{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "zoom-scheduler",
    "name": "Zoom Scheduler API",
    "vendor": "Zoom Communications, Inc.",
    "vendorUrl": "https://www.zoom.com",
    "kind": "http-api",
    "category": "scheduling",
    "summary": "Zoom's REST API for Zoom Scheduler, its appointment booking product. It reads schedules, availability and scheduled events, lists open slots, creates and cancels bookings and sends booking webhooks, with OAuth access on api.zoom.us.",
    "url": "https://www.anchorterminal.com/tools/zoom-scheduler",
    "markdownUrl": "https://www.anchorterminal.com/tools/zoom-scheduler.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/zoom-scheduler.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/zoom-scheduler.json",
    "license": "Proprietary service under the Zoom API Licence and Terms of Use",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.zoom.us/v2",
    "packages": [],
    "auth": "oauth",
    "authNotes": "OAuth 2.0 only. A person creates an app in the Zoom App Marketplace and picks Scheduler scopes. User apps use the authorisation code grant (PKCE supported) and get one-hour access tokens with 90-day refresh tokens. Server-to-Server OAuth apps exchange an account ID, client ID and client secret for a one-hour token with no user step, and an account administrator authorises the scopes. Granular scopes exist per operation, each with an `:admin` variant. The docs show refresh tokens and device codes sent as URL query parameters as one option.",
    "pricing": "paid",
    "pricingNotes": "Scheduler costs $5.99 a user a month, or $4.99 billed yearly, and is included in Workplace Business ($21.99 monthly). The pricing page lists \"Connect to Scheduler APIs\" under the paid Scheduler plan. Scheduler Basic is free with no card, with one booking page and one calendar, and whether it can call the API was not established. A 14-day trial is advertised. No per-call charge was found (checked 2026-10-09).",
    "priceSummary": "$5.99 / seat-mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the Scheduler reference, the rate limit and OAuth docs or the pricing page (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://developers.zoom.us/docs/api/scheduler/",
    "llmsTxt": "https://developers.zoom.us/llms.txt",
    "capabilities": [
      "calendar.read",
      "calendar.availability",
      "calendar.booking",
      "calendar.webhooks"
    ],
    "tags": [
      "hosted",
      "paid",
      "free-plan",
      "rest",
      "oauth",
      "webhooks",
      "llms-txt",
      "closed-source",
      "status-page",
      "soc2",
      "bug-bounty"
    ],
    "lastRelease": "2026-08-17",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 50.6,
      "grade": "D",
      "agentReady": false,
      "rank": 767,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 43,
        "maintenance": 28,
        "payments": 25,
        "reliability": 63,
        "schema": 61,
        "security": 54,
        "transparency": 69
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 63,
          "points": 12.6,
          "reason": "Graded as a hosted API. Statuspage site at status.zoom.us (redirects to www.zoomstatus.com) with Zoom Scheduler as its own component and REST API and Webhooks under Zoom Developer Platform (20). The front page shows 25 September to 9 October 2026, with no incident naming Scheduler or the REST API. The developer documentation site was degraded for 1 hour 54 minutes on 3 October. The history page is drawn by script and the status API is closed by robots.txt, so 90 days could not be read (10). Every Scheduler operation is labelled Light, which is 4 a second and 6,000 a day on Free, 30 a second on Pro and 80 a second on Business and above, per account (15). The docs say to wait and retry on 429 and that the daily-limit response carries a header saying when to resume. No `Retry-After` is named and no idempotency key exists for booking writes (8). No SLA found, and the API terms say Zoom does not guarantee uptime (0). No beta label on the Scheduler API, and Zoom's lifecycle page treats an initial release as stable (10). Total 63."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 61,
          "points": 9.91,
