Skip to main content

At a glance

  • Availability: Experimental (how to enable).
  • Authentication: OAuth 2.0.
  • Connection: A user authorizes the connection in the provider’s consent screen.
  • Scopes: ZohoCRM.modules.READ, ZohoSearch.securesearch.READ, ZohoCRM.settings.fields.READ, ZohoCRM.coql.READ.
  • Optional scopes: ZohoCRM.modules.CREATE, ZohoCRM.modules.UPDATE.
  • Provider documentation: Authentication reference.

Credentials

Set these per environment. See Connect an integration. These variables are required only when you supply your own OAuth app. If a managed app is available, you can connect without setting them. Provider permissions and consent still apply.

Setup

  1. Create a Zoho account with CRM: Sign up at https://www.zoho.com/crm/ - the free edition (up to 3 users) is enough for development, or use an existing Zoho CRM org. Zoho also offers a developer sandbox via Zoho CRM Settings > Sandbox.
  2. Register an OAuth client: Open the Zoho API Console at https://api-console.zoho.com/, click Add Client, and choose Server-based Applications. Set the Authorized Redirect URI to your app’s callback URL (the /oauth/callback/zoho-crm path on your deployment).
  3. Copy the client credentials: After creating the client, copy the Client ID into ZOHO_CLIENT_ID and the Client Secret into ZOHO_CLIENT_SECRET.
  4. Authorize with the right scopes: The default scopes grant read, search, field-metadata, and COQL access (ZohoCRM.modules.READ, ZohoSearch.securesearch.READ, ZohoCRM.settings.fields.READ, ZohoCRM.coql.READ). Enable the optional ZohoCRM.modules.CREATE and ZohoCRM.modules.UPDATE scopes if agents should create or update records.

Provider notes

  • Zoho accounts live in region-specific datacenters. This connector defaults to accounts.zoho.com (US). If your org is in another region, use the matching accounts domain for the authorization and token URLs: accounts.zoho.eu (EU), accounts.zoho.in (India), accounts.zoho.com.au (Australia), accounts.zoho.jp (Japan), accounts.zohocloud.ca (Canada), accounts.zoho.sa (Saudi Arabia), or accounts.zoho.com.cn (China).
  • API calls automatically use the api_domain returned with your OAuth token (for example https://www.zohoapis.com for US or https://www.zohoapis.eu for EU), so tool URLs follow your org’s region.
  • The authorization request uses access_type=offline so Zoho issues a refresh token; access tokens expire after one hour and are refreshed automatically.
  • The fields query parameter is mandatory when listing module records and accepts at most 50 field API names.
Provider API reference.

Tools

Verify the connection

Call a read tool such as zoho-crm__list_records with arguments for your account. Confirm that the result comes from the intended account or workspace before enabling write tools.