# Fleet - how does the "Oauth2 Endpoint Params" field work in integration configuration

**URL:** <https://discuss.elastic.co/t/fleet-how-does-the-oauth2-endpoint-params-field-work-in-integration-configuration/344833>\
**Category:** Elastic Agent\
**Tags:** fleet, integrations\
**Created:** [October 11, 2023, 2:56pm UTC](https://discuss.elastic.co/t/fleet-how-does-the-oauth2-endpoint-params-field-work-in-integration-configuration/344833 "2023-10-11T14:56:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mik0w](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mik0w/32/121794_2.png) [@mik0w](https://discuss.elastic.co/u/mik0w)\
**Post date:** [October 11, 2023, 2:56pm UTC](https://discuss.elastic.co/t/fleet-how-does-the-oauth2-endpoint-params-field-work-in-integration-configuration/344833/1 "2023-10-11T14:56:51Z")

</div>

Hello,  
I am trying to integrate Elastic with Zoom API. Even though there's a Zoom Webhook integration plugin available in Elastic, I want to query Zoom's REST API.

Zoom's API requires user to authenticate using OAuth and the flow to get the token is:

- you send the POST request to [zoom.us/oauth/token](http://zoom.us/oauth/token) (the request contains the Basic Auth header with ClientID and ClientSecret) and in the request's body you attach the following parameters: _grant\_type:account\_credentials_ and _account\_id:acc0untid\_str1ng_
- then, after authentication the endpoint returns a JSON with a field "access\_token", which contains JWT token that enables one to query the API.

I tried to configure this integration in the Integrations (as a new Custom API integration), but there are some differences in the Zoom Oauth flow, that makes it hard to integrate Elastic with Zoom:

- from my experience, to get access token in OAuth flow, you need to send "Authorization" header with value such as: _client\_id:something, client\_secret:something_ - it's not the case for Zoom, as it requires you to provide the credentials using HTTP Basic Auth (so client id and secret are encoded using Base64)
- you need to provide account\_id in the body as well

I haven't found a way to ensure those conditions are met using Integrations UI in Elastic.

Do you have any tips how can I overcome those issues while integrating Zoom API with Elastic? Maybe you have some experience integrating this specific API with elastic?

Thanks in advance,  
Mikołaj

---

<div class="post-metadata">

**Author:** ![Julia\_Bardi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julia_bardi/32/79463_2.png) [@Julia\_Bardi](https://discuss.elastic.co/u/Julia_Bardi)\
**Post date:** [October 12, 2023, 7:53am UTC](https://discuss.elastic.co/t/fleet-how-does-the-oauth2-endpoint-params-field-work-in-integration-configuration/344833/2 "2023-10-12T07:53:47Z")

</div>

Hi Mikolaj, welcome to the community!  
There is a Zoom integration in elastic, can you try with that? [Zoom | Documentation](https://docs.elastic.co/integrations/zoom)

---

<div class="post-metadata">

**Author:** ![mik0w](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mik0w/32/121794_2.png) [@mik0w](https://discuss.elastic.co/u/mik0w)\
**Post date:** [October 12, 2023, 8:14am UTC](https://discuss.elastic.co/t/fleet-how-does-the-oauth2-endpoint-params-field-work-in-integration-configuration/344833/3 "2023-10-12T08:14:12Z")

</div>

Yes, I know, but as I said in the beginning of the thread - for a few reasons I prefer using REST API - first of all I’d have to configure an external IP address that would serve as the webhook listener. As there is the REST API in Zoom, I’d rather use it. Main obstacle is getting this strange OAuth flow to work.

---

<div class="post-metadata">

**Author:** ![kcreddy](https://avatars.discourse-cdn.com/v4/letter/k/6f9a4e/32.png) [@kcreddy](https://discuss.elastic.co/u/kcreddy)\
**Post date:** [October 12, 2023, 12:04pm UTC](https://discuss.elastic.co/t/fleet-how-does-the-oauth2-endpoint-params-field-work-in-integration-configuration/344833/4 "2023-10-12T12:04:00Z")

</div>

You could alternately try [CEL input's Basic Authentication](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-cel.html#:~:text=Request-,Basic%20Authentication,-Do%20Request)  
like this: `.basic_authentication("Client_ID", "Client_Secret")`

The integration in this case would be `CEL Custom API`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2023, 12:04pm UTC](https://discuss.elastic.co/t/fleet-how-does-the-oauth2-endpoint-params-field-work-in-integration-configuration/344833/5 "2023-11-09T12:04:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
