Zoom Rest Api logo

Zoom Rest Api

Organization
zoom
zoom-rest-api

Zoom REST API - 600+ endpoints for meetings, users, webinars, recordings, reports, and more. Server-side API for managing Zoom resources programmatically with OAuth 2.0 authentication.

Overview

Publisherzoom
Repositoryskills
Skill namezoom-rest-api
Stars
78
Forks
16
Bundled files
123
LicenseMIT
Links
  • Markdown instructions

    A SKILL.md file the model loads on demand, so it only costs tokens when a request actually matches.

  • Works with any LLM

    AI skills are plain Markdown, not provider-specific code, so this works with GPT, Claude, Gemini, Grok, or a local model.

  • 123 bundled files

    Scripts, templates, and references the model can read while it works. Files are read-only and never executed.

  • Open source

    Published by zoom on GitHub. Read the source before you install it.

Installation

Install the Zoom Rest Api AI skill in TypingMind to use it with any LLM, or drop it into another agent that reads SKILL.md.

1

Install in TypingMind

TypingMind installs a skill straight from its GitHub folder — it reads SKILL.md, bundles the resource files, and stores the result locally.

  1. Open the app and go to Plugins → Skills.
  2. Choose "Install from GitHub".
  3. Paste the skill folder URL below and confirm.
  4. Enable the skill in any chat where you want it available.
Plugins → Skills → Add skill → From GitHub URL, then paste the folder URL and press Continue.
2

Install in another agent

Any agent that reads the Agent Skills format can use this skill — copy the folder into that agent's skills directory.

Claude Code — .claude/skills
git clone --depth 1 https://github.com/zoom/skills.git /tmp/skills
mkdir -p .claude/skills
cp -r /tmp/skills/skills/rest-api .claude/skills/zoom-rest-api
Restart Claude Code after copying so it picks up the new skill.

Use it in TypingMind

Enable Zoom Rest Api in any TypingMind chat and the model takes it from there. Its name and description sit in the system prompt, and the moment a request matches, the model loads the full instructions itself — you never invoke it by hand, and it costs no tokens until it is actually used.

The model loads Zoom Rest Api on its own as soon as a request matches it.

Works with any AI model

AI skills are plain Markdown instructions rather than provider-specific code, so Zoom Rest Api is not tied to the model it was written for. Install it once in TypingMind and use it with GPT-5, Claude, Gemini, Grok, DeepSeek, Mistral, Llama, or a local model you run yourself — all on your own API keys.

  • Loaded only when it is needed

    The system prompt carries just the name and description. The instructions are fetched on the first matching request, so an idle skill costs nothing.

  • Switch models mid-chat

    Because the skill is instructions rather than code, changing model does not break it — the next model reads the same SKILL.md.

Skill instructions

This is the SKILL.md content the model loads. Read it before installing — a skill is instructions your model will follow.

Zoom REST API

Expert guidance for building server-side integrations with the Zoom REST API. This API provides 600+ endpoints for managing meetings, users, webinars, recordings, reports, and all Zoom platform resources programmatically.

Official Documentation: https://developers.zoom.us/api-hub/ API Hub Reference: https://developers.zoom.us/api-hub/meetings/ OpenAPI Inventories: https://developers.zoom.us/api-hub/<domain>/methods/endpoints.json

Quick Links

New to Zoom REST API? Follow this path:

  1. API Architecture - Base URLs, regional URLs, me keyword, ID vs UUID, time formats
  2. Authentication Flows - OAuth setup (S2S, User, PKCE, Device Code)
  3. Meeting URLs vs Meeting SDK - Stop mixing join_url with Meeting SDK
  4. Meeting Lifecycle - Create → Update → Start → End → Delete with webhooks
  5. Rate Limiting Strategy - Plan tiers, per-user limits, retry patterns

Reference:

  • Meetings - Meeting CRUD, types, settings
  • Users - User provisioning and management
  • Recordings - Cloud recording access and download
  • AI Services - Scribe, Summarizer, and Translator endpoint inventory and current AI Services path surface
  • Marketplace Apps - App creation, manifest validation, native app types, and response quirks
  • Marketplace Templates - Scenario manifests, native create requests, and merge-only feature fragments
  • Connect, Actions, and Triggers - External REST/MCP connectors and manifest-managed workflow capabilities
  • GraphQL Queries - Alternative query API (beta)
  • Integrated Index - see the section below in this file

Most domain files under references/ are aligned to the official API Hub endpoints.json inventories. Treat those files as the local source of truth for method/path discovery.

