Zoom
Purpose
Collects one Zoom account's active, inactive, and pending users with their roles and assigned plan types.
tip
Secret fields below accept either an AWS Secrets Manager ARN or a value pasted directly into SubImage's managed vault. See Secrets for details.
Required Fields
| Field | Secret? | Description |
|---|---|---|
zoom_account_id |
No | Account ID from the Server-to-Server OAuth app's App Credentials page |
zoom_client_id |
No | Client ID from the same page |
zoom_client_secret |
Yes | Client secret from the same page: its AWS Secrets Manager ARN, or the vault value |
Required Permissions
| OAuth scope | Purpose |
|---|---|
user:read:list_users:admin |
List active, inactive, and pending users |
No write, meeting, recording, or billing scopes are needed.
Setup Steps
- Sign in to the Zoom App Marketplace as an account owner or admin of the account to sync.
- Select Developers, then + > Build app on the Created apps page. Choose Server to Server OAuth App and name it
SubImage. - On App Credentials, copy the Account ID, Client ID, and Client Secret.
- Fill in the Information page with your company and a monitored contact email.
- Skip Feature; SubImage does not use event subscriptions.
- On Scopes, click Add Scopes, search for
user:read:list_users:admin, and add View users. - On Activation, click Activate your app and confirm Zoom shows the app as activated.
- In SubImage, enter the three values in
zoom_account_id,zoom_client_id, andzoom_client_secret. - Save the module and run a sync.
Notes
- The sync is read-only.
- SubImage exchanges the app credentials for a short-lived access token on each run. You do not paste an access token or complete an interactive login.
- One Zoom account per module configuration. Zoom for Government is not supported.
Troubleshooting
- Zoom app not activated: Zoom refused to issue a token. Activate the app on its Activation page and confirm
zoom_account_idis the Account ID from App Credentials, not an email or account number. - 401 Unauthorized: the client ID or secret is wrong, or the app was deactivated.
- 403 Forbidden: the app is missing
user:read:list_users:admin. Add the scope and reactivate the app.