          "reason": "The reference states OpenAPI version 3.1.1, but no specification file is linked from the page, the API catalogue or llms.txt. A Markdown copy of the whole reference is published (10). llms.txt, Markdown copies of pages and an API catalogue at `/.well-known/api-catalog.json` (10). Most operations carry one line such as \"Patches a scheduled event\". The available times and booking operations say when to use them (8). Request bodies are typed, with 55 required marks, 38 enumerated fields and email, date and date-time formats. The Markdown copy and the static page omit query and path parameters (9). Every request body has an example and each operation lists its error statuses with a code name, some misspelt (11). The path is versioned v2 and the changelog has dated Scheduler entries (13). Total 61."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 43,
          "points": 6.99,
          "reason": "No field selection was found, and a schedule object runs to several hundred lines of fields. Query parameters could not be read (8). List responses return `next_page_token`, and the changelog records filters by team, account scope and created or updated time. The parameter list itself was not readable (14). Errors carry a status and a short code name such as InvalidArgument, NotFound or Conflict, with a 409 on booking conflicts and little detail (12). No idempotency key or safe-retry guidance for `POST /scheduler/attendee` (3). Booking needs six fields. No official SDK covers Scheduler, and Zoom Rivet 0.3.0 has no Scheduler module (6). Total 43."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 54,
          "points": 9.45,
          "reason": "OAuth 2.0 with granular scopes per operation, user and admin variants, PKCE, one-hour access tokens and revocation (30). The OAuth docs show refresh tokens and device codes sent in the URL query string as an option, which takes 10 off (20). Read scopes are separate from write, update and delete scopes, and Server-to-Server scopes need an administrator's approval. No confirmation step for cancelling or deleting (14). Booker names, answers and meeting notes written by outsiders reach the model, with no injection guidance found (0). No audit log of API calls was found in the pages read (0). security.txt valid to 31 December 2029, a disclosure policy with safe harbour, a private HackerOne bounty, security bulletins, and a SOC 2 Type 2 report for October 2024 to October 2025 that names Zoom Scheduler and Zoom APIs (20). Total 54."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 25,
          "points": 3.13,
          "reason": "No x402, MPP or L402 (0). Seat prices are public, $5.99 a user a month or $4.99 billed yearly, with nothing per call (10). Scheduler Basic is free with no card and a 14-day trial is advertised, but the pricing page lists API access under the paid plan and whether the free plan or the trial can call the API was not established (15). A person signs up and creates a Marketplace app in a browser (0). Total 25."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 28,
          "points": 2.45,
          "reason": "The latest Scheduler changelog entry is 17 August 2026, 53 days before this check (20). Two dated entries in the last 90 days, 13 July and 17 August (0). A public changelog with a developer forum thread for each entry and a developer support page. Whether the forum answers was not checked (8). No official SDK covers Scheduler (0). No package to assess (0). Total 28."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 69,
          "points": 6.04,
          "note": "editorial 59, provenance 79",
          "reason": "Closed service under the Zoom API Licence and Terms of Use of 16 July 2025 (15). The Privacy Statement of 17 September 2026 gives no fixed retention periods. The Terms of Service delete customer content 30 days after termination, and both documents say communications-like customer content is not used to train AI models. The DPA is a PDF we did not read (18). A lifecycle page describes deprecation and sunset stages and the changelog tags them, but the API terms let Zoom change or deprecate APIs without prior notice, with only commercially reasonable efforts to tell developers (8). The sub-processor list, updated 2 October 2026, names 24 third parties and 23 affiliates with locations and has an email sign-up for changes (18). Total 59."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "No field selection was found, and a schedule object runs to several hundred lines of fields. Query parameters could not be read (8). List responses return `next_page_token`, and the changelog records filters by team, account scope and created or updated time. The parameter list itself was not readable (14). Errors carry a status and a short code name such as InvalidArgument, NotFound or Conflict, with a 409 on booking conflicts and little detail (12). No idempotency key or safe-retry guidance for `POST /scheduler/attendee` (3). Booking needs six fields. No official SDK covers Scheduler, and Zoom Rivet 0.3.0 has no Scheduler module (6). Total 43.",
