Skip to content
Cloud Recording Exporter / Documentation

How to export Zoom recordings to your cloud.

Cloud Recording Exporter securely exports an authorized user’s completed Zoom cloud recordings and transcripts to Google Drive, Amazon S3, or Azure Blob Storage.

A friendly whale scientist moving Zoom recordings to Amazon S3, Azure Blob Storage, and Google Drive
Overview

A focused post-meeting export workflow.

Cloud Recording Exporter is a user-managed Zoom OAuth application. It acts only for the Zoom user who authorizes it. The service listens for completed recording and transcript events, retrieves authorized download information from Zoom, and transfers selected files to the storage destination configured for that user.

Marketplace installation flow

This product is configured as From your site in Zoom Marketplace. A visitor first creates or signs in to a Nimbus Whale account, verifies the email address when registering, and then chooses Connect Zoom. The authorization callback must be reached from that flow; opening the callback URL directly is not a supported installation method.

Self-service destination setup

Google Drive OAuth, Amazon S3 credentials, and Azure Blob credentials are configured from the authenticated dashboard. Setup is available on every plan; copying allowances and automatic transfers depend on the selected plan.

Prerequisites

  • A Nimbus Whale account with a verified email address.
  • A Zoom account with Cloud Recording enabled.
  • A paid Zoom plan that supports the recording and transcription features you intend to export.
  • Audio transcription enabled in Zoom if transcript exports are required.
  • Access to the Google Drive folder, S3 bucket, or Azure container selected as the destination.
Quickstart

Connect in four steps.

1
Choose Connect Zoom

Cloud Recording Exporter redirects you to Zoom’s authorization page. Confirm the app name and requested permissions.

2
Approve user-level access

Authorization applies only to recordings owned by the Zoom user completing the connection.

3
Configure a destination

Open the dashboard and choose Google Drive, Amazon S3, or Azure Blob. Google uses OAuth; the S3 and Azure setup dialogs provide console and CLI instructions and validate read/write access. Never send credentials by email.

4
Complete a test recording

Record a short Zoom meeting to the cloud, end it, and allow Zoom to finish processing the files and transcript.

Authorization is not destination access.

Zoom OAuth permits access to the authorized user’s Zoom recording data. Access to Google Drive, S3, or Azure is configured separately and can be revoked independently.

Google Drive authorization

How to export Zoom recordings to Google Drive.

Cloud Recording Exporter requests only https://www.googleapis.com/auth/drive.file. It uses that permission to create and manage its Nimbus Whale Exports folder and upload the Zoom recordings and transcripts you select. It cannot browse your entire Google Drive or read unrelated files.

Connect

  1. Sign in and open the dashboard.
  2. Choose Setup on the Google Drive card.
  3. Select a Google account, review the limited permission, and approve access.
  4. Return to the dashboard and confirm that Google Drive shows Connected.

The service stores encrypted OAuth access and refresh tokens, the granted scope, and the app-created folder ID and name. File identifiers, basic metadata, and upload results are processed only for files created by the app.

Check your first export

Connecting Google Drive authorizes the destination; it does not by itself confirm a transfer. Use Manual Export for a completed recording, within your plan’s allowance, or enable Google Drive for automatic exports on Pro. Check the transfer status in the dashboard and open the delivered files in the Nimbus Whale Exports folder in Drive. A queued job is not yet a completed export.

Transcript files may arrive after the recording. See transcript processing and troubleshooting if an expected file is missing. Compare manual and automatic options on the Cloud Recording Exporter product page.

Disconnect, revoke, and delete connection data

Use the unplug icon on the dashboard to revoke the Google grant and delete the encrypted local tokens and folder configuration. You can also remove access from Google Account third-party connections. Files already uploaded stay in your Drive until you delete them there.

See the Privacy Policy for complete access, use, storage, sharing, retention, and Limited Use disclosures, or follow the detailed connection and removal guide.

Architecture and data flow

Event-driven, verified, and observable.

