zoom-meeting-admin
List, create, delete, and query Zoom meetings, cloud recordings, and account users via a fixed CLI (scripts/zoom-s2s.py, 7 whitelisted actions) using Server-to-Server OAuth. Use when the user asks to schedule, reschedule, cancel, find, or look up a Zoom meeting; set up a recurring Zoom; pull cloud recordings or past meeting metadata; or look up account users. Triggers on phrases like "Zoom meeting", "zoom 会议", "约 Zoom", "取消 Zoom", "录像", "schedule a Zoom", "cancel the meeting", "who's on the call", "云录制". create_meeting requires explicit confirmation of topic, start_time, duration; delete_meeting requires --yes and visible confirmation. Agent must only invoke the 7 whitelisted CLI actions and must not modify the script, import internals, or call Zoom REST directly. Requires .env with ACCOUNT_ID/CLIENT_ID/CLIENT_SECRET/USER_ID. Documentation is in Chinese; outputs follow.
Rank
62
Safety
84
Downloads
1.5k
Updated
Oct 10, 2026
Version
1.0.6
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.5K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.0.6release · observed Sep 27, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17fqnnawywqwp37410y5w9r1h83pwab:zoom-meeting-admin- Install using `clawhub skill install s17fqnnawywqwp37410y5w9r1h83pwab:zoom-meeting-admin` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/mebusw/zoom-meeting-admin before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/snapshot"
Documentation
CLAWHUB
92,980 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: zoom-meeting-admin
allowed-tools: Bash(python3 zoom-s2s.py:*) Read
compatibility: Requires Python 3.7+; performs HTTPS calls to zoom.us and api.zoom.us (network); writes a token cache to ~/.zoom-s2s-token.json (auto chmod 600); reads ZOOM_ACCOUNT_ID / ZOOM_CLIENT_ID / ZOOM_CLIENT_SECRET / ZOOM_USER_ID from a local .env.
description: List, create, delete, and query Zoom meetings, cloud recordings, and account users via a fixed CLI (scripts/zoom-s2s.py, 7 whitelisted actions) using Server-to-Server OAuth. Use when the user asks to schedule, reschedule, cancel, find, or look up a Zoom meeting; set up a recurring Zoom; pull cloud recordings or past meeting metadata; or look up account users. Triggers on phrases like "Zoom meeting", "zoom 会议", "约 Zoom", "取消 Zoom", "录像", "schedule a Zoom", "cancel the meeting", "who's on the call", "云录制". create_meeting requires explicit confirmation of topic, start_time, duration; delete_meeting requires --yes and visible confirmation. Agent must only invoke the 7 whitelisted CLI actions and must not modify the script, import internals, or call Zoom REST directly. Requires .env with ACCOUNT_ID/CLIENT_ID/CLIENT_SECRET/USER_ID. Documentation is in Chinese; outputs follow.
---
> ⚠️ **安全提示 — 凭证等同于账户管理员口令**
>
> 本 Skill 通过 `.env` 中的 `ZOOM_CLIENT_SECRET` 等 Server-to-Server OAuth 凭证访问 Zoom 账户。
> `ACCOUNT_ID + CLIENT_ID + CLIENT_SECRET` 三元组可换取 1 小时有效的账户级访问令牌,**能够读取该账户下所有会议元数据、云录像,并执行删除等破坏性操作**。
>
> **使用前请先完整阅读 [`## 凭证安全`](#凭证安全)**,遵守 `.gitignore`、`chmod 600`、最小 scope、专用 App、泄露应急等要求。
> 任何**修改脚本、import 内部函数、构造任意 payload 调用 `api_call`** 的尝试都构成越权,会被本文档明确禁止。
# Zoom Server-to-Server OAuth REST API
## 权限与约束
本 Skill 通过 `scripts/zoom-s2s.py` 调用 Zoom Server-to-Server OAuth REST API,不实现"通用 REST 代理"。
- **声明的工具**:`Bash(python3 zoom-s2s.py:*)`(仅执行本 skill 的 CLI 脚本)、`Read`(读取 SKILL.md、脚本源码、`.env.sample`、token cache 等)。
- **网络访问**:向 `https://zoom.us/oauth/token` 与 `https://api.zoom.us/v2/*` 发起 HTTPS 请求,传输头包含 `Authorization: Bearer <token>`。
- **文件写入**:在 `~/.zoom-s2s-token.json` 缓存访问令牌(已自动 `chmod 600`)。
- **凭证读取**:从仓库根目录的 `.env` 读取 `ZOOM_ACCOUNT_ID` / `ZOOM_CLIENT_ID` / `ZOOM_CLIENT_SECRET` / `ZOOM_USER_ID`。
- **允许的 Action(白名单)**——禁止构造任意 Zoom REST 请求或调用未列出的端点:
- 会议:`list_meetings` / `get_meeting` / `create_meeting` / `delete_meeting`
- 用户:`get_user` / `list_users`
- 录像:`recordings`
- **越权防护**:脚本内部包含一个 `api_call` 函数供 CLI action 复用,但这是**私有实现细节,不是对外可调用的接口**。Agent 不得通过以下任何方式旁路调用白名单外的 Zoom 端点(如 `DELETE /users/{id}`、`PATCH /accounts/{id}` 等高风险端点):
- 修改 `scripts/zoom-s2s.py`、新增 CLI action、暴露 `api_call`;
- `from zoom_s2s import api_call` 或以其他方式直接调用脚本内部函数;
- 在调用本 Skill 的同时**另起进程**用相同凭证调任意 Zoom REST API(如 `curl` 直接打 `api.zoom.us`);
- 注入参数、拼接 URL、构造任意 JSON payload 绕过 CLI 校验逻辑。
脚本遵循"最小暴露面"原则:CLI 只暴露 7 个白名单 action,**任何其他调用路径都视为越权**。
- **强人类确认**:`create_meeting` 与 `delete_meeting` 在执行前必须获得用户显式确认;`delete_meeting` 命令还需附加 `--yes` 参数。
## 凭证配置
在 `.env` 文件中配置(**仅 chmod 600,不要提交到任何 Git 仓库**):
```env
ZOOM_ACCOUNT_ID=你的AccountID
ZOOMREADME.md
# SKILL of Zoom Server-to-Server OAuth REST API Manage and schedule Zoom meetings REST API directly via Server-to-Server OAuth — no VPS required, no MCP protocol needed. > EN | [中文](README.zh-cn.md) ## Setup Steps 1. Log in to https://marketplace.zoom.us/ 2. From the "Develop" dropdown, select "build app" and create an app of type `Server-to-Server OAuth` 3. Add required OAuth Scopes 4. Get the credentials 5. Activate the app 6. Invoke this SKILL in your AI agent ## Credentials > ⚠️ **The `ZOOM_CLIENT_SECRET` in `.env` is equivalent to an account-admin password.** Anyone holding the `ACCOUNT_ID + CLIENT_ID + CLIENT_SECRET` triple can mint a 1-hour account-level access token that reads all meeting metadata, cloud recordings, and can delete meetings. > > - Never commit `.env` to git. Confirm your IDE, backup tools, and file-sync services (iCloud / Dropbox / OneDrive / Nutstore) are not auto-uploading it. > - `chmod 600 .env`. The token cache at `~/.zoom-s2s-token.json` is auto-set to `chmod 600` by the script. > - Use the **minimum scopes** you actually need (see table below). Do not enable `meeting:write:delete`, `cloud_recording:read:*`, or `user:read:list_users` unless required. > - Create a **dedicated** Server-to-Server App for this skill — do not reuse credentials from other business apps. > - If leaked: delete the App in Zoom Marketplace → re-create and rotate all four values → `rm -f ~/.zoom-s2s-token.json`. Edit the `.env` file with your Zoom Server-to-Server OAuth App credentials: ```env ZOOM_ACCOUNT_ID=yourAccountID ZOOM_CLIENT_ID=yourClientID ZOOM_CLIENT_SECRET=yourClientSecret ZOOM_USER_ID=your_user_email_or_user_id ``` ## Required OAuth Scopes Enable these in your Zoom Marketplace Server-to-Server OAuth App: | Scope | Purpose | |-------|---------| | `meeting:read:list_meetings` | List meetings | | `meeting:write:create` | Create meetings | | `meeting:write:delete` | Delete meetings | | `cloud_recording:read:list_user_recordings` | View cloud recordings | | `user:read:list_users` | List users | | `user:read:user` | Get user info | ## Quick Start ```bash cd ~/.agents/skills/zoom-s2s-oauth/scripts # List upcoming meetings python3 zoom-s2s.py list_meetings [email protected] 5 upcoming # Create a meeting (start_time format: YYYY-MM-DDTHH:MM:SS) python3 zoom-s2s.py create_meeting "Pancake Discussion" "2026-05-05T10:00:00" 60 Asia/Shanghai # Get cloud recordings python3 zoom-s2s.py recordings [email protected] 10 ``` ## Directory Structure ``` zoom-s2s-oauth/ ├── SKILL.md # AI Agent invocation guide ├── README.md # This file ├── README.zh-cn.md # 中文版 ├── .env # Credentials (do NOT commit to git!) └── scripts/ └── zoom-s2s.py # Main script (pure Python3, no external dependencies) ``` ## Comparison: MCP vs Server-to-Server REST | | MCP | Server-to-Server REST | |---|---|---| | Requires VPS | ✅ Yes (OAuth callback) | ❌ No | | Protocol | MCP (JSON-RPC) | Standard REST (pure Pyt
_meta.json
{
"ownerId": "kn75w6500mvryv9p0k3czdfww982r5xh",
"slug": "zoom-meeting-admin",
"version": "1.0.6",
"publishedAt": 1790477470935
}README.zh-cn.md
# SKILL of Zoom Server-to-Server OAuth REST API 用 Server-to-Server OAuth 直接调 Zoom meeting REST API,不需要 VPS,不需要 MCP 协议,管理和安排ZOOM会议。 > [EN](README.md) | 中文 ## 配置步骤 1. 需要先手动登录 https://marketplace.zoom.us/ 2. 在 "Develop" 下拉菜单选 "build app", 创建一个 `Server-to-Server OAuth`类型的APP 3. 添加必要的OAuth Scope。 4. 获取相关凭证密码 5. 激活APP 6. 在AI agent中调用此 SKILL ## 凭证配置 > ⚠️ **`.env` 中的 `ZOOM_CLIENT_SECRET` 等同于账户管理员口令。** 持有 `ACCOUNT_ID + CLIENT_ID + CLIENT_SECRET` 三元组即可换取 1 小时有效的账户级访问令牌,**能读取该账户下所有会议元数据、云录像,并执行删除等破坏性操作**。 > > - 千万不要把 `.env` 提交到 git。确认你的 IDE、备份工具、文件同步服务(iCloud / Dropbox / OneDrive / 坚果云)没有自动上传该文件。 > - `chmod 600 .env`。脚本缓存的 token 文件 `~/.zoom-s2s-token.json` 由脚本自动 `chmod 600`。 > - **按需开通最小 scope**(见下表)。未用到的功能不要勾选对应权限;不要轻易开启 `meeting:write:delete`、`cloud_recording:read:*`、`user:read:list_users`。 > - 为本 Skill **单独创建一个** Server-to-Server App,不要复用其他业务 App 的凭据。 > - 一旦泄露:在 Zoom Marketplace 删除该 App → 重新创建并轮换四项值 → `rm -f ~/.zoom-s2s-token.json` 强制重新认证。 编辑 `.env` 文件,填入你的 Zoom Server-to-Server OAuth App 凭证: ```env ZOOM_ACCOUNT_ID=你的AccountID ZOOM_CLIENT_ID=你的ClientID ZOOM_CLIENT_SECRET=你的ClientSecret ZOOM_USER_ID=你的用户邮箱或user_id ``` ## 需要的 OAuth Scope 在 Zoom Marketplace 你的 Server-to-Server OAuth App 里开通: | Scope | 用途 | |-------|------| | `meeting:read:list_meetings` | 列出会议 | | `meeting:write:create` | 创建会议 | | `meeting:write:delete` | 删除会议 | | `cloud_recording:read:list_user_recordings` | 查看云录像 | | `user:read:list_users` | 列出用户 | | `user:read:user` | 获取用户信息 | ## 快速开始 ```bash cd ~/.agents/skills/zoom-s2s-oauth/scripts # 列出最近5个会议 python3 zoom-s2s.py list_meetings [email protected] 5 upcoming # 创建会议 (start_time 格式: YYYY-MM-DDTHH:MM:SS) python3 zoom-s2s.py create_meeting "煎饼果子讨论会" "2026-05-05T10:00:00" 60 Asia/Shanghai # 获取云录像 python3 zoom-s2s.py recordings [email protected] 10 ``` ## 目录结构 ``` zoom-s2s-oauth/ ├── SKILL.md # AI Agent 调用说明 ├── README.md # 本文件 ├── .env # 凭证配置 (不要提交到 git!) └── scripts/ └── zoom-s2s.py # 主脚本 (纯 Python3,无外部依赖) ``` ## 对比:MCP vs Server-to-Server REST | | MCP 方式 | Server-to-Server REST | |---|---|---| | 需要 VPS | ✅ 需要 (OAuth 回调) | ❌ 不需要 | | 协议 | MCP (JSON-RPC) | 标准 REST (Python 无外部依赖) | | Token | User-Managed OAuth | Server-to-Server OAuth | | 复杂度 | 高 (代理+OAuth) | 低 (直接调) | | 功能 | Zoom MCP 工具集 | 7 个白名单 CLI action(list/get/create/delete meeting、get/list user、list recordings) | 如果你只需要调用 Zoom 会议/录像等核心功能,Server-to-Server REST 方式更简单。
skill-card.md
