Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 4 additions & 5 deletions third_party/zoom/.cursor-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "zoom",
"displayName": "Zoom",
"version": "1.0.0",
"version": "1.0.1",
"description": "Search meetings, pull transcripts, and work with Zoom Docs.",
"author": {
"name": "Cursor",
Expand Down Expand Up @@ -31,17 +31,16 @@
"CLIENT_ID": {
"type": "string",
"title": "Zoom Client ID",
"description": "OAuth Client ID from your Zoom App Marketplace General app → Basic Information → App Credentials."
"description": "Public Client ID (recommended) or Client ID from your Zoom App Marketplace General app → Basic Information → App Credentials. The Public Client ID appears after turning on Use Public Client OAuth."
},
"CLIENT_SECRET": {
"type": "string",
"title": "Zoom Client Secret",
"description": "OAuth Client Secret from the same Zoom General app."
"description": "Optional. Leave blank with a Public Client ID; Cursor then signs in with PKCE and no secret. Only set it alongside the confidential Client ID from the same app."
}
},
"required": [
"CLIENT_ID",
"CLIENT_SECRET"
"CLIENT_ID"
]
},
"mcpServers": "./mcp.json"
Expand Down
5 changes: 5 additions & 0 deletions third_party/zoom/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,11 @@

All notable changes to this plugin will be documented here.

## 1.0.1

- Made `CLIENT_SECRET` optional so a Zoom Public Client ID signs in with PKCE and no secret, which is what Zoom requires for the desktop loopback redirect.
- Documented the desktop redirect as `http://127.0.0.1:8787/callback`, since Zoom rejects `localhost`.

## 1.0.0 — initial release

- Logo: Zoom's official 180×180 apple-touch icon.
Expand Down
15 changes: 9 additions & 6 deletions third_party/zoom/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ Search meetings and recordings, pull summaries and transcripts, and work with Zo

1. Open **Cursor Settings → Plugins**.
2. Search for **Zoom**.
3. Click **Install**, then set the client ID and secret (below) and complete the Zoom sign-in prompt.
3. Click **Install**, then set the client ID (below) and complete the Zoom sign-in prompt.

Or run `/add-plugin zoom` in chat.

Expand All @@ -22,7 +22,7 @@ Or run `/add-plugin zoom` in chat.
"url": "https://mcp.zoom.us/mcp/zoom/streamable",
"auth": {
"CLIENT_ID": "${CLIENT_ID}",
"CLIENT_SECRET": "${CLIENT_SECRET}"
"CLIENT_SECRET": "${CLIENT_SECRET:-}"
}
}
}
Expand All @@ -36,12 +36,15 @@ Zoom's MCP servers only support manual client registration — Dynamic Client Re
1. A Zoom admin or developer logs into the [Zoom App Marketplace](https://marketplace.zoom.us) and creates a **General app** under **Develop → Build app**.
2. Add the scopes listed for each tool in [Zoom's MCP server docs](https://developers.zoom.us/docs/mcp/servers/). Meeting search and recordings need `ai_companion:read:search` for cross-Zoom search.
3. Under **Basic Information → OAuth Information**, register both redirect URIs:
- Desktop: `http://localhost:8787/callback`
- Desktop: `http://127.0.0.1:8787/callback`
- Web and Cloud Agents: `https://www.cursor.com/agents/mcp/oauth/callback`
4. In **Dashboard → Plugins → Configure**, set **Zoom Client ID** and **Zoom Client Secret** from that app's **App Credentials**.
5. Complete the Zoom OAuth login when Cursor prompts.
4. Under **Basic Information → App Credentials**, turn on **Use Public Client OAuth** and copy the **Public Client ID**.
5. In **Dashboard → Plugins → Configure**, set **Zoom Client ID** to that Public Client ID and leave **Zoom Client Secret** blank.
6. Complete the Zoom OAuth login when Cursor prompts.

Each member needs a license for the Zoom products they want to reach. On a team marketplace an admin sets the client ID and secret once for everyone; each member still completes their own Zoom OAuth login, so tool calls run with that member's Zoom permissions.
Zoom only accepts a loopback redirect such as `http://127.0.0.1:8787/callback` for a public client, and rejects `localhost` outright. A public client proves each sign-in with PKCE instead of a shared secret, so there is no secret to store or leak. The confidential Client ID and Client Secret pair still works for Web and Cloud Agents, but Zoom refuses its desktop loopback redirect.

Each member needs a license for the Zoom products they want to reach. On a team marketplace an admin sets the client ID once for everyone; each member still completes their own Zoom OAuth login, so tool calls run with that member's Zoom permissions.

## Other Zoom MCP servers

Expand Down
2 changes: 1 addition & 1 deletion third_party/zoom/mcp.json
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
"url": "https://mcp.zoom.us/mcp/zoom/streamable",
"auth": {
"CLIENT_ID": "${CLIENT_ID}",
"CLIENT_SECRET": "${CLIENT_SECRET}"
"CLIENT_SECRET": "${CLIENT_SECRET:-}"
}
}
}
Expand Down
Loading