setup

Zoom

Purpose

Collects one Zoom account's active, inactive, and pending users with their roles and assigned plan types.

tip

Secret fields below accept either an AWS Secrets Manager ARN or a value pasted directly into SubImage's managed vault. See Secrets for details.

Required Fields

Field Secret? Description
zoom_account_id No Account ID from the Server-to-Server OAuth app's App Credentials page
zoom_client_id No Client ID from the same page
zoom_client_secret Yes Client secret from the same page: its AWS Secrets Manager ARN, or the vault value

Required Permissions

OAuth scope Purpose
user:read:list_users:admin List active, inactive, and pending users

No write, meeting, recording, or billing scopes are needed.

Setup Steps

  1. Sign in to the Zoom App Marketplace as an account owner or admin of the account to sync.
  2. Select Developers, then + > Build app on the Created apps page. Choose Server to Server OAuth App and name it SubImage.
  3. On App Credentials, copy the Account ID, Client ID, and Client Secret.
  4. Fill in the Information page with your company and a monitored contact email.
  5. Skip Feature; SubImage does not use event subscriptions.
  6. On Scopes, click Add Scopes, search for user:read:list_users:admin, and add View users.
  7. On Activation, click Activate your app and confirm Zoom shows the app as activated.
  8. In SubImage, enter the three values in zoom_account_id, zoom_client_id, and zoom_client_secret.
  9. Save the module and run a sync.

Notes

  • The sync is read-only.
  • SubImage exchanges the app credentials for a short-lived access token on each run. You do not paste an access token or complete an interactive login.
  • One Zoom account per module configuration. Zoom for Government is not supported.

Troubleshooting

  • Zoom app not activated: Zoom refused to issue a token. Activate the app on its Activation page and confirm zoom_account_id is the Account ID from App Credentials, not an email or account number.
  • 401 Unauthorized: the client ID or secret is wrong, or the app was deactivated.
  • 403 Forbidden: the app is missing user:read:list_users:admin. Add the scope and reactivate the app.