Stackleaks
Sign in

Zoom: adding, using and removing the Stackleaks app

Stackleaks reads your Zoom user list to find seats you pay for but nobody uses — read-only, revocable at any time, from either side. This page is the complete guide to the integration's lifecycle.

What the app can see

  • user:read:list_users:admin — your Zoom user list: emails, Basic vs Licensed seat type, and each user's last sign-in — the whole ghost/dormant check in one read.
  • user:read:user:admin — reading a single user's details when the list needs disambiguating.

Both scopes are read-only. Stackleaks can never create, change, or delete Zoom users, meetings, or settings, and it never reads meeting content, recordings, or chat. The full per-connector access list lives on What we can see.

Adding the app

  1. You need a Stackleaks account (free — sign up and connect your Google Workspace or Microsoft 365 directory first; that roster is what Zoom seats are cross-checked against).
  2. You need to be a Zoom account admin — the app reads the account-wide user list, so a member account can't authorize it.
  3. In Stackleaks, go to Connectors (or the "Connect your tools" step of onboarding) and click Connect Zoom →.
  4. Zoom shows its consent screen listing exactly the two read scopes above. Click Allow.
  5. You land back in Stackleaks and the first scan starts automatically — results appear in your report within a minute or two.
Connect Zoom → Create a free account

Using the app

There is nothing to configure. After connecting:

  • Your report at stackleaks.com/report lists every Zoom seat: Licensed seats are valued at list price, Basic (free) seats are honestly counted as $0 and never flagged as waste.
  • Ghost seats — people offboarded from your identity directory who still hold an active Zoom seat — and dormant seats (a Licensed seat with no sign-in for 90+ days) appear as findings with their annual cost.
  • On the free Scan tier you can re-scan manually every 7 days. On Monitor, Zoom re-syncs nightly, new ghosts trigger a same-week alert mail, and the Monday digest tracks what you recovered.
  • Users with no recorded sign-in are marked "activity unknown" — we never call a seat dormant just because Zoom didn't tell us.

Removing the app

Two ways:

  1. From Stackleaks: Connectors → Zoom → Disconnect. We revoke our OAuth tokens with Zoom immediately and delete them, so we can read nothing from that moment on. Your scan history — Zoom seats, findings, recovered money — stays, so reconnecting never costs you your history. Want the Zoom data gone as well? Remove the app in Zoom (below) or mail [email protected].
  2. From Zoom: sign in at zoom.us → Admin → Advanced → App Marketplace → Manage → Added Apps → find Stackleaks → Remove. Zoom notifies us, our tokens stop working instantly, and we hard-delete everything read through the connector — Zoom seats, their findings, the lot. Backups roll off within 30 days.

Data-deletion requests are acknowledged within 2 business days and executed within 7 — the same promise as on our security page.

Support

Stuck, or seeing something odd? stackleaks.com/support reaches a human, or mail [email protected] directly.