{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/hubspot-mcp.json",
        "name": "HubSpot API + MCP",
        "score": 71.5,
        "shared": [
          "crm.records",
          "crm.pipeline",
          "crm.activities",
          "crm.search",
          "crm.webhooks"
        ],
        "slug": "hubspot-mcp"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/dynamics-365-sales.json",
        "name": "Microsoft Dynamics 365 Sales",
        "score": 69.7,
        "shared": [
          "crm.records",
          "crm.pipeline",
          "crm.activities",
          "crm.search",
          "crm.webhooks"
        ],
        "slug": "dynamics-365-sales"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/close.json",
        "name": "Close API + MCP",
        "score": 66.7,
        "shared": [
          "crm.records",
          "crm.pipeline",
          "crm.activities",
          "crm.search",
          "crm.webhooks"
        ],
        "slug": "close"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/twenty.json",
        "name": "Twenty API + MCP",
        "score": 65.9,
        "shared": [
          "crm.records",
          "crm.pipeline",
          "crm.activities",
          "crm.search",
          "crm.webhooks"
        ],
        "slug": "twenty"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/affinity.json",
        "name": "Affinity",
        "score": 63.4,
        "shared": [
          "crm.records",
          "crm.pipeline",
          "crm.activities",
          "crm.search",
          "crm.webhooks"
        ],
        "slug": "affinity"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/attio.json",
        "name": "Attio API + MCP",
        "score": 63.1,
        "shared": [
          "crm.records",
          "crm.pipeline",
          "crm.activities",
          "crm.search",
          "crm.webhooks"
        ],
        "slug": "attio"
      }
    ],
    "tool": {
      "slug": "zoho-crm",
      "name": "Zoho CRM",
      "vendor": "Zoho",
      "vendorUrl": "https://www.zoho.com/crm/",
      "kind": "http-api",
      "category": "crm",
      "summary": "Zoho CRM is a hosted sales CRM from Zoho. Agents reach it through the REST API v8, with record, search, query, bulk and notification endpoints behind OAuth 2.0, or through four pre-built remote MCP servers.",
      "url": "https://www.anchorterminal.com/tools/zoho-crm",
      "markdownUrl": "https://www.anchorterminal.com/tools/zoho-crm.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/zoho-crm.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/zoho-crm.json",
      "repo": "https://github.com/zoho/crm-oas",
      "license": "Proprietary service under Zoho's Terms of Service. The server-side SDKs on GitHub are Apache-2.0",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@zohocrm/nodejs-sdk-8.0"
        },
        {
          "registry": "pypi",
          "name": "zohocrmsdk8-0"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 only. A person registers a client in the Zoho API console (a web application, or a self client for one organisation) and approves scopes, which narrow to one module and one operation. The access token lasts one hour and goes in `Authorization: Zoho-oauthtoken \u003ctoken\u003e`. The refresh token lasts until revoked. Each data centre has its own accounts host and API domain. Registration is self-serve, with no app review or sales approval for use inside one's own organisation.",
      "pricing": "freemium",
      "pricingNotes": "Free edition for three users with 5,000 API credits a day and no card at signup. Paid editions cost $14 to $52 a user a month billed yearly ($20 to $65 monthly) and have a 15-day trial. API calls draw on a daily credit allowance set by edition and user licences. Extra credits are pay as you go from $0.14 per 1,000 a day (https://www.zoho.com/crm/zohocrm-pricing.html, checked 2026-10-08).",
      "priceSummary": "$14 / seat-mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI files or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 830,
        "pypiWeekly": 6148,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.zoho.com/crm/developer/docs/api/v8/",
      "openapi": "https://github.com/zoho/crm-oas/tree/main/v8.0",
      "capabilities": [
        "crm.records",
        "crm.pipeline",
        "crm.activities",
        "crm.search",
        "crm.webhooks"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "oauth",
        "openapi",
        "mcp",
        "webhooks",
        "free-tier",
        "no-card",
        "python",
        "nodejs",
        "java",
        "status-page",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-09-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.8,
        "grade": "BB",
        "agentReady": true,
        "rank": 128,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 81,
          "maintenance": 77,
          "payments": 40,
          "reliability": 72,
          "schema": 81,
          "security": 67,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 72,
            "points": 14.4,
            "reason": "Graded on the REST API v8, read as a hosted service. status.zoho.com redirects to us.zohostatus.com, which has a Zoho CRM component and incident history back to November 2025 (20). No incident in the last 90 days names CRM. On 3 September 2026 a Zoho Deluge outage ran 2 hours 34 minutes and the status feed shows the CRM component changing state when it ended, so we read the record as minor incidents only (20 of 30). Only the US page was read. Daily credits and concurrency are published with numbers per edition (15). 429 is documented and `X-API-CREDITS-REMAINING` appears once half the allowance is used, but no Retry-After or backoff guidance was found. Upsert and `If-Unmodified-Since` make writes safer to retry (7 of 15). No SLA found (0). v8 is the current documented version (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 81,
            "points": 13.16,
            "reason": "zoho/crm-oas on GitHub holds OpenAPI 3.1 files for 103 resources and 644 operations (25). No llms.txt at zoho.com, but the same repository carries a compressed Markdown page and examples per operation, written for Zoho's CRM agent skills (7 of 10). Operation descriptions state the purpose and name the call that supplies each ID, with little on when not to use one (15 of 20). Parameters carry enums, patterns and length limits. Record bodies accept any property because modules have custom fields, and search criteria are a string grammar (11 of 15). Each reference page has curl samples and a Possible Errors list with a resolution per code (15). The version is in the path, and What's New in V8 lists changes without dates. No dated changelog found (8 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 81,
            "points": 13.16,
            "reason": "Graded on the REST API. `fields` is mandatory on list calls with at most 50 names, and COQL selects columns, so responses can be kept small (22 of 25). `per_page` up to 200, `page` to 2,000 records and `page_token` to 100,000, plus search by criteria, email, phone or word, custom views and COQL (20). Errors carry a code, a message and details naming the field or the existing record, each documented with a resolution (18 of 20). Upsert on duplicate check fields and `If-Unmodified-Since`, with no idempotency key (10 of 20). Official SDKs in six languages, but the one-hour token, the refresh step and per-data-centre hosts add setup (11 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 67,
            "points": 11.73,
            "reason": "OAuth 2.0 with scopes down to one module and one operation, one-hour access tokens and revocable refresh tokens (30). Less 10 because the documented refresh and revoke calls carry the refresh token and client secret in the URL query string (20 of 30). READ-only scopes per module and a read-only Data Insights MCP server. Calls are also bound by the user's CRM role. No approval step for deletes, and mass delete exists (14 of 20). Records hold text from outside parties and no prompt-injection guidance was found (3 of 15). Audit Logs in paid editions, and an API dashboard of credits by application (10 of 15). security.txt valid to 30 June 2028, a bug bounty, SOC 2 Type 2 and ISO/IEC 27001, 27701 and 27017 (20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 40,
            "points": 5,
            "reason": "No x402, MPP or L402 (0). Edition prices are public, $14 to $52 a user a month billed yearly, and extra API credits have a published unit price from $0.14 per 1,000 a day (20). The Free edition covers three users with 5,000 API credits a day and needs no card at signup (20). A person signs up in a browser, registers an OAuth client in the API console and approves scopes (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 77,
            "points": 6.74,
            "reason": "The Node.js SDK for v8 reached 4.0.0 on 21 September 2026, 17 days before this check (30). Three dated changes in the last 90 days, Python SDK 7.0.0 on 24 July, the OpenAPI files on 2 September and Node.js SDK 4.0.0 on 21 September (20). No dated API changelog. The docs link to community posts on help.zoho.com, which we did not test for replies (8 of 25). Current official SDKs for Java, Python, PHP, Node.js, C# and Ruby (15). The SDK repositories show no public CI, and the Java SDK was last released on 7 January 2026 (4 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 75,
