Recent Platform Updates
Zoho has rolled out several recent updates that affect how you sync files, respond to support tickets, and integrate with third-party systems. Some are feature enhancements; others are security policy changes that need your attention.
โ ๏ธ Action Required: Zoho OAuth Connector and Deluge Credentials
If you use the default Zoho OAuth connector, plan your move to service-specific or custom connections: Zoho will disable creation of new Zoho OAuth connections on January 31, 2026 (originally announced for December 31, 2025). If your Deluge scripts embed credentials in the invokeURL URL field, those calls already fail. Keep reading for details.
WorkDrive TrueSync: Linux Desktop Support
Zoho WorkDrive desktop app (TrueSync) is now available for Linux as a beta, announced in October 2025, alongside the existing Windows and macOS apps.
What This Means for You
- Supported Distributions: Ubuntu LTS-based distributions (22.04, 24.04 and derivatives) and the latest stable Fedora Workstation
- Developer-Friendly: Development teams using Linux workstations can access WorkDrive files from the desktop without workarounds
- Beta Limitations: Some features are not available yet; for example, the Linux app does not support syncing multiple accounts
Try WorkDrive TrueSync on Linux
If you're running Ubuntu or Fedora, try the WorkDrive TrueSync client for Linux (beta) to access your WorkDrive files from the desktop.
Start Free Trial 15-day free trial - Includes in Zoho OneTechnical Details
The Linux TrueSync client supports:
- Access to WorkDrive files through a virtual drive, without using local storage
- Automatic sync of changes with the WorkDrive web app
- Selective offline access (mark specific files or folders for offline use)
- Sharing files with team members and external collaborators
Zoho Desk: Mass-Reply & AI Enhancements
Zoho Desk updates bring two improvements for support teams: templates and snippets in mass replies, and Zia AI assistance inside tickets.
1. Mass-Reply Templates + Snippets
Agents can now insert email templates and snippets directly from the Mass Reply editor, so they can respond uniformly when handling multiple tickets with similar issues (Professional and Enterprise editions). This is particularly useful for:
- Outage Communications: Send consistent updates to all affected customers
- Product Announcements: Reply to inquiries about new features with standardized responses
- Policy Changes: Ensure all customers receive accurate information
- Seasonal Responses: Holiday hours, shipping updates, or promotional information
2. Zia AI-Powered Assistance
Zia's AI features in Desk offer three key capabilities inside tickets:
- Ticket Summaries: Automatically generate concise summaries of long ticket threads
- Reply Help: Draft replies that combine the ticket conversation with your knowledge base articles
- Insights: Sentiment analysis (positive, neutral or negative) and key-topic tagging
Real-World Impact
Potential benefits include:
- Higher consistency in customer communications
- Faster onboarding for new support agents (AI suggestions serve as training)
- Better ticket prioritization through Zia's insights
Upgrade Your Support with Zoho Desk
Experience AI-powered support ticketing with Zoho Desk. Start your free trial today.
Try Zoho Desk Free 15-day free trial - Included in Zoho OnePlatform & Automation Essentials
A few core platform behaviors are worth understanding for your integrations and automations:
Bulk Write Async Jobs in CRM
Bulk Write jobs in Zoho CRM are asynchronous: the response isn't available immediately. Here's what you need to know:
- Set a callback URL to be notified when a job completes
- Or check the job status periodically to monitor long-running jobs
Webhook HMAC Signing
Zoho Projects and Zoho Sign can sign webhooks with HMAC-SHA256. Projects sends the signature in the X-ZP-WEBHOOK-SIGNATURE header and Sign in X-ZS-WEBHOOK-SIGNATURE; both are base64-encoded and computed over the raw payload string. Important: always validate these headers in your webhook receivers.
Best Practice: Always Validate HMAC Signatures
// Example webhook validation (Node.js) - Zoho Projects / Zoho Sign
const crypto = require('crypto');
function validateWebhook(rawBody, signature, secret) {
// Hash the raw payload string, not re-serialized JSON
const expected = Buffer.from(crypto
.createHmac('sha256', secret)
.update(rawBody)
.digest('base64'));
const received = Buffer.from(signature || '');
return expected.length === received.length &&
crypto.timingSafeEqual(expected, received);
}
// In your webhook handler
// Projects: x-zp-webhook-signature | Sign: x-zs-webhook-signature
if (!validateWebhook(rawBody, req.headers['x-zp-webhook-signature'], SECRET)) {
return res.status(401).send('Invalid signature');
}
Records Upsert Semantics
The Records Upsert API checks duplicate-check fields: if a matching record exists, it is updated; otherwise a new record is inserted. Pass duplicate_check_fields to control which fields are checked; if you omit it, system-defined fields are checked first, then user-defined unique fields.
Security-Critical Policy Shifts (Action Required)
This is where you need to pay close attention. Zoho is making two significant security-related changes that will impact how you authenticate API calls and manage OAuth connections.
๐จ Plan These Changes Now
Deluge invokeURL calls with credentials embedded in the URL already fail with execution errors. Existing Zoho OAuth connections keep working for now, but new ones can't be created after January 31, 2026, and Zoho plans to deprecate existing ones later with advance notice. Mark your calendar and plan your updates now.
OAuth Connector Deprecation: January 31, 2026
Revised date: January 31, 2026 (originally December 31, 2025)
Zoho is deprecating the default Zoho OAuth connector in all Zoho services that support Deluge connections, except Zoho Creator. On January 31, 2026, creation of new Zoho OAuth connections will be disabled and the connector will be removed from the default services list. Use service-specific connectors or a custom connector instead.
What's Changing
- Default OAuth Connector Removed: The generic "Zoho OAuth" connector will be removed from the default services list, and new connections can't be created
- Service-Specific Connections: Use the built-in connector for each Zoho service (CRM, Books, Projects, etc.)
