQ and that answered your question about the JWT app type.

We are noticing that a number of emails get dropped by our current system and are looking into revamping this. If your developer contact email is a role based email (i.e., engineering@shariq.com or devs@shariq.com) our current system drops these addresses. If you are not a part of the monthly developer release emails, I would also subscribe to this. The message about the access token deprecation was also included here.

I should have dropped the link to the FAQ in the forum thread , especially since I was wrong about this deprecation not affecting the JWT app type. So, I apologize for that.

If you feel comfortable, please DM me your email and I can make sure that you are on the developer release emails so that you don’t miss out important info.

Thanks for the update. No one on my team ever received these emails, unfortunately. We only received the initial notice back in November 2022. I believe myself and my teammate have subscribed by hitting ‘Follow’ on the Zoom API page.

This topic was automatically closed 368 days after the last reply. New replies are no longer allowed.