# SugarAI (SugarCRM) (slim) > SugarAI, formerly SugarCRM, sells the Sugar Sell, Serve and Enterprise CRM applications, hosted on SugarCloud or installed on-site. Agents reach records through a versioned REST API (v11.27 in release 26.1) on each customer instance, with a legacy SOAP API. - Full: https://www.anchorterminal.com/tools/sugarcrm.md (~8,800 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/sugarcrm.json · canonical https://www.anchorterminal.com/tools/sugarcrm - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **D · 49.5/100 · rank #793 of 950 · #13 in CRM & customer platforms · not agent-ready · confidence medium** Assessment: The REST reference covers 350 endpoint pages with filters, field selection, bulk calls and upsert by `sync_key`. SugarAI's AI Supplemental Terms forbid connecting a customer's or third party's AI agent or MCP connector to the APIs unless Sugar has approved it, tokens carry no scopes, and no OpenAPI file, trial or SLA was found. ## Facts - Kind: HTTP API · vendor: SugarAI Software Inc. · category: CRM & customer platforms · legal entity: SugarAI Software Inc. · provenance 70/100 - Local only (HTTP) - Auth: OAuth · pricing: Paid · x402: no · licence: Proprietary service under the SugarAI Customer Terms of Service - Probe metrics: not measured yet (probes haven't run) - APIs: REST v11.27 at `https:///rest/v11_27/` for Sugar 25.2 and 26.1, JSON in and out. Legacy SOAP v4.1 at `/service/v4_1/soap.php`. Each instance serves its own reference at `/rest/v{version}/help` - Products covered: Sugar Sell, Sugar Serve and Sugar Enterprise, on SugarCloud or on-site. Sugar Market has a separate REST API that this listing does not grade - Read and write: 350 endpoint pages in the 26.1 guide. Generic `/` create, read, update and delete for any module, relationships through `/link`, files, mass update, duplicate check, lead conversion, forecasts, quotes, emails, calls, meetings and SugarBPM - Credentials: OAuth 2.0 password grant with a user's username and password, `OAuth-Token` header, 60-minute access token and refresh token of up to two weeks. No scopes. Admin sudo to any user - Rate limits: SugarCloud may block an IP address above 20 requests a second. SELECT queries end after 120 seconds. Seven days' notice through a support case to exceed the limit - Pagination and filters: `max_num` (default 20), `offset` and `next_offset`, `fields`, `view`, `order_by`, `q`, and filters with 13 operators such as `$starts`, `$in` and `$gte`, grouped with `$and` and `$or` - Bulk and upsert: `POST /bulk` runs calls in sequence and returns a status for each. `/integrate/:module/:sync_key_field_name/:sync_key_field_value` inserts or updates by `sync_key` - Errors: JSON with `error` and `error_message`. 21 documented exception classes, among them 401 `need_login`, 403 `not_authorized`, 409 `edit_conflict`, 422 `invalid_parameter` and 503 `maintenance` - Audit: SugarIdentity audit log of logins with CSV export, record audit endpoints, and PHP error and access logs in SugarCloud Insights - Certifications: SOC 2 Type II, ISO/IEC 27001:2022 and a CSA STAR registry listing per the trust page. The security FAQ states a bug bounty programme - Status: status.cloud.sugarai.com on Better Stack, with components per region and cluster for Sugar Cloud, SugarIdentity, Market, Discover and Predict - Data handling: Hosted on AWS in the United States, the United Kingdom, Germany and Australia per the trust page, with data kept in the chosen region. Daily backups kept 30 days. Data available for 120 days after termination, then deleted - Upgrades: SugarCloud instances are upgraded within 30 days of each release with seven days' notice and no opt-out. On-site versions get 24 months of support - Client: `ventana`, a JavaScript REST client under Apache-2.0 on GitHub, last pushed on 16 January 2026. No other official SDK was found - Prices: Sugar Sell Standard+ $68 per seat per month; Sugar Sell Advanced+ $98 per seat per month; Sugar Sell Premier+ $155 per seat per month; Sugar Connect+ add-on $20 per seat per month - Scores: Reliability 61, Performance pending, Schema & documentation 48, Agent ergonomics 69, Security & auth 51, Payments & pricing 10, Task success pending, Maintenance & community 22, Transparency & trust 71 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines, for the SugarCloud REST API. · Schema & documentation, No OpenAPI file was found. · Agent ergonomics, List and filter calls take `fields`, `view` and `max_num`, with a default of 20 records (20 of 25). · Security & auth, Tokens come from an OAuth 2.0 password grant that sends a user's username and plaintext password. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The newest dated evidence of an API release is the 26.1 Developer Guide, whose REST pages are stamped 15 May 2026, 147 days before the check… · Transparency & trust, Closed service with clear terms that name the contracting entity by region, SugarAI Software Inc. - Sources: 34, open questions: 13, both in the full twin - Capabilities: crm.records, crm.search, crm.pipeline, crm.activities - JSON: https://www.anchorterminal.com/api/v1/tools/sugarcrm.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/sugarcrm.svg` or a link to https://www.anchorterminal.com/tools/sugarcrm from a page on sugarai.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Confirm that Sugar has approved the agent integration before connecting. The AI Supplemental Terms forbid unapproved AI agents and MCP connectors on the APIs 2. POST to `/rest/v11_27/oauth2/token` with `grant_type` `password` and a `platform` other than `base`, `mobile` or `portal`, or the login can end the user's own session 3. Send the access token in the `OAuth-Token` header. It lasts 60 minutes by default, so store the refresh token and not the password 4. Stay under 20 requests a second on SugarCloud and reuse one session for batches. Over-limit traffic is blocked by IP address until support lifts it 5. Page with `max_num` and `offset` until `next_offset` is -1, and pass `fields` to keep responses small 6. Use `PATCH /integrate/:module/:sync_key_field_name/:sync_key_field_value` for writes that may be retried, since it inserts or updates by `sync_key` ## Connect ```bash curl -X POST -H Cache-Control:no-cache -H "Content-Type: application/json" -d '{ "grant_type":"password", "client_id":"sugar", "client_secret":"", "username":"", "password":"", "platform":"custom" }' https:///rest//oauth2/token ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/sugarcrm ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | HubSpot API + MCP | BB | 71.5 | crm.records, crm.pipeline, crm.activities, crm.search | https://www.anchorterminal.com/tools/hubspot-mcp.min.md | | Zoho CRM | BB | 70.8 | crm.records, crm.pipeline, crm.activities, crm.search | https://www.anchorterminal.com/tools/zoho-crm.min.md | | Microsoft Dynamics 365 Sales | B | 69.7 | crm.records, crm.pipeline, crm.activities, crm.search | https://www.anchorterminal.com/tools/dynamics-365-sales.min.md | | Close API + MCP | B | 66.7 | crm.records, crm.pipeline, crm.activities, crm.search | https://www.anchorterminal.com/tools/close.min.md | | Twenty API + MCP | B | 65.9 | crm.records, crm.pipeline, crm.activities, crm.search | https://www.anchorterminal.com/tools/twenty.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)