{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/apideck-accounting.json",
        "name": "Apideck Accounting API + MCP",
        "score": 72.9,
        "shared": [
          "accounting.ledger",
          "accounting.invoices",
          "accounting.bills"
        ],
        "slug": "apideck-accounting"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/merge-accounting.json",
        "name": "Merge Accounting API",
        "score": 70,
        "shared": [
          "accounting.ledger",
          "accounting.invoices",
          "accounting.bills"
        ],
        "slug": "merge-accounting"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/xero.json",
        "name": "Xero API + MCP",
        "score": 67.2,
        "shared": [
          "accounting.ledger",
          "accounting.invoices",
          "accounting.bills"
        ],
        "slug": "xero"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/codat.json",
        "name": "Codat",
        "score": 64.3,
        "shared": [
          "accounting.bills",
          "accounting.ledger",
          "accounting.invoices"
        ],
        "slug": "codat"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/freeagent.json",
        "name": "FreeAgent API",
        "score": 57.2,
        "shared": [
          "accounting.ledger",
          "accounting.invoices",
          "accounting.bills"
        ],
        "slug": "freeagent"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/odoo.json",
        "name": "Odoo External API",
        "score": 55.9,
        "shared": [
          "accounting.ledger",
          "accounting.invoices",
          "accounting.bills"
        ],
        "slug": "odoo"
      }
    ],
    "tool": {
      "slug": "zoho-books",
      "name": "Zoho Books",
      "vendor": "Zoho",
      "vendorUrl": "https://www.zoho.com/books/",
      "kind": "http-api",
      "category": "accounting",
      "summary": "Zoho Books is hosted accounting software from Zoho for small and mid-sized businesses. Agents reach it through the REST API v3, covering invoices, bills, payments, banking, journals and the chart of accounts behind OAuth 2.0.",
      "url": "https://www.anchorterminal.com/tools/zoho-books",
      "markdownUrl": "https://www.anchorterminal.com/tools/zoho-books.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/zoho-books.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/zoho-books.json",
      "license": "Proprietary service under Zoho's Terms of Service",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://www.zohoapis.com/books/v3",
      "packages": [],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 only. A person registers a client in the Zoho developer console (a server-based application, or a self client for one's own organisation) and approves scopes, which narrow to one module and one operation. The access token lasts one hour and goes in `Authorization: Zoho-oauthtoken \u003ctoken\u003e`. The refresh token lasts until revoked. Every call also needs `organization_id`. Each data centre has its own accounts host and API domain. Registration is self-serve, with no app review or sales approval found for use inside one's own organisation.",
      "pricing": "freemium",
      "pricingNotes": "Free plan for one user and one accountant with 1,000 API requests a day, open to businesses with yearly revenue under $50,000. Paid plans cost $15 to $240 an organisation a month billed yearly in the US edition ($20 to $275 monthly) and have a 14-day trial. The plan sets the daily API cap, up to 10,000. No sandbox organisation was found, so an agent starts on the Free plan or a trial (https://www.zoho.com/us/books/pricing/, checked 2026-10-08).",
      "priceSummary": "$15 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI files or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.zoho.com/books/api/v3/introduction/",
      "llmsTxt": "https://www.zoho.com/us/books/help/llms.txt",
      "openapi": "https://www.zoho.com/books/api/v3/openapi-all.zip",
      "capabilities": [
        "accounting.ledger",
        "accounting.invoices",
        "accounting.bills"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "oauth",
        "openapi",
        "mcp",
        "webhooks",
        "free-tier",
        "status-page",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61.1,
        "grade": "C",
        "agentReady": false,
        "rank": 377,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 51,
          "maintenance": 56,
          "payments": 30,
          "reliability": 71,
          "schema": 71,
          "security": 68,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 71,
            "points": 14.2,
            "reason": "Graded on the REST API v3, read as a hosted service. status.zoho.com redirects to us.zohostatus.com, which has a Zoho Books component and incident history back to November 2025 (20). None of the 33 incidents since 10 July 2026 names Books. On 3 September 2026 a Zoho Deluge outage ran 2 hours 34 minutes and the status feed shows the Books component returning to operational in the same second, so we read the record as minor incidents only (20 of 30). Only the US page was read. Limits are published with numbers, 100 requests a minute per organisation, 1,000 to 10,000 a day by plan and 5 or 10 concurrent calls (15). 429 is documented with codes 44, 45 and 1070, but no Retry-After header or backoff guidance was found. `X-Unique-Identifier-Key` with `X-Upsert` makes 15 update operations safe to repeat, and creates have no idempotency key (6 of 15). No SLA found (0). v3 is the current documented version (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 71,
            "points": 11.54,
            "reason": "The docs link a downloadable archive, `openapi-all.zip`, holding OpenAPI 3.0.0 files for 45 resources and 885 operations (25). No llms.txt at zoho.com or under the API docs. Every operation in the API docs has a Markdown twin, and the help centre has an llms.txt with 328 pages (8 of 10). Operation descriptions are short (median 47 characters), while parameter descriptions name the call that supplies each ID. Little on when not to use an operation (14 of 20). Required fields are marked, but only 26 enums appear across the 45 files, allowed values sit in prose and `filter_by` is a string grammar (8 of 15). Each operation has request and response examples. The files declare only 200 and 201 responses, and the errors page lists eight HTTP statuses and three sample codes with no error catalogue (8 of 15). The version is in the path. No dated API changelog was found, and the product What's New page is dated and carries some API items (8 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 51,
            "points": 8.29,
            "reason": "Graded on the REST API. Lists default to 200 records a page and `per_page` lowers that. No field selection parameter was found (10 of 25). `page`, `per_page` and `has_more_page` in `page_context`, with `filter_by`, `search_text`, `sort_column` and, on 17 operations, `last_modified_time` (18 of 20). Errors return a JSON `code` and `message`, documented thinly (10 of 20). Upsert by a unique custom field on 15 update operations, with no idempotency key on creates (8 of 20). No official SDK for the Books API was found, every call needs `organization_id`, access tokens last one hour and hosts differ by data centre (5 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 68,
            "points": 11.9,
            "reason": "OAuth 2.0 with scopes per module and operation (81 scope strings in the OpenAPI files, such as `ZohoBooks.invoices.READ`), one-hour access tokens and refresh tokens the user can revoke (30). Less 10 because the documented token and refresh calls carry the client secret and refresh token in the URL query string, and the page tells readers to use the query string (20 of 30). READ scopes per module allow a read-only agent. No approval step for deletes through the API was found (13 of 20). Records hold text from customers and vendors and no prompt-injection guidance was found. The MCP help page asks users to get an admin's approval first and to add tools only when required (3 of 15). The API Usage dashboard lists recent calls by user, module, IP address and application, and plans include an activity log (12 of 15). security.txt valid to 30 June 2028, a bug bounty, SOC 2 Type 2 and ISO/IEC 27001 (20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 30,
            "points": 3.75,
            "reason": "No x402, MPP or L402 (0). Plan prices are public, $15 to $240 an organisation a month billed yearly in the US edition. Calls have no unit price, and the API add-on that raises the daily limit has no public price (10). The Free plan includes 1,000 API requests a day per the plan comparison, and the signup steps on the pricing page ask for a company name, email address, phone number and password, with no card mentioned (20). A person signs up in a browser, registers an OAuth client in the developer console and approves scopes (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 56,
            "points": 4.9,
