Connecting to Zoho CRM
This walk-through connects your membership site to Zoho CRM. At the end your site holds a long-lived refresh token, contact sync works, and you never have to log into the Zoho developer console again unless you disconnect.
The connection is a one-time setup with two halves: a small registration in Zoho's developer console, and a paste-and-click on your site. Nothing changes in your CRM while you do it, and nothing syncs until you ask it to.
What you need
- An administrator login to Zoho CRM, and an idea of which Zoho domain you sign in on (
zoho.comfor US accounts,zoho.eufor Europe, and so on). - An administrator login to your WordPress site.
- About ten minutes.
The two screens talk to each other only at the very end, so keep both open in separate browser tabs. Zoho's grant code expires in three minutes, and the last step is a copy, a paste, and a click.
Open the Zoho API Console
The developer screens live outside the CRM itself, in the Zoho API Console. There are two ways in:
- Go directly to
https://api-console.zoho.com. If your CRM runs on a regional domain, use the matching one, such asapi-console.zoho.eufor Europe. - Or start inside Zoho CRM: click the gear icon for Setup, look under Developer Space for APIs, and follow the link to the API Console from there.
Sign in with the same account you use for the CRM. The console lists the API clients registered to your organization; a fresh account shows none.
Create a self-client
The connector authenticates as a Self Client, Zoho's client type for an application acting on behalf of one organization. There is no published app and no review by Zoho.
- In the API Console, choose Self Client and start creating it. The button reads GET STARTED in most versions of the console.
- Name it after your site, something like "Torii membership site", so you recognize it a year from now.
- Open the Client Secret tab if it isn't already showing.
Copy the Client ID and Client Secret somewhere private. The ID looks like 1000.XXXXXXXXXXXXXXXX and the secret is longer. You'll paste both into WordPress in a moment.
Generate the grant code
The grant code is Zoho's way of saying "this application may act on my CRM data". It is a short-lived, single-use code that your site exchanges for a permanent refresh token.
- Switch to the Generate Code tab of your self-client.
- In the Scope box, paste this exact list:
ZohoCRM.org.READ,ZohoCRM.modules.ALL,ZohoCRM.settings.tags.ALL,ZohoCRM.settings.fields.ALL,ZohoCRM.notifications.ALL
- Set the time duration to the shortest on offer. The code dies when it expires, so a short clock just keeps you honest.
- If the form asks for a Redirect URI, use your site's home page URL, exactly as it appears in the setup guide box on your connector screen,
https://example.comwith no trailing slash. Nothing actually redirects there; Zoho just wants the exchange to name the same URI both times. - Click Generate, and copy the code it prints. It looks like the Client ID but longer.
Connect on your site
In your WordPress admin, go to Membership → Zoho. The API Connection section has a setup guide box at the top and four fields:
- Datacenter: pick the domain family your CRM lives on. Zoho US is the default; the choices include EU, IN, AU, JP, SA, CA, and CN.
- Client ID: paste the ID you copied.
- Client Secret: paste the secret. Both fields have a show/hide toggle if you want to check the paste.
- Grant Code: paste the code you just generated.
Click Connect API. The site exchanges the grant code for a refresh token, stores it encrypted, and discards the grant code. On success the credentials collapse out of view, the section reads Connected to Zoho CRM, and the Data Sync section appears below.
Verify it
- Click Test Connection. The connector fetches your organization details from Zoho and reports the result in the Connection Status area. If your org's name comes back, the credentials, datacenter, and scopes are all good.
- Click Sync Tags to pull the master list of tags from your CRM.
- Click Sync Custom Fields to pull the master list of contact fields.
Those two buttons import the field and tag catalogs that the rest of the connector picks from, including the Magic Link Sync Field and the enrollment dropdowns in the same section. Neither touches your members' data; they just build the menus.
After it works
The refresh token has no fixed expiry, and the connector renews its short-lived access tokens on its own, so there is no recurring reauthorization. You log back into the API Console only if you disconnect, delete the self-client, or rotate its secret.
Disconnect keeps the Client ID and Secret and clears the stored token; reconnecting is one fresh grant code and one click. Deleting the self-client in the console breaks the connection the same way, less obviously.
If it won't connect
- An "invalid client" error means the Datacenter doesn't match where the client was created, or the ID or secret lost a character in the copy. Toggle the field open and compare against the console.
- An "invalid code" error means the grant code was already used, or the three minutes ran out. Generate a fresh one and exchange it right away.
- If Zoho rejects the scopes, paste the list exactly as given above. Zoho validates it character by character, and a scope that's missing shows up later as sync failures instead of a clear error.
- Fields grayed out and reading "managed by Secret Vault" mean your site defines credentials in
wp-config.phpvia theTORII_ZOHO_CLIENT_ID,TORII_ZOHO_CLIENT_SECRET, orTORII_ZOHO_DCconstants, which take precedence over the screen. See the Secret Vault for how that works.