          "maintenance": "The latest Scheduler changelog entry is 17 August 2026, 53 days before this check (20). Two dated entries in the last 90 days, 13 July and 17 August (0). A public changelog with a developer forum thread for each entry and a developer support page. Whether the forum answers was not checked (8). No official SDK covers Scheduler (0). No package to assess (0). Total 28.",
          "payments": "No x402, MPP or L402 (0). Seat prices are public, $5.99 a user a month or $4.99 billed yearly, with nothing per call (10). Scheduler Basic is free with no card and a 14-day trial is advertised, but the pricing page lists API access under the paid plan and whether the free plan or the trial can call the API was not established (15). A person signs up and creates a Marketplace app in a browser (0). Total 25.",
          "reliability": "Graded as a hosted API. Statuspage site at status.zoom.us (redirects to www.zoomstatus.com) with Zoom Scheduler as its own component and REST API and Webhooks under Zoom Developer Platform (20). The front page shows 25 September to 9 October 2026, with no incident naming Scheduler or the REST API. The developer documentation site was degraded for 1 hour 54 minutes on 3 October. The history page is drawn by script and the status API is closed by robots.txt, so 90 days could not be read (10). Every Scheduler operation is labelled Light, which is 4 a second and 6,000 a day on Free, 30 a second on Pro and 80 a second on Business and above, per account (15). The docs say to wait and retry on 429 and that the daily-limit response carries a header saying when to resume. No `Retry-After` is named and no idempotency key exists for booking writes (8). No SLA found, and the API terms say Zoom does not guarantee uptime (0). No beta label on the Scheduler API, and Zoom's lifecycle page treats an initial release as stable (10). Total 63.",
          "schema": "The reference states OpenAPI version 3.1.1, but no specification file is linked from the page, the API catalogue or llms.txt. A Markdown copy of the whole reference is published (10). llms.txt, Markdown copies of pages and an API catalogue at `/.well-known/api-catalog.json` (10). Most operations carry one line such as \"Patches a scheduled event\". The available times and booking operations say when to use them (8). Request bodies are typed, with 55 required marks, 38 enumerated fields and email, date and date-time formats. The Markdown copy and the static page omit query and path parameters (9). Every request body has an example and each operation lists its error statuses with a code name, some misspelt (11). The path is versioned v2 and the changelog has dated Scheduler entries (13). Total 61.",
          "security": "OAuth 2.0 with granular scopes per operation, user and admin variants, PKCE, one-hour access tokens and revocation (30). The OAuth docs show refresh tokens and device codes sent in the URL query string as an option, which takes 10 off (20). Read scopes are separate from write, update and delete scopes, and Server-to-Server scopes need an administrator's approval. No confirmation step for cancelling or deleting (14). Booker names, answers and meeting notes written by outsiders reach the model, with no injection guidance found (0). No audit log of API calls was found in the pages read (0). security.txt valid to 31 December 2029, a disclosure policy with safe harbour, a private HackerOne bounty, security bulletins, and a SOC 2 Type 2 report for October 2024 to October 2025 that names Zoom Scheduler and Zoom APIs (20). Total 54.",
          "transparency": "Closed service under the Zoom API Licence and Terms of Use of 16 July 2025 (15). The Privacy Statement of 17 September 2026 gives no fixed retention periods. The Terms of Service delete customer content 30 days after termination, and both documents say communications-like customer content is not used to train AI models. The DPA is a PDF we did not read (18). A lifecycle page describes deprecation and sunset stages and the changelog tags them, but the API terms let Zoom change or deprecate APIs without prior notice, with only commercially reasonable efforts to tell developers (8). The sub-processor list, updated 2 October 2026, names 24 third parties and 23 affiliates with locations and has an email sign-up for changes (18). Total 59."