            "reason": "The OpenAPI archive was last modified on 7 October 2026, one day before this check, though we could not tell what changed in it. The newest dated entry on the product What's New page is 31 July 2026 (25 of 30). That page has entries on 14, 17, 22, 29, 30 and 31 July 2026, inside the last 90 days (20). A dated product changelog, a community forum and support by email, which we did not test for replies (8 of 25). No official SDK for the Books API was found. An official Zoho Books MCP connection exists through Zoho MCP and a Claude connector, and no Zoho server appears in the official MCP registry (3 of 15). No package to assess (0 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 75,
            "points": 6.56,
            "note": "editorial 54, provenance 95",
            "reason": "Closed service under the Zoho Terms of Service, last updated 2 March 2022 (15 of 30). The privacy policy of 22 December 2025 says Zoho does not sell personal information, and that data is deleted from the active database within six months of account termination and from backups three months later. The DPA is sent on request by email (24 of 30). No API deprecation policy or dated retirement notice was found. The help centre notes a new API domain from 1 June 2024 without an end date for the old one (0). A sub-processor page exists, but its directory loads by script and we could not read the list. The data centre page names locations and their certifications (15 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Graded on the REST API. Lists default to 200 records a page and `per_page` lowers that. No field selection parameter was found (10 of 25). `page`, `per_page` and `has_more_page` in `page_context`, with `filter_by`, `search_text`, `sort_column` and, on 17 operations, `last_modified_time` (18 of 20). Errors return a JSON `code` and `message`, documented thinly (10 of 20). Upsert by a unique custom field on 15 update operations, with no idempotency key on creates (8 of 20). No official SDK for the Books API was found, every call needs `organization_id`, access tokens last one hour and hosts differ by data centre (5 of 15).",
            "maintenance": "The OpenAPI archive was last modified on 7 October 2026, one day before this check, though we could not tell what changed in it. The newest dated entry on the product What's New page is 31 July 2026 (25 of 30). That page has entries on 14, 17, 22, 29, 30 and 31 July 2026, inside the last 90 days (20). A dated product changelog, a community forum and support by email, which we did not test for replies (8 of 25). No official SDK for the Books API was found. An official Zoho Books MCP connection exists through Zoho MCP and a Claude connector, and no Zoho server appears in the official MCP registry (3 of 15). No package to assess (0 of 10).",
            "payments": "No x402, MPP or L402 (0). Plan prices are public, $15 to $240 an organisation a month billed yearly in the US edition. Calls have no unit price, and the API add-on that raises the daily limit has no public price (10). The Free plan includes 1,000 API requests a day per the plan comparison, and the signup steps on the pricing page ask for a company name, email address, phone number and password, with no card mentioned (20). A person signs up in a browser, registers an OAuth client in the developer console and approves scopes (0).",
            "reliability": "Graded on the REST API v3, read as a hosted service. status.zoho.com redirects to us.zohostatus.com, which has a Zoho Books component and incident history back to November 2025 (20). None of the 33 incidents since 10 July 2026 names Books. On 3 September 2026 a Zoho Deluge outage ran 2 hours 34 minutes and the status feed shows the Books component returning to operational in the same second, so we read the record as minor incidents only (20 of 30). Only the US page was read. Limits are published with numbers, 100 requests a minute per organisation, 1,000 to 10,000 a day by plan and 5 or 10 concurrent calls (15). 429 is documented with codes 44, 45 and 1070, but no Retry-After header or backoff guidance was found. `X-Unique-Identifier-Key` with `X-Upsert` makes 15 update operations safe to repeat, and creates have no idempotency key (6 of 15). No SLA found (0). v3 is the current documented version (10).",
            "schema": "The docs link a downloadable archive, `openapi-all.zip`, holding OpenAPI 3.0.0 files for 45 resources and 885 operations (25). No llms.txt at zoho.com or under the API docs. Every operation in the API docs has a Markdown twin, and the help centre has an llms.txt with 328 pages (8 of 10). Operation descriptions are short (median 47 characters), while parameter descriptions name the call that supplies each ID. Little on when not to use an operation (14 of 20). Required fields are marked, but only 26 enums appear across the 45 files, allowed values sit in prose and `filter_by` is a string grammar (8 of 15). Each operation has request and response examples. The files declare only 200 and 201 responses, and the errors page lists eight HTTP statuses and three sample codes with no error catalogue (8 of 15). The version is in the path. No dated API changelog was found, and the product What's New page is dated and carries some API items (8 of 15).",
            "security": "OAuth 2.0 with scopes per module and operation (81 scope strings in the OpenAPI files, such as `ZohoBooks.invoices.READ`), one-hour access tokens and refresh tokens the user can revoke (30). Less 10 because the documented token and refresh calls carry the client secret and refresh token in the URL query string, and the page tells readers to use the query string (20 of 30). READ scopes per module allow a read-only agent. No approval step for deletes through the API was found (13 of 20). Records hold text from customers and vendors and no prompt-injection guidance was found. The MCP help page asks users to get an admin's approval first and to add tools only when required (3 of 15). The API Usage dashboard lists recent calls by user, module, IP address and application, and plans include an activity log (12 of 15). security.txt valid to 30 June 2028, a bug bounty, SOC 2 Type 2 and ISO/IEC 27001 (20).",
            "transparency": "Closed service under the Zoho Terms of Service, last updated 2 March 2022 (15 of 30). The privacy policy of 22 December 2025 says Zoho does not sell personal information, and that data is deleted from the active database within six months of account termination and from backups three months later. The DPA is sent on request by email (24 of 30). No API deprecation policy or dated retirement notice was found. The help centre notes a new API domain from 1 June 2024 without an end date for the old one (0). A sub-processor page exists, but its directory loads by script and we could not read the list. The data centre page names locations and their certifications (15 of 20)."
          },
          "sources": [
            {
              "what": "API introduction, limits and data centres",
              "url": "https://www.zoho.com/books/api/v3/introduction/",
              "seen": "2026-10-08"
            },
            {
              "what": "API introduction as Markdown",
              "url": "https://www.zoho.com/books/api/v3/introduction/overview.md",
              "seen": "2026-10-08"
            },
            {
              "what": "OAuth and scopes",
              "url": "https://www.zoho.com/books/api/v3/oauth/",
              "seen": "2026-10-08"
            },
            {
              "what": "errors",
              "url": "https://www.zoho.com/books/api/v3/errors/",
              "seen": "2026-10-08"
            },
            {
              "what": "pagination",
              "url": "https://www.zoho.com/books/api/v3/pagination/",
              "seen": "2026-10-08"
            },
            {
              "what": "invoices reference",
              "url": "https://www.zoho.com/books/api/v3/invoices/",
              "seen": "2026-10-08"
            },
            {
              "what": "create an invoice as Markdown",
              "url": "https://www.zoho.com/books/api/v3/invoices/create-an-invoice.md",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI archive (downloaded and parsed)",
              "url": "https://www.zoho.com/books/api/v3/openapi-all.zip",
              "seen": "2026-10-08"
            },
            {
              "what": "US pricing",
              "url": "https://www.zoho.com/us/books/pricing/",
              "seen": "2026-10-08"
            },
            {
              "what": "US plan comparison",
              "url": "https://www.zoho.com/us/books/pricing/pricing-comparison.html",
              "seen": "2026-10-08"
            },
            {
              "what": "product What's New",
              "url": "https://www.zoho.com/books/whats-new.html",
              "seen": "2026-10-08"
            },
            {
              "what": "Zoho Books MCP help page",
              "url": "https://www.zoho.com/us/books/help/mcp/zoho-books-mcp.html",
              "seen": "2026-10-08"
            },
            {
              "what": "Zoho MCP",
              "url": "https://www.zoho.com/mcp/",
              "seen": "2026-10-08"
            },
            {
              "what": "Zoho MCP pricing",
              "url": "https://www.zoho.com/mcp/pricing.html",
              "seen": "2026-10-08"
            },
            {
              "what": "API Usage help page",
              "url": "https://www.zoho.com/us/books/help/settings/developer-and-data/api-usage.html",
              "seen": "2026-10-08"
            },
            {
              "what": "webhooks help page",
