Sessions · Zoom integration
How CoCap uses Zoom
CoCap Sessions are 20-minute, one-to-one English practice conversations between members. Verified hosts connect their own Zoom account so CoCap can create and run only the meetings needed for the Sessions booked with them.
What the Zoom connection does
- Reads the connected host’s basic Zoom account identity so CoCap can confirm which account was authorized.
- Creates, reads, moves, ends and deletes the host’s CoCap Session meetings.
- Requests the short-lived Zoom authorization tokens needed for the host and the booked member to enter that meeting through the Zoom Meeting SDK.
- Does not read cloud recordings, chat history, contacts, webinars, billing information or unrelated meetings.
- Does not ask for or receive the host’s Zoom password.
Connect Zoom
- Become a verified CoCap host and open Sessions → Hosting.
- Select Connect Zoom. CoCap opens Zoom’s own authorization page.
- Sign in to Zoom and review the permissions shown by Zoom, then select Allow.
- Zoom returns you to CoCap. The Hosting screen shows the connected account in masked form.
- Add your available hours. A host is bookable only when CoCap has approved the host, Zoom is connected and availability is open.
What happens for a booked Session
CoCap creates a private scheduled meeting on the host’s Zoom account close to the Session start. Automatic recording is disabled. The host enters as the Zoom host and the booked member enters as the participant inside CoCap. CoCap does not expose the meeting number or passcode as a shareable link.
The host must be present for an external-account participant to join. CoCap does not run a bot, record the call, transcribe the Session, or access raw Zoom audio/video for Sessions.
Remove CoCap from Zoom
You can remove the integration in either place:
- In CoCap, open Sessions → Hosting → Zoom connected → Disconnect. CoCap revokes the Zoom authorization when possible.
- Or sign in to the Zoom App Marketplace, open Manage → Added Apps, choose CoCap, and select Remove. Zoom notifies CoCap that the app was deauthorized.
Removing the integration makes the host unavailable for new bookings and cancels future hosted Sessions that depended on that Zoom connection. CoCap removes the stored Zoom authorization, granted scopes and Zoom profile/account identifiers from the connection. CoCap-local booking, attendance and safety records follow the retention rules in the Privacy Policy.
If you want to host again later, you can reconnect through the same Zoom authorization screen.
Privacy & security
- OAuth access and refresh tokens are encrypted before they are stored.
- The connection uses a single-use OAuth state and PKCE to protect the authorization callback.
- Meeting SDK authorization is short-lived and issued only to a member who is on that booking and inside the join window.
- CoCap verifies Zoom webhook signatures before acting on a deauthorization event.
- CoCap does not record Sessions. Members are also prohibited from recording, screenshotting or streaming them.
Troubleshooting
- Zoom says the app needs approval
- Some Zoom accounts require an account administrator to pre-approve third-party apps. Ask your Zoom administrator to approve CoCap, then try again.
- CoCap says “Reconnect Zoom”
- Your Zoom authorization is no longer valid. Open Hosting and authorize CoCap again. CoCap does not ask you for a Zoom password.
- A Session cannot open
- Return to the Session screen and try again. If it still fails, use Help & support and include the Session time; never send a meeting passcode or OAuth token.
Policies & support
Need help with the Zoom connection? Write to hello@cocap.in. We normally reply within about 2 working days.
Last reviewed: 21 September 2026.