        },
        "sources": [
          {
            "what": "Scheduler API reference, Markdown copy",
            "url": "https://developers.zoom.us/docs/api/scheduler.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Scheduler webhook events, Markdown copy",
            "url": "https://developers.zoom.us/docs/api/scheduler/events.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Scheduler introduction",
            "url": "https://developers.zoom.us/docs/scheduler.md",
            "seen": "2026-10-09"
          },
          {
            "what": "llms.txt",
            "url": "https://developers.zoom.us/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "API catalogue",
            "url": "https://developers.zoom.us/.well-known/api-catalog.json",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP catalogue",
            "url": "https://developers.zoom.us/.well-known/mcp/server-card.json",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP servers overview",
            "url": "https://developers.zoom.us/docs/mcp/servers.md",
            "seen": "2026-10-09"
          },
          {
            "what": "rate limits",
            "url": "https://developers.zoom.us/docs/api/rate-limits.md",
            "seen": "2026-10-09"
          },
          {
            "what": "OAuth 2.0",
            "url": "https://developers.zoom.us/docs/integrations/oauth.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Server-to-Server OAuth",
            "url": "https://developers.zoom.us/docs/internal-apps/s2s-oauth.md",
            "seen": "2026-10-09"
          },
          {
            "what": "developer lifecycle",
            "url": "https://developers.zoom.us/docs/build-flow/basic-info/lifecycle.md",
            "seen": "2026-10-09"
          },
          {
            "what": "changelog. The entries were read from the data the page itself carries in its HTML, because the list is drawn by script",
            "url": "https://developers.zoom.us/changelog/",
            "seen": "2026-10-09"
          },
          {
            "what": "Zoom API Licence and Terms of Use",
            "url": "https://www.zoom.com/en/trust/legal/zoom-api-license-and-tou/",
            "seen": "2026-10-09"
          },
          {
            "what": "Zoom Terms of Service",
            "url": "https://www.zoom.com/en/trust/terms/",
            "seen": "2026-10-09"
          },
          {
            "what": "Privacy Statement",
            "url": "https://www.zoom.com/en/trust/privacy/privacy-statement/",
            "seen": "2026-10-09"
          },
          {
            "what": "sub-processors",
            "url": "https://www.zoom.com/en/trust/subprocessors/",
            "seen": "2026-10-09"
          },
          {
            "what": "security page",
            "url": "https://www.zoom.com/en/trust/security/",
            "seen": "2026-10-09"
          },
          {
            "what": "vulnerability reporting and bug bounty",
            "url": "https://www.zoom.com/en/trust/reporting-vulnerability/",
            "seen": "2026-10-09"
          },
          {
            "what": "SOC 2 page",
            "url": "https://www.zoom.com/en/trust/legal-compliance/soc2/",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt",
            "url": "https://zoom.us/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "Scheduler product page",
            "url": "https://www.zoom.com/en/products/appointment-scheduler/",
            "seen": "2026-10-09"
          },
          {
            "what": "Scheduler pricing",
            "url": "https://zoom.us/pricing/scheduler",
            "seen": "2026-10-09"
          },
          {
            "what": "status page",
            "url": "https://www.zoomstatus.com/",
            "seen": "2026-10-09"
          },
          {
            "what": "Zoom Rivet for JavaScript repository",
            "url": "https://github.com/zoom/rivet-javascript",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "Zoom's API terms (section 3.7.9) forbid using the APIs to monitor availability, performance or functionality, or for benchmarking. This matters before any probe is run",
          "Whether Scheduler Basic (free) or the 14-day trial can call the Scheduler API",
          "Whether `POST /scheduler/attendee` deduplicates a repeated request",
          "The registration date of zoom.us (rdap.org answered 404)",
          "unchecked: query and path parameters of every operation, which the Markdown copy and the static page omit",
          "unchecked: status history before 25 September 2026 (the history page is drawn by script and robots.txt closes /api/)",