              "url": "https://www.zoho.com/us/books/help/settings/automation/workflow-actions/webhooks.html",
              "seen": "2026-10-08"
            },
            {
              "what": "help centre llms.txt",
              "url": "https://www.zoho.com/us/books/help/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "official MCP registry search for zoho",
              "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=zoho",
              "seen": "2026-10-08"
            },
            {
              "what": "status page",
              "url": "https://us.zohostatus.com/",
              "seen": "2026-10-08"
            },
            {
              "what": "status incident history",
              "url": "https://us.zohostatus.com/incident_history",
              "seen": "2026-10-08"
            },
            {
              "what": "status RSS",
              "url": "https://us.zohostatus.com/rss",
              "seen": "2026-10-08"
            },
            {
              "what": "terms of service",
              "url": "https://www.zoho.com/terms.html",
              "seen": "2026-10-08"
            },
            {
              "what": "contracting entities",
              "url": "https://www.zoho.com/legal/zoho-contracting-entities.html",
              "seen": "2026-10-08"
            },
            {
              "what": "developer agreement",
              "url": "https://www.zoho.com/developer/terms.html",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.zoho.com/privacy.html",
              "seen": "2026-10-08"
            },
            {
              "what": "sub-processors",
              "url": "https://www.zoho.com/privacy/sub-processors.html",
              "seen": "2026-10-08"
            },
            {
              "what": "GDPR and DPA",
              "url": "https://www.zoho.com/gdpr.html",
              "seen": "2026-10-08"
            },
            {
              "what": "data centres",
              "url": "https://www.zoho.com/know-your-datacenter.html",
              "seen": "2026-10-08"
            },
            {
              "what": "compliance",
              "url": "https://www.zoho.com/compliance.html",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://www.zoho.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP for zoho.com",
              "url": "https://rdap.verisign.com/com/v1/domain/zoho.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the tools of the Zoho Books MCP connection. The help page refers to a Tools list it does not show, and the Zoho MCP setup guide on help.zoho.com loads by script",
            "unchecked: the sub-processor directory at zoho.com/privacy/sub-processors.html, which loads by script",
            "unchecked: status pages for data centres other than the US",
            "unchecked: whether the Books API was affected during the Deluge outage of 3 September 2026",
            "unchecked: what changed in the OpenAPI archive on 7 October 2026. Only its modification date was read",
            "unchecked: GitHub. The shell could not list Zoho's repositories, so the absence of an official Books SDK rests on the API docs naming none",
            "The US pricing page lists API Access under Standard, while the plan comparison and the API docs give the Free plan 1,000 requests a day. We followed the comparison and the docs",
            "The price of the API add-on that raises the daily limit is shown only inside the product",
            "No SLA page, API deprecation policy or dated API changelog was found",
            "The Terms of Service forbid using the services for any form of competitive or benchmarking purposes, which matters before our probes run. Recorded as a fact, with no deduction",
            "The Markdown help pages open with a line addressed to AI readers telling them to read the help llms.txt first. Recorded as a fact, with no deduction",
            "The lead was right on the vendor, URL, docs link, OAuth 2.0 and the limits. It was wrong on reports, since no report endpoint is documented, and it did not mention the MCP connection"
          ]
        },
        "negative": 0,
        "verdict": "The public OpenAPI files cover 885 operations with OAuth scopes per module and operation, and the Free plan allows 1,000 API requests a day. No report endpoint, official SDK, SLA or dated API changelog was found, and the documented token calls put the client secret in the URL.",
        "bestFor": "Small businesses already on Zoho that want an agent to raise invoices, record bills and payments, reconcile bank transactions and post journals with narrow scopes.",
        "strengths": [
          "OpenAPI 3.0.0 files for 45 resources and 885 operations download from the docs as `openapi-all.zip`",
          "OAuth scopes narrow to one module and one operation, such as `ZohoBooks.invoices.READ`",
          "Every API reference operation has a Markdown twin, such as `/books/api/v3/invoices/create-an-invoice.md`",
          "The Free plan includes 1,000 API requests a day per the plan comparison",
          "The API Usage dashboard lists recent calls by user, module, IP address and application"
        ],
        "weaknesses": [
          "No profit and loss, balance sheet or other report endpoint appears in the API docs or the OpenAPI files",
          "The documented token and refresh calls put the client secret and refresh token in the URL query string",
          "Daily caps are low, 1,000 requests on Free and 10,000 on the top three plans",
          "No official SDK, SLA, API deprecation policy or dated API changelog found in the reviewed pages",
          "429 is documented without a Retry-After header or backoff guidance"
        ],
        "agentNotes": [
          "Send `organization_id` as a query parameter on every call. Read it from `GET /organizations` first",
          "Use the `api_domain` returned with the token, since each of the nine data centres has its own host (zohoapis.com, zohoapis.eu, zohoapis.in and others)",
          "Send `Authorization: Zoho-oauthtoken \u003ctoken\u003e` and refresh hourly. Each user keeps at most 20 refresh tokens and the oldest is deleted",
          "Stay under 100 requests a minute and the plan's daily cap. Codes 44, 45 and 1070 on a 429 mean minute, day and concurrency limits",
          "To repeat an update safely, send `X-Unique-Identifier-Key`, `X-Unique-Identifier-Value` and `X-Upsert` with a unique custom field. Creates have no idempotency key"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61.1
          }
        ],
        "editorialScores": {
          "ergonomics": 51,
          "maintenance": 56,
          "payments": 30,
          "reliability": 71,
          "schema": 71,
          "security": 68,
          "transparency": 54
        },
        "provenanceScore": 95
      },
      "connect": {
        "http": "curl -X GET 'https://www.zohoapis.com/books/v3/organizations' \\\n  -H \"Authorization: Zoho-oauthtoken $ZOHO_ACCESS_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/accounting.ledger",
        "tool": "https://letme.dev/zoho-books"
      },
      "sameCompany": [
        "zoho-zeptomail",
        "zoho-crm",
        "zoho-recruit",
        "zoho-people"
      ],
      "notable": [
        "Limits are 100 requests a minute per organisation and a daily cap by plan, 1,000 on Free, 2,000 on Standard, 5,000 on Professional and 10,000 on Premium, Elite and Ultimate (https://www.zoho.com/books/api/v3/introduction/)",
        "The OpenAPI archive holds 45 YAML files with 885 operations, last modified on 7 October 2026 (https://www.zoho.com/books/api/v3/openapi-all.zip)",
        "No report endpoint is documented. The API reference has 45 resource sections from contacts to reporting tags, and none returns the profit and loss or balance sheet (https://www.zoho.com/books/api/v3/introduction/)",
        "The documented token and refresh calls are POSTs with `client_id`, `client_secret` and `refresh_token` in the query string, and the page says to put the parameters there (https://www.zoho.com/books/api/v3/oauth/)",
        "Zoho documents an official Zoho Books MCP connection through Zoho MCP and a Claude connector. Calls draw on the same API limits and Zoho MCP has no separate price (https://www.zoho.com/us/books/help/mcp/zoho-books-mcp.html, https://www.zoho.com/mcp/pricing.html)",
        "The Terms of Service forbid using the services for any form of competitive or benchmarking purposes (https://www.zoho.com/terms.html)",
        "The US status page lists a Zoho Books component. Its one Books-named incident in the past year lasted 44 minutes on 6 February 2026 (https://us.zohostatus.com/incident_history)"
      ],
      "area": "domain-data",
      "details": [
        {
          "label": "API",
          "value": "REST API v3 at https://www.zohoapis.com/books/v3 (US). 885 operations across contacts, estimates, sales orders, invoices, credit notes, customer payments, expenses, purchase orders, bills, vendor credits, vendor payments, bank accounts, bank transactions, bank rules, chart of accounts, journals, fixed assets, projects, time entries, items, taxes and settings"
        },
        {
          "label": "Not in the API",
          "value": "No report endpoints (profit and loss, balance sheet, trial balance) in the API docs or the OpenAPI files"
        },
        {
          "label": "MCP",
