Connected Apps are registered in the Zoho API Console. You choose the client type (Web Application, Self Client, or Server-based Application), specify the authorized redirect URIs, and select the scopes (permissions) the app needs. The console generates a Client ID and Client Secret that are used in the OAuth 2.0 authorization flow.
Zoho CRM API scopes control what the Connected App can access. For example, ZohoCRM.modules.ALL grants read and write access to all CRM modules, while ZohoCRM.modules.leads.READ grants read-only access to the Leads module. Following the principle of least privilege, Connected Apps should request only the scopes they actually need.
A Connected App is an OAuth 2.0 client registration that enables external applications to authenticate with Zoho CRM’s API. It generates a Client ID and Client Secret used in the OAuth flow to obtain access tokens for making authorised API calls.
Yes. All Zoho CRM REST API calls require OAuth 2.0 authentication, which requires a Connected App registration. The app registration gives you the Client ID and Client Secret needed to generate access tokens.
Aaxonix is a certified Zoho implementation partner based in Pune. Architecture-first, no surprises.