            "points": 6.56,
            "note": "editorial 54, provenance 95",
            "reason": "Closed service under the Zoho Terms of Service, last updated 2 March 2022, with Apache-2.0 SDKs (15 of 30). The privacy policy of 22 December 2025 says Zoho does not sell personal information, and that data is deleted from the active database within six months of account termination and from backups three months later. The DPA is sent on request by email (24 of 30). No API deprecation policy or dated notices found (0). A sub-processor page exists, but its directory loads by script and we could not read the list. The data centre page names locations and their certifications (15 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Graded on the REST API. `fields` is mandatory on list calls with at most 50 names, and COQL selects columns, so responses can be kept small (22 of 25). `per_page` up to 200, `page` to 2,000 records and `page_token` to 100,000, plus search by criteria, email, phone or word, custom views and COQL (20). Errors carry a code, a message and details naming the field or the existing record, each documented with a resolution (18 of 20). Upsert on duplicate check fields and `If-Unmodified-Since`, with no idempotency key (10 of 20). Official SDKs in six languages, but the one-hour token, the refresh step and per-data-centre hosts add setup (11 of 15).",
            "maintenance": "The Node.js SDK for v8 reached 4.0.0 on 21 September 2026, 17 days before this check (30). Three dated changes in the last 90 days, Python SDK 7.0.0 on 24 July, the OpenAPI files on 2 September and Node.js SDK 4.0.0 on 21 September (20). No dated API changelog. The docs link to community posts on help.zoho.com, which we did not test for replies (8 of 25). Current official SDKs for Java, Python, PHP, Node.js, C# and Ruby (15). The SDK repositories show no public CI, and the Java SDK was last released on 7 January 2026 (4 of 10).",
            "payments": "No x402, MPP or L402 (0). Edition prices are public, $14 to $52 a user a month billed yearly, and extra API credits have a published unit price from $0.14 per 1,000 a day (20). The Free edition covers three users with 5,000 API credits a day and needs no card at signup (20). A person signs up in a browser, registers an OAuth client in the API console and approves scopes (0).",
            "reliability": "Graded on the REST API v8, read as a hosted service. status.zoho.com redirects to us.zohostatus.com, which has a Zoho CRM component and incident history back to November 2025 (20). No incident in the last 90 days names CRM. On 3 September 2026 a Zoho Deluge outage ran 2 hours 34 minutes and the status feed shows the CRM component changing state when it ended, so we read the record as minor incidents only (20 of 30). Only the US page was read. Daily credits and concurrency are published with numbers per edition (15). 429 is documented and `X-API-CREDITS-REMAINING` appears once half the allowance is used, but no Retry-After or backoff guidance was found. Upsert and `If-Unmodified-Since` make writes safer to retry (7 of 15). No SLA found (0). v8 is the current documented version (10).",
            "schema": "zoho/crm-oas on GitHub holds OpenAPI 3.1 files for 103 resources and 644 operations (25). No llms.txt at zoho.com, but the same repository carries a compressed Markdown page and examples per operation, written for Zoho's CRM agent skills (7 of 10). Operation descriptions state the purpose and name the call that supplies each ID, with little on when not to use one (15 of 20). Parameters carry enums, patterns and length limits. Record bodies accept any property because modules have custom fields, and search criteria are a string grammar (11 of 15). Each reference page has curl samples and a Possible Errors list with a resolution per code (15). The version is in the path, and What's New in V8 lists changes without dates. No dated changelog found (8 of 15).",
            "security": "OAuth 2.0 with scopes down to one module and one operation, one-hour access tokens and revocable refresh tokens (30). Less 10 because the documented refresh and revoke calls carry the refresh token and client secret in the URL query string (20 of 30). READ-only scopes per module and a read-only Data Insights MCP server. Calls are also bound by the user's CRM role. No approval step for deletes, and mass delete exists (14 of 20). Records hold text from outside parties and no prompt-injection guidance was found (3 of 15). Audit Logs in paid editions, and an API dashboard of credits by application (10 of 15). security.txt valid to 30 June 2028, a bug bounty, SOC 2 Type 2 and ISO/IEC 27001, 27701 and 27017 (20).",
            "transparency": "Closed service under the Zoho Terms of Service, last updated 2 March 2022, with Apache-2.0 SDKs (15 of 30). The privacy policy of 22 December 2025 says Zoho does not sell personal information, and that data is deleted from the active database within six months of account termination and from backups three months later. The DPA is sent on request by email (24 of 30). No API deprecation policy or dated notices found (0). A sub-processor page exists, but its directory loads by script and we could not read the list. The data centre page names locations and their certifications (15 of 20)."
          },
          "sources": [
            {
              "what": "API v8 index",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/",
              "seen": "2026-10-08"
            },
            {
              "what": "API limits",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/api-limits.html",
              "seen": "2026-10-08"
            },
            {
              "what": "scopes",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/scopes.html",
              "seen": "2026-10-08"
            },
            {
              "what": "OAuth overview",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/oauth-overview.html",
              "seen": "2026-10-08"
            },
            {
              "what": "refresh access tokens",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/refresh.html",
              "seen": "2026-10-08"
            },
            {
              "what": "revoke tokens",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/revoke-tokens.html",
              "seen": "2026-10-08"
            },
            {
              "what": "authorisation request",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/auth-request.html",
              "seen": "2026-10-08"
            },
            {
              "what": "get records",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/get-records.html",
              "seen": "2026-10-08"
            },
            {
              "what": "upsert records",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/upsert-records.html",
              "seen": "2026-10-08"
            },
            {
              "what": "delete records",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/delete-records.html",
              "seen": "2026-10-08"
            },
            {
              "what": "search records",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/search-records.html",
              "seen": "2026-10-08"
            },
            {
              "what": "status codes",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/status-codes.html",
              "seen": "2026-10-08"
            },
            {
              "what": "notification APIs",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/notifications/overview.html",
              "seen": "2026-10-08"
            },
            {
              "what": "multi data centre support",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/multi-dc.html",
              "seen": "2026-10-08"
            },
            {
              "what": "what's new in v8",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/whats-new.html",
              "seen": "2026-10-08"
            },
            {
              "what": "increase API credits",
              "url": "https://www.zoho.com/crm/developer/docs/api/v8/purchase-from-dashboard.html",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP servers overview",
              "url": "https://www.zoho.com/crm/developer/docs/mcp/overview.html",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP setup for Cursor",
              "url": "https://www.zoho.com/crm/developer/docs/mcp/setup/cursor.html",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI repository (clone)",
              "url": "https://github.com/zoho/crm-oas",
              "seen": "2026-10-08"
            },
            {
              "what": "Node.js SDK repository (clone)",
              "url": "https://github.com/zoho/zohocrm-nodejs-sdk-8.0",
              "seen": "2026-10-08"
            },
            {
              "what": "Python SDK repository (clone)",
              "url": "https://github.com/zoho/zohocrm-python-sdk-8.0",
              "seen": "2026-10-08"
            },
            {
              "what": "Java SDK repository (clone)",
