Skip to content
Last updated

Zuora integration

Zuora is a subscription management and billing platform for recurring revenue businesses.

Agen.co connects to Zuora through Zuora's own hosted MCP server as an Official connector. A OneID administrator creates an OAuth 2.0 client in Zuora, and each user then signs in with their own Zuora account, so agents only reach what that account is allowed to do.


Prerequisites

  • A OneID Organization Administrator must enable Zuora AI for the tenant you are connecting. Without it the tenant's MCP endpoint is not available.
  • Administrator access to OneID, to create the OAuth 2.0 client.
  • The tenant's AI Permission Level decides what agents can do: Read-Only lets AI answer questions and surface insights but blocks write actions, while Read-Write lets AI propose write actions, which need explicit user approval before they run.

Enable Zuora AI for the tenant

A OneID Organization Administrator does this once per tenant, sandbox or production:

  1. In the OneID console, go to Admin Console → AI.
  2. Find the tenant and click Enable.
  3. Set the AI Permission Level to Read-Only or Read-Write.

Get the callback URLs from Agen.co

Zuora does not support dynamic client registration for its MCP server, so you create the OAuth 2.0 client yourself and give Agen.co its Client ID and Client Secret. The client needs Agen.co's callback URLs, so start in Agen.co.

  1. In the Agen.co portal, go to Connectors → My connectors and click Add connector.
  2. In the Select connector drawer, search for Zuora and select it. The Add Zuora panel opens.
  3. Copy both read-only URLs at the bottom of the panel:
    • Callback URL — completes the initial OAuth handshake between Agen.co and Zuora.
    • Gateway callback URL — used by the Agen.co MCP gateway for per-user authorization at runtime.

Leave this panel open — you return to it after creating the OAuth client in Zuora.

Create the OAuth 2.0 client in OneID

  1. Log in to OneID and go to Settings → Manage OAuth 2.0 Clients, then click + New.

  2. Enter the client details:

    FieldValue
    Client NameA name of your choice, for example Agen.co
    Authorization Grant TypeAuthorization Code
    TypeMCP Client
    Application TypeBilling
    Redirect URIThe callback URLs from Agen.co
  3. Click Save.

  4. Copy the Client ID and Client Secret shown after saving. Store them securely.

Zuora ties each OAuth client to a specific redirect URI and recommends one OAuth client per MCP client. Add both Agen.co callback URLs to the client's redirect URIs. If the field accepts only one, create a second OAuth client for the other URL.

Connect Zuora in Agen.co

Return to the open Add Zuora panel and fill in the fields:

FieldRequiredDescription
Instance SlugYesNamespaces this instance — it prefixes each imported tool as slug__tool, so several instances of the same MCP can coexist. Prefilled with zuora. Use lowercase kebab-case. You can change it later from the connector's settings.
Zuora environmentYesThe Zuora environment hosting your tenant. The MCP endpoint is tenant-specific. Options: rest (US Production - rest.zuora.com, the default), rest.na (US Production (NA) - rest.na.zuora.com), rest.apisandbox (US API Sandbox - rest.apisandbox.zuora.com), rest.sandbox.na (US Sandbox (NA) - rest.sandbox.na.zuora.com), rest.test (US Central Sandbox - rest.test.zuora.com), rest.eu (EU Production - rest.eu.zuora.com), rest.sandbox.eu (EU Sandbox - rest.sandbox.eu.zuora.com), or rest.ap (APAC Production - rest.ap.zuora.com).
Client IDYesThe OAuth client ID from your Zuora app.
Client SecretYesThe OAuth client secret from your Zuora app.
Callback URL—Read-only. Add it as a redirect URI in your OAuth client.
Gateway callback URL—Read-only. Also add it as a redirect URI — the MCP gateway uses it for per-user authorization at runtime.

Each connector instance connects to exactly one Zuora environment. To connect another tenant, such as a sandbox alongside production, add the Zuora connector again with a different Instance Slug and the other environment, using an OAuth client created in that tenant.

  1. Click Connect. You are redirected to Zuora to sign in and approve access.
  2. After you approve, the panel switches to Select the tools to import from Zuora. Every tool is on by default; turn off any you do not want your agents to see.
  3. Click Add. The connector is created and the selected tools are imported only when you click Add — if you close the panel first, nothing is saved, even if the Zuora callback page reported success.

Which tools are available, and whether they can write, follows the tenant's AI Permission Level. Zuora does not publish a fixed tool list for the remote MCP server, so the tool selection screen shows what your tenant serves.

Enabling the Zuora connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Additional resources