Zoho MCP: Connecting Zoho Apps to an AI Assistant
Zoho MCP is a console where you build your own MCP servers from Zoho and third-party tools, then paste one URL into Claude, ChatGPT, Cursor or VS Code. How setup works, where the scopes really come from, why the URL is a password, and what to approve by hand.
7 min read
Zoho MCP is not one fixed server. It is a console where you build your own MCP servers: you name a server, add tools from Zoho apps such as CRM, Desk, Books or Projects (and from some third-party services), choose how people authorize, and get back a single server URL. You paste that URL into Claude, ChatGPT, Cursor, VS Code, Windsurf or any client that speaks MCP over HTTP. There is no scope list to write. What the assistant can do is set by the tools you add, then capped by each person’s own Zoho permissions. The URL carries a secret key, so treat it like a password.
What Zoho MCP is, and what it is not
Zoho’s product page for Zoho MCP (opens in a new tab) describes it as the infrastructure, configuration UI, security and integrations for standing up MCP servers across Zoho apps and beyond. It is model-agnostic: it does not run an AI model itself, and any assistant that can act as an MCP client can call it. Zoho names CRM, Mail, Calendar, Desk, Cliq, Projects and WorkDrive among the apps it works with today, and says third-party tools can be added too.
Some Zoho apps also describe their own MCP offerings on top of the console, and it helps to know which one a guide is talking about:
- Zoho CRM. The Zoho CRM MCP page (opens in a new tab) describes four composable servers: Data Insights (read-only), Data Operations (create, update and delete records), Modules (fields, layouts and modules) and Workflow & Automation (workflow rules and blueprints). You pick them from a Server Registry.
- Zoho Projects. An admin has to switch MCP on first, under Portal Configuration, AI Hub, MCP Access, before the Projects tools work.
- Zoho Analytics. Its MCP server can be hosted through Zoho MCP, self-hosted, or run locally, and Zoho’s Analytics MCP documentation (opens in a new tab) says the project is still in its development phase. Treat it as early.
Pick the console for your data center
Zoho accounts live in one data center, and the MCP console follows it. Zoho’s Zoho Projects MCP article (opens in a new tab) lists the addresses: mcp.zoho.com for the United States, with separate consoles such as mcp.zoho.eu, mcp.zoho.in, mcp.zoho.com.au and mcp.zoho.jp for other regions. Zoho’s implementation guide links the India console, so check the address before you sign in and use the one that matches your account.
Setup: build a server
The steps in Zoho’s implementation guide (opens in a new tab) are short:
- Open the console and click Create MCP Server, give it a name and click Create. You can also start from a ready-made server such as CRM Data & Metadata Operations, which comes with tools already added.
- In the server’s Tools section, click Add Tools, filter by app (for example Zoho CRM), tick only the tools the job needs and click Add Now.
- Under Connections, choose how people authorize (more on this below).
- Open Connect, pick your client, and copy the server URL or the ready-made config snippet.
Name servers after the job, not the app: “Support triage, read-only” tells the next person more than “Zoho 2”. One server per job also keeps each tool list short, which matters for the reason in the next-but-one section.
Connect a client
- Claude: in Claude’s settings, open Connectors, add a custom connector with your server’s name, paste the URL and click Connect. Zoho’s Projects guide notes that in a Claude organization, only an admin can add the integration, and members then use it.
- ChatGPT: open Settings, then Apps, click Create App, paste the URL and choose OAuth as the authentication type.
- Cursor and VS Code: the Connect section has one-click “Add to Cursor” and “Add to VS Code” buttons. In VS Code, GitHub Copilot must be in Agent mode.
- Windsurf and other clients: paste the JSON snippet from the Connect section into the client’s MCP config.
