Zoho MCP: How to Connect Claude or ChatGPT to Zoho CRM Safely

Zoho MCP lets an AI assistant such as Claude or ChatGPT read and change records in your Zoho apps from a chat window. Setting it up takes minutes. Deciding what the assistant is allowed to do is the part that deserves your time.

Four permission levels for an AI assistant in Zoho CRM: read from day one, create after asking, update with confirmation, delete kept out
The assistant can only use the tools you add to the MCP server, so the tool list is your main control.

Quick answer

Zoho MCP lets an AI assistant such as Claude or ChatGPT use tools in your Zoho apps. Create a server in the Zoho MCP console, add only the tools you need, copy the MCP URL into your assistant and authorize with your Zoho account. Start with read-only tools, keep each user on their own authorization, and require confirmation before any change.

Until recently, asking an AI assistant about your CRM meant exporting a spreadsheet and pasting it into a chat. The Model Context Protocol (MCP) removes that step. It is an open standard, introduced by Anthropic in late 2024, that lets an AI assistant call tools in other systems. Zoho now offers its own MCP service, so an assistant can search deals, create tasks or draft invoices in your Zoho account directly.

This guide covers what Zoho MCP is, how to set it up, and the decisions that keep it safe. The product is new and changing quickly, so we link to Zoho’s own documentation for anything that is likely to move. The details here were checked in October 2026.

What Zoho MCP is

Zoho MCP is a service where you create MCP servers. A server is a named set of tools, and each tool is one action in one app, such as “search records” in Zoho CRM or “create invoice” in Zoho Books. You then give the server’s address to an AI assistant, which Zoho calls the MCP client.

Three points are worth understanding before you start:

  • Zoho MCP is not an AI. The intelligence comes from the assistant you connect. Zoho MCP only gives it a controlled way to act.
  • The assistant can use only the tools you add. If the server has no delete tool, the assistant cannot delete anything through it.
  • It covers more than CRM. Zoho lists tools for CRM, Books, Desk, Mail, Calendar, Projects, Creator and other Zoho apps, plus a growing set of third-party services.

Zoho CRM also publishes four ready-made CRM servers, for data insights, data operations, module customization, and workflow and process automation. They are a quick way to try the idea, though a server you build yourself gives you tighter control over the tool list.

What you need

SideRequirementNotes
ZohoA Zoho account with the apps you want to connect, and access to the Zoho MCP consoleZoho states that MCP is free to use for now and that it will give notice before introducing pricing
ClaudeA plan that supports custom connectors: Pro, Max, Team or EnterpriseOn Team and Enterprise plans, only an Owner can add the connector; members then connect individually
ChatGPTDeveloper mode with MCP appsWrite actions are in beta on Business, Enterprise and Edu plans; Pro can connect for read and fetch only
Other clientsAny client that supports MCP connectionsZoho names Cursor, VS Code and Windsurf alongside Claude and ChatGPT

Plan requirements change often. Confirm them on the Zoho MCP site and in your AI provider’s help centre before you promise this to your team.

How to set it up

  1. Create a server. In the Zoho MCP console, choose Create MCP Server and give it a name that says what it is for, such as sales_readonly. You can also start from a pre-configured server.
  2. Add tools. Open Tools, choose Add Tools, pick the app and tick only the actions you need. For a first server, search and get tools are enough.
  3. Check authorization. Under Connections, confirm how users will authorize. The next section explains the two options.
  4. Copy the MCP URL. The Connect section shows the server’s URL. Treat it like a password.
  5. Add it to your assistant. In Claude, add a custom connector under Customize > Connectors, paste the URL and click Connect. In ChatGPT, create an app under Settings > Apps, paste the URL and choose OAuth.
  6. Test with a read-only question. For example: “List open deals over 500,000 with no activity in the last 14 days.” Check the answer against a CRM report before you trust it.

Menu names change as the product develops. Zoho’s implementation guide has the current screens for each client.

The two authorization modes

This is the most important setting on the server, because it decides whose access the assistant uses.

Authorize on DemandAuthorize via Connections
Who signs inEach user, with their own Zoho accountThe Super Admin, once
Whose access is usedThe individual user’sThe Super Admin’s tokens, shared with trusted members
Default forZoho appsThird-party services
Best forTeams, where people should see only what they normally canA single shared integration, or third-party tools that need it

For Zoho apps, keep Authorize on Demand unless you have a specific reason not to. A sales rep who connects the assistant should not gain a Super Admin’s reach through it. If you do need a shared connection, pair it with a server that has very few tools.

What to let the assistant do

We sort actions by how hard they are to undo, the same way we do for any automation.

