zoom: make CLIENT_SECRET optional for Zoom public clients - #467
Merged
SamSokolin merged 1 commit intoSep 30, 2026
Merged
Conversation
Co-authored-by: Cursor <cursoragent@cursor.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Zoom refuses
localhostand127.0.0.1redirects for a confidential client ID and secret pair, so desktop sign-in fails with the credentials the README asked for. A Zoom Public Client ID (Use Public Client OAuth) accepts the loopback redirect and signs in with PKCE, but the plugin required a secret that the public client does not have.CLIENT_SECRETis now optional and expands to an empty value when unset, so Cursor omits it and exchanges the code with PKCE alone. The README now recommends the Public Client ID and documents the desktop redirect ashttp://127.0.0.1:8787/callback, which is the host Cursor sends to Zoom.Note
Low Risk
Documentation and plugin variable defaults for Zoom OAuth only; no application runtime or shared auth infrastructure changes.
Overview
Bumps the Zoom plugin to 1.0.1 and fixes desktop OAuth by treating Public Client ID + PKCE as the recommended path instead of requiring a client secret.
CLIENT_SECRETis optional inplugin.json(onlyCLIENT_IDis required), with copy that explains PKCE when the secret is blank. MCP auth inmcp.jsonand the README example use${CLIENT_SECRET:-}so an unset secret is omitted and Cursor can complete the token exchange with PKCE alone.Setup docs now steer admins to Use Public Client OAuth, register the desktop redirect as
http://127.0.0.1:8787/callback(notlocalhost), and leave the secret empty for desktop; confidential ID/secret remains noted for Web and Cloud Agents.Reviewed by Cursor Bugbot for commit 370e9ff. Bugbot is set up for automated code reviews on this repo. Configure here.