- Custom Connectors for Multi-Service Needs: If one connection needs scopes from several Zoho services, create a custom connector
- Existing Connections Keep Working (for Now): Existing Zoho OAuth connections continue to function temporarily; Zoho will deprecate them later, with advance notice to users still relying on them
Why This Matters
The default OAuth connector was convenient, but Zoho cites growing technical complexity and security concerns:
- Broad in scope (one authentication across multiple Zoho services, supporting all of their scopes)
- Service-specific connections follow the principle of least privilege
How to Migrate
- Audit Your Connections: List all integrations using the default OAuth connector
- Create Service-Specific Connections: Use each Zoho app's Connections settings (in Zoho CRM: Setup โ Developer Hub โ Connections)
- Create Custom Connectors Where Needed: If a connection must span several Zoho services, create a custom connector (you can register your own OAuth client in the Zoho API Console)
- Update Your Integrations: Replace default OAuth references with new service-specific connections
- Test Thoroughly: Verify all integrations work with the new connections before January 31, 2026
Migration Timeline
- Now: Audit existing Zoho OAuth connections
- Before January 31, 2026: Create service-specific (or custom) connections, then update and test integrations
- January 31, 2026: New Zoho OAuth connections can no longer be created; the connector leaves the default services list
- Later (with advance notice): Existing Zoho OAuth connections will be deprecated
Deluge invokeURL Security Changes
Status: Already in Effect
Deluge's deprecation of credentials embedded in the invokeURL URL field took effect in September 2025; affected calls now return execution errors. The URL field should contain only the endpoint URL. Use Connections to handle authentication securely.
What Changed
Previously, you could embed a username and password directly in the invokeURL URL field like this:
โ Old Method (No Longer Works)
// NO LONGER SUPPORTED - DO NOT USE
response = invokeurl
[
url: "https://username:password@api.example.com/endpoint"
type: GET
];
Use a Connection instead:
โ Recommended Method
// Create a Connection in Zoho first, then reference it
response = invokeurl
[
url: "https://api.example.com/endpoint"
type: GET
connection: "your_connection_name"
];
Why This Change Was Made
- Security: Credentials embedded in URLs can be logged inadvertently in browser histories, proxy servers, or server logs, or exposed through phishing
- Compatibility: Popular browsers and API tools block URLs with embedded credentials
- Rotation: Update credentials in one place (Connection settings) rather than hunting through scripts
How to Update Your Scripts
- Identify Affected Scripts: Search your Deluge code for invokeURL calls with credentials in the URL (username:password@host)
- Create Connections: For each external service, create a Connection in Zoho
- Update invokeURL Calls: Replace embedded credentials with connection references
- Test Thoroughly: Verify all API calls work with the new Connection-based approach
- Remove Old Credentials: Delete embedded credentials from your code
Connection Types Available
- OAuth 2.0
- OAuth 1.0
- API Key (sent as a query string, form data, or header)
- Basic Authentication (username/password)
- AWS Signature Version 4
Your Action Items Checklist
Here's your prioritized action plan for these December updates:
๐ด Critical - Action Required
- โ Audit all OAuth connections for default Zoho OAuth connector usage
- โ Create service-specific OAuth connections for each Zoho app you integrate
- โ Update integrations to use new OAuth connections
- โ Test all integrations before the January 31, 2026 cutoff
- โ Scan Deluge scripts for invokeURL calls with credentials embedded in the URL
- โ Create Connections for all external API calls
- โ Update and test all Deluge scripts
๐ก Important - Recommended Updates
- ๐ Try the WorkDrive TrueSync Linux beta if you use Ubuntu/Fedora
- ๐ Use templates and snippets in Zoho Desk mass replies
- ๐ Configure Zia AI assistance in Desk for faster ticket responses
- ๐ Review webhook HMAC validation in your integrations
- ๐ Document your OAuth connection strategy for future maintenance
๐ข Optional - Good to Know
- ๐ Review Bulk Write API patterns to ensure best practices
- ๐ Familiarize yourself with upsert semantics for future development
- ๐ Explore new Zia features in other Zoho apps
Need Help with These Updates?
If you're feeling overwhelmed by these security changes or aren't sure where to start, we can help. ZMCOR specializes in Zoho integrations, API development, and platform migrations.
Expert Zoho Migration Assistance
Our Zoho consultants can audit your current setup, plan your migration strategy, and implement the necessary changes before the January 31, 2026 cutoff.
Schedule Consultation No obligation - let's discuss your specific needsServices We Offer
- OAuth Migration: Audit and migrate from default OAuth to service-specific connections
- Deluge Script Updates: Convert embedded credentials to secure Connections
- Integration Testing: Comprehensive testing to ensure nothing breaks
- Documentation: Document your new connection architecture
- Training: Train your team on new security best practices
Stay Ahead of Zoho Updates
Zoho continues to evolve rapidly, with new features, security improvements, and platform changes announced regularly. December 2025's updates are particularly important because they involve security changes that require action.
The key takeaways:
- WorkDrive TrueSync is now available for Linux (beta) - great for development teams
- Zoho Desk AI features continue to improve support efficiency
- Zoho OAuth connector: new connections can't be created after January 31, 2026 - migrate to service-specific or custom connections
- Credentials embedded in Deluge invokeURL URLs are no longer supported - use Connections
Don't wait until the last minute. Start your migration planning today, test thoroughly, and ensure your integrations continue running smoothly into 2026.
Get the Complete Zoho Platform
All of these updates are included in Zoho One - 45+ apps for one unified price. No per-app licensing, no surprise fees.
Try Zoho One Free 30-day free trial - Full access to all apps