              "url": "https://github.com/zoho/zohocrm-java-sdk-8.0",
              "seen": "2026-10-08"
            },
            {
              "what": "npm weekly downloads",
              "url": "https://api.npmjs.org/downloads/point/last-week/@zohocrm/nodejs-sdk-8.0",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI recent downloads",
              "url": "https://pypistats.org/api/packages/zohocrmsdk8-0/recent",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://www.zoho.com/crm/zohocrm-pricing.html",
              "seen": "2026-10-08"
            },
            {
              "what": "price values read by the pricing page",
              "url": "https://www.zohowebstatic.com/sites/zweb/json/pricing/crm-pricing-val.json",
              "seen": "2026-10-08"
            },
            {
              "what": "free edition",
              "url": "https://www.zoho.com/crm/free-crm.html",
              "seen": "2026-10-08"
            },
            {
              "what": "feature list by edition",
              "url": "https://www.zoho.com/crm/complete-feature-list.html",
              "seen": "2026-10-08"
            },
            {
              "what": "status page",
              "url": "https://us.zohostatus.com/",
              "seen": "2026-10-08"
            },
            {
              "what": "status incident history",
              "url": "https://us.zohostatus.com/incident_history",
              "seen": "2026-10-08"
            },
            {
              "what": "status RSS",
              "url": "https://us.zohostatus.com/rss",
              "seen": "2026-10-08"
            },
            {
              "what": "terms of service",
              "url": "https://www.zoho.com/terms.html",
              "seen": "2026-10-08"
            },
            {
              "what": "contracting entities",
              "url": "https://www.zoho.com/legal/zoho-contracting-entities.html",
              "seen": "2026-10-08"
            },
            {
              "what": "developer agreement",
              "url": "https://www.zoho.com/developer/terms.html",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.zoho.com/privacy.html",
              "seen": "2026-10-08"
            },
            {
              "what": "sub-processors",
              "url": "https://www.zoho.com/privacy/sub-processors.html",
              "seen": "2026-10-08"
            },
            {
              "what": "GDPR and DPA",
              "url": "https://www.zoho.com/gdpr.html",
              "seen": "2026-10-08"
            },
            {
              "what": "data centres",
              "url": "https://www.zoho.com/know-your-datacenter.html",
              "seen": "2026-10-08"
            },
            {
              "what": "security",
              "url": "https://www.zoho.com/security.html",
              "seen": "2026-10-08"
            },
            {
              "what": "compliance",
              "url": "https://www.zoho.com/compliance.html",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://www.zoho.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP for zoho.com",
              "url": "https://rdap.verisign.com/com/v1/domain/zoho.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: GitHub star counts for the SDK and OpenAPI repositories, the repositories were cloned and the web pages not read",
            "unchecked: the sub-processor directory at zoho.com/privacy/sub-processors.html, which loads by script",
            "unchecked: status pages for data centres other than the US",
            "unchecked: the number and definitions of tools on the four MCP servers, which need a signed-in session",
            "unchecked: whether the CRM REST API was affected during the Deluge outage of 3 September 2026",
            "No SLA page, API deprecation policy or dated API changelog was found. Zoho may publish version retirement notices in its community forum, which we did not search",
            "Whether failed calls and 429 responses use credits is not stated in the reviewed pages",
            "The lead was right on the vendor, URL, docs link and interface. It did not mention the four MCP servers"
          ]
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.1 description of 644 operations and OAuth scopes down to one module and one operation suit agent use, and the Free edition includes 5,000 API credits a day. The documented token refresh puts the client secret in the URL, and no SLA, deprecation policy or dated API changelog was found.",
        "bestFor": "Teams already on Zoho who want an agent to read and write leads, contacts, deals and activities with narrow scopes, and small teams that want a free edition with API access.",
        "strengths": [
          "OpenAPI 3.1 files for 103 resources and 644 operations are public on GitHub, with a Markdown page per operation",
          "OAuth scopes narrow to one module and one operation, such as `ZohoCRM.modules.leads.READ`",
          "The `fields` parameter is mandatory on list calls, so responses carry only the fields requested (50 at most)",
          "Upsert matches on duplicate check fields, so a repeated create updates the record",
          "Free edition for three users with 5,000 API credits a day and no card at signup"
        ],
        "weaknesses": [
          "The documented refresh and revoke calls put the refresh token and client secret in the URL query string",
          "No SLA, API deprecation policy or dated API changelog found in the reviewed pages",
          "429 is documented without a Retry-After header or backoff guidance",
          "Access tokens last one hour and hosts differ by data centre, so setup needs a token exchange and the right domain",
          "Sub-processor directory loads by script and the DPA is sent on request by email"
        ],
        "agentNotes": [
          "Use the `api_domain` returned with the token, since each data centre has its own host (zohoapis.com, zohoapis.eu, zohoapis.in and others)",
          "Send `Authorization: Zoho-oauthtoken \u003ctoken\u003e` and refresh hourly. Put refresh parameters in the POST body, not the URL",
          "Pass `fields` on every list call. Page with `page` up to 2,000 records, then `page_token` up to 100,000",
          "Create through `/{module}/upsert` so a retry updates instead of duplicating",
          "Budget credits. Convert Lead costs 5, Send Mail 20, a bulk read 50, and calls through the MCP servers draw on the same allowance"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.8
          }
        ],
        "editorialScores": {
          "ergonomics": 81,
          "maintenance": 77,
          "payments": 40,
          "reliability": 72,
          "schema": 81,
          "security": 67,
          "transparency": 54
        },
        "provenanceScore": 95
      },
      "connect": {
        "install": "pip install zohocrmsdk8-0",
        "http": "curl \"https://www.zohoapis.com/crm/v8/Leads?fields=Last_Name,Email\u0026per_page=5\" \\\n  -X GET -H \"Authorization: Zoho-oauthtoken $ZOHO_ACCESS_TOKEN\"",
        "config": {
          "mcpServers": {
            "zoho-crm-data-insights": {
              "url": "https://zoho-crm-data-insights-60065097786.zohomcp.in/mcp/d17dfe13292e0414a929516bb8f8e797/message"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/crm.records",
        "tool": "https://letme.dev/zoho-crm"
      },
      "sameCompany": [
        "zoho-books",
        "zoho-zeptomail",
        "zoho-recruit",
        "zoho-people"
      ],
      "notable": [
        "API usage is counted in credits over a rolling 24 hours. Free has 5,000, Standard 50,000 plus 250 a user licence up to 100,000, Enterprise 50,000 plus 1,000 a licence up to 5,000,000 (https://www.zoho.com/crm/developer/docs/api/v8/api-limits.html)",
        "There is no per-minute limit. Concurrent calls per organisation and app are capped at 5 on Free, 10 on Standard, 15 on Professional, 20 on Enterprise and 25 on Ultimate, with a sub-limit of 10 for heavy calls (https://www.zoho.com/crm/developer/docs/api/v8/api-limits.html)",
        "zoho/crm-oas holds OpenAPI 3.1 files for 103 resources and 644 operations, last changed on 2 September 2026, with compressed Markdown and examples per operation (https://github.com/zoho/crm-oas)",
        "Four pre-built remote MCP servers (Data Insights, Data Operations, Module Customisation, Workflow and Process Automation) sign in by OAuth and act with the user's CRM role. Data Insights is read-only (https://www.zoho.com/crm/developer/docs/mcp/overview.html)",
        "Extra API credits are pay as you go, from $0.14 per 1,000 credits a day for the first 25,000 down to $0.025 above 250,000 (https://www.zoho.com/crm/developer/docs/api/v8/purchase-from-dashboard.html)",
        "The refresh call is documented as a POST with `refresh_token`, `client_id` and `client_secret` in the query string (https://www.zoho.com/crm/developer/docs/api/v8/refresh.html)",
        "The US status page lists a Zoho CRM component. Its one CRM-named incident in the past year lasted 6 minutes 41 seconds on 3 May 2026 (https://us.zohostatus.com/incident_history)"
      ],
      "area": "business",
      "details": [
        {
          "label": "API",