Having issues?

Building event-driven integrations?

Quick Start

Get an Access Token (Server-to-Server OAuth)

bash
curl -X POST "https://zoom.us/oauth/token" \
  -H "Authorization: Basic $(echo -n 'CLIENT_ID:CLIENT_SECRET' | base64)" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=account_credentials&account_id=ACCOUNT_ID"

Response:

json
{
  "access_token": "eyJhbGciOiJIUzI1NiJ9...",
  "token_type": "bearer",
  "expires_in": 3600,
  "scope": "meeting:read meeting:write user:read"
}

Create a Meeting

bash
curl -X POST "https://api.zoom.us/v2/users/HOST_USER_ID/meetings" \
  -H "Authorization: Bearer ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "topic": "Team Standup",
    "type": 2,
    "start_time": "2025-03-15T10:00:00Z",
    "duration": 30,
    "settings": {
      "join_before_host": false,
      "waiting_room": true
    }
  }'

For S2S OAuth, use an explicit host user ID or email in the path. Do not use me.

List Users with Pagination

bash
curl "https://api.zoom.us/v2/users?page_size=300&status=active" \
  -H "Authorization: Bearer ACCESS_TOKEN"

Base URL

https://api.zoom.us/v2

Regional Base URLs

The api_url field in OAuth token responses indicates the user's region. Use regional URLs for data residency compliance:

RegionURL
Global (default)https://api.zoom.us/v2
Australiahttps://api-au.zoom.us/v2
Canadahttps://api-ca.zoom.us/v2
European Unionhttps://api-eu.zoom.us/v2
Indiahttps://api-in.zoom.us/v2
Saudi Arabiahttps://api-sa.zoom.us/v2
Singaporehttps://api-sg.zoom.us/v2
United Kingdomhttps://api-uk.zoom.us/v2
United Stateshttps://api-us.zoom.us/v2

Note: You can always use the global URL https://api.zoom.us regardless of the api_url value.

Key Features

FeatureDescription
Meeting ManagementCreate, read, update, delete meetings with full scheduling control
User ProvisioningAutomated user lifecycle (create, update, deactivate, delete)
Webinar OperationsWebinar CRUD, registrant management, panelist control
Cloud RecordingsList, download, delete recordings with file-type filtering
Reports & AnalyticsUsage reports, participant data, daily statistics
Team ChatChannel management, messaging, chatbot integration
Zoom PhoneCall management, voicemail, call routing
Zoom RoomsRoom management, device control, scheduling
WebhooksReal-time event notifications for 100+ event types
WebSocketsPersistent event streaming without public endpoints
GraphQL (Beta)Single-endpoint flexible queries at v3/graphql
AI CompanionMeeting summaries, transcripts, AI-generated content
AI ServicesScribe transcription, Summarizer transcript summaries, and Translator text translation via Build-platform JWT-authenticated endpoints

Prerequisites

  • Zoom account (Free tier has API access with lower rate limits)
  • App registered on Zoom App Marketplace
  • OAuth credentials (Server-to-Server OAuth or General App OAuth/client credentials)
  • Appropriate scopes for target endpoints

Need to create or validate the app first? Use Marketplace app management before implementing REST calls. It covers General App manifests, S2S rollout quirks, app-owned client_credentials scopes, event subscription setup, credential response shapes, and the requirement to manually create a first bootstrap app before the app-creation API can authorize creation of later apps. For automation, select from the machine-readable Marketplace template index and follow the manifest update workflow when changing an existing General App.

Need help with authentication? See the zoom-oauth skill for complete OAuth flow implementation.

Critical Gotchas and Best Practices

⚠️ JWT App Type is Deprecated

The JWT app type is deprecated. Migrate to Server-to-Server OAuth. This does NOT affect JWT token signatures used in Video SDK — only the Marketplace "JWT" app type for REST API access.

javascript
// OLD (JWT app type - DEPRECATED)
const token = jwt.sign({ iss: apiKey, exp: expiry }, apiSecret);

// NEW (Server-to-Server OAuth)
const token = await getServerToServerToken(accountId, clientId, clientSecret);

⚠️ The me Keyword Rules

  • General App user-level scoped tokens: MUST use me instead of userId for current-user endpoints (otherwise: invalid token error)
  • Server-to-Server OAuth apps: MUST NOT use me — provide the actual userId or email
  • General App admin/account-level scoped tokens: Can use me or an allowed userId, depending on the endpoint and granted scopes

