HockeyStick AI × Zoom

Zoom integration

Turn an approved HockeyStick Webinar brief into a verified Zoom Webinar, a hosted registration journey and trustworthy post-event attendance. This page is the public reviewer resource; no HockeyStick account is required to read it.

Updated 24 August 2026

One connected journey

What the integration does

HockeyStick AI connects one designated, licensed Zoom Webinar host to one authenticated HockeyStick engagement. It keeps the customer in control while HockeyStick performs three launch workflows: it supports Webinar provisioning, hosted Webinar enrolment and post-event attendance only.

Provision

Create or update a Webinar from an approved brief, then read it back before HockeyStick treats the binding as verified.

Enrol

Send a consented registration from the HockeyStick-hosted Webinar page to Zoom and reconcile the registrant before any retry.

Reconcile

After the Webinar, match occurrence-scoped participation to the enrolment and calculate attendance evidence.

Not part of this release. The integration does not access Zoom recordings, AI Companion summaries or account-wide administration. Adding AI Companion summaries later would require an updated permission declaration and reauthorization.

Before you connect

Prerequisites

  • An active HockeyStick AI engagement with Activate enabled, and a designated integration contact who can sign in.
  • A Zoom Workplace account and a paid Webinar licence assigned to the authorizing host.
  • The authorizing host must be the engagement's designated integration contact.
  • Where Zoom app controls are enabled, an administrator may need to pre-approve HockeyStick AI first.
  • For Production, use a Zoom account not already connected to another HockeyStick engagement.

Install from HockeyStick

Connect from your engagement

Sign in, open the correct engagement, then go to Activate → Settings → Integrations and select Connect with Zoom.

Sign in to HockeyStick AI. An unauthenticated visitor cannot select an engagement from a public page.
Open the engagement and go to Activate → Settings → Integrations.
Select Connect with Zoom. Only the designated contact can start this. HockeyStick creates short-lived, single-use state bound to the engagement, stores only its SHA-256 hash and redirects to Zoom.
Review and approve in Zoom. Confirm the app name, the seven permissions below and the licensed host. In Production, the account must not already be connected to another engagement.
Wait for verification. HockeyStick reads the connected user, validates the permissions and queues an account check before the connection is shown as ready.
No public OAuth shortcut. This page never creates authorization state or links directly to Zoom authorization. Start in the authenticated engagement every time. Sign in to HockeyStick AI →

Webinar lifecycle

Create, bind and reconcile

When an authorized user confirms Create Zoom webinar, HockeyStick sends the approved timing and configuration once, records the returned Webinar identity, then performs an exact authenticated read-back. A Webinar is not treated as verified until the returned identity and expected configuration reconcile; an ambiguous result stays visible for review and HockeyStick does not blindly create another Webinar.

A participant registers on the HockeyStick-hosted page with first name, last name, email and consent; HockeyStick checks Zoom's registrant list, adds the person when needed and reconciles the enrolment. The private join link is returned to the participant and is not stored. After the event, HockeyStick reads the completed occurrence's participant timing, matches to enrolments by Zoom registrant identifier, calculates watch time and flags ambiguous matches for review.

Removal

Disconnect, remove or reconnect

Disconnect from HockeyStick: Activate → Settings → Integrations → Revoke Zoom. HockeyStick removes local authorization material immediately and asks Zoom to revoke the access token when no other active engagement shares the account.

Remove from Zoom: Zoom has already removed the app before it sends the signed app_deauthorized event, so HockeyStick does not call Zoom's revocation endpoint again. It removes local grants, pending state, direct Zoom identifiers and legacy recording links, and marks every affected engagement as requiring authorization. Zoom-derived person data is deleted or anonymized within 24 hours of that event. See the privacy policy for the full lifecycle.

Exact initial declaration

Requested permissions and why

user:read:user
Identify the authorizing Webinar hostConfirms which licensed host connected Zoom and which Zoom account owns the authorization.
webinar:read:list_webinars
List the host's WebinarsFinds Webinars owned by the connected host so HockeyStick can reconcile provider state.
webinar:read:webinar
Read one WebinarReads back the exact Webinar HockeyStick created or bound before treating it as verified.
webinar:write:webinar
Create and update WebinarsCreates an approved Webinar and keeps its timing and configuration aligned with the engagement.
webinar:write:registrant
Add hosted-Webinar registrantsEnrols a person who submits the HockeyStick-hosted Webinar registration form.
webinar:read:list_registrants
Reconcile enrolmentChecks the registrant list before and after enrolment to avoid blind duplicate writes.
webinar:read:list_past_participants
Reconcile post-event attendanceReads participant timing for the completed occurrence so attendance can be matched and measured.
Deferred: no AI Companion summary permission is requested by this release.

Support

Get help

Use the Hockey Stick Advisory contact form for Zoom integration support. No fixed support hours or response-time commitment is published for the beta.

Provide your name, organisation and a safe reply address, the engagement and Webinar identifier, the issue type, the approximate time and any visible error. For a security incident, begin the message with SECURITY; for a privacy request (access, correction, deletion, consent), begin with PRIVACY.

Never send a password, one-time code, access or refresh token, client secret, private join link or full participant list.