          "value": "REST API v8 at https://www.zohoapis.com/crm/v8 (US). Records, related records, search, COQL query, composite (five calls in one request), bulk read and write, notifications, metadata, workflow and data sharing endpoints"
        },
        {
          "label": "MCP servers",
          "value": "Four pre-built remote servers on zohomcp.in hosts. Data Insights (read-only, COQL queries, module and field metadata), Data Operations (record create, read, update, delete and bulk), Module Customisation, Workflow and Process Automation. OAuth sign-in in a browser on first use. Tool counts not published"
        },
        {
          "label": "Credentials",
          "value": "OAuth 2.0 authorisation code grant, or a self client with authorisation code or client credentials. Access tokens last one hour. Refresh tokens last until revoked"
        },
        {
          "label": "Auth scopes",
          "value": "`ZohoCRM.\u003cgroup\u003e.\u003cname\u003e.\u003coperation\u003e` with operations ALL, READ, CREATE, UPDATE and DELETE. Groups are users, org, settings, modules, bulk, notifications and coql. Module scopes name one module, such as `ZohoCRM.modules.leads.READ`"
        },
        {
          "label": "Rate limits",
          "value": "Credits per rolling 24 hours. Free 5,000. Standard 50,000 plus 250 a user licence, at most 100,000. Professional 50,000 plus 500 a licence, at most 3,000,000. Enterprise 50,000 plus 1,000 a licence, at most 5,000,000. Ultimate 50,000 plus 2,000 a licence, no maximum. Concurrency 5, 10, 15, 20 and 25 by edition, sub-concurrency 10"
        },
        {
          "label": "Credit costs",
          "value": "Most calls 1. Insert, update or upsert 1 per 10 records (100 records a call). Convert Lead 5. Send Mail 20. Bulk read 50. Bulk write 500. COQL 1 to 3 by LIMIT"
        },
        {
          "label": "Read and write",
          "value": "Leads, Accounts, Contacts, Deals, Campaigns, Tasks, Cases, Meetings, Calls, Products, Vendors, Price Books, Quotes, Sales Orders, Purchase Orders, Invoices, Appointments, Services and custom modules"
        },
        {
          "label": "Pagination",
          "value": "`per_page` up to 200. `page` reaches 2,000 records, `page_token` reaches 100,000. Search returns 2,000 records at most. `fields` is mandatory on list calls, 50 names at most"
        },
        {
          "label": "Webhooks",
          "value": "Notification API channels per module for create, update and delete, with field conditions and an expiry time. Webhooks are also a workflow action"
        },
        {
          "label": "Data centres",
          "value": "US, EU, India, Australia, Japan, Canada, China and Saudi Arabia, each with its own accounts host and API domain"
        },
        {
          "label": "SDKs",
          "value": "Java, Python, PHP, Node.js, C# and Ruby, Apache-2.0. Node.js @zohocrm/nodejs-sdk-8.0 4.0.0 (21 September 2026), Python zohocrmsdk8-0 7.0.0 (24 July 2026)"
        },
        {
          "label": "Free tier",
          "value": "Free edition for three users with 5,000 API credits a day, no card at signup. 15-day trial of paid editions with the paid edition's API limits"
        },
        {
          "label": "Audit",
          "value": "Audit Logs in paid editions per the feature list. The API dashboard shows credits used by application and function"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type 2, SOC 1 Type 2, ISO/IEC 27001, 27701 and 27017 per zoho.com/compliance.html. Bug bounty at bugbounty.zohocorp.com"
        },
        {
          "label": "Status",
          "value": "status.zoho.com redirects to us.zohostatus.com, with a Zoho CRM component and incident history back to November 2025"
        }
      ],
      "unitPrices": [
        {
          "item": "Standard",
          "unit": "seat-month",
          "usd": 14,
          "note": "billed yearly; $20 billed monthly"
        },
        {
          "item": "Professional",
          "unit": "seat-month",
          "usd": 23,
          "note": "billed yearly; $35 billed monthly"
        },
        {
          "item": "Enterprise",
          "unit": "seat-month",
          "usd": 40,
          "note": "billed yearly; $50 billed monthly"
        },
        {
          "item": "Ultimate",
          "unit": "seat-month",
          "usd": 52,
          "note": "billed yearly; $65 billed monthly"
        },
        {
          "item": "Add-on API credits, first 25,000 a day",
          "unit": "credit",
          "usd": 0.00014,
          "note": "$0.14 per 1,000 credits per 24 hours, falling to $0.025 per 1,000 above 250,000; billed for credits used"
        }
      ],
      "provenance": {
        "legalEntity": "Zoho Corporation Private Limited",
        "domain": "zoho.com",
        "domainRegistered": "2004-01-16",
        "domainNote": "API calls go to www.zohoapis.com and its regional equivalents, and the MCP servers to zohomcp.in hosts, both Zoho domains other than zoho.com.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.zoho.com/terms.html",
        "privacy": "https://www.zoho.com/privacy.html",
        "statusPage": "https://status.zoho.com",
        "changelog": "https://www.zoho.com/crm/developer/docs/api/v8/whats-new.html",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Service (last updated 2 March 2022) are the service agreement for Zoho's online services. The contracting entity depends on the customer's region, Zoho Corporation Private Limited for India and Zoho Corporation for the United States (https://www.zoho.com/legal/zoho-contracting-entities.html).",
          "A separate Zoho Developer Agreement at https://www.zoho.com/developer/terms.html covers the developer tools and names Zoho Corporation Private Limited and its affiliates.",
          "The privacy policy was last updated on 22 December 2025 and covers Zoho's websites and the products on them.",
          "security.txt at www.zoho.com gives a bug bounty contact, security@zohocorp.com, a policy link and an expiry of 30 June 2028.",
          "What's New in V8 lists the additions in v8 without dates. No dated API changelog was found.",
          "RDAP for zoho.com gives a registration date of 2004-01-16."
        ],
        "score": 95,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Zoho Corporation Private Limited",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "zoho.com, registered 2004-01-16 (22 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "zoho.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 7.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
            "points": 8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.zoho.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "valid",
            "points": 10,
            "max": 10,
            "state": "ok"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.zoho.com/terms.html",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2022-03-02",
            "words": 4052,
            "points": 7.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated on: 2nd March 2022.",
                "says": "Last updated 2022-03-02"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "Accordingly, each party agrees to the governing law (without regard to choice or conflicts of law rules) and to the exclusive jurisdiction of the courts mentioned herein in case of any dispute or lawsuit arising out of or in connection with this Agreement ."
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "IN NO EVENT SHALL ZOHO’S ENTIRE LIABILITY TO YOU IN RESPECT OF ANY SERVICE, WHETHER DIRECT OR INDIRECT, EXCEED ONE THOUSAND DOLLARS ($1000) OR THE FEES PAID BY YOU DURING THE TWELVE (12) MONTHS PRIOR TO THE FIRST EVENT GIVING RISE TO SUCH LIABILITY, WHICHEVER IS HIGHER.",
                "says": "Capped at the fees paid in the 12 months before the claim or $1000"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "If you provide any information that is untrue, inaccurate, outdated, or incomplete, or if Zoho has reasonable grounds to suspect that such information is untrue, inaccurate, outdated, or incomplete, Zoho may terminate your user account and refuse current or future use of any or all of the Services."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "If we make significant changes to the Agreement that affect your rights, you will be provided with at least 30 days advance notice of the changes by email to your primary email address.",
                "says": "Gives 30 days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "In addition to all other terms and conditions of this Agreement, you shall not: (i) transfer the Services or otherwise make it available to any third party;"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "use the Services for any form of competitive or benchmarking purposes",
                "costsPoints": true
              },
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Last updated on: 2nd March 2022."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Subscriptions renew automatically and the customer must give at least seven days' notice before the renewal date to stop renewal.",
                "quote": "If you do not wish to renew the subscription, you must inform us at least seven days prior to the renewal date."
