Connecting Zoho Books & Keka
Connect your own Zoho Books organization for invoicing and your own Keka account for HR data — what to click, where the Keka credentials live, and how to undo either.
What you can do here
- Connect your own Zoho Books organization so invoices are created in your accounting system.
- Let Zoho Books push payment updates back to Kaizen.
- Connect your own Keka account so HR data can be pulled across.
- Disconnect or replace either connection.
Both live under Admin → Integrations. Both are per workspace — they hold your organisation's own accounts, and nothing is shared with anyone else.
Zoho Books
Zoho Books is where invoices actually exist. Kaizen requests, approves and tracks them; Zoho creates and sends them. Connecting is what makes that possible.
Connecting
Choose Connect Zoho. You're taken to Zoho to approve access, and sent back when you're done. Sign in there as someone who administers your Zoho Books organization — a Zoho account without those rights can complete the sign-in and still fail to grant what's needed.
Kaizen never sees your Zoho password. The approval happens on Zoho's side; what comes back is permission, not credentials.
Once connected, the card shows the date and the Zoho datacenter your organization lives in. Finance still picks the Zoho organization per invoice, exactly as before.
If it doesn't complete, the card says so and invites you to try again. That usually means the approval was cancelled, the link went stale, or the Zoho account wasn't an administrator of the Books organization.
The invoice status webhook
Payment updates — sent, paid, overdue — come back to Kaizen through a webhook. Zoho Books has no way to create one automatically, so this is the one part you set up by hand.
- Copy the webhook URL shown on the card.
- Generate a secret with Generate secret, and copy it. It is shown once and never again.
- In Zoho Books go to Settings → Automation → Webhooks, add a webhook with that URL, and paste the secret there.
Rotate secret replaces it later. The old secret stops working immediately, so updates from Zoho Books are rejected until you paste the new one in — do the two together rather than leaving a gap.
Disconnecting
Disconnect stops Kaizen creating invoices in Zoho Books for this workspace until someone connects again. Invoices already in Zoho are untouched, and the webhook secret is kept. Reconnect re-approves without disconnecting first.
Keka
Keka connects with credentials rather than an approval screen, so there's a short trip to your Keka admin area first. You need to be a global admin in Keka to see them.
Where to find the credentials
- In Keka, open Settings → Integrations and Automation → Api Access.
- At the top of that page, copy the Client ID, then reveal and copy the Client Secret.
- Further down under API Keys, choose Create New Key, name it something recognisable such as Kaizen, and copy the key it generates.
Once you've typed your Keka address into the form, the card offers an Open Keka API settings link that takes you straight to that page.
Entering them in Kaizen
Fill in four values:
- Keka base URL — your Keka address, in the form
https://yourcompany.keka.com - Client ID
- Client secret
- API key
Then choose Save & verify. Kaizen signs in to Keka with those values before saving anything — so a save that succeeds is a connection that genuinely works, and a typo is caught immediately rather than surfacing as a mysterious empty import weeks later.
The credentials are stored encrypted, and never shown back to you. The card afterwards displays only your Keka address and the date they were verified.
Checking, replacing and removing
- Test connection re-checks the saved credentials against Keka on demand.
- Replace credentials opens an empty form. Nothing is pre-filled, on purpose — secrets are never displayed, so replacing means entering all four values again.
- Remove deletes them. HR data sync stops for this workspace until new ones are saved. Nothing in Keka itself is changed.
Keka credentials expire or get revoked on Keka's side from time to time. When a sync starts failing, Test connection is the quickest way to tell a credential problem from a data one.
What Keka is used for
Keka is a source you can import from — employees, and the org structure around them — during first-time setup and afterwards from the import wizard. See Importing data & onboarding for the import itself.
Connecting here saves the credentials once for the workspace, so the import doesn't ask for them each time.
Good to know
- "Available on your tenant workspace" on either card means you're signed in somewhere without a workspace of its own. Sign in on your organisation's own Kaizen address and the cards become editable.
- Neither connection is required to use Kaizen. Without Zoho, invoice requests can still be raised and approved — only the push to create a real invoice stops. Without Keka, you import from a spreadsheet instead.
- These are your accounts, not ours. Disconnecting here never changes anything inside Zoho Books or Keka.
- Microsoft sign-in and Teams meetings are set up separately, under Admin → Authentication — see System settings & sign-in.