          "value": "Official Zoho Books connection through Zoho MCP (a hosted hub where a user builds a server from chosen tools) and a default Claude connector. Tool list not published on the help page"
        },
        {
          "label": "Credentials",
          "value": "OAuth 2.0 authorisation code grant, or a self client that generates a grant token in the developer console. Access tokens last one hour. Refresh tokens last until revoked, 20 at most per user"
        },
        {
          "label": "Auth scopes",
          "value": "`ZohoBooks.\u003cmodule\u003e.\u003coperation\u003e` with operations CREATE, READ, UPDATE, DELETE and ALL. Modules include contacts, settings, estimates, invoices, customerpayments, creditnotes, projects, expenses, salesorders, purchaseorders, bills, debitnotes, vendorpayments, banking and accountants"
        },
        {
          "label": "Rate limits",
          "value": "100 requests a minute per organisation. Daily caps of 1,000 (Free), 2,000 (Standard), 5,000 (Professional) and 10,000 (Premium, Elite, Ultimate). 5 concurrent calls on Free and 10 on paid plans, a soft limit"
        },
        {
          "label": "Errors",
          "value": "JSON `code` and `message`. HTTP 400, 401, 404, 405, 429 and 500 are listed. On 429, code 44 is the minute limit, 45 the daily cap and 1070 the concurrency limit"
        },
        {
          "label": "Pagination",
          "value": "`page` and `per_page`, 200 records by default, with `has_more_page` in `page_context`. `filter_by`, `search_text`, `sort_column` and `last_modified_time` on list calls"
        },
        {
          "label": "Safe retries",
          "value": "`X-Unique-Identifier-Key`, `X-Unique-Identifier-Value` and `X-Upsert` on 15 update operations match a record by a unique custom field. No idempotency key on creates"
        },
        {
          "label": "Webhooks",
          "value": "Outgoing webhooks are a workflow action with an optional secret token for a payload hash, up to 20 retries and a daily limit by plan. Incoming webhooks are a separate setting"
        },
        {
          "label": "Data centres",
          "value": "US, Europe, India, Australia, Japan, Canada, China, Saudi Arabia and the United Arab Emirates, each with its own accounts host and API domain"
        },
        {
          "label": "SDKs",
          "value": "None named in the API docs. Samples are curl and code snippets per operation"
        },
        {
          "label": "Free tier",
          "value": "Free plan, one user and one accountant, 1,000 API requests a day, yearly revenue under $50,000 and 1,000 invoices a year. 14-day trial of paid plans"
        },
        {
          "label": "Audit",
          "value": "API Usage dashboard with a 30-day timeline, top modules, applications, IP addresses and users, and recent calls, refreshed every 3 hours. Activity log in the plan comparison"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type 2, SOC 1 and ISO/IEC 27001 per zoho.com/compliance.html. Bug bounty at bugbounty.zohocorp.com"
        },
        {
          "label": "Status",
          "value": "status.zoho.com redirects to us.zohostatus.com, with a Zoho Books component and incident history back to November 2025"
        }
      ],
      "unitPrices": [
        {
          "item": "Standard",
          "unit": "month",
          "usd": 15,
          "note": "per organisation, billed yearly; $20 billed monthly; 3 users, 2,000 API requests a day"
        },
        {
          "item": "Professional",
          "unit": "month",
          "usd": 40,
          "note": "per organisation, billed yearly; $50 billed monthly; 5 users, 5,000 API requests a day"
        },
        {
          "item": "Premium",
          "unit": "month",
          "usd": 60,
          "note": "per organisation, billed yearly; $70 billed monthly; 10 users, 10,000 API requests a day"
        },
        {
          "item": "Elite",
          "unit": "month",
          "usd": 120,
          "note": "per organisation, billed yearly; $150 billed monthly; 10 users, 10,000 API requests a day"
        },
        {
          "item": "Ultimate",
          "unit": "month",
          "usd": 240,
          "note": "per organisation, billed yearly; $275 billed monthly; 15 users, 10,000 API requests a day"
        },
        {
          "item": "Additional user",
          "unit": "seat-month",
          "usd": 2.5,
          "note": "billed yearly; $3 billed monthly; paid plans only"
        }
      ],
      "provenance": {
        "legalEntity": "Zoho Corporation Private Limited",
        "domain": "zoho.com",
        "domainRegistered": "2004-01-16",
        "domainNote": "API calls go to www.zohoapis.com and its regional equivalents, a Zoho domain other than zoho.com.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.zoho.com/terms.html",
        "privacy": "https://www.zoho.com/privacy.html",
        "statusPage": "https://status.zoho.com",
        "changelog": "https://www.zoho.com/books/whats-new.html",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Service (last updated 2 March 2022) are the service agreement for Zoho's online services. The contracting entity depends on the customer's region, Zoho Corporation Private Limited for India and Zoho Corporation for the United States (https://www.zoho.com/legal/zoho-contracting-entities.html).",
          "A separate Zoho Developer Agreement at https://www.zoho.com/developer/terms.html covers the developer tools.",
          "The privacy policy was last updated on 22 December 2025 and covers Zoho's websites and the products on them.",
          "security.txt at www.zoho.com gives a bug bounty contact, security@zohocorp.com, a policy link and an expiry of 30 June 2028.",
          "The changelog link is the product What's New page, newest entry 31 July 2026. No dated API changelog was found.",
          "RDAP for zoho.com gives a registration date of 2004-01-16."
        ],
        "score": 95,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Zoho Corporation Private Limited",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "zoho.com, registered 2004-01-16 (22 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "www.zohoapis.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 7.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
            "points": 8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.zoho.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "valid",
            "points": 10,
            "max": 10,
            "state": "ok"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.zoho.com/terms.html",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2022-03-02",
            "words": 4052,
            "points": 7.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated on: 2nd March 2022.",
                "says": "Last updated 2022-03-02"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "Accordingly, each party agrees to the governing law (without regard to choice or conflicts of law rules) and to the exclusive jurisdiction of the courts mentioned herein in case of any dispute or lawsuit arising out of or in connection with this Agreement ."
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "IN NO EVENT SHALL ZOHO’S ENTIRE LIABILITY TO YOU IN RESPECT OF ANY SERVICE, WHETHER DIRECT OR INDIRECT, EXCEED ONE THOUSAND DOLLARS ($1000) OR THE FEES PAID BY YOU DURING THE TWELVE (12) MONTHS PRIOR TO THE FIRST EVENT GIVING RISE TO SUCH LIABILITY, WHICHEVER IS HIGHER.",
                "says": "Capped at the fees paid in the 12 months before the claim or $1000"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "If you provide any information that is untrue, inaccurate, outdated, or incomplete, or if Zoho has reasonable grounds to suspect that such information is untrue, inaccurate, outdated, or incomplete, Zoho may terminate your user account and refuse current or future use of any or all of the Services."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "If we make significant changes to the Agreement that affect your rights, you will be provided with at least 30 days advance notice of the changes by email to your primary email address.",
                "says": "Gives 30 days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "In addition to all other terms and conditions of this Agreement, you shall not: (i) transfer the Services or otherwise make it available to any third party;"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "use the Services for any form of competitive or benchmarking purposes",
                "costsPoints": true
              },
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Last updated on: 2nd March 2022."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Subscriptions renew automatically and the customer must give at least seven days' notice before the renewal date to stop renewal.",
                "quote": "If you do not wish to renew the subscription, you must inform us at least seven days prior to the renewal date."
              },
              {
                "date": "2026-10-08",
                "text": "Unpaid accounts inactive for 120 continuous days may be terminated and their data deleted, with prior notice, and activity in one service does not keep another active.",
                "quote": "We reserve the right to terminate unpaid user accounts that are inactive for a continuous period of 120 days."