          "unchecked: the general Using Zoom APIs page (error format and pagination rules), not read within the page budget for the docs host",
          "unchecked: the Data Processing Addendum (a PDF) and any API call log in the Marketplace or admin console",
          "unchecked: the main pricing page at zoom.us/pricing, which is drawn by script. Prices come from zoom.us/pricing/scheduler and the product page",
          "unchecked: ISO 27001 and other certification pages listed in the trust centre sitemap"
        ]
      },
      "negative": 0,
      "verdict": "Each of the 24 operations has its own granular OAuth scope, and Zoom Scheduler and the REST API are separate components on the status page. No operation moves a booking, no official SDK covers Scheduler, and Zoom's API terms forbid benchmarking or monitoring the service.",
      "bestFor": "An agent booking into a Zoom Scheduler user's or team's booking pages, with slot lookup, booking, cancellation and two webhooks.",
      "strengths": [
        "Granular OAuth scopes per operation, with separate read, write, update and delete scopes and user and admin variants",
        "A slot lookup (`GET /scheduler/schedules/{scheduleId}/available_times`) and a booking call (`POST /scheduler/attendee`), added in July and June 2026",
        "llms.txt and a Markdown copy of the full reference, with request examples and 400, 401, 404, 409, 429 and 500 responses listed",
        "Rate limits published by plan. Every Scheduler operation is labelled Light, 30 requests a second on Pro",
        "SOC 2 Type 2 report (October 2024 to October 2025) names Zoom Scheduler and Zoom APIs in scope, and security.txt is valid to 2029"
      ],
      "weaknesses": [
        "Zoom's API terms (section 3.7.9) forbid using the APIs to monitor availability or performance, or for benchmarking. This matters before any probe is run",
        "No operation moves a booking. `PATCH /scheduler/events/{eventId}` changes status, notes and no-show marks only",
        "No idempotency key or safe-retry guidance for booking writes was found in the reviewed documentation",
        "No official SDK covers Scheduler. Zoom Rivet 0.3.0 has no Scheduler module",
        "No downloadable OpenAPI file is linked, and the Markdown reference omits query and path parameters",
        "The API terms allow Zoom to change or deprecate APIs without prior notice and disclaim any uptime guarantee"
      ],
      "agentNotes": [
        "Call `GET /scheduler/schedules/{scheduleId}/available_times` and book only a spot whose status is `available`",
        "Send `start_date_time` in ISO 8601 with the booker's IANA `time_zone` to `POST /scheduler/attendee`. Expect 409 on a conflict",
        "To move a booking, cancel it with `PATCH /scheduler/events/{eventId}` and `status` set to `cancelled`, then book the new slot",
        "List scheduled events before retrying a booking, because no idempotency key is documented",
        "Request a new Server-to-Server OAuth token every hour. That grant issues no refresh token"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 50.6
        }
      ],
      "editorialScores": {
        "ergonomics": 43,
        "maintenance": 28,
        "payments": 25,
        "reliability": 63,
        "schema": 61,
        "security": 54,
        "transparency": 59
      },
      "provenanceScore": 79
    },
    "connect": {
      "http": "curl -H \"Authorization: Bearer $ZOOM_ACCESS_TOKEN\" \"https://api.zoom.us/v2/scheduler/schedules\""
    },
    "letme": {
      "capability": "https://letme.dev/calendar.read",
      "tool": "https://letme.dev/zoom-scheduler"
    },
    "notable": [
      "The reference lists 24 operations under https://api.zoom.us/v2/scheduler, all with Rate Limit Label Light (https://developers.zoom.us/docs/api/scheduler.md)",
      "The Scheduler changelog has 17 entries from 14 May 2024 to 17 August 2026. Available times arrived on 13 July 2026 and attendee creation on 29 June 2026 (https://developers.zoom.us/changelog/)",
      "Two webhook events, `scheduler.scheduled_event_created` and `scheduler.scheduled_event_canceled` (https://developers.zoom.us/docs/api/scheduler/events.md)",
      "Zoom's MCP catalogue lists servers for meetings, whiteboard, docs, chat and others, with none for Scheduler (https://developers.zoom.us/.well-known/mcp/server-card.json)",
      "The Zoom API Licence and Terms of Use, last updated 16 July 2025, forbid AI training on customer content obtained through the APIs without written permission, and scraping or building databases of API data (https://www.zoom.com/en/trust/legal/zoom-api-license-and-tou/)",
