# Zoho Books (slim) > Zoho Books is hosted accounting software from Zoho for small and mid-sized businesses. Agents reach it through the REST API v3, covering invoices, bills, payments, banking, journals and the chart of accounts behind OAuth 2.0. - Full: https://www.anchorterminal.com/tools/zoho-books.md (~8,200 tokens) · this version ~1,980 tokens · JSON https://www.anchorterminal.com/tools/zoho-books.json · canonical https://www.anchorterminal.com/tools/zoho-books - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 61.1/100 · rank #377 of 722 · #5 in Accounting & invoicing · not agent-ready · confidence medium** Assessment: The public OpenAPI files cover 885 operations with OAuth scopes per module and operation, and the Free plan allows 1,000 API requests a day. No report endpoint, official SDK, SLA or dated API changelog was found, and the documented token calls put the client secret in the URL. ## Facts - Kind: HTTP API · vendor: Zoho · category: Accounting & invoicing · legal entity: Zoho Corporation Private Limited · provenance 95/100 - Endpoint: `https://www.zohoapis.com/books/v3` (HTTP) - Auth: OAuth · pricing: Freemium · x402: no · licence: Proprietary service under Zoho's Terms of Service - Probe metrics: not measured yet (probes haven't run) - API: REST API v3 at https://www.zohoapis.com/books/v3 (US). 885 operations across contacts, estimates, sales orders, invoices, credit notes, customer payments, expenses, purchase orders, bills, vendor credits, vendor payments, bank accounts, bank transactions, bank rules, chart of accounts, journals, fixed assets, projects, time entries, items, taxes and settings - Not in the API: No report endpoints (profit and loss, balance sheet, trial balance) in the API docs or the OpenAPI files - MCP: Official Zoho Books connection through Zoho MCP (a hosted hub where a user builds a server from chosen tools) and a default Claude connector. Tool list not published on the help page - Credentials: OAuth 2.0 authorisation code grant, or a self client that generates a grant token in the developer console. Access tokens last one hour. Refresh tokens last until revoked, 20 at most per user - Auth scopes: `ZohoBooks..` with operations CREATE, READ, UPDATE, DELETE and ALL. Modules include contacts, settings, estimates, invoices, customerpayments, creditnotes, projects, expenses, salesorders, purchaseorders, bills, debitnotes, vendorpayments, banking and accountants - Rate limits: 100 requests a minute per organisation. Daily caps of 1,000 (Free), 2,000 (Standard), 5,000 (Professional) and 10,000 (Premium, Elite, Ultimate). 5 concurrent calls on Free and 10 on paid plans, a soft limit - Errors: JSON `code` and `message`. HTTP 400, 401, 404, 405, 429 and 500 are listed. On 429, code 44 is the minute limit, 45 the daily cap and 1070 the concurrency limit - Pagination: `page` and `per_page`, 200 records by default, with `has_more_page` in `page_context`. `filter_by`, `search_text`, `sort_column` and `last_modified_time` on list calls - Safe retries: `X-Unique-Identifier-Key`, `X-Unique-Identifier-Value` and `X-Upsert` on 15 update operations match a record by a unique custom field. No idempotency key on creates - Webhooks: Outgoing webhooks are a workflow action with an optional secret token for a payload hash, up to 20 retries and a daily limit by plan. Incoming webhooks are a separate setting - Data centres: US, Europe, India, Australia, Japan, Canada, China, Saudi Arabia and the United Arab Emirates, each with its own accounts host and API domain - SDKs: None named in the API docs. Samples are curl and code snippets per operation - Free tier: Free plan, one user and one accountant, 1,000 API requests a day, yearly revenue under $50,000 and 1,000 invoices a year. 14-day trial of paid plans - Audit: API Usage dashboard with a 30-day timeline, top modules, applications, IP addresses and users, and recent calls, refreshed every 3 hours. Activity log in the plan comparison - Certifications: SOC 2 Type 2, SOC 1 and ISO/IEC 27001 per zoho.com/compliance.html. Bug bounty at bugbounty.zohocorp.com - Status: status.zoho.com redirects to us.zohostatus.com, with a Zoho Books component and incident history back to November 2025 - Prices: Standard $15 per month (plan); Professional $40 per month (plan); Premium $60 per month (plan); Elite $120 per month (plan); Ultimate $240 per month (plan); Additional user $2.50 per seat per month - Scores: Reliability 71, Performance pending, Schema & documentation 71, Agent ergonomics 51, Security & auth 68, Payments & pricing 30, Task success pending, Maintenance & community 56, Transparency & trust 75 · total over the 7 assessed categories - Why: Reliability, Graded on the REST API v3, read as a hosted service. · Schema & documentation, The docs link a downloadable archive, `openapi-all.zip`, holding OpenAPI 3.0.0 files for 45 resources and 885 operations (25). · Agent ergonomics, Graded on the REST API. · Security & auth, OAuth 2.0 with scopes per module and operation (81 scope strings in the OpenAPI files, such as `ZohoBooks.invoices.READ`), one-hour access t… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The OpenAPI archive was last modified on 7 October 2026, one day before this check, though we could not tell what changed in it. · Transparency & trust, Closed service under the Zoho Terms of Service, last updated 2 March 2022 (15 of 30). - Sources: 31, open questions: 12, both in the full twin - Capabilities: accounting.ledger, accounting.invoices, accounting.bills - JSON: https://www.anchorterminal.com/api/v1/tools/zoho-books.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/zoho-books.svg` or a link to https://www.anchorterminal.com/tools/zoho-books from a page on zoho.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `organization_id` as a query parameter on every call. Read it from `GET /organizations` first 2. Use the `api_domain` returned with the token, since each of the nine data centres has its own host (zohoapis.com, zohoapis.eu, zohoapis.in and others) 3. Send `Authorization: Zoho-oauthtoken ` and refresh hourly. Each user keeps at most 20 refresh tokens and the oldest is deleted 4. Stay under 100 requests a minute and the plan's daily cap. Codes 44, 45 and 1070 on a 429 mean minute, day and concurrency limits 5. To repeat an update safely, send `X-Unique-Identifier-Key`, `X-Unique-Identifier-Value` and `X-Upsert` with a unique custom field. Creates have no idempotency key ## Connect ```bash curl -X GET 'https://www.zohoapis.com/books/v3/organizations' \ -H "Authorization: Zoho-oauthtoken $ZOHO_ACCESS_TOKEN" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/zoho-books ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Apideck Accounting API + MCP | BB | 72.9 | accounting.ledger, accounting.invoices, accounting.bills | https://www.anchorterminal.com/tools/apideck-accounting.min.md | | Merge Accounting API | BB | 70 | accounting.ledger, accounting.invoices, accounting.bills | https://www.anchorterminal.com/tools/merge-accounting.min.md | | Xero API + MCP | B | 67.2 | accounting.ledger, accounting.invoices, accounting.bills | https://www.anchorterminal.com/tools/xero.min.md | | Codat | B | 64.3 | accounting.bills, accounting.ledger, accounting.invoices | https://www.anchorterminal.com/tools/codat.min.md | | FreeAgent API | C | 57.2 | accounting.ledger, accounting.invoices, accounting.bills | https://www.anchorterminal.com/tools/freeagent.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)