              },
              {
                "date": "2026-10-08",
                "text": "If the customer does not answer a forwarded complaint within 10 days, Zoho may give the customer's name and contact information to the complainant.",
                "quote": "If you do not respond to the complainant within 10 days from the date of our email to you, we may disclose your name and contact information to the complainant for enabling the complainant to take legal action against you."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.zoho.com/privacy.html",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-12-22",
            "words": 6377,
            "points": 8,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated on: 22nd Dec 2025.",
                "says": "Last updated 2025-12-22"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This policy tells you what information we collect from you, what we do with it, who can access it, and what you can do about it."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "After you terminate your account, your data will be automatically deleted from our active database within 6 months and from our backups within 3 months after that.",
                "says": "Names a period of 6 months"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "If you ask about our products through one of our referral programs or reselling partners, or sign in to one of our products through an authentication service provider like LinkedIn or Google, they'll pass on your contact information to us."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We share your information only in the ways that are described in this Privacy Policy, and only with parties who adopt appropriate confidentiality and security measures."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "The European Economic Area (EEA) provides certain rights to data subjects (including access, rectification, erasure, restriction of processing, data portability, and the right to object and to complain)."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you wish to update or delete your testimonial, you can contact us at privacy@zohocorp.com",
                "says": "privacy@zohocorp.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "…or otherwise providing personal information or service data to us, you understand that the processing, transfer, and storage of your personal information or Service Data within the United States of America, the European Economic Area (EEA) and other countries where Zoho operates.",
                "says": "Data goes to the United States"
              }
            ],
            "toKnow": [
              {
                "key": "training",
                "label": "Says it may use customer content to train or improve models, and no opt-out was found",
                "found": true,
                "quote": "In keeping with Zoho's promise not to exploit your data in a way that is not respectful of your privacy and confidentiality expectations, we make only the following limited use of service data for these technologies: (i) using anonymized crops of service data to improve accuracy of the algorithms;",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Zoho employees and contractors may open service data to resolve errors and to check by hand emails reported as spam and scanned images.",
                "quote": "so that they can (i) identify, analyze and resolve errors, (ii) manually verify emails reported as spam to improve spam detection, or (iii) manually verify scanned images that you submit to us to verify the accuracy of optical character recognition."
              },
              {
                "date": "2026-10-08",
                "text": "Zoho says it uses an organisation's data to develop models specific to that organisation.",
                "quote": "(ii) using your organization's data for developing models specific for your organization."
              },
              {
                "date": "2026-10-08",
                "text": "After an account is terminated, data leaves the active database at a clean-up run once every six months and leaves backups three months later.",
                "quote": "Once you terminate your Zoho user account, your data will eventually get deleted from active database during the next clean-up that occurs once in 6 months."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/zoho-books.json",
      "live": {
        "slug": "zoho-books",
        "probe": {
          "target": "https://www.zohoapis.com/books/v3",
          "method": "get",
          "lastAt": "2026-10-08T21:12:26.720239875Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 427,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 448,
          "p95ms24h": 486,
          "samples24h": 21,
          "samples30d": 21,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 21,
              "ok": 21
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.zoho.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:39:22.344999716Z"
        },
        "updatedAt": "2026-10-08T21:12:26.720239875Z"
      }
    },
    "verify": {
      "accepts": "a page on zoho.com or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/zoho-books.svg",
      "body": {
        "slug": "zoho-books",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/zoho-books",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/zoho-books\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/zoho-books.svg\" alt=\"Zoho Books on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Zoho Books on Anchor Terminal](https://www.anchorterminal.com/badges/zoho-books.svg)](https://www.anchorterminal.com/tools/zoho-books)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/zoho-books\"\u003eZoho Books on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/zoho-books",
    "json": "https://www.anchorterminal.com/tools/zoho-books.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/zoho-books.md",
    "slim": "https://www.anchorterminal.com/tools/zoho-books.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 61.1/100 · rank #377 of 722 · #5 in Accounting \u0026 invoicing · not agent-ready · confidence medium**\n\n\nMore from Zoho, listed separately because each is its own product: [Zoho CPaaS (formerly ZeptoMail)](https://www.anchorterminal.com/tools/zoho-zeptomail.md) (Email delivery APIs), [Zoho CRM](https://www.anchorterminal.com/tools/zoho-crm.md) (CRM \u0026 customer platforms), [Zoho Recruit](https://www.anchorterminal.com/tools/zoho-recruit.md) (Recruiting \u0026 applicant tracking), [Zoho People](https://www.anchorterminal.com/tools/zoho-people.md) (HR \u0026 employee operations).\n\n## Assessment\n\nThe public OpenAPI files cover 885 operations with OAuth scopes per module and operation, and the Free plan allows 1,000 API requests a day. No report endpoint, official SDK, SLA or dated API changelog was found, and the documented token calls put the client secret in the URL.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Zoho (https://www.zoho.com/books/) |\n| Kind | HTTP API |\n| Category | Accounting \u0026 invoicing (https://www.anchorterminal.com/categories/accounting) |\n| Transport | HTTP |\n| Endpoint | `https://www.zohoapis.com/books/v3` |\n| Auth | OAuth · OAuth 2.0 only. A person registers a client in the Zoho developer console (a server-based application, or a self client for one's own organisation) and approves scopes, which narrow to one module and one operation. The access token lasts one hour and goes in `Authorization: Zoho-oauthtoken \u003ctoken\u003e`. The refresh token lasts until revoked. Every call also needs `organization_id`. Each data centre has its own accounts host and API domain. Registration is self-serve, with no app review or sales approval found for use inside one's own organisation. |\n| Pricing | Freemium ($15 / mo) · Free plan for one user and one accountant with 1,000 API requests a day, open to businesses with yearly revenue under $50,000. Paid plans cost $15 to $240 an organisation a month billed yearly in the US edition ($20 to $275 monthly) and have a 14-day trial. The plan sets the daily API cap, up to 10,000. No sandbox organisation was found, so an agent starts on the Free plan or a trial (https://www.zoho.com/us/books/pricing/, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the API docs, the OpenAPI files or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under Zoho's Terms of Service |\n| Docs | https://www.zoho.com/books/api/v3/introduction/ |\n| llms.txt | https://www.zoho.com/us/books/help/llms.txt |\n| Last release | 2026-10-07 |\n| API | REST API v3 at https://www.zohoapis.com/books/v3 (US). 