Proof Key for Code Exchange (PKCE) -enabled clients and native app clients can use a loopback redirect URI to receive the OAuth authorization response without exposing a publicly reachable endpoint. Your app starts a temporary local HTTP server, opens the user's system browser to Zoom's authorization endpoint, and captures the authorization code when the browser redirects back to http://127.0.0.1:{port}/{path}. This approach follows the security recommendations in RFC 8252, OAuth 2.0 for Native Apps .
Loopback redirects are useful for desktop applications, command-line interface (CLI) tools, and local development environments that can't receive inbound HTTPS callbacks from the internet. Zoom ignores the port when it matches loopback redirect URIs, so your app can use a different ephemeral port on each run.
See using a loopback redirect URI for details.