⚠️ Meeting ID vs UUID — Double Encoding

UUIDs that begin with / or contain // must be double URL-encoded:

javascript
// UUID: /abc==
// Single encode: %2Fabc%3D%3D
// Double encode: %252Fabc%253D%253D  ← USE THIS

const uuid = '/abc==';
const encoded = encodeURIComponent(encodeURIComponent(uuid));
const url = `https://api.zoom.us/v2/meetings/${encoded}`;

⚠️ Time Formats

  • yyyy-MM-ddTHH:mm:ssZUTC time (note the Z suffix)
  • yyyy-MM-ddTHH:mm:ssLocal time (no Z, uses timezone field)
  • Some report APIs only accept UTC. Check the API reference for each endpoint.

⚠️ Rate Limits Are Per-Account, Not Per-App

All apps on the same Zoom account share rate limits. One heavy app can impact others. Monitor X-RateLimit-Remaining headers proactively.

⚠️ Per-User Daily Limits

Meeting/Webinar create/update operations are limited to 100 per day per user (resets at 00:00 UTC). Distribute operations across different host users when doing bulk operations.

⚠️ Download URLs Require Auth and Follow Redirects

Recording download_url values require Bearer token authentication and may redirect. Always follow redirects:

bash
curl -L -H "Authorization: Bearer ACCESS_TOKEN" "https://zoom.us/rec/download/..."

Use Webhooks Instead of Polling

javascript
// DON'T: Poll every minute (wastes API quota)
setInterval(() => getMeetings(), 60000);

// DO: Receive webhook events in real-time
app.post('/webhook', (req, res) => {
  if (req.body.event === 'meeting.started') {
    handleMeetingStarted(req.body.payload);
  }
  res.status(200).send();
});

Webhook setup details: See the zoom-webhooks skill for comprehensive webhook implementation.

Complete Documentation Library

This skill includes comprehensive guides organized by category:

Core Concepts

Complete Examples

Troubleshooting

  • Common Errors - HTTP status codes, Zoom error codes, error response formats
  • Common Issues - Rate limits, token refresh, pagination pitfalls, gotchas

References (39 files covering all Zoom API domains)

Core APIs
Communication
Infrastructure
Advanced
Additional API Domains

Sample Repositories

Official (by Zoom)

TypeRepository
OAuth Sampleoauth-sample-app
S2S OAuth Starterserver-to-server-oauth-starter-api
General App user OAuthuser-level-oauth-starter
S2S Tokenserver-to-server-oauth-token
Rivet Libraryrivet-javascript
WebSocket Samplewebsocket-js-sample
Webhook Samplewebhook-sample-node.js
Python S2Sserver-to-server-python-sample

Resources


Need help? Start with Integrated Index section below for complete navigation.


Integrated Index

This section was migrated from SKILL.md.

Quick Start Path

If you're new to the Zoom REST API, follow this order:

  1. Run preflight checks firstRUNBOOK.md

  2. Understand the API designconcepts/api-architecture.md

    • Base URLs, regional endpoints, me keyword rules
    • Meeting ID vs UUID, double-encoding, time formats
  3. Set up authenticationconcepts/authentication-flows.md

    • Server-to-Server OAuth (backend automation)
    • General App OAuth with PKCE when needed (user-facing or admin-installed apps)
    • Cross-reference: zoom-oauth
  4. Create your first meetingexamples/meeting-lifecycle.md

    • Full CRUD with curl and Node.js examples
    • Webhook event integration
  5. Handle rate limitsconcepts/rate-limiting-strategy.md

    • Plan-based limits, retry patterns, request queuing
  6. Set up webhooksexamples/webhook-server.md

    • CRC validation, signature verification, event handling
  7. Troubleshoot issuestroubleshooting/common-issues.md