885 operations across contacts, estimates, sales orders, invoices, credit notes, customer payments, expenses, purchase orders, bills, vendor credits, vendor payments, bank accounts, bank transactions, bank rules, chart of accounts, journals, fixed assets, projects, time entries, items, taxes and settings |\n| Not in the API | No report endpoints (profit and loss, balance sheet, trial balance) in the API docs or the OpenAPI files |\n| MCP | Official Zoho Books connection through Zoho MCP (a hosted hub where a user builds a server from chosen tools) and a default Claude connector. Tool list not published on the help page |\n| Credentials | OAuth 2.0 authorisation code grant, or a self client that generates a grant token in the developer console. Access tokens last one hour. Refresh tokens last until revoked, 20 at most per user |\n| Auth scopes | `ZohoBooks.\u003cmodule\u003e.\u003coperation\u003e` with operations CREATE, READ, UPDATE, DELETE and ALL. Modules include contacts, settings, estimates, invoices, customerpayments, creditnotes, projects, expenses, salesorders, purchaseorders, bills, debitnotes, vendorpayments, banking and accountants |\n| Rate limits | 100 requests a minute per organisation. Daily caps of 1,000 (Free), 2,000 (Standard), 5,000 (Professional) and 10,000 (Premium, Elite, Ultimate). 5 concurrent calls on Free and 10 on paid plans, a soft limit |\n| Errors | JSON `code` and `message`. HTTP 400, 401, 404, 405, 429 and 500 are listed. On 429, code 44 is the minute limit, 45 the daily cap and 1070 the concurrency limit |\n| Pagination | `page` and `per_page`, 200 records by default, with `has_more_page` in `page_context`. `filter_by`, `search_text`, `sort_column` and `last_modified_time` on list calls |\n| Safe retries | `X-Unique-Identifier-Key`, `X-Unique-Identifier-Value` and `X-Upsert` on 15 update operations match a record by a unique custom field. No idempotency key on creates |\n| Webhooks | Outgoing webhooks are a workflow action with an optional secret token for a payload hash, up to 20 retries and a daily limit by plan. Incoming webhooks are a separate setting |\n| Data centres | US, Europe, India, Australia, Japan, Canada, China, Saudi Arabia and the United Arab Emirates, each with its own accounts host and API domain |\n| SDKs | None named in the API docs. Samples are curl and code snippets per operation |\n| Free tier | Free plan, one user and one accountant, 1,000 API requests a day, yearly revenue under $50,000 and 1,000 invoices a year. 14-day trial of paid plans |\n| Audit | API Usage dashboard with a 30-day timeline, top modules, applications, IP addresses and users, and recent calls, refreshed every 3 hours. Activity log in the plan comparison |\n| Certifications | SOC 2 Type 2, SOC 1 and ISO/IEC 27001 per zoho.com/compliance.html. Bug bounty at bugbounty.zohocorp.com |\n| Status | status.zoho.com redirects to us.zohostatus.com, with a Zoho Books component and incident history back to November 2025 |\n| Capabilities | accounting.ledger, accounting.invoices, accounting.bills |\n| Tags | hosted, closed-source, oauth, openapi, mcp, webhooks, free-tier, status-page, bug-bounty, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/zoho-books.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 71 | 14.2 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 71 | 11.5 |\n| Agent ergonomics | 13% | 16.2 | 51 | 8.3 |\n| Security \u0026 auth | 14% | 17.5 | 68 | 11.9 |\n| Payments \u0026 pricing | 10% | 12.5 | 30 | 3.8 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 56 | 4.9 |\n| Transparency \u0026 trust (editorial 54, provenance 95) | 7% | 8.8 | 75 | 6.6 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **61.1 → C** |\n\n### Why each score\n\n- Reliability 71: Graded on the REST API v3, read as a hosted service. status.zoho.com redirects to us.zohostatus.com, which has a Zoho Books component and incident history back to November 2025 (20). None of the 33 incidents since 10 July 2026 names Books. On 3 September 2026 a Zoho Deluge outage ran 2 hours 34 minutes and the status feed shows the Books component returning to operational in the same second, so we read the record as minor incidents only (20 of 30). Only the US page was read. Limits are published with numbers, 100 requests a minute per organisation, 1,000 to 10,000 a day by plan and 5 or 10 concurrent calls (15). 429 is documented with codes 44, 45 and 1070, but no Retry-After header or backoff guidance was found. `X-Unique-Identifier-Key` with `X-Upsert` makes 15 update operations safe to repeat, and creates have no idempotency key (6 of 15). No SLA found (0). v3 is the current documented version (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 71: The docs link a downloadable archive, `openapi-all.zip`, holding OpenAPI 3.0.0 files for 45 resources and 885 operations (25). No llms.txt at zoho.com or under the API docs. Every operation in the API docs has a Markdown twin, and the help centre has an llms.txt with 328 pages (8 of 10). Operation descriptions are short (median 47 characters), while parameter descriptions name the call that supplies each ID. Little on when not to use an operation (14 of 20). Required fields are marked, but only 26 enums appear across the 45 files, allowed values sit in prose and `filter_by` is a string grammar (8 of 15). Each operation has request and response examples. The files declare only 200 and 201 responses, and the errors page lists eight HTTP statuses and three sample codes with no error catalogue (8 of 15). The version is in the path. No dated API changelog was found, and the product What's New page is dated and carries some API items (8 of 15).\n- Agent ergonomics 51: Graded on the REST API. Lists default to 200 records a page and `per_page` lowers that. No field selection parameter was found (10 of 25). `page`, `per_page` and `has_more_page` in `page_context`, with `filter_by`, `search_text`, `sort_column` and, on 17 operations, `last_modified_time` (18 of 20). Errors return a JSON `code` and `message`, documented thinly (10 of 20). Upsert by a unique custom field on 15 update operations, with no idempotency key on creates (8 of 20). No official SDK for the Books API was found, every call needs `organization_id`, access tokens last one hour and hosts differ by data centre (5 of 15).\n- Security \u0026 auth 68: OAuth 2.0 with scopes per module and operation (81 scope strings in the OpenAPI files, such as `ZohoBooks.invoices.READ`), one-hour access tokens and refresh tokens the user can revoke (30). Less 10 because the documented token and refresh calls carry the client secret and refresh token in the URL query string, and the page tells readers to use the query string (20 of 30). READ scopes per module allow a read-only agent. No approval step for deletes through the API was found (13 of 20). Records hold text from customers and vendors and no prompt-injection guidance was found. The MCP help page asks users to get an admin's approval first and to add tools only when required (3 of 15). The API Usage dashboard lists recent calls by user, module, IP address and application, and plans include an activity log (12 of 15). security.txt valid to 30 June 2028, a bug bounty, SOC 2 Type 2 and ISO/IEC 27001 (20).\n- Payments \u0026 pricing 30: No x402, MPP or L402 (0). Plan prices are public, $15 to $240 an organisation a month billed yearly in the US edition. Calls have no unit price, and the API add-on that raises the daily limit has no public price (10). The Free plan includes 1,000 API requests a day per the plan comparison, and the signup steps on the pricing page ask for a company name, email address, phone number and password, with no card mentioned (20). A person signs up in a browser, registers an OAuth client in the developer console and approves scopes (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 56: The OpenAPI archive was last modified on 7 October 2026, one day before this check, though we could not tell what changed in it. The newest dated entry on the product What's New page is 31 July 2026 (25 of 30). That page has entries on 14, 17, 22, 29, 30 and 31 July 2026, inside the last 90 days (20). A dated product changelog, a community forum and support by email, which we did not test for replies (8 of 25). No official SDK for the Books API was found. An official Zoho Books MCP connection exists through Zoho MCP and a Claude connector, and no Zoho server appears in the official MCP registry (3 of 15). No package to assess (0 of 10).