Zoom
Connecting Zoom lets big read your account's cloud recordings, so coaching call transcripts are stored against the right client records. Once an hour big picks up each new transcript, who attended and, when Zoom made one, the AI Companion summary. You connect it with a Server-to-Server OAuth app that an admin on your Zoom account creates just for big
Use an app made just for big, with read-only scopes
A Server-to-Server OAuth app belongs to your Zoom account, not to a person, so the connection keeps working when someone leaves the team. You decide exactly what it can do by choosing its scopes.
Give the app read-only scopes and nothing else. big needs these four:
| Scope | Why big needs it |
|---|---|
user:read:user:admin | To check the connection works and show which Zoom account it is. |
user:read:list_users:admin | To find the people on your account who host calls. |
cloud_recording:read:list_user_recordings:admin | To find the cloud recordings for your calls. |
cloud_recording:read:recording:admin | To read a recording's transcript files. |
Two more are optional. Without them big still stores transcripts, just with less to match on:
| Optional scope | What it adds |
|---|---|
meeting:read:list_past_participants:admin | Who attended, so each call is linked to the right clients. |
meeting:read:summary:admin | Zoom's AI Companion summary, shown next to the transcript. |
big checks the scopes Zoom reports every time it signs in. If the app has any scope that can write, update or delete, big refuses the connection, so a too-powerful app is caught rather than silently used.
Create the app
You need to be a Zoom admin, or have a role that allows creating Server-to-Server OAuth apps.
- Sign in to the Zoom App Marketplace, open Develop → Build App, and choose Server-to-Server OAuth App. Name it, for example "big".
- On App Credentials, note the Account ID, Client ID and Client secret. You'll paste all three into big
- Fill in the Information page (app name, company name and a contact email are required).
- On Scopes, choose Add Scopes and add only the scopes above.
- On Activation, choose Activate your app. An app that isn't activated can't sign in, and big's test will fail.
Keep the client secret somewhere safe only until you've pasted it into big
Connect it in big
Open Connect → Integrations → Browse catalog, choose Zoom, paste the Account ID, Client ID and Client secret, and save. big signs in to Zoom with them, makes one read-only call that returns the account's own user, and shows that user's email once it is connected. The full walkthrough, including rotating and disconnecting, is Connect an integration.
Only the client secret is treated as a secret. The Account ID and Client ID identify the app but can't be used without the secret, so big keeps them as plain settings. Each time big talks to Zoom it exchanges these for an access token that lasts about an hour. That token is kept only in memory and is never saved or logged.
When you rotate or disconnect
big can't revoke a Zoom app. After rotating or disconnecting in big, regenerate the client secret on the app's App Credentials page, or deactivate the app in the Zoom App Marketplace.