              },
              {
                "date": "2026-10-08",
                "text": "Unpaid accounts inactive for 120 continuous days may be terminated and their data deleted, with prior notice, and activity in one service does not keep another active.",
                "quote": "We reserve the right to terminate unpaid user accounts that are inactive for a continuous period of 120 days."
              },
              {
                "date": "2026-10-08",
                "text": "If the customer does not answer a forwarded complaint within 10 days, Zoho may give the customer's name and contact information to the complainant.",
                "quote": "If you do not respond to the complainant within 10 days from the date of our email to you, we may disclose your name and contact information to the complainant for enabling the complainant to take legal action against you."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.zoho.com/privacy.html",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-12-22",
            "words": 6377,
            "points": 8,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated on: 22nd Dec 2025.",
                "says": "Last updated 2025-12-22"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This policy tells you what information we collect from you, what we do with it, who can access it, and what you can do about it."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "After you terminate your account, your data will be automatically deleted from our active database within 6 months and from our backups within 3 months after that.",
                "says": "Names a period of 6 months"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "If you ask about our products through one of our referral programs or reselling partners, or sign in to one of our products through an authentication service provider like LinkedIn or Google, they'll pass on your contact information to us."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We share your information only in the ways that are described in this Privacy Policy, and only with parties who adopt appropriate confidentiality and security measures."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "The European Economic Area (EEA) provides certain rights to data subjects (including access, rectification, erasure, restriction of processing, data portability, and the right to object and to complain)."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you wish to update or delete your testimonial, you can contact us at privacy@zohocorp.com",
                "says": "privacy@zohocorp.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "…or otherwise providing personal information or service data to us, you understand that the processing, transfer, and storage of your personal information or Service Data within the United States of America, the European Economic Area (EEA) and other countries where Zoho operates.",
                "says": "Data goes to the United States"
              }
            ],
            "toKnow": [
              {
                "key": "training",
                "label": "Says it may use customer content to train or improve models, and no opt-out was found",
                "found": true,
                "quote": "In keeping with Zoho's promise not to exploit your data in a way that is not respectful of your privacy and confidentiality expectations, we make only the following limited use of service data for these technologies: (i) using anonymized crops of service data to improve accuracy of the algorithms;",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Zoho employees and contractors may open service data to resolve errors and to check by hand emails reported as spam and scanned images.",
                "quote": "so that they can (i) identify, analyze and resolve errors, (ii) manually verify emails reported as spam to improve spam detection, or (iii) manually verify scanned images that you submit to us to verify the accuracy of optical character recognition."
              },
              {
                "date": "2026-10-08",
                "text": "Zoho says it uses an organisation's data to develop models specific to that organisation.",
                "quote": "(ii) using your organization's data for developing models specific for your organization."
              },
              {
                "date": "2026-10-08",
                "text": "After an account is terminated, data leaves the active database at a clean-up run once every six months and leaves backups three months later.",
                "quote": "Once you terminate your Zoho user account, your data will eventually get deleted from active database during the next clean-up that occurs once in 6 months."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/zoho-crm.json",
      "live": {
        "slug": "zoho-crm",
        "vendorStatus": {
          "page": "https://status.zoho.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T17:51:21.048151944Z"
        },
        "pages": [
          {
            "url": "https://www.zoho.com/crm/developer/docs/api/v8/whats-new.html",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:31:58.479396601Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1ebe95070909"
          },
          {
            "url": "https://www.zoho.com/crm/zohocrm-pricing.html",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:32:00.474417695Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "33ebba011ea1"
          },
          {
            "url": "https://www.zoho.com/privacy.html",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:32:02.487387166Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "08dac5e34d5e"
          },
          {
            "url": "https://www.zoho.com/terms.html",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:32:04.479029194Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "05eeda99f291"
          }
        ],
        "updatedAt": "2026-10-08T18:32:04.479029194Z"
      }
    },
    "verify": {
      "accepts": "a page on zoho.com or one of its subdomains, or the README of github.com/zoho/crm-oas",
      "badgeUrl": "https://www.anchorterminal.com/badges/zoho-crm.svg",
      "body": {
        "slug": "zoho-crm",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/zoho-crm",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/zoho-crm\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/zoho-crm.svg\" alt=\"Zoho CRM on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Zoho CRM on Anchor Terminal](https://www.anchorterminal.com/badges/zoho-crm.svg)](https://www.anchorterminal.com/tools/zoho-crm)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/zoho-crm\"\u003eZoho CRM on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/zoho-crm",
    "json": "https://www.anchorterminal.com/tools/zoho-crm.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/zoho-crm.md",
    "slim": "https://www.anchorterminal.com/tools/zoho-crm.min.md"
  },
  "markdown": "## Overview\n\n**Grade BB · 70.8/100 · rank #128 of 722 · #2 in CRM \u0026 customer platforms · agent-ready · confidence medium**\n\n\nMore from Zoho, listed separately because each is its own product: [Zoho Books](https://www.anchorterminal.com/tools/zoho-books.md) (Accounting \u0026 invoicing), [Zoho CPaaS (formerly ZeptoMail)](https://www.anchorterminal.com/tools/zoho-zeptomail.md) (Email delivery APIs), [Zoho Recruit](https://www.anchorterminal.com/tools/zoho-recruit.md) (Recruiting \u0026 applicant tracking), [Zoho People](https://www.anchorterminal.com/tools/zoho-people.md) (HR \u0026 employee operations).\n\n## Assessment\n\nA public OpenAPI 3.1 description of 644 operations and OAuth scopes down to one module and one operation suit agent use, and the Free edition includes 5,000 API credits a day. The documented token refresh puts the client secret in the URL, and no SLA, deprecation policy or dated API changelog was found.