Skip to navigation

Zoom Marketplace App Setup

View as Markdown

Create one Zoom Meeting SDK app, save its Client ID and Client Secret in MeetStream, and every Zoom bot you create runs as that app.

Zoom only lets Meeting SDK apps join meetings through an app you register in the Zoom App Marketplace. MeetStream uses your app’s Client ID and Client Secret to authorize each bot’s Meeting SDK session. You do this once per MeetStream account, not once per bot.

What you configure where

PieceWhere it livesWhat it does
Meeting SDK app (Client ID and Client Secret)Zoom App Marketplace, saved in MeetStream Integrations > ZoomIdentifies the app every Zoom bot runs as. Required for all Zoom bots
User authorization (OAuth)Your own serverOnly needed for signed-in (ZAK) or on-behalf-of (OBF) joins. Your server keeps each user’s refresh token and returns a fresh token when MeetStream asks
Token URL (zoom.zak_url or zoom.obf_url)Sent on each create_bot requestTells the bot where to fetch the ZAK or OBF token at join time. See Zoom Authenticated Bots

MeetStream does not run a Zoom OAuth flow for you and does not store your users’ Zoom refresh tokens. Do not point your app’s OAuth redirect URL at a MeetStream address.

1. Create a General app with Meeting SDK

These steps follow Zoom’s current build flow (Zoom: Quick start guide, Zoom: Get Meeting SDK credentials). Zoom sometimes renames Marketplace menus; if a label differs, the Zoom pages linked here have the latest wording.

1

Start a new General app

Sign in to the Zoom App Marketplace. Click Develop > Build App (in the newer layout, open Developer in the lower-left navigation, then Develop > Build an app). Select General app and click Create.

2

Name the app and choose how it is managed

On the Basic Information page, rename the app with the edit icon. Under Select how the app is managed, choose:

  • User-managed if each of your users will authorize their own Zoom account (the usual choice for per-user ZAK or OBF joins).
  • Admin-managed if a Zoom account admin will install the app for their whole account.

If you only plan guest joins, either option works.

3

Copy the App Credentials

The build flow generates App Credentials: a Client ID and a Client Secret. Zoom gives you a development pair for building and testing and a production pair for the published app (Zoom: App credentials). Start with the development pair.

4

Set the OAuth redirect URL and allow list (ZAK or OBF only)

Zoom asks for an OAuth redirect URL and OAuth allow lists. If you will use signed-in or on-behalf-of joins, enter your own server’s HTTPS callback, for example https://api.example.com/zoom/oauth/callback, in both fields, and use exactly the same redirect URI when you authorize users and exchange codes. For guest-only use, enter a URL on your own domain.

5

Turn on Meeting SDK

Open Features, select the Embed tab, and toggle Meeting SDK on. Without it, the bot cannot authorize its Meeting SDK session and typically ends with Error: Zoom authentication failed with result: <n>.

6

Add scopes

Open Scopes, select Add Scopes, pick the Zoom product and the scopes from the table below, then select Done. Zoom asks you to explain each scope in the Scope Description field.

7

Authorize the app on your own account for testing (optional)

On the Local Test page, select Add App Now to authorize the app for your own Zoom user. To let teammates in the same Zoom account authorize it, use Generate and Copy in the Authorization URL section.

2. Choose scopes for your join mode

Scopes control what your app can do with a user’s OAuth token. MeetStream’s bot itself only needs the Client ID and Client Secret; scopes matter for the tokens your server mints.

You wantScope to addUsed by
Guest joins onlyNone required by MeetStream
Signed-in joins (zoom.zak_url)user:read:zak (in the Zoom UI: User > View a user’s zak token). Zoom documents User > View all user information for admin-managed appsYour token server, to call GET /v2/users/me/token?type=zak
On-behalf-of joins (zoom.obf_url)user:read:tokenYour token server, to call GET /v2/users/me/token?type=onbehalf&meeting_id=<id>
Look up the Zoom user in your callbackuser:read:user (optional)Your server

Sources: Zoom: Get Meeting SDK credentials, Zoom: OBF FAQ, Zoom: Transitioning to OBF tokens.

