Zoom: adding, using and removing the Stackleaks app
Stackleaks reads your Zoom user list to find seats you pay for but nobody uses — read-only, revocable at any time, from either side. This page is the complete guide to the integration's lifecycle.
What the app can see
user:read:list_users:admin— your Zoom user list: emails, Basic vs Licensed seat type, and each user's last sign-in — the whole ghost/dormant check in one read.user:read:user:admin— reading a single user's details when the list needs disambiguating.
Both scopes are read-only. Stackleaks can never create, change, or delete Zoom users, meetings, or settings, and it never reads meeting content, recordings, or chat. The full per-connector access list lives on What we can see.
Adding the app
- You need a Stackleaks account (free — sign up and connect your Google Workspace or Microsoft 365 directory first; that roster is what Zoom seats are cross-checked against).
- You need to be a Zoom account admin — the app reads the account-wide user list, so a member account can't authorize it.
- In Stackleaks, go to Connectors (or the "Connect your tools" step of onboarding) and click Connect Zoom →.
- Zoom shows its consent screen listing exactly the two read scopes above. Click Allow.
- You land back in Stackleaks and the first scan starts automatically — results appear in your report within a minute or two.
Using the app
There is nothing to configure. After connecting:
- Your report at
stackleaks.com/reportlists every Zoom seat: Licensed seats are valued at list price, Basic (free) seats are honestly counted as $0 and never flagged as waste. - Ghost seats — people offboarded from your identity directory who still hold an active Zoom seat — and dormant seats (a Licensed seat with no sign-in for 90+ days) appear as findings with their annual cost.
- On the free Scan tier you can re-scan manually every 7 days. On Monitor, Zoom re-syncs nightly, new ghosts trigger a same-week alert mail, and the Monday digest tracks what you recovered.
- Users with no recorded sign-in are marked "activity unknown" — we never call a seat dormant just because Zoom didn't tell us.
Removing the app
Two ways:
- From Stackleaks: Connectors → Zoom → Disconnect. We revoke our OAuth tokens with Zoom immediately and delete them, so we can read nothing from that moment on. Your scan history — Zoom seats, findings, recovered money — stays, so reconnecting never costs you your history. Want the Zoom data gone as well? Remove the app in Zoom (below) or mail [email protected].
- From Zoom: sign in at zoom.us → Admin → Advanced → App Marketplace → Manage → Added Apps → find Stackleaks → Remove. Zoom notifies us, our tokens stop working instantly, and we hard-delete everything read through the connector — Zoom seats, their findings, the lot. Backups roll off within 30 days.
Data-deletion requests are acknowledged within 2 business days and executed within 7 — the same promise as on our security page.
Support
Stuck, or seeing something odd? stackleaks.com/support reaches a human, or mail [email protected] directly.