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Zoho (https://www.zoho.com/crm/) |\n| Kind | HTTP API |\n| Category | CRM \u0026 customer platforms (https://www.anchorterminal.com/categories/crm) |\n| Transport | HTTP |\n| Auth | OAuth · OAuth 2.0 only. A person registers a client in the Zoho API console (a web application, or a self client for one organisation) and approves scopes, which narrow to one module and one operation. The access token lasts one hour and goes in `Authorization: Zoho-oauthtoken \u003ctoken\u003e`. The refresh token lasts until revoked. Each data centre has its own accounts host and API domain. Registration is self-serve, with no app review or sales approval for use inside one's own organisation. |\n| Pricing | Freemium ($14 / seat-mo) · Free edition for three users with 5,000 API credits a day and no card at signup. Paid editions cost $14 to $52 a user a month billed yearly ($20 to $65 monthly) and have a 15-day trial. API calls draw on a daily credit allowance set by edition and user licences. Extra credits are pay as you go from $0.14 per 1,000 a day (https://www.zoho.com/crm/zohocrm-pricing.html, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the API docs, the OpenAPI files or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under Zoho's Terms of Service. The server-side SDKs on GitHub are Apache-2.0 |\n| Packages | npm: `@zohocrm/nodejs-sdk-8.0`; pypi: `zohocrmsdk8-0` |\n| Source | https://github.com/zoho/crm-oas |\n| Docs | https://www.zoho.com/crm/developer/docs/api/v8/ |\n| llms.txt | not found |\n| Last release | 2026-09-21 |\n| npm downloads / week | 830 |\n| PyPI downloads / week | 6,148 |\n| API | REST API v8 at https://www.zohoapis.com/crm/v8 (US). Records, related records, search, COQL query, composite (five calls in one request), bulk read and write, notifications, metadata, workflow and data sharing endpoints |\n| MCP servers | Four pre-built remote servers on zohomcp.in hosts. Data Insights (read-only, COQL queries, module and field metadata), Data Operations (record create, read, update, delete and bulk), Module Customisation, Workflow and Process Automation. OAuth sign-in in a browser on first use. Tool counts not published |\n| Credentials | OAuth 2.0 authorisation code grant, or a self client with authorisation code or client credentials. Access tokens last one hour. Refresh tokens last until revoked |\n| Auth scopes | `ZohoCRM.\u003cgroup\u003e.\u003cname\u003e.\u003coperation\u003e` with operations ALL, READ, CREATE, UPDATE and DELETE. Groups are users, org, settings, modules, bulk, notifications and coql. Module scopes name one module, such as `ZohoCRM.modules.leads.READ` |\n| Rate limits | Credits per rolling 24 hours. Free 5,000. Standard 50,000 plus 250 a user licence, at most 100,000. Professional 50,000 plus 500 a licence, at most 3,000,000. Enterprise 50,000 plus 1,000 a licence, at most 5,000,000. Ultimate 50,000 plus 2,000 a licence, no maximum. Concurrency 5, 10, 15, 20 and 25 by edition, sub-concurrency 10 |\n| Credit costs | Most calls 1. Insert, update or upsert 1 per 10 records (100 records a call). Convert Lead 5. Send Mail 20. Bulk read 50. Bulk write 500. COQL 1 to 3 by LIMIT |\n| Read and write | Leads, Accounts, Contacts, Deals, Campaigns, Tasks, Cases, Meetings, Calls, Products, Vendors, Price Books, Quotes, Sales Orders, Purchase Orders, Invoices, Appointments, Services and custom modules |\n| Pagination | `per_page` up to 200. `page` reaches 2,000 records, `page_token` reaches 100,000. Search returns 2,000 records at most. `fields` is mandatory on list calls, 50 names at most |\n| Webhooks | Notification API channels per module for create, update and delete, with field conditions and an expiry time. Webhooks are also a workflow action |\n| Data centres | US, EU, India, Australia, Japan, Canada, China and Saudi Arabia, each with its own accounts host and API domain |\n| SDKs | Java, Python, PHP, Node.js, C# and Ruby, Apache-2.0. Node.js @zohocrm/nodejs-sdk-8.0 4.0.0 (21 September 2026), Python zohocrmsdk8-0 7.0.0 (24 July 2026) |\n| Free tier | Free edition for three users with 5,000 API credits a day, no card at signup. 15-day trial of paid editions with the paid edition's API limits |\n| Audit | Audit Logs in paid editions per the feature list. The API dashboard shows credits used by application and function |\n| Certifications | SOC 2 Type 2, SOC 1 Type 2, ISO/IEC 27001, 27701 and 27017 per zoho.com/compliance.html. Bug bounty at bugbounty.zohocorp.com |\n| Status | status.zoho.com redirects to us.zohostatus.com, with a Zoho CRM component and incident history back to November 2025 |\n| Capabilities | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks |\n| Tags | hosted, closed-source, oauth, openapi, mcp, webhooks, free-tier, no-card, python, nodejs, java, status-page, bug-bounty, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/zoho-crm.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 72 | 14.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 81 | 13.2 |\n| Agent ergonomics | 13% | 16.2 | 81 | 13.2 |\n| Security \u0026 auth | 14% | 17.5 | 67 | 11.7 |\n| Payments \u0026 pricing | 10% | 12.5 | 40 | 5.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 77 | 6.7 |\n| Transparency \u0026 trust (editorial 54, provenance 95) | 7% | 8.8 | 75 | 6.6 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **70.8 → BB** |\n\n### Why each score\n\n- Reliability 72: Graded on the REST API v8, read as a hosted service. status.zoho.com redirects to us.zohostatus.com, which has a Zoho CRM component and incident history back to November 2025 (20). No incident in the last 90 days names CRM. On 3 September 2026 a Zoho Deluge outage ran 2 hours 34 minutes and the status feed shows the CRM component changing state when it ended, so we read the record as minor incidents only (20 of 30). Only the US page was read. Daily credits and concurrency are published with numbers per edition (15). 429 is documented and `X-API-CREDITS-REMAINING` appears once half the allowance is used, but no Retry-After or backoff guidance was found. Upsert and `If-Unmodified-Since` make writes safer to retry (7 of 15). No SLA found (0). v8 is the current documented version (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 81: zoho/crm-oas on GitHub holds OpenAPI 3.1 files for 103 resources and 644 operations (25). No llms.txt at zoho.com, but the same repository carries a compressed Markdown page and examples per operation, written for Zoho's CRM agent skills (7 of 10). Operation descriptions state the purpose and name the call that supplies each ID, with little on when not to use one (15 of 20). Parameters carry enums, patterns and length limits. Record bodies accept any property because modules have custom fields, and search criteria are a string grammar (11 of 15). Each reference page has curl samples and a Possible Errors list with a resolution per code (15). The version is in the path, and What's New in V8 lists changes without dates. No dated changelog found (8 of 15).\n- Agent ergonomics 81: Graded on the REST API. `fields` is mandatory on list calls with at most 50 names, and COQL selects columns, so responses can be kept small (22 of 25). `per_page` up to 200, `page` to 2,000 records and `page_token` to 100,000, plus search by criteria, email, phone or word, custom views and COQL (20). Errors carry a code, a message and details naming the field or the existing record, each documented with a resolution (18 of 20). Upsert on duplicate check fields and `If-Unmodified-Since`, with no idempotency key (10 of 20). Official SDKs in six languages, but the one-hour token, the refresh step and per-data-centre hosts add setup (11 of 15).\n- Security \u0026 auth 67: OAuth 2.0 with scopes down to one module and one operation, one-hour access tokens and revocable refresh tokens (30). Less 10 because the documented refresh and revoke calls carry the refresh token and client secret in the URL query string (20 of 30). READ-only scopes per module and a read-only Data Insights MCP server. Calls are also bound by the user's CRM role. No approval step for deletes, and mass delete exists (14 of 20). Records hold text from outside parties and no prompt-injection guidance was found (3 of 15). Audit Logs in paid editions, and an API dashboard of credits by application (10 of 15). security.txt valid to 30 June 2028, a bug bounty, SOC 2 Type 2 and ISO/IEC 27001, 27701 and 27017 (20).\n- Payments \u0026 pricing 40: No x402, MPP or L402 (0). Edition prices are public, $14 to $52 a user a month billed yearly, and extra API credits have a published unit price from $0.14 per 1,000 a day (20). The Free edition covers three users with 5,000 API credits a day and needs no card at signup (20). A person signs up in a browser, registers an OAuth client in the API console and approves scopes (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 77: The Node.js SDK for v8 reached 4.0.0 on 21 September 2026, 17 days before this check (30). Three dated changes in the last 90 days, Python SDK 7.0.0 on 24 July, the OpenAPI files on 2 September and Node.js SDK 4.0.0 on 21 September (20). No dated API changelog. The docs link to community posts on help.zoho.com, which we did not test for replies (8 of 25). Current official SDKs for Java, Python, PHP, Node.js, C# and Ruby (15). The SDK repositories show no public CI, and the Java SDK was last released on 7 January 2026 (4 of 10).