      "Zoom Scheduler is a top-level component on the Statuspage site, and REST API, Marketplace and Webhooks sit under Zoom Developer Platform (https://www.zoomstatus.com/)"
    ],
    "area": "everyday",
    "details": [
      {
        "label": "API",
        "value": "24 operations under https://api.zoom.us/v2/scheduler. Schedules, availability, available times, scheduled events, attendees, single-use links, shares, routing form responses, teams, analytics and user"
      },
      {
        "label": "Booking",
        "value": "`POST /scheduler/attendee` needs `schedule_id`, `start_date_time`, `duration` and the booker's email, first name and last name. Cancel by `PATCH` with `status` `cancelled` or by `DELETE`. No reschedule operation"
      },
      {
        "label": "Credentials",
        "value": "OAuth 2.0. User apps use the authorisation code grant with optional PKCE, one-hour access tokens and 90-day refresh tokens. Server-to-Server OAuth apps use the `account_credentials` grant with one-hour tokens and no refresh token"
      },
      {
        "label": "Scopes",
        "value": "Classic `scheduler:read`, `scheduler:write` and admin forms, or granular scopes such as `scheduler:read:list_scheduled_events`, `scheduler:write:scheduled_event` and `scheduler:delete:scheduled_event`, each with an `:admin` variant"
      },
      {
        "label": "Rate limits",
        "value": "Light APIs, per account. Free 4 a second and 6,000 a day, Pro 30 a second, Business and above 80 a second (https://developers.zoom.us/docs/api/rate-limits.md)"
      },
      {
        "label": "Webhooks",
        "value": "`scheduler.scheduled_event_created` and `scheduler.scheduled_event_canceled`. Rescheduling and invitee ID fields were added on 17 August 2026"
      },
      {
        "label": "Calendars",
        "value": "Zoom's product page names Google Calendar, Microsoft 365 or Outlook and Apple iCloud, with one primary calendar and up to five more on the paid plan"
      },
      {
        "label": "Docs for agents",
        "value": "llms.txt, an API catalogue at `/.well-known/api-catalog.json` and Markdown copies of pages. No OpenAPI file is linked, though the reference states OpenAPI version 3.1.1"
      },
      {
        "label": "SDKs",
        "value": "None for Scheduler. Zoom Rivet for JavaScript 0.3.0 (5 January 2026) has modules for accounts, chatbot, commerce, marketplace, meetings, phone, team chat, users and Video SDK"
      },
      {
        "label": "Status",
        "value": "status.zoom.us redirects to www.zoomstatus.com (Atlassian Statuspage). The front page shows 25 September to 9 October 2026, with no incident naming Scheduler or the REST API"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type 2 for October 2024 to October 2025, naming Zoom Scheduler and Zoom APIs and SDKs. Private bug bounty on HackerOne and a disclosure policy with safe harbour"
      },
      {
        "label": "Sub-processors",
        "value": "List updated 2 October 2026 with 24 third parties and 23 Zoom affiliates, each with locations, and an email sign-up for changes"
      }
    ],
    "unitPrices": [
      {
        "item": "Zoom Scheduler (the plan that lists Scheduler API access)",
        "unit": "seat-month",
        "usd": 5.99,
        "note": "Monthly billing. $4.99 a user a month billed yearly"
      }
    ],
    "provenance": {
      "legalEntity": "Zoom Communications, Inc.",
      "domain": "zoom.us",
      "domainRegistered": "",
      "endpointOnVendorDomain": true,
      "terms": "https://www.zoom.com/en/trust/legal/zoom-api-license-and-tou/",
      "privacy": "https://www.zoom.com/en/trust/privacy/privacy-statement/",
      "statusPage": "https://status.zoom.us",
      "changelog": "https://developers.zoom.us/changelog/",
      "securityTxt": "valid",
      "checked": "2026-10-09",
      "notes": [
        "The Zoom API Licence and Terms of Use (last updated 16 July 2025) and the Privacy Statement (last updated 17 September 2026) both name Zoom Communications, Inc., 55 Almaden Blvd, Suite 600, San Jose, CA 95113.",
        "The API answers at https://api.zoom.us/v2 and tokens are issued at https://zoom.us/oauth/token. Legal pages sit on www.zoom.com.",
        "zoom.us/.well-known/security.txt gives a report form, security-reports@zoom.us, a PGP key and an expiry of 31 December 2029.",
        "status.zoom.us redirects to www.zoomstatus.com, an Atlassian Statuspage site.",
        "The registration date of zoom.us was not established. rdap.org answered 404 for the domain.",
        "The account holder's use of Scheduler itself falls under the Zoom Terms of Service (effective 11 August 2023), which the API terms cite for the definition of Customer Content."