Action typeExamplesOur recommendation
ReadSearch records, get a record, get related recordsAllow from day one
Create, low riskTasks, notes, call logs, draft emailsAllow after a week of read-only use, with the assistant asking before each action
UpdateDeal stage, owner, amount, contact detailsAllow selectively, always with a confirmation step
Money and commitmentsInvoices, quotes, payments, emails sent to customersLet the assistant draft; a person approves and sends
Delete and configurationDeleting records, changing fields, layouts or workflowsLeave out of the server

Two habits make this easier to manage. Build separate servers for separate jobs, for example one read-only server for reporting and another for sales follow-up. And keep each server small. Zoho recommends around 100 tools per server for best results, because an assistant choosing among too many tools is more likely to pick the wrong one.

The risks to plan for

  • Hidden instructions in your data. An assistant reads whatever is in a record, including text a stranger typed into a web form or an email. That text can contain instructions aimed at the assistant. This is called prompt injection, and it is the main reason to keep write and send actions behind a human confirmation.
  • The wrong record. “Update the Atlas deal” is ambiguous when there are three. Ask the assistant to show the record it found before it changes anything.
  • A leaked URL. The MCP URL gives access to everything on that server. Do not paste it into chats or documents. If it leaks, regenerate the key in the Connect section.
  • “Always allow”. Assistants ask before using a tool and offer to stop asking. Use that option only for read tools.
  • Data leaving Zoho. Whatever the assistant reads is sent to the AI provider to produce the answer. Check your provider’s data-use terms and your own privacy obligations before you connect customer or financial data.

Zoho MCP keeps a log of every tool call, which you can filter by tool and by success or failure. Logs are kept for 30 days, so review them weekly while the setup is new.

MCP, workflows or Deluge: which to use

MCP does not replace the automation you already have. It suits a different kind of work.

UseWhenExample
Workflow rules and BlueprintThe same thing must happen every timeRequire approval for discounts above a set level
Deluge functionsThe logic is fixed but too complex for a ruleCreate a Zoho Books invoice when a deal is won
An assistant through MCPThe request is different each time and a person is present“Which customers have open tickets and an overdue invoice?”

If a task runs on a schedule or must never be skipped, build it as a rule or a function. Our Deluge script examples show the pattern. If it is a question someone asks on a Monday morning, MCP is a good fit. For a wider view of where AI helps in a CRM, see our guide to AI agents in Zoho CRM.

A four-week rollout plan

  1. Week 1: read-only, two or three people. One server with search and get tools. Collect the questions people actually ask.
  2. Week 2: check accuracy. Compare the assistant’s answers with CRM reports. Wrong answers usually point to data problems such as duplicates or empty fields, which are worth fixing anyway.
  3. Week 3: add low-risk create tools. Tasks, notes and drafts, with a confirmation each time.
  4. Week 4: review logs and decide. Keep what was used, remove what was not, and write a one-page rule on what the assistant may and may not do.

Clean data makes the biggest difference to the result. If your records are inconsistent, start with the data, as described in our data foundations guide.

Cost and limits

At the time of writing, Zoho says MCP is free to use and that calls made through it count against each app’s normal API limits. There is no stated limit on the number of servers. The real costs are the AI subscription for each user and the time spent on setup, permissions and review.

If you want help deciding which tools to expose, or need the underlying automation and integrations tidied up first, that is the kind of work we do.

Frequently asked questions

At the time of writing, Zoho states that Zoho MCP is free to use and that it will notify users in advance if pricing is introduced. Calls made through MCP follow each Zoho app's normal API limits. You still pay for your Zoho apps and for the AI assistant you connect.

Any client that supports MCP connections. Zoho names Claude, ChatGPT, Cursor, VS Code and Windsurf. Each has its own plan requirements for custom connectors, so check your provider's help centre.

With Authorize on Demand, each user signs in with their own Zoho account, so the assistant works within that user's access. With Authorize via Connections, the Super Admin's authorization is shared, so use it carefully and with a small set of tools.

It can be, with limits. Add only the tools you need, keep delete and configuration tools out of the server, require confirmation before any change, and review the MCP logs regularly. Start with read-only access.

No. Creating a server and connecting an assistant is done through menus. Where help is useful is in deciding which tools to expose, cleaning the data the assistant will read, and building rule-based automation for tasks that must happen the same way every time.

Zia is Zoho's own AI, built into Zoho apps. Zoho MCP is a connection layer that lets an outside assistant, such as Claude or ChatGPT, use tools in your Zoho apps. Many teams will use both.

Related services: Business process automation · Zoho integrations · Zoho CRM implementation · Zoho development

Planning a Zoho project?

Fixed prices for defined projects, hourly billing for smaller work, and one month of free support after launch.