## Description: Helps agents manage Zoom meetings and look up account users and cloud recordings through seven approved Server-to-Server OAuth actions. This skill is ready for commercial/non-commercial use. ## Publisher: [mebusw](https://clawhub.ai/user/mebusw) ### License/Terms of Use: MIT-0 ## Use Case: Zoom account administrators and their agents use this skill to schedule, find, and cancel meetings, retrieve cloud recording information, and look up account users. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Account-level credentials and cached access tokens could expose meeting and recording data. Mitigation: Use a dedicated Zoom app, keep .env and token files private and out of repositories and sync tools, and avoid shared machines. Risk: Unnecessary Zoom permissions could enable deletion or access to sensitive recordings. Mitigation: Grant only the required OAuth scopes; leave deletion and recording access disabled unless needed. Risk: Meeting deletion is irreversible and meeting host links are sensitive. Mitigation: Require explicit confirmation before creating or deleting meetings, use --yes only after confirming deletion, and share attendee links rather than host links. ## Reference(s): - [Source repository](https://github.com/mebusw/zoom-meeting-admin) - [ClawHub skill release](https://clawhub.ai/mebusw/skills/zoom-meeting-admin) - [Zoom App Marketplace](https://marketplace.zoom.us/) ## Skill Output: **Output Type(s):** [Text, Shell commands, Guidance] **Output Format:** [Markdown with meeting details and links] **Output Parameters:** [1D] **Other Properties Related to Output:** [May include meeting IDs, attendee links, user details, and recording information; never disclose credentials or host links.] ## Skill Version(s): 1.0.6 (source: ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/mebusw/skills/zoom-meeting-admin",
"sourceUrl": "https://clawhub.ai/mebusw/skills/zoom-meeting-admin",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T09:47:59.817Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T09:47:59.817Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.5K downloads",
"href": "https://clawhub.ai/mebusw/zoom-meeting-admin",
"sourceUrl": "https://clawhub.ai/mebusw/zoom-meeting-admin",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T09:47:59.817Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.0.6",
"href": "https://clawhub.ai/mebusw/zoom-meeting-admin",
"sourceUrl": "https://clawhub.ai/mebusw/zoom-meeting-admin",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-27T02:51:10.935Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.0.6",
"description": "zoom-meeting-admin v1.0.6 - Simplified and clarified agent documentation in SKILL.md; usage notes moved and refocused. - Updated allowed tool list: Bash invocation now limited to \"python3 zoom-s2s.py\" from within scripts/ directory. - Out-of-scope functionality and response handling guidance are now explicitly documented. - Removed deprecated scripts and the skill-card.md file for a cleaner repo. - Skill trigger guidance and example agent outputs improved for clarity and precision.",
"href": "https://clawhub.ai/mebusw/zoom-meeting-admin",
"sourceUrl": "https://clawhub.ai/mebusw/zoom-meeting-admin",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-27T02:51:10.935Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
