IP Addresses

The IP Address list feature allows you to declare which IP addresses your app uses to make API requests to Zoom accounts. This enables Zoom account administrators to enforce IP-based access controls for enhanced security.

When you provide IP addresses in the build flow, account administrators who install your app can:

  • Review the IP addresses your app uses.
  • Approve or reject specific IP addresses.
  • Enable IP allowlist enforcement to restrict API access to approved addresses only.

Best practice: include address in the IP Address list

We recommend you not leave the address list empty. If an account administrator enables IP Allowlist on the Zoom admin portal, and your app has no approved IP addresses, Zoom blocks all API requests from your app to that account.

For information about the experience from the administrator's perspective, see Managing the IP and domain allowlist for Marketplace apps.

Adding IP addresses to the address list

  1. Go to the Created Apps screen on the Zoom Marketplace.
  2. Open your app's configuration, and go to Basic Information > IP Addresses.
  3. Select Add IP Address/CIDR, and add the addresses your app uses.
  4. Save your changes.

IP Address format

You can provide IP addresses in two formats:

  • Single IP address: A specific IPv4 address (e.g., 192.168.1.100)
  • IP range using CIDR notation: A range of addresses (e.g., 192.168.1.0/24)

What Gets Blocked

When an account administrator enables IP allowlisting, API requests from non-approved IP addresses are blocked at the following endpoints:

  • OAuth token exchange (/oauth/token).
  • Token revocation (/oauth/revoke).
  • MCP server discovery endpoint.
  • OpenID Connect discovery endpoint.
  • All other Zoom API endpoints.

Best Practices

  • Provide IP addresses early - Configure your IP list before publishing your app to the Marketplace.
  • Use IP ranges when appropriate - If your app runs on multiple servers in the same network, use CIDR notation to cover the entire range.
  • Keep your list updated - If your infrastructure changes, update your IP list in the build flow promptly.
  • Plan for redundancy - Include all production IP addresses, including backup or failover infrastructure.

Server to Server App

S2S apps are intended for customer internal developers so they do not have IP list configuration in the build flow. If you are customer internal developer building Server-to-Server app, coordinate with your admin to declare IPs that govern S2S apps within the App IP allowlist configuration.