Skip to navigation

Zoom App Production Submission

View as Markdown

Start with Zoom Marketplace App Setup. Production approval and join authorization are separate: an approved app still needs the appropriate ZAK or OBF token and must satisfy Zoom’s meeting admission rules. See Zoom’s Meeting SDK authorization documentation.

Verify development and production settings

In the Zoom App Marketplace, check the settings for each environment:

  • Enable Meeting SDK under Features → Embed on your General App.
  • Register your own server’s HTTPS OAuth callback and matching allow-list entry for customer authorization. Use the exact redirect URI in your authorization and code-exchange requests.
  • Request scopes for the flow you implement: user:read:zak (User > View a user’s zak token) for ZAK, user:read:token for OBF, and user:read:user only if you look up user identity. Explain each scope you actually use in its Scope Description. Guest-only apps do not need these scopes for MeetStream.
  • Save the corresponding app Client ID and Client Secret in MeetStream Dashboard → Integrations → Zoom (Configure credentials or Update credentials). These identify the Meeting SDK app running the bot. The dashboard holds one pair at a time.
  • Configure your own server to perform customer OAuth, store and rotate refresh tokens, and mint tokens through HTTPS URLs at join time. MeetStream does not store end-user Zoom OAuth refresh tokens for join.

Prepare the app submission

Complete the listing and review requirements shown in your app’s Marketplace submission checklist. Use your company’s app name, description, support contact, privacy policy, terms, and documentation.

Describe the actual integration and data handling in your scope justifications and technical design. Your architecture should show:

  1. A Zoom user authorizes your app through your OAuth callback.
  2. Your server stores the user’s refresh token and exposes an authenticated HTTPS mint URL.
  3. Your application calls MeetStream create_bot with zoom.zak_url or zoom.obf_url.
  4. At join time, MeetStream calls the URL; your server obtains the Zoom token and returns it.
  5. The bot joins using the Meeting SDK app credentials and the returned token.
  6. After it is admitted, the bot asks the host for recording permission through Zoom’s standard request. If the host denies it or does not answer within the configured timeout, the bot leaves. If the host revokes permission during the meeting, the bot stops recording and leaves.

Zoom’s Meeting SDK feature review requirements cover this: apps used by participants request recording permission from the host through the SDK, and must stop accessing content if permission is revoked.

Provide accurate security answers and supporting evidence for your own implementation. Include reviewer instructions and any requested demonstration of authorization, bot admission, recording, and disconnection.

For an OBF demonstration, have the parent user join first. Mint a fresh token when called, and show that the bot leaves when the parent leaves. Do not put meeting_number on the configured obf_url; MeetStream appends it.

Submit and switch credentials

  1. Resolve incomplete items in the Marketplace submission checklist and submit for review.
  2. Zoom’s guidance is to use the production credentials for the initial publish request and the development credentials for testing later updates (Zoom: App credentials). Save the pair you are running in the MeetStream Zoom integration with Update credentials; after approval, make sure the production pair is the one saved.
  3. Ensure your OAuth server uses the matching production configuration and registered callback. Obtain the required user authorization for that configuration.
  4. Test the mint endpoint, then test a bot join with the selected ZAK or OBF mode and verify recording permission.

See Zoom Authenticated Bots for the token endpoint contract and failure diagnosis. The deprecated use_zoom_obf and zoom_oauth_connection_user_id fields are rejected; use customer-hosted token URLs.