I seriously doubt any company (especially the three listed) would give Zendesk admin access to their service. Why would such a thing be necessary, anyway?
I think he meant it the other way around. Having their API token would allow the attacker to have access to all of Twitter/Tumblr/Pinterest's information that's accessible via the Zendesk API.