      ],
      "score": 79,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Zoom Communications, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "zoom.us, no registry record we could read",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.zoom.us",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects, and has 3 clauses that cost points",
          "points": 4,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.zoom.us",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.zoom.com/en/trust/legal/zoom-api-license-and-tou/",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2025-07-16",
          "words": 7458,
          "points": 4,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: July 16, 2025",
              "says": "Last updated 2025-07-16"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "(iv) in Clause 17, the SCCs will be governed by the laws of Switzerland, and (vii) in Clause 18(b), disputes will be resolved before the competent courts of Switzerland.",
              "says": "The law of Switzerland"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "NOTWITHSTANDING ANYTHING TO THE CONTRARY IN THESE API TERMS, ZOOM’S AGGREGATE LIABILITY TO YOU, YOUR END USERS, OR ANY OTHER THIRD PARTY ARISING OUT OF OR RELATING TO THESE API TERMS, YOUR USE OF THE ZOOM APIs, OR YOUR APPLICATION SHALL IN NO EVENT EXCEED FIVE HUNDRED U.S."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Zoom may, without prior notice or liability to you, suspend or terminate these API Terms, any rights granted herein, and/or your license to the Zoom APIs or the Zoom Marks, in our sole discretion, for any reason."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You agree not to use the Zoom APIs to (i) create, design, develop, enhance, produce, sell, license, promote, market, or distribute any material, software, or content that is intended for any use other than use with Zoom’s services or software;"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Notwithstanding the foregoing, Zoom is not obligated to provide any support to you for the Zoom APIs or your Application, and Zoom does not guarantee any uptime, availability, performance, or integrity of the Zoom APIs."
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "To scrape, build databases, or otherwise create copies of any data accessed or obtained using the Zoom APIs by your Application.",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "To monitor the availability, performance, or functionality of Zoom’s services or software, or for any similar performance testing, benchmarking, or competitive purposes.",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Zoom may, without prior notice or liability to you, suspend or terminate these API Terms, any rights granted herein, and/or your license to the Zoom APIs or the Zoom Marks, in our sole discretion, for any reason."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "Unless otherwise excluded (see Section 14.2), all disputes between you and Zoom will be resolved by binding arbitration in Santa Clara County, California, in English."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Zoom's total liability under the API terms is capped at 500 US dollars.",
              "quote": "ZOOM’S AGGREGATE LIABILITY TO YOU, YOUR END USERS, OR ANY OTHER THIRD PARTY ARISING OUT OF OR RELATING TO THESE API TERMS, YOUR USE OF THE ZOOM APIs, OR YOUR APPLICATION SHALL IN NO EVENT EXCEED FIVE HUNDRED U.S. DOLLARS ($500.00)."
