Skip to content

zoom: make CLIENT_SECRET optional for Zoom public clients - #467

Merged
SamSokolin merged 1 commit into
cursor:mainfrom
JacobSampson:jacobsampson/zoom-public-client
Sep 30, 2026
Merged

SamSokolin merged 1 commit into
cursor:mainfrom
JacobSampson:jacobsampson/zoom-public-client

Conversation

@JacobSampson

@JacobSampson JacobSampson commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Zoom refuses localhost and 127.0.0.1 redirects for a confidential client ID and secret pair, so desktop sign-in fails with the credentials the README asked for. A Zoom Public Client ID (Use Public Client OAuth) accepts the loopback redirect and signs in with PKCE, but the plugin required a secret that the public client does not have.

CLIENT_SECRET is now optional and expands to an empty value when unset, so Cursor omits it and exchanges the code with PKCE alone. The README now recommends the Public Client ID and documents the desktop redirect as http://127.0.0.1:8787/callback, which is the host Cursor sends to Zoom.


Note

Low Risk
Documentation and plugin variable defaults for Zoom OAuth only; no application runtime or shared auth infrastructure changes.

Overview
Bumps the Zoom plugin to 1.0.1 and fixes desktop OAuth by treating Public Client ID + PKCE as the recommended path instead of requiring a client secret.

CLIENT_SECRET is optional in plugin.json (only CLIENT_ID is required), with copy that explains PKCE when the secret is blank. MCP auth in mcp.json and the README example use ${CLIENT_SECRET:-} so an unset secret is omitted and Cursor can complete the token exchange with PKCE alone.

Setup docs now steer admins to Use Public Client OAuth, register the desktop redirect as http://127.0.0.1:8787/callback (not localhost), and leave the secret empty for desktop; confidential ID/secret remains noted for Web and Cloud Agents.

Reviewed by Cursor Bugbot for commit 370e9ff. Bugbot is set up for automated code reviews on this repo. Configure here.

Co-authored-by: Cursor <cursoragent@cursor.com>
@SamSokolin
SamSokolin merged commit 5f9a00e into cursor:main Sep 30, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants