From 370e9ff5ae240f77507244ba8ca21eb977fd2895 Mon Sep 17 00:00:00 2001 From: Jacob Sampson Date: Wed, 30 Sep 2026 10:57:10 -0500 Subject: [PATCH] zoom: make CLIENT_SECRET optional for Zoom public clients (1.0.1) Co-authored-by: Cursor --- third_party/zoom/.cursor-plugin/plugin.json | 9 ++++----- third_party/zoom/CHANGELOG.md | 5 +++++ third_party/zoom/README.md | 15 +++++++++------ third_party/zoom/mcp.json | 2 +- 4 files changed, 19 insertions(+), 12 deletions(-) diff --git a/third_party/zoom/.cursor-plugin/plugin.json b/third_party/zoom/.cursor-plugin/plugin.json index e1f29f01f..7a0ac4fc2 100644 --- a/third_party/zoom/.cursor-plugin/plugin.json +++ b/third_party/zoom/.cursor-plugin/plugin.json @@ -1,7 +1,7 @@ { "name": "zoom", "displayName": "Zoom", - "version": "1.0.0", + "version": "1.0.1", "description": "Search meetings, pull transcripts, and work with Zoom Docs.", "author": { "name": "Cursor", @@ -31,17 +31,16 @@ "CLIENT_ID": { "type": "string", "title": "Zoom Client ID", - "description": "OAuth Client ID from your Zoom App Marketplace General app → Basic Information → App Credentials." + "description": "Public Client ID (recommended) or Client ID from your Zoom App Marketplace General app → Basic Information → App Credentials. The Public Client ID appears after turning on Use Public Client OAuth." }, "CLIENT_SECRET": { "type": "string", "title": "Zoom Client Secret", - "description": "OAuth Client Secret from the same Zoom General app." + "description": "Optional. Leave blank with a Public Client ID; Cursor then signs in with PKCE and no secret. Only set it alongside the confidential Client ID from the same app." } }, "required": [ - "CLIENT_ID", - "CLIENT_SECRET" + "CLIENT_ID" ] }, "mcpServers": "./mcp.json" diff --git a/third_party/zoom/CHANGELOG.md b/third_party/zoom/CHANGELOG.md index 6fe3efdbf..20f86f1d0 100644 --- a/third_party/zoom/CHANGELOG.md +++ b/third_party/zoom/CHANGELOG.md @@ -2,6 +2,11 @@ All notable changes to this plugin will be documented here. +## 1.0.1 + +- Made `CLIENT_SECRET` optional so a Zoom Public Client ID signs in with PKCE and no secret, which is what Zoom requires for the desktop loopback redirect. +- Documented the desktop redirect as `http://127.0.0.1:8787/callback`, since Zoom rejects `localhost`. + ## 1.0.0 — initial release - Logo: Zoom's official 180×180 apple-touch icon. diff --git a/third_party/zoom/README.md b/third_party/zoom/README.md index 4497b2008..46c110833 100644 --- a/third_party/zoom/README.md +++ b/third_party/zoom/README.md @@ -8,7 +8,7 @@ Search meetings and recordings, pull summaries and transcripts, and work with Zo 1. Open **Cursor Settings → Plugins**. 2. Search for **Zoom**. -3. Click **Install**, then set the client ID and secret (below) and complete the Zoom sign-in prompt. +3. Click **Install**, then set the client ID (below) and complete the Zoom sign-in prompt. Or run `/add-plugin zoom` in chat. @@ -22,7 +22,7 @@ Or run `/add-plugin zoom` in chat. "url": "https://mcp.zoom.us/mcp/zoom/streamable", "auth": { "CLIENT_ID": "${CLIENT_ID}", - "CLIENT_SECRET": "${CLIENT_SECRET}" + "CLIENT_SECRET": "${CLIENT_SECRET:-}" } } } @@ -36,12 +36,15 @@ Zoom's MCP servers only support manual client registration — Dynamic Client Re 1. A Zoom admin or developer logs into the [Zoom App Marketplace](https://marketplace.zoom.us) and creates a **General app** under **Develop → Build app**. 2. Add the scopes listed for each tool in [Zoom's MCP server docs](https://developers.zoom.us/docs/mcp/servers/). Meeting search and recordings need `ai_companion:read:search` for cross-Zoom search. 3. Under **Basic Information → OAuth Information**, register both redirect URIs: - - Desktop: `http://localhost:8787/callback` + - Desktop: `http://127.0.0.1:8787/callback` - Web and Cloud Agents: `https://www.cursor.com/agents/mcp/oauth/callback` -4. In **Dashboard → Plugins → Configure**, set **Zoom Client ID** and **Zoom Client Secret** from that app's **App Credentials**. -5. Complete the Zoom OAuth login when Cursor prompts. +4. Under **Basic Information → App Credentials**, turn on **Use Public Client OAuth** and copy the **Public Client ID**. +5. In **Dashboard → Plugins → Configure**, set **Zoom Client ID** to that Public Client ID and leave **Zoom Client Secret** blank. +6. Complete the Zoom OAuth login when Cursor prompts. -Each member needs a license for the Zoom products they want to reach. On a team marketplace an admin sets the client ID and secret once for everyone; each member still completes their own Zoom OAuth login, so tool calls run with that member's Zoom permissions. +Zoom only accepts a loopback redirect such as `http://127.0.0.1:8787/callback` for a public client, and rejects `localhost` outright. A public client proves each sign-in with PKCE instead of a shared secret, so there is no secret to store or leak. The confidential Client ID and Client Secret pair still works for Web and Cloud Agents, but Zoom refuses its desktop loopback redirect. + +Each member needs a license for the Zoom products they want to reach. On a team marketplace an admin sets the client ID once for everyone; each member still completes their own Zoom OAuth login, so tool calls run with that member's Zoom permissions. ## Other Zoom MCP servers diff --git a/third_party/zoom/mcp.json b/third_party/zoom/mcp.json index a630263ab..0e09713ec 100644 --- a/third_party/zoom/mcp.json +++ b/third_party/zoom/mcp.json @@ -5,7 +5,7 @@ "url": "https://mcp.zoom.us/mcp/zoom/streamable", "auth": { "CLIENT_ID": "${CLIENT_ID}", - "CLIENT_SECRET": "${CLIENT_SECRET}" + "CLIENT_SECRET": "${CLIENT_SECRET:-}" } } }