ZoomProcesses recording
Nimbus WhaleVerifies event
Export workerTransfers files
Your storageReceives objects
  1. Zoom sends a signed completion notification to the Cloud Recording Exporter webhook.
  2. The service verifies the HMAC signature and timestamp before accepting the event.
  3. For automatic exports, the service refreshes the meeting recording details through the authorized Zoom connection, then runs the same destination-index, per-meeting metadata, and remote-object checks used by Manual Export.
  4. The service uses the user’s encrypted OAuth token to request recording or transcript download information.
  5. Files are transferred to the configured destination using one consistent layout: dated YYYY/MM/DD/ media keys/folders under the configured prefix.
  6. The destination response is verified, then the worker updates root-level index.json and dated YYYY/MM/DD/<meetingUUID>.json for Google Drive, S3, and Azure, with source IDs, relative paths, sizes, SHA-256 checksums, and completion status. Missing metadata or destination objects are never treated as complete, so a later webhook or manual export can queue them again. Legacy Google Drive/Azure monthly indexes and old media paths remain readable. Zoom recordings are never deleted merely because an export was attempted.

After a manual or automatic transfer reaches a terminal state, the dashboard refreshes the destination JSON and verifies the remote objects before displaying the final exported status. Webhook requests are acknowledged quickly; file transfer, metadata index updates, retry, and destination verification happen outside the webhook response path.

Permissions

Why Cloud Recording Exporter requests each scope.

All permissions are user-level. Cloud Recording Exporter does not request account-wide :admin scopes.

ScopePurposeWhen used
user:read:userRead the authorized user's Zoom identifier, account identifier, and email address.After OAuth to label the connection and route signed recording webhooks to the correct Nimbus Whale workspace. The Zoom email is used transiently for identity handling and is not retained as profile data.
cloud_recording:read:recordingRead recording details and authorize the recording lifecycle notifications used by the workflow.When Zoom completes a recording or transcript; Zoom documents this scope for the recording.completed event.
cloud_recording:read:list_user_recordingsList recordings owned by the authorized user.For export history and reconciliation.
cloud_recording:read:list_recording_filesRead the files associated with a meeting recording.To identify video, audio, chat, caption, and related export files.
cloud_recording:read:meeting_transcriptRead transcript readiness and obtain its authorized download URL.When transcript export is enabled.
cloud_recording:delete:meeting_recordingMove all recording files for a meeting to trash or permanently delete them.Only after an explicit user deletion instruction.
cloud_recording:delete:recording_fileDelete one selected recording file.Only after an explicit user deletion instruction.
cloud_recording:delete:meeting_transcriptDelete a selected meeting transcript.Only after an explicit user deletion instruction.
Deletion permissions do not enable automatic deletion.

The service defaults recording deletion to Zoom trash. Permanent deletion requires a separate, explicit confirmation and is never part of the normal export trigger.

Event subscriptions

Two completion events, one endpoint.

EventUse
recording.completedStarts retrieval of completed video, audio, chat, caption, and related recording files.
recording.transcript_completedSignals that Zoom’s audio transcript has finished processing and can be retrieved.

In Zoom Marketplace open Features → Access → Event Subscriptions, add these two events, set the event notification endpoint to the URL below, and choose Only for users who have added this app. Click Validate before saving. If subscriptions are changed after publication, Zoom requires the app to be resubmitted.

Zoom automatically sends endpoint.url_validation while the webhook URL is configured. App removal is delivered separately to the Deauthorization Notification Endpoint as app_deauthorized.

Webhook URL: https://nimbuswhale.com/api/zoom/webhooks
Deauthorization URL: https://nimbuswhale.com/api/zoom/deauthorization
Transcripts

Transcript processing has its own clock.

A recording can finish before its audio transcript. Cloud Recording Exporter listens for the transcript completion event and also checks Zoom’s transcript endpoint. If Zoom reports NOT_READY, the service retries with backoff rather than treating the export as failed.

Transcripts are exported only when transcription is enabled for the host and Zoom has produced a supported transcript file. Closed captions and audio transcripts are distinct files and may contain different attribution information.

Deletion controls

Export first. Verify second. Delete only on request.