{
"mcpServers": {
"ZohoMCP": {
"command": "npx",
"args": [
"mcp-remote",
"YOUR-MCP-URL",
"--transport",
"http-only"
]
}
}
}Zoho does not publish Claude Code steps, but its FAQ says any client that supports MCP connections will work, and Claude Code adds remote servers with claude mcp add --transport http. Keep it at local scope, so the URL and its key stay in your own config and out of the project’s shared .mcp.json:
claude mcp add --transport http --scope local zoho "YOUR-MCP-URL" # then, inside Claude Code, check the connection and the tool list /mcp
Scopes: where the limits really come from
You never type an OAuth scope string into Zoho MCP. The limits come from three layers, and each is worth setting on purpose:
- The tools on the server. Zoho’s FAQ is plain about it: the access a server gives a client depends entirely on the configured tools. A server with only search and read tools cannot create a deal, however the assistant is prompted. This is your main control.
- How people authorize. Authorize on Demand, the default for Zoho tools, makes each person sign in to Zoho with OAuth when a tool first needs it, so actions run as that person. Authorize via Connections, required for third-party services, lets a Super Admin share their own access and refresh tokens with members. Use it only where acting as one shared account is what you want.
- The person’s own Zoho permissions. Zoho says an agent operates under user-level permissions and inherits yours and nothing beyond them. A Super Admin who connects an assistant has given it a Super Admin’s reach.
Then there is the app’s own switch, such as the MCP Access tab in Zoho Projects, and the normal API limits of each app, which Zoho says still apply to calls made through MCP. For the general idea of giving an assistant only what the job needs, see roles and permissions for humans and AI agents.
The URL is the key
The server URL includes an API key, and anyone who has it can call the tools on that server. Zoho’s Zoho MCP FAQ (opens in a new tab) says to treat it with the confidentiality of a password and, if it leaks, to use the Regenerate API Key button to get a new URL. In practice:
- Never commit it. A project-scoped
.mcp.jsonis shared through version control, so the URL belongs in local or user config only. - Never paste it into a chat, a ticket or a task note, including your own board.
- Regenerate it when someone leaves the team or a laptop is lost, then reconnect each client.
- Disable a server you are not using. The console lets you disable, re-enable or delete a server from its menu.
How many tools per server
Zoho sets no limit on the number of servers or tools, but its own guidance is inconsistent. The implementation guide and one FAQ answer suggest keeping to 300 tools per server; another answer in the same FAQ recommends about 100 for the best results, and notes that Cursor allows at most 40. The smaller numbers are the ones to plan around. Every tool description is text the assistant reads on every turn, so a short list is cheaper and the assistant picks the right tool more often. Split by job: a read-only reporting server, a separate server for record updates, and nothing structural (fields, layouts, workflows) unless an admin is driving.
Logs, revoking and what to approve by hand
The console’s Logs section shows each tool call, filterable by status and tool, and keeps entries for 30 days, so anything you need longer has to be recorded elsewhere. Under Connections you can revoke a person’s authorization, which removes their access to the server’s tools without deleting the server.
- Keep write tools on ask in the client. In Claude Code, that is the default for MCP tools; the details are in auto-approve in Claude Code.
- Approve anything that sends: emails, replies to support tickets, invoices, and campaign launches.
- Approve deletes and bulk updates, and structural changes such as new fields or workflow rules, which affect everyone’s reports.
- Be careful with text customers wrote. A ticket or an email can carry instructions aimed at the assistant; that is indirect prompt injection, and it is the main reason to keep write tools off a server that reads support threads.
Where the follow-up work goes
A session with Zoho MCP turns up work that should outlive the chat: a pipeline stage nobody uses, duplicate contacts, a Desk queue with no owner. fenbs is a task board your assistant can connect to next to Zoho, at https://fenbs.ai/api/mcp. Each finding becomes a bug or an enhancement with the problem in the note and the steps in the plan, sits in To Do, Next Up, In Progress or Completed, and every change is recorded in History with who made it. A standing instruction such as “no bulk CRM updates through an assistant” goes on the Decisions and rules page, which every connected assistant reads first. fenbs does not connect to Zoho or see its data, and it has no due dates, sprints or settable assignee; it keeps the list, not the schedule. The HubSpot version of this setup is in HubSpot MCP.
Related
The CRM next door: Salesforce MCP server. The security checklist for any server: MCP security best practices. How remote sign-in works: MCP OAuth explained. Connecting fenbs: the MCP docs.