\n- Transparency \u0026 trust 75: Closed service under the Zoho Terms of Service, last updated 2 March 2022, with Apache-2.0 SDKs (15 of 30). The privacy policy of 22 December 2025 says Zoho does not sell personal information, and that data is deleted from the active database within six months of account termination and from backups three months later. The DPA is sent on request by email (24 of 30). No API deprecation policy or dated notices found (0). A sub-processor page exists, but its directory loads by script and we could not read the list. The data centre page names locations and their certifications (15 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/zoho-crm.md (JSON https://www.anchorterminal.com/fixes/zoho-crm.json)\n\n### What we couldn't check\n\n- unchecked: GitHub star counts for the SDK and OpenAPI repositories, the repositories were cloned and the web pages not read\n- unchecked: the sub-processor directory at zoho.com/privacy/sub-processors.html, which loads by script\n- unchecked: status pages for data centres other than the US\n- unchecked: the number and definitions of tools on the four MCP servers, which need a signed-in session\n- unchecked: whether the CRM REST API was affected during the Deluge outage of 3 September 2026\n- No SLA page, API deprecation policy or dated API changelog was found. Zoho may publish version retirement notices in its community forum, which we did not search\n- Whether failed calls and 429 responses use credits is not stated in the reviewed pages\n- The lead was right on the vendor, URL, docs link and interface. It did not mention the four MCP servers\n\n### Sources\n\n- API v8 index: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/\u003e (seen 2026-10-08)\n- API limits: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/api-limits.html\u003e (seen 2026-10-08)\n- scopes: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/scopes.html\u003e (seen 2026-10-08)\n- OAuth overview: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/oauth-overview.html\u003e (seen 2026-10-08)\n- refresh access tokens: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/refresh.html\u003e (seen 2026-10-08)\n- revoke tokens: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/revoke-tokens.html\u003e (seen 2026-10-08)\n- authorisation request: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/auth-request.html\u003e (seen 2026-10-08)\n- get records: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/get-records.html\u003e (seen 2026-10-08)\n- upsert records: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/upsert-records.html\u003e (seen 2026-10-08)\n- delete records: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/delete-records.html\u003e (seen 2026-10-08)\n- search records: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/search-records.html\u003e (seen 2026-10-08)\n- status codes: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/status-codes.html\u003e (seen 2026-10-08)\n- notification APIs: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/notifications/overview.html\u003e (seen 2026-10-08)\n- multi data centre support: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/multi-dc.html\u003e (seen 2026-10-08)\n- what's new in v8: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/whats-new.html\u003e (seen 2026-10-08)\n- increase API credits: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/purchase-from-dashboard.html\u003e (seen 2026-10-08)\n- MCP servers overview: \u003chttps://www.zoho.com/crm/developer/docs/mcp/overview.html\u003e (seen 2026-10-08)\n- MCP setup for Cursor: \u003chttps://www.zoho.com/crm/developer/docs/mcp/setup/cursor.html\u003e (seen 2026-10-08)\n- OpenAPI repository (clone): \u003chttps://github.com/zoho/crm-oas\u003e (seen 2026-10-08)\n- Node.js SDK repository (clone): \u003chttps://github.com/zoho/zohocrm-nodejs-sdk-8.0\u003e (seen 2026-10-08)\n- Python SDK repository (clone): \u003chttps://github.com/zoho/zohocrm-python-sdk-8.0\u003e (seen 2026-10-08)\n- Java SDK repository (clone): \u003chttps://github.com/zoho/zohocrm-java-sdk-8.0\u003e (seen 2026-10-08)\n- npm weekly downloads: \u003chttps://api.npmjs.org/downloads/point/last-week/@zohocrm/nodejs-sdk-8.0\u003e (seen 2026-10-08)\n- PyPI recent downloads: \u003chttps://pypistats.org/api/packages/zohocrmsdk8-0/recent\u003e (seen 2026-10-08)\n- pricing: \u003chttps://www.zoho.com/crm/zohocrm-pricing.html\u003e (seen 2026-10-08)\n- price values read by the pricing page: \u003chttps://www.zohowebstatic.com/sites/zweb/json/pricing/crm-pricing-val.json\u003e (seen 2026-10-08)\n- free edition: \u003chttps://www.zoho.com/crm/free-crm.html\u003e (seen 2026-10-08)\n- feature list by edition: \u003chttps://www.zoho.com/crm/complete-feature-list.html\u003e (seen 2026-10-08)\n- status page: \u003chttps://us.zohostatus.com/\u003e (seen 2026-10-08)\n- status incident history: \u003chttps://us.zohostatus.com/incident_history\u003e (seen 2026-10-08)\n- status RSS: \u003chttps://us.zohostatus.com/rss\u003e (seen 2026-10-08)\n- terms of service: \u003chttps://www.zoho.com/terms.html\u003e (seen 2026-10-08)\n- contracting entities: \u003chttps://www.zoho.com/legal/zoho-contracting-entities.html\u003e (seen 2026-10-08)\n- developer agreement: \u003chttps://www.zoho.com/developer/terms.html\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.zoho.com/privacy.html\u003e (seen 2026-10-08)\n- sub-processors: \u003chttps://www.zoho.com/privacy/sub-processors.html\u003e (seen 2026-10-08)\n- GDPR and DPA: \u003chttps://www.zoho.com/gdpr.html\u003e (seen 2026-10-08)\n- data centres: \u003chttps://www.zoho.com/know-your-datacenter.html\u003e (seen 2026-10-08)\n- security: \u003chttps://www.zoho.com/security.html\u003e (seen 2026-10-08)\n- compliance: \u003chttps://www.zoho.com/compliance.html\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://www.zoho.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- RDAP for zoho.com: \u003chttps://rdap.verisign.com/com/v1/domain/zoho.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 95/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Zoho Corporation Private Limited | 20/20 |\n| Domain age | zoho.com, registered 2004-01-16 (22 years) | 15/15 |\n| Endpoint on the vendor's domain | zoho.com | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects, and has 1 clause that costs points | 8/10 |\n| Status page | status.zoho.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | valid | 10/10 |\n\nAPI calls go to www.zohoapis.com and its regional equivalents, and the MCP servers to zohomcp.in hosts, both Zoho domains other than zoho.com.\n\nThe Terms of Service (last updated 2 March 2022) are the service agreement for Zoho's online services. The contracting entity depends on the customer's region, Zoho Corporation Private Limited for India and Zoho Corporation for the United States (https://www.zoho.com/legal/zoho-contracting-entities.html).\n\nA separate Zoho Developer Agreement at https://www.zoho.com/developer/terms.html covers the developer tools and names Zoho Corporation Private Limited and its affiliates.\n\nThe privacy policy was last updated on 22 December 2025 and covers Zoho's websites and the products on them.\n\nsecurity.txt at www.zoho.com gives a bug bounty contact, security@zohocorp.com, a policy link and an expiry of 30 June 2028.\n\nWhat's New in V8 lists the additions in v8 without dates. No dated API changelog was found.\n\nRDAP for zoho.com gives a registration date of 2004-01-16.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.zoho.com/terms.html), read 2026-10-08, dated 2022-03-02, states 6 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"use the Services for any form of competitive or benchmarking purposes\"\n- To know. Has not been updated for three years or more. \"Last updated on: 2nd March 2022.\"\n- Gives the date it was last updated. Last updated 2022-03-02.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim or $1000.\n- Says how changes to the terms are announced. Gives 30 days of notice before a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Subscriptions renew automatically and the customer must give at least seven days' notice before the renewal date to stop renewal. \"If you do not wish to renew the subscription, you must inform us at least seven days prior to the renewal date.