HEX
Server: Apache/2.4.46 (Win64) OpenSSL/1.1.1j PHP/8.4.25
System: Windows NT DESKTOP-4TAV2RJ 10.0 build 19045 (Windows 10) AMD64
User: fred (0)
PHP: 8.4.25
Disabled: NONE
Upload Files
File: C:/Users/fred/.codex/.tmp/plugins/plugins/zoom/skills/team-chat/concepts/security.md
# Security Best Practices

## Webhooks

- Verify webhook requests using Zoom’s verification mechanism for Team Chat subscriptions.
- Treat webhook payloads as untrusted input; validate fields before using them.

## OAuth

- Store refresh tokens securely (encrypt at rest).
- Rotate client secrets if they leak.
- Use least-privilege scopes.

## Operational

- Add rate limiting on your webhook endpoint.
- Log request IDs and correlation IDs (but avoid logging tokens / PII).