            },
            {
              "date": "2026-10-08",
              "text": "Customer Content obtained through the Zoom APIs may not be used to train, test or improve AI models without Zoom's written permission, except for a consenting account owner's own model.",
              "quote": "You may not use any Customer Content (as defined in the Zoom Terms of Service) accessed or obtained using the Zoom APIs or your Application to train, develop, evaluate, test, improve, or modify artificial intelligence or machine learning models (including language models) (“AI Training”)"
            },
            {
              "date": "2026-10-08",
              "text": "An application built on the Zoom APIs may be used only internally unless it is published on the Zoom App Marketplace or Zoom approves third-party use in writing.",
              "quote": "Except as expressly provided in this Section 6.1, your Application may be used only for internal business purposes, and you agree not to share, sell, transfer, outsource, resell, rent, lease, lend, or otherwise provide access to your Application or the Zoom APIs to a Third Party."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.zoom.com/en/trust/privacy/privacy-statement/",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2026-09-17",
          "words": 8974,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: September 17, 2026",
              "says": "Last updated 2026-09-17"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Statement describes the personal data we collect and/or process (which may include collecting, organizing, structuring, storing, using, or disclosing) to provide products and services offered directly by Zoom Communications, Inc."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We retain personal data for as long as required to engage in the uses described in this Privacy Statement, unless a longer retention period is required by applicable law.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Contact Information: Contact information added by accounts and/or their licensed end users to create contact lists on Zoom products and services, which may include contact information a user integrates from a third-party app, or provided by users to process referral invitations."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not sell your personal data governed by this Privacy Statement in the conventional sense.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Right of access and/or portability: You have the right to access any personal data that we hold about you and, in some circumstances, have that data provided to you so that you can provide or “port” that data to another provider;"
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you don’t want to learn about products and services we or our partners offer, you can opt-out of marketing communications in the communication sent to you (for example, via email or SMS), or by emailing privacy@zoom.us.",
              "says": "privacy@zoom.us"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "…level of data protection, we ensure that the transfer is governed by the European Commission’s standard contractual clauses or other lawful mechanisms for transfers of personal data.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "Zoom may permit advertising and analytics services that are intended to deliver advertising to you and/or analyze your interactions, based on your interactions with our website or app which may constitute a “sale” or “sharing” of data for targeted advertising purposes under certain state privacy laws."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "A third-party reseller that sold the account may be able to access users' personal data and content, including meetings and messages.",
              "quote": "If an account owner licensed or purchased Zoom products and services from a third-party reseller of Zoom products and services, the reseller may be able to access personal data and content for users, including meetings, webinars, and messages hosted by the account owner."
            },
            {
              "date": "2026-10-08",
              "text": "Zoom automatically scans some content, including files uploaded or exchanged through chat, to detect breaches of its terms and illegal or harmful activity.",
              "quote": "Zoom uses advanced tools to automatically scan certain types of content such as virtual backgrounds, profile images, incoming emails to Zoom’s native email service from someone who is not a Zoom Email user, and files uploaded or exchanged through chat"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/zoom-scheduler.json",
    "live": {
      "slug": "zoom-scheduler",
      "probe": {
        "target": "https://api.zoom.us/v2",
        "method": "get",
        "lastAt": "2026-10-10T01:38:15.193356884Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 196,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 176,
        "p95ms24h": 301,
        "samples24h": 102,
        "samples30d": 102,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 17,
            "ok": 17
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.zoom.us",
        "indicator": "minor",
        "summary": "Partially Degraded Service",
        "checkedAt": "2026-10-10T01:34:15.81072679Z"
      },
      "pages": [
        {
          "url": "https://developers.zoom.us/changelog/",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-09T18:36:20.102873356Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "e3b0c44298fc"
        },
        {
          "url": "https://www.zoom.com/en/trust/privacy/privacy-statement/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:56:06.989690084Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "91c109d39062"
        },
        {
          "url": "https://www.zoom.com/en/trust/legal/zoom-api-license-and-tou/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:56:04.552901735Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "c294e7e03b58"
        }
      ],
      "updatedAt": "2026-10-10T01:38:15.193356884Z"
    }
  }
}