  • Exports do not delete Zoom data by default.
  • Trash is preferred over permanent deletion.
  • Permanent deletion requires explicit confirmation.
  • Deletion requires an authenticated internal request.
  • Transcript deletion is controlled separately.
  • Destination verification should precede deletion.

Zoom may require the host’s Host can delete cloud recordings setting to be enabled before a user-level recording deletion succeeds. The reviewer test account should enable that setting when testing the deletion scopes.

Disconnect and remove

You can revoke access from Zoom at any time.

  1. Sign in to the Zoom App Marketplace.
  2. Open Manage, then Added Apps.
  3. Select Cloud Recording Exporter.
  4. Choose Remove and confirm.

Zoom then sends a signed deauthorization notification. Cloud Recording Exporter deletes the associated Zoom access and refresh tokens and stops future exports. Files already delivered to your chosen storage remain under your control and must be removed there separately.

Removing a destination connection is not the same as removing the Zoom app.

Use Zoom Marketplace removal to revoke Zoom authorization and trigger server-side credential cleanup.

Marketplace review

Copy-ready reviewer test plan.

Use this section as the test plan in the Marketplace submission. Do not publish passwords or client secrets here; provide reviewer credentials through the submission form or a separate secure channel.

  1. Reviewer setup: use the Production client ID for a first-time submission. The listing’s From your site link should open https://nimbuswhale.com/zoom-cloud-recording-export. Create or use a Nimbus Whale test account, verify its email, and sign in.
  2. Authorize Zoom: choose Connect Zoom, approve the exact user-level scopes listed above, and confirm the callback returns to the dashboard. The Nimbus and Zoom email addresses do not need to match; the installation is bound to the Zoom user ID returned by /users/me.
  3. Configure a destination: connect Google Drive and confirm the app-created Nimbus Whale Exports folder. S3 and Azure can be tested with the credentials and setup instructions supplied by the reviewer. The dashboard validates destination access before it is marked ready.
  4. Fetch history: open Recent Zoom recordings, refresh, and page through results. Confirm the one-time Zoom page token is consumed only once and that available transcripts are identified.
  5. Exercise manual export: select one or more ready destinations, choose a recording, start export, and verify queued, transferring, completed, and failed states. The worker checks the destination index and remote object before skipping an existing file, so deleting a remote object makes it exportable again.
  6. Exercise automatic export: for a Pro test workspace, select destinations and enable automatic export. Create a short cloud recording and verify recording.completed; when audio transcription is enabled, verify recording.transcript_completed. For a Starter test workspace, verify that the control remains entitlement-gated while webhook receipt still responds correctly.
  7. Security and deletion: confirm application logs do not expose OAuth tokens, client secrets, webhook secrets, or signed download URLs. Test the two-step Zoom trash confirmation; permanent deletion is separately confirmed and is never triggered by a normal export.
  8. Disconnect and remove: disconnect Google Drive and confirm its encrypted connection data is removed. In Zoom Marketplace choose Manage → Added Apps → Cloud Recording Exporter → Remove, then confirm the deauthorization endpoint receives the notification and the Zoom installation/token record is cleaned up.

For testing credentials, access issues, or a Pro entitlement on the reviewer workspace, use Cloud Recording Exporter Support at [email protected].

Troubleshooting

Common setup issues.

Authorization is rejected

Confirm the Zoom user owns the recordings being exported and approved every required user-level scope. Restart from the Connect Zoom link if the authorization code expired.

Google Drive needs attention

The Google grant may have expired or been revoked. Use the round reconnect icon on the Google Drive card to authorize it again, or use the unplug icon to remove the connection.

No recording event arrives

Confirm the meeting was recorded to the Zoom cloud, the app remains installed, and the event subscription is enabled for the app environment being tested.

The recording arrives but the transcript does not

Enable audio transcription in Zoom recording settings. Transcript processing may take longer than the recording and may depend on the user’s Zoom plan.

A download fails

Cloud recording download URLs require a current OAuth bearer token and may redirect. The service refreshes tokens and follows authorized redirects.

Need help?

Email [email protected]. Do not include tokens, client secrets, webhook secrets, recording passcodes, or cloud-provider credentials.