# Setup Zoom OAUTH

> Implement Zoom authentication correctly. Use when setting up app credentials, choosing an OAuth grant, requesting scopes, handling token refresh, or debugging auth failures.

- Skill: `zoom/setup-zoom-oauth` (Agent Skill)
- Install (CLI): `npx skillmds@latest add zoom/setup-zoom-oauth`
- Raw SKILL.md: https://api.skillmd.com/api/skills/zoom/setup-zoom-oauth/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Integrations & APIs
- Author: zoom (https://skillmd.com/u/zoom)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/zoom/setup-zoom-oauth

---


# /setup-zoom-oauth

Use this skill when auth is the blocker or when auth choices will shape the entire integration.

## Scope

- App type selection
- OAuth grant selection
- Scope planning
- Token exchange and refresh
- Auth debugging and environment assumptions

## Workflow

1. Determine the app model and who is authorizing whom.
2. Create or validate the Marketplace app and manifest through [setup-zoom-marketplace-app](../setup-zoom-marketplace-app/SKILL.md).
3. Choose the correct grant flow.
4. Identify minimum scopes for the user flow.
5. Define token storage and refresh behavior.
6. Route into the deepest relevant reference docs only after the above is clear.

## Primary References

- [oauth](../oauth/SKILL.md)
- [setup-zoom-marketplace-app](../setup-zoom-marketplace-app/SKILL.md)
- [general](../general/SKILL.md)
- [rest-api](../rest-api/SKILL.md)

## Common Mistakes

- Picking a grant before clarifying the actor and tenant model
- Asking for broad scopes before confirming the exact workflow
- Forgetting refresh-token behavior and token lifecycle handling
- Reusing an old refresh token after a successful refresh instead of storing the newly returned one
- Treating auth failures as API failures without checking app configuration first

