- Shipped
- September 4, 2026 at 11:41 PM UTC
- Author
- Kamo
- Commit
- 979397f
The same rule the mailbox flow now follows, for Zoom and Teams meetings: an organization on its OWN app registered that app against api.<its own domain>, so that is what goes on the wire. The callback is public and sessionless, so both the organization and the provider come out of `state` — the provider as well as the org, because an org may be on its own Zoom app and Kamo's Entra app at once and the two must get different answers. An org on Kamo's app keeps the platform host: that registration holds one redirect URI and a per-org address against it is a mismatch nobody can fix from inside Kamo.