\"\n- Also in the text (2026-10-08). Unpaid accounts inactive for 120 continuous days may be terminated and their data deleted, with prior notice, and activity in one service does not keep another active. \"We reserve the right to terminate unpaid user accounts that are inactive for a continuous period of 120 days.\"\n- Also in the text (2026-10-08). If the customer does not answer a forwarded complaint within 10 days, Zoho may give the customer's name and contact information to the complainant. \"If you do not respond to the complainant within 10 days from the date of our email to you, we may disclose your name and contact information to the complainant for enabling the complainant to take legal action against you.\"\n\n**Privacy policy** (https://www.zoho.com/privacy.html), read 2026-10-08, dated 2025-12-22, states 8 of the 8 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). \"In keeping with Zoho's promise not to exploit your data in a way that is not respectful of your privacy and confidentiality expectations, we make only the following limited use of service data for these technologies: (i) using anonymized crops of service data to improve accuracy of the algorithms;\"\n- Gives the date it was last updated. Last updated 2025-12-22.\n- Says how long data is kept. Names a period of 6 months.\n- Gives a privacy contact. privacy@zohocorp.com.\n- Says where data is transferred or stored. Data goes to the United States.\n- Also in the text (2026-10-08). Zoho employees and contractors may open service data to resolve errors and to check by hand emails reported as spam and scanned images. \"so that they can (i) identify, analyze and resolve errors, (ii) manually verify emails reported as spam to improve spam detection, or (iii) manually verify scanned images that you submit to us to verify the accuracy of optical character recognition.\"\n- Also in the text (2026-10-08). Zoho says it uses an organisation's data to develop models specific to that organisation. \"(ii) using your organization's data for developing models specific for your organization.\"\n- Also in the text (2026-10-08). After an account is terminated, data leaves the active database at a clean-up run once every six months and leaves backups three months later. \"Once you terminate your Zoho user account, your data will eventually get deleted from active database during the next clean-up that occurs once in 6 months.\"\n\n## Live (updated 2026-10-08 18:32 UTC)\n\n- Vendor status page: unknown, no machine-readable status found\n- Watching changelog \u003chttps://www.zoho.com/crm/developer/docs/api/v8/whats-new.html\u003e\n- Watching pricing \u003chttps://www.zoho.com/crm/zohocrm-pricing.html\u003e\n- Watching privacy \u003chttps://www.zoho.com/privacy.html\u003e\n- Watching terms \u003chttps://www.zoho.com/terms.html\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/zoho-crm.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Standard | $14 | per seat per month | billed yearly; $20 billed monthly |\n| Professional | $23 | per seat per month | billed yearly; $35 billed monthly |\n| Enterprise | $40 | per seat per month | billed yearly; $50 billed monthly |\n| Ultimate | $52 | per seat per month | billed yearly; $65 billed monthly |\n| Add-on API credits, first 25,000 a day | $0.0001 | per credit | $0.14 per 1,000 credits per 24 hours, falling to $0.025 per 1,000 above 250,000; billed for credits used |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- OpenAPI 3.1 files for 103 resources and 644 operations are public on GitHub, with a Markdown page per operation\n- OAuth scopes narrow to one module and one operation, such as `ZohoCRM.modules.leads.READ`\n- The `fields` parameter is mandatory on list calls, so responses carry only the fields requested (50 at most)\n- Upsert matches on duplicate check fields, so a repeated create updates the record\n- Free edition for three users with 5,000 API credits a day and no card at signup\n\n## Weaknesses\n\n- The documented refresh and revoke calls put the refresh token and client secret in the URL query string\n- No SLA, API deprecation policy or dated API changelog found in the reviewed pages\n- 429 is documented without a Retry-After header or backoff guidance\n- Access tokens last one hour and hosts differ by data centre, so setup needs a token exchange and the right domain\n- Sub-processor directory loads by script and the DPA is sent on request by email\n\n## Before you call it (notes for agents)\n\n1. Use the `api_domain` returned with the token, since each data centre has its own host (zohoapis.com, zohoapis.eu, zohoapis.in and others)\n2. Send `Authorization: Zoho-oauthtoken \u003ctoken\u003e` and refresh hourly. Put refresh parameters in the POST body, not the URL\n3. Pass `fields` on every list call. Page with `page` up to 2,000 records, then `page_token` up to 100,000\n4. Create through `/{module}/upsert` so a retry updates instead of duplicating\n5. Budget credits. Convert Lead costs 5, Send Mail 20, a bulk read 50, and calls through the MCP servers draw on the same allowance\n\n## Connect\n\nInstall:\n\n```bash\npip install zohocrmsdk8-0\n```\n\nFirst request:\n\n```bash\ncurl \"https://www.zohoapis.com/crm/v8/Leads?fields=Last_Name,Email\u0026per_page=5\" \\\n  -X GET -H \"Authorization: Zoho-oauthtoken $ZOHO_ACCESS_TOKEN\"\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"zoho-crm-data-insights\": {\n      \"url\": \"https://zoho-crm-data-insights-60065097786.zohomcp.in/mcp/d17dfe13292e0414a929516bb8f8e797/message\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/zoho-crm. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| HubSpot API + MCP | BB | 71.5 | 105 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | no | https://www.anchorterminal.com/tools/hubspot-mcp.md |\n| Microsoft Dynamics 365 Sales | B | 69.7 | 150 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | no | https://www.anchorterminal.com/tools/dynamics-365-sales.md |\n| Close API + MCP | B | 66.7 | 229 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | no | https://www.anchorterminal.com/tools/close.md |\n| Twenty API + MCP | B | 65.9 | 250 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | no | https://www.anchorterminal.com/tools/twenty.md |\n| Affinity | B | 63.4 | 311 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | no | https://www.anchorterminal.com/tools/affinity.md |\n| Attio API + MCP | B | 63.1 | 318 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | no | https://www.anchorterminal.com/tools/attio.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- API usage is counted in credits over a rolling 24 hours. Free has 5,000, Standard 50,000 plus 250 a user licence up to 100,000, Enterprise 50,000 plus 1,000 a licence up to 5,000,000 (source: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/api-limits.html\u003e)\n- There is no per-minute limit. Concurrent calls per organisation and app are capped at 5 on Free, 10 on Standard, 15 on Professional, 20 on Enterprise and 25 on Ultimate, with a sub-limit of 10 for heavy calls (source: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/api-limits.html\u003e)\n- zoho/crm-oas holds OpenAPI 3.1 files for 103 resources and 644 operations, last changed on 2 September 2026, with compressed Markdown and examples per operation (source: \u003chttps://github.com/zoho/crm-oas\u003e)\n- Four pre-built remote MCP servers (Data Insights, Data Operations, Module Customisation, Workflow and Process Automation) sign in by OAuth and act with the user's CRM role. Data Insights is read-only (source: \u003chttps://www.zoho.com/crm/developer/docs/mcp/overview.html\u003e)\n- Extra API credits are pay as you go, from $0.14 per 1,000 credits a day for the first 25,000 down to $0.025 above 250,000 (source: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/purchase-from-dashboard.html\u003e)\n- The refresh call is documented as a POST with `refresh_token`, `client_id` and `client_secret` in the query string (source: \u003chttps://www.zoho.com/crm/developer/docs/api/v8/refresh.html\u003e)\n- The US status page lists a Zoho CRM component. Its one CRM-named incident in the past year lasted 6 minutes 41 seconds on 3 May 2026 (source: \u003chttps://us.zohostatus.com/incident_history\u003e)\n\n## Compare\n\n- [Affinity vs Zoho CRM](https://www.anchorterminal.com/compare/affinity-vs-zoho-crm.md): B 63.4 vs BB 70.8\n- [Attio API + MCP vs Zoho CRM](https://www.anchorterminal.