Some accounts connect their Zoom app to MeetStream with OAuth for the Zoom account that hosts the meetings, so bots can ask Zoom for a join token for local recording (fewer waiting room and recording prompts). This is not self-serve today; contact support first. It needs these granular scopes (use the :admin variants for admin-managed apps), as listed in Zoom: Granular scopes:

ScopeWhy
meeting:read:local_recording_tokenGet the meeting’s join token for local recording
meeting:read:meetingCheck whether the connected account can see a meeting
meeting:read:list_meetingsSync the account’s upcoming meetings
meeting:update:meetingTurn on the waiting room for a meeting that has not been synced yet
user:read:userRead the connected user’s personal meeting ID

Behavior details are in Zoom Meeting Bots: account-connected Zoom apps.

3. Save the credentials in MeetStream

1

Open the Zoom integration

In the MeetStream dashboard, click Integrations in the sidebar and select the Zoom tab. With no credentials saved, the page shows No Zoom credentials configured yet.

2

Paste the Client ID and Client Secret

Click Configure credentials (or Update credentials if a pair is already saved). In the Configure Zoom Credentials dialog, paste the Client ID and Client Secret from your app’s App Credentials, then click Configure (or Update).

MeetStream dashboard Integrations page on the Zoom tab with the sidebar item, the Zoom tab, the Update credentials button and the masked credential fields numbered 1 to 4
Integrations > Zoom: (1) Integrations, (2) Zoom tab, (3) Configure or Update credentials, (4) the saved Client ID and Client Secret
3

Confirm the credentials are active

The Zoom Integration card shows a green Credentials active indicator. Both values are masked after saving.

Zoom Integration card with the Credentials active indicator and the masked Client ID and Client Secret fields highlighted
The saved Zoom credentials: (1) Credentials active, (2) masked Client ID and Client Secret

The dashboard keeps one Client ID and Client Secret pair. Update credentials replaces it, which is how you switch from development to production credentials. There is no delete button for Zoom credentials in the dashboard.

4. Test a bot

  1. Start a Zoom meeting hosted by the same Zoom account that owns your Marketplace app. With development credentials, that is the only kind of meeting your bot can join.

  2. Create a bot with the meeting’s /j/ invite link, including ?pwd= if the meeting has a passcode:

    curl -X POST "https://api.meetstream.ai/api/v1/bots/create_bot" \
    -H "Authorization: Token <YOUR_API_KEY>" \
    -H "Content-Type: application/json" \
    -d '{
    "meeting_link": "https://zoom.us/j/81234567890?pwd=AbCdEf123",
    "bot_name": "Notetaker"
    }'
  3. Admit the bot if your meeting has a waiting room, then allow recording when Zoom asks. You should receive bot.in_waiting_room, bot.inmeeting, bot.recording_permission_allowed (when Zoom asked the host) and bot.recording.

To join meetings hosted by other Zoom accounts, Zoom requires your app to pass its review and the bot to join with a ZAK or OBF token (Zoom: Meeting SDK authorization). Continue with Zoom App Production Submission and Zoom Authenticated Bots.

Troubleshooting

SymptomLikely causeFix
create_bot returns 400 Zoom bots require Zoom credentials in user profileNo credentials savedComplete step 3
Bot ends with Error: Zoom authentication failed with result: <n>Wrong Client ID or Secret, or Meeting SDK not enabledRe-copy both values; turn on Meeting SDK under Features > Embed
Bot ends with Stopped and Unable to join external meetingThe meeting is hosted outside your app’s Zoom accountTest with your own account’s meeting, or get the app reviewed and use a ZAK or OBF join
Bot ends with Error: Failed to join meeting: Invalid meeting_link formatThe link is not a /j/ linkUse the meeting’s /j/ invite link
Bot joins but leaves with bot.recording_permission_deniedThe host did not allow recording in timeSee Recording permission

Every Zoom status and message is listed in Zoom Meeting Bots and in Bot status and error codes.