    • Token refresh, pagination pitfalls, common gotchas

Documentation Structure

rest-api/
├── SKILL.md                              # Main skill overview + quick start
├── SKILL.md                              # This file - navigation guide
├── concepts/                             # Core architectural concepts
│   ├── api-architecture.md              # REST design, URLs, IDs, time formats
│   ├── authentication-flows.md          # OAuth flows (S2S, User, PKCE, Device)
│   └── rate-limiting-strategy.md        # Limits by plan, retry, queuing
├── examples/                             # Complete working code
│   ├── meeting-lifecycle.md             # Create→Update→Start→End→Delete
│   ├── user-management.md              # CRUD users, pagination, bulk ops
│   ├── recording-pipeline.md           # Download recordings via webhooks
│   ├── webhook-server.md               # Express.js CRC + signature verification
│   └── graphql-queries.md              # GraphQL queries, mutations, pagination
├── troubleshooting/                      # Problem solving
│   ├── common-errors.md                # HTTP codes, Zoom error codes table
│   └── common-issues.md               # Rate limits, tokens, pagination pitfalls
└── references/                           # 39 domain-specific reference files
    ├── authentication.md                # Auth methods reference
    ├── meetings.md                      # Meeting endpoints
    ├── users.md                         # User management endpoints
    ├── webinars.md                      # Webinar endpoints
    ├── recordings.md                    # Cloud recording endpoints
    ├── reports.md                       # Reports & analytics
    ├── accounts.md                      # Account management
    ├── rate-limits.md                   # Rate limit details
    ├── graphql.md                       # GraphQL API (beta)
    ├── zoom-team-chat.md                     # Team Chat messaging
    ├── chatbot.md                       # Chatbot integration
    ├── phone.md                         # Zoom Phone
    ├── rooms.md                         # Zoom Rooms
    ├── calendar.md                      # Zoom Calendar
    ├── mail.md                          # Zoom Mail
    ├── ai-companion.md                  # AI features
    ├── openapi.md                       # OpenAPI specs
    ├── qss.md                           # Quality of Service
    ├── contact-center.md                # Contact Center
    ├── events.md                        # Zoom Events
    ├── whiteboard.md                    # Whiteboard
    ├── clips.md                         # Zoom Clips
    ├── scheduler.md                     # Scheduler
    ├── scim2.md                         # SCIM 2.0
    ├── marketplace-apps.md              # App management
    ├── zoom-video-sdk-api.md                 # Video SDK REST
    └── ... (39 total files)

By Use Case

I want to create and manage meetings

  1. API Architecture - Base URL, time formats
  2. Meeting Lifecycle - Full CRUD + webhook events
  3. Meetings Reference - All endpoints, types, settings

I want to manage users programmatically

  1. User Management - CRUD, pagination, bulk ops
  2. Users Reference - Endpoints, user types, scopes

I want to download recordings automatically

  1. Recording Pipeline - Webhook-triggered downloads
  2. Recordings Reference - File types, download auth

I want to receive real-time events

  1. Webhook Server - CRC validation, signature check
  2. Cross-reference: zoom-webhooks for comprehensive webhook docs
  3. Cross-reference: zoom-websockets for WebSocket events

I want to use GraphQL instead of REST

  1. GraphQL Queries - Queries, mutations, pagination
  2. GraphQL Reference - Available entities, scopes, rate limits

I want to set up authentication

  1. Authentication Flows - All OAuth methods
  2. Cross-reference: zoom-oauth for full OAuth implementation

I'm hitting rate limits

  1. Rate Limiting Strategy - Limits by plan, strategies
  2. Rate Limits Reference - Detailed tables
  3. Common Issues - Practical solutions

I'm getting errors

  1. Common Errors - Error code tables
  2. Common Issues - Diagnostic workflow

I want to build webinars

  1. Webinars Reference - Endpoints, types, registrants
  2. Meeting Lifecycle - Similar patterns apply

I want to integrate Zoom Phone

  1. Phone Reference - Phone API endpoints
  2. Rate Limiting Strategy - Separate Phone rate limits

Most Critical Documents

1. API Architecture (FOUNDATION)

concepts/api-architecture.md

Essential knowledge before making any API call:

  • Base URLs and regional endpoints
  • The me keyword rules (different per app type!)
  • Meeting ID vs UUID double-encoding
  • ISO 8601 time formats (UTC vs local)
  • Download URL authentication

2. Rate Limiting Strategy (MOST COMMON PRODUCTION ISSUE)

concepts/rate-limiting-strategy.md

Rate limits are per-account, shared across all apps:

  • Free: 4/sec Light, 2/sec Medium, 1/sec Heavy
  • Pro: 30/sec Light, 20/sec Medium, 10/sec Heavy
  • Business+: 80/sec Light, 60/sec Medium, 40/sec Heavy
  • Per-user: 100 meeting create/update per day

3. Meeting Lifecycle (MOST COMMON TASK)

examples/meeting-lifecycle.md

Complete CRUD with webhook integration — the pattern most developers need first.


Key Learnings

Critical Discoveries:

  1. JWT app type is deprecated — use Server-to-Server OAuth

  2. me keyword behaves differently by app type

    • General App user-level tokens: MUST use me
    • S2S OAuth: MUST NOT use me
    • See: API Architecture
  3. Rate limiting is nuanced (don’t assume a single global rule)

    • Limits can vary by endpoint and may be enforced at account/app/user levels
    • Treat quotas as potentially shared across your account and implement backoff
    • Monitor rate limit response headers (for example X-RateLimit-Remaining)
    • See: Rate Limiting Strategy
  4. 100 meeting creates per user per day

    • This is a hard per-user limit, not related to rate limits
    • Distribute across host users for bulk operations
    • See: Rate Limiting Strategy
  5. UUID double-encoding is required for certain UUIDs

    • UUIDs starting with / or containing // must be double-encoded
    • See: API Architecture
  6. Pagination: use next_page_token, not page_number

    • page_number is legacy and being phased out
    • next_page_token is the recommended approach
    • See: Common Issues
  7. GraphQL is at /v3/graphql, not /v2/

    • Single endpoint, cursor-based pagination
    • Rate limits apply per-field (each field = one REST equivalent)
    • See: GraphQL Queries

Quick Reference

"401 Unauthorized"

Authentication Flows - Token expired or wrong scopes

"429 Too Many Requests"

Rate Limiting Strategy - Check headers for reset time

"Invalid token" when using userId

API Architecture - General App user-level tokens must use me

"How do I paginate results?"

Common Issues - Use next_page_token

"Webhooks not arriving"

Webhook Server - CRC validation required

"Recording download fails"

Recording Pipeline - Bearer auth + follow redirects

"How do I create a meeting?"

Meeting Lifecycle - Full working examples


Related Skills

SkillUse When
zoom-oauthImplementing OAuth flows, token management
zoom-webhooksDeep webhook implementation, event catalog
zoom-websocketsWebSocket event streaming
zoom-generalCross-product patterns, community repos

Based on Zoom REST API v2 (current) and GraphQL v3 (beta)

Environment Variables

Bundled files

The model reads these on demand while the skill is loaded. They are exposed as readable files and are never executed.

and 63 more files.

Frequently asked questions

What does the Zoom Rest Api AI skill do?

Zoom REST API - 600+ endpoints for meetings, users, webinars, recordings, reports, and more. Server-side API for managing Zoom resources programmatically with OAuth 2.0 authentication.

Why use Zoom Rest Api on TypingMind?

Because you install it once and use it with any model. Zoom Rest Api is plain Markdown rather than provider-specific code, so the same skill runs on GPT-5, Claude, Gemini, Grok, or a local model — and you can switch model mid-chat without it breaking. TypingMind runs on your own API keys, so you pay providers directly instead of a per-seat subscription, and your skills and chats stay in your own storage.

How do I install Zoom Rest Api in TypingMind?

Open Plugins → Skills → Install from GitHub in TypingMind and paste https://github.com/zoom/skills/tree/main/skills/rest-api. TypingMind reads its SKILL.md and bundles its files and installs it as a skill you can enable per chat.

Which AI models can use Zoom Rest Api?

Any model you connect in TypingMind. AI skills are plain Markdown instructions rather than provider-specific code, so GPT, Claude, Gemini, Grok, and local models can all load this skill when a request matches it.

How many AI models can I use with Zoom Rest Api?

As many as you like. As long as a model supports skills, you can use Zoom Rest Api with it — GPT, Claude, Gemini, Grok, DeepSeek, Mistral, Llama and more — all on TypingMind with your own API keys.

Is the Zoom Rest Api AI skill free?

Yes. It is published on GitHub by zoom under the MIT license. You only pay your own AI provider for the tokens you use.

What are AI skills?

An AI skill is a reusable instruction bundle that teaches an AI model how to do one specific task. It follows the open Agent Skills format: a SKILL.md file with a name and description, plus any scripts, templates or reference files the model may need. The model reads the instructions only when your request matches the skill, so an installed skill costs nothing until it is used.

How are AI skills different from plugins or MCP servers?

A plugin or MCP server gives a model new tools to call — code that runs somewhere and returns a result. An AI skill gives the model knowledge and process instead: how to approach a task, which steps to follow, what good output looks like. Skills are plain Markdown, so they need no server, no API key and no runtime, and they work with any model.

View all

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