\n- Transparency \u0026 trust 75: Closed service under the Zoho Terms of Service, last updated 2 March 2022 (15 of 30). The privacy policy of 22 December 2025 says Zoho does not sell personal information, and that data is deleted from the active database within six months of account termination and from backups three months later. The DPA is sent on request by email (24 of 30). No API deprecation policy or dated retirement notice was found. The help centre notes a new API domain from 1 June 2024 without an end date for the old one (0). A sub-processor page exists, but its directory loads by script and we could not read the list. The data centre page names locations and their certifications (15 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (21 items): https://www.anchorterminal.com/fixes/zoho-books.md (JSON https://www.anchorterminal.com/fixes/zoho-books.json)\n\n### What we couldn't check\n\n- unchecked: the tools of the Zoho Books MCP connection. The help page refers to a Tools list it does not show, and the Zoho MCP setup guide on help.zoho.com loads by script\n- unchecked: the sub-processor directory at zoho.com/privacy/sub-processors.html, which loads by script\n- unchecked: status pages for data centres other than the US\n- unchecked: whether the Books API was affected during the Deluge outage of 3 September 2026\n- unchecked: what changed in the OpenAPI archive on 7 October 2026. Only its modification date was read\n- unchecked: GitHub. The shell could not list Zoho's repositories, so the absence of an official Books SDK rests on the API docs naming none\n- The US pricing page lists API Access under Standard, while the plan comparison and the API docs give the Free plan 1,000 requests a day. We followed the comparison and the docs\n- The price of the API add-on that raises the daily limit is shown only inside the product\n- No SLA page, API deprecation policy or dated API changelog was found\n- The Terms of Service forbid using the services for any form of competitive or benchmarking purposes, which matters before our probes run. Recorded as a fact, with no deduction\n- The Markdown help pages open with a line addressed to AI readers telling them to read the help llms.txt first. Recorded as a fact, with no deduction\n- The lead was right on the vendor, URL, docs link, OAuth 2.0 and the limits. It was wrong on reports, since no report endpoint is documented, and it did not mention the MCP connection\n\n### Sources\n\n- API introduction, limits and data centres: \u003chttps://www.zoho.com/books/api/v3/introduction/\u003e (seen 2026-10-08)\n- API introduction as Markdown: \u003chttps://www.zoho.com/books/api/v3/introduction/overview.md\u003e (seen 2026-10-08)\n- OAuth and scopes: \u003chttps://www.zoho.com/books/api/v3/oauth/\u003e (seen 2026-10-08)\n- errors: \u003chttps://www.zoho.com/books/api/v3/errors/\u003e (seen 2026-10-08)\n- pagination: \u003chttps://www.zoho.com/books/api/v3/pagination/\u003e (seen 2026-10-08)\n- invoices reference: \u003chttps://www.zoho.com/books/api/v3/invoices/\u003e (seen 2026-10-08)\n- create an invoice as Markdown: \u003chttps://www.zoho.com/books/api/v3/invoices/create-an-invoice.md\u003e (seen 2026-10-08)\n- OpenAPI archive (downloaded and parsed): \u003chttps://www.zoho.com/books/api/v3/openapi-all.zip\u003e (seen 2026-10-08)\n- US pricing: \u003chttps://www.zoho.com/us/books/pricing/\u003e (seen 2026-10-08)\n- US plan comparison: \u003chttps://www.zoho.com/us/books/pricing/pricing-comparison.html\u003e (seen 2026-10-08)\n- product What's New: \u003chttps://www.zoho.com/books/whats-new.html\u003e (seen 2026-10-08)\n- Zoho Books MCP help page: \u003chttps://www.zoho.com/us/books/help/mcp/zoho-books-mcp.html\u003e (seen 2026-10-08)\n- Zoho MCP: \u003chttps://www.zoho.com/mcp/\u003e (seen 2026-10-08)\n- Zoho MCP pricing: \u003chttps://www.zoho.com/mcp/pricing.html\u003e (seen 2026-10-08)\n- API Usage help page: \u003chttps://www.zoho.com/us/books/help/settings/developer-and-data/api-usage.html\u003e (seen 2026-10-08)\n- webhooks help page: \u003chttps://www.zoho.com/us/books/help/settings/automation/workflow-actions/webhooks.html\u003e (seen 2026-10-08)\n- help centre llms.txt: \u003chttps://www.zoho.com/us/books/help/llms.txt\u003e (seen 2026-10-08)\n- official MCP registry search for zoho: \u003chttps://registry.modelcontextprotocol.io/v0.1/servers?search=zoho\u003e (seen 2026-10-08)\n- status page: \u003chttps://us.zohostatus.com/\u003e (seen 2026-10-08)\n- status incident history: \u003chttps://us.zohostatus.com/incident_history\u003e (seen 2026-10-08)\n- status RSS: \u003chttps://us.zohostatus.com/rss\u003e (seen 2026-10-08)\n- terms of service: \u003chttps://www.zoho.com/terms.html\u003e (seen 2026-10-08)\n- contracting entities: \u003chttps://www.zoho.com/legal/zoho-contracting-entities.html\u003e (seen 2026-10-08)\n- developer agreement: \u003chttps://www.zoho.com/developer/terms.html\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.zoho.com/privacy.html\u003e (seen 2026-10-08)\n- sub-processors: \u003chttps://www.zoho.com/privacy/sub-processors.html\u003e (seen 2026-10-08)\n- GDPR and DPA: \u003chttps://www.zoho.com/gdpr.html\u003e (seen 2026-10-08)\n- data centres: \u003chttps://www.zoho.com/know-your-datacenter.html\u003e (seen 2026-10-08)\n- compliance: \u003chttps://www.zoho.com/compliance.html\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://www.zoho.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- RDAP for zoho.com: \u003chttps://rdap.verisign.com/com/v1/domain/zoho.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 95/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Zoho Corporation Private Limited | 20/20 |\n| Domain age | zoho.com, registered 2004-01-16 (22 years) | 15/15 |\n| Endpoint on the vendor's domain | www.zohoapis.com | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects, and has 1 clause that costs points | 8/10 |\n| Status page | status.zoho.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | valid | 10/10 |\n\nAPI calls go to www.zohoapis.com and its regional equivalents, a Zoho domain other than zoho.com.\n\nThe Terms of Service (last updated 2 March 2022) are the service agreement for Zoho's online services. The contracting entity depends on the customer's region, Zoho Corporation Private Limited for India and Zoho Corporation for the United States (https://www.zoho.com/legal/zoho-contracting-entities.html).\n\nA separate Zoho Developer Agreement at https://www.zoho.com/developer/terms.html covers the developer tools.\n\nThe privacy policy was last updated on 22 December 2025 and covers Zoho's websites and the products on them.\n\nsecurity.txt at www.zoho.com gives a bug bounty contact, security@zohocorp.com, a policy link and an expiry of 30 June 2028.\n\nThe changelog link is the product What's New page, newest entry 31 July 2026. No dated API changelog was found.\n\nRDAP for zoho.com gives a registration date of 2004-01-16.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.zoho.com/terms.html), read 2026-10-08, dated 2022-03-02, states 6 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"use the Services for any form of competitive or benchmarking purposes\"\n- To know. Has not been updated for three years or more. \"Last updated on: 2nd March 2022.\"\n- Gives the date it was last updated. Last updated 2022-03-02.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim or $1000.\n- Says how changes to the terms are announced. Gives 30 days of notice before a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Subscriptions renew automatically and the customer must give at least seven days' notice before the renewal date to stop renewal. \"If you do not wish to renew the subscription, you must inform us at least seven days prior to the renewal date.\"\n- Also in the text (2026-10-08). Unpaid accounts inactive for 120 continuous days may be terminated and their data deleted, with prior notice, and activity in one service does not keep another active. \"We reserve the right to terminate unpaid user accounts that are inactive for a continuous period of 120 days.\"\n- Also in the text (2026-10-08). If the customer does not answer a forwarded complaint within 10 days, Zoho may give the customer's name and contact information to the complainant. \"If you do not respond to the complainant within 10 days from the date of our email to you, we may disclose your name and contact information to the complainant for enabling the complainant to take legal action against you.\"\n\n**Privacy policy** (https://www.zoho.com/privacy.html), read 2026-10-08, dated 2025-12-22, states 8 of the 8 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). \"In keeping with Zoho's promise not to exploit your data in a way that is not respectful of your privacy and confidentiality expectations, we make only the following limited use of service data for these technologies: (i) using anonymized crops of service data to improve accuracy of the algorithms;\"\n- Gives the date it was last updated. Last updated 2025-12-22.\n- Says how long data is kept. Names a period of 6 months.\n- Gives a privacy contact. privacy@zohocorp.com.\n- Says where data is transferred or stored. Data goes to the United States.\n- Also in the text (2026-10-08). Zoho employees and contractors may open service data to resolve errors and to check by hand emails reported as spam and scanned images. \"so that they can (i) identify, analyze and resolve errors, (ii) manually verify emails reported as spam to improve spam detection, or (iii) manually verify scanned images that you submit to us to verify the accuracy of optical character recognition.\"\n- Also in the text (2026-10-08). Zoho says it uses an organisation's data to develop models specific to that organisation. \"(ii) using your organization's data for developing models specific for your organization.\"\n- Also in the text (2026-10-08). After an account is terminated, data leaves the active database at a clean-up run once every six months and leaves backups three months later. \"Once you terminate your Zoho user account, your data will eventually get deleted from active database during the next clean-up that occurs once in 6 months.\"\n\n## Live (updated 2026-10-08 21:12 UTC)\n\n- Right now: up, HTTP 404, 427 ms, checked 2026-10-08 21:12 UTC (get on `https://www.zohoapis.com/books/v3`)\n- Uptime 24h 100.0% (21 probes) · 30 days 100.0% (21 probes) · p50 448 ms · p95 486 ms\n- Vendor status page: unknown, no machine-readable status found\n- Always current: https://www.anchorterminal.com/api/v1/live/zoho-books.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Standard | $15 | per month (plan) | per organisation, billed yearly; $20 billed monthly; 3 users, 2,000 API requests a day |\n| Professional | $40 | per month (plan) | per organisation, billed yearly; $50 billed monthly; 5 users, 5,000 API requests a day |\n| Premium | $60 | per month (plan) | per organisation, billed yearly; $70 billed monthly; 10 users, 10,000 API requests a day |\n| Elite | $120 | per month (plan) | per organisation, billed yearly; $150 billed monthly; 10 users, 10,000 API requests a day |\n| Ultimate | $240 | per month (plan) | per organisation, billed yearly; $275 billed monthly; 15 users, 10,000 API requests a day |\n| Additional user | $2.50 | per seat per month | billed yearly; $3 billed monthly; paid plans only |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- OpenAPI 3.0.0 files for 45 resources and 885 operations download from the docs as `openapi-all.zip`\n- OAuth scopes narrow to one module and one operation, such as `ZohoBooks.invoices.READ`\n- Every API reference operation has a Markdown twin, such as `/books/api/v3/invoices/create-an-invoice.md`\n- The Free plan includes 1,000 API requests a day per the plan comparison\n- The API Usage dashboard lists recent calls by user, module, IP address and application\n\n## Weaknesses\n\n- No profit and loss, balance sheet or other report endpoint appears in the API docs or the OpenAPI files\n- The documented token and refresh calls put the client secret and refresh token in the URL query string\n- Daily caps are low, 1,000 requests on Free and 10,000 on the top three plans\n- No official SDK, SLA, API deprecation policy or dated API changelog found in the reviewed pages\n- 429 is documented without a Retry-After header or backoff guidance\n\n## Before you call it (notes for agents)\n\n1. Send `organization_id` as a query parameter on every call. Read it from `GET /organizations` first\n2. Use the `api_domain` returned with the token, since each of the nine data centres has its own host (zohoapis.com, zohoapis.eu, zohoapis.in and others)\n3. Send `Authorization: Zoho-oauthtoken \u003ctoken\u003e` and refresh hourly. Each user keeps at most 20 refresh tokens and the oldest is deleted\n4. Stay under 100 requests a minute and the plan's daily cap. Codes 44, 45 and 1070 on a 429 mean minute, day and concurrency limits\n5. To repeat an update safely, send `X-Unique-Identifier-Key`, `X-Unique-Identifier-Value` and `X-Upsert` with a unique custom field. Creates have no idempotency key\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -X GET 'https://www.zohoapis.com/books/v3/organizations' \\\n  -H \"Authorization: Zoho-oauthtoken $ZOHO_ACCESS_TOKEN\"\n```\n\nThrough letme (picks today, calling later): https://letme.dev/zoho-books. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Apideck Accounting API + MCP | BB | 72.9 | 83 | accounting.ledger, accounting.invoices, accounting.bills | no | https://www.anchorterminal.com/tools/apideck-accounting.md |\n| Merge Accounting API | BB | 70 | 143 | accounting.ledger, accounting.invoices, accounting.bills | no | https://www.anchorterminal.com/tools/merge-accounting.md |\n| Xero API + MCP | B | 67.2 | 213 | accounting.ledger, accounting.invoices, accounting.bills | no | https://www.anchorterminal.com/tools/xero.md |\n| Codat | B | 64.3 | 280 | accounting.bills, accounting.ledger, accounting.invoices | no | https://www.anchorterminal.com/tools/codat.md |\n| FreeAgent API | C | 57.2 | 481 | accounting.ledger, accounting.invoices, accounting.bills | no | https://www.anchorterminal.com/tools/freeagent.md |\n| Odoo External API | C | 55.9 | 499 | accounting.ledger, accounting.invoices, accounting.bills | no | https://www.anchorterminal.com/tools/odoo.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Limits are 100 requests a minute per organisation and a daily cap by plan, 1,000 on Free, 2,000 on Standard, 5,000 on Professional and 10,000 on Premium, Elite and Ultimate (source: \u003chttps://www.zoho.com/books/api/v3/introduction/\u003e)\n- The OpenAPI archive holds 45 YAML files with 885 operations, last modified on 7 October 2026 (source: \u003chttps://www.zoho.com/books/api/v3/openapi-all.zip\u003e)\n- No report endpoint is documented. The API reference has 45 resource sections from contacts to reporting tags, and none returns the profit and loss or balance sheet (source: \u003chttps://www.zoho.com/books/api/v3/introduction/\u003e)\n- The documented token and refresh calls are POSTs with `client_id`, `client_secret` and `refresh_token` in the query string, and the page says to put the parameters there (source: \u003chttps://www.zoho.com/books/api/v3/oauth/\u003e)\n- Zoho documents an official Zoho Books MCP connection through Zoho MCP and a Claude connector. Calls draw on the same API limits and Zoho MCP has no separate price (source: \u003chttps://www.zoho.com/us/books/help/mcp/zoho-books-mcp.html, https://www.zoho.com/mcp/pricing.html\u003e)\n- The Terms of Service forbid using the services for any form of competitive or benchmarking purposes (source: \u003chttps://www.zoho.com/terms.html\u003e)\n- The US status page lists a Zoho Books component. Its one Books-named incident in the past year lasted 44 minutes on 6 February 2026 (source: \u003chttps://us.zohostatus.com/incident_history\u003e)\n\n## Compare\n\n- [Apideck Accounting API + MCP vs Zoho Books](https://www.anchorterminal.com/compare/apideck-accounting-vs-zoho-books.md): BB 72.9 vs C 61.1\n- [Codat vs Zoho Books](https://www.anchorterminal.com/compare/codat-vs-zoho-books.md): B 64.3 vs C 61.1\n- [FreeAgent API vs Zoho Books](https://www.anchorterminal.com/compare/freeagent-vs-zoho-books.md): C 57.2 vs C 61.1\n- [FreshBooks API vs Zoho Books](https://www.anchorterminal.com/compare/freshbooks-vs-zoho-books.md): E 45.4 vs C 61.1\n- [Merge Accounting API vs Zoho Books](https://www.anchorterminal.com/compare/merge-accounting-vs-zoho-books.md): BB 70 vs C 61.1\n- [Odoo External API vs Zoho Books](https://www.anchorterminal.com/compare/odoo-vs-zoho-books.md): C 55.9 vs C 61.1\n- [QuickBooks Online API + MCP vs Zoho Books](https://www.anchorterminal.com/compare/quickbooks-online-vs-zoho-books.md): D 49.2 vs C 61.1\n- [Rutter Accounting API vs Zoho Books](https://www.anchorterminal.com/compare/rutter-vs-zoho-books.md): C 55.6 vs C 61.1\n- [Xero API + MCP vs Zoho Books](https://www.anchorterminal.com/compare/xero-vs-zoho-books.md): B 67.2 vs C 61.1\n- [Invoice Ninja API vs Zoho Books](https://www.anchorterminal.com/compare/invoice-ninja-vs-zoho-books.md): D 52.1 vs C 61.1\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on zoho.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"zoho-books\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/zoho-books\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/zoho-books.svg\" alt=\"Zoho Books on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Zoho Books on Anchor Terminal](https://www.anchorterminal.com/badges/zoho-books.svg)](https://www.anchorterminal.com/tools/zoho-books)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/zoho-books\"\u003eZoho Books on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Zoho Books is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/zoho-books-dark.png\n- Light: https://www.anchorterminal.com/assets/share/zoho-books-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Accounting \u0026 invoicing",
        "url": "https://www.anchorterminal.com/categories/accounting"
      },
      {
        "name": "Zoho Books",
        "url": ""
      }
    ],
    "description": "Zoho Books is hosted accounting software from Zoho for small and mid-sized businesses. Agents reach it through the REST API v3, covering invoices, bills, payments, banking, journals and the chart of accounts behind OAuth 2.0.",
    "facts": [
      "rank #377 of 722",
      "OAuth auth",
      "0 desk reviews"
    ],
    "h1": "Zoho Books",
    "image": "https://www.anchorterminal.com/assets/og/tools-zoho-books.png",
    "path": "/tools/zoho-books",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Zoho Books review for AI agents, grade C (61.1/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/zoho-books"
  },
  "tokens": {
    "markdown": 8200,
    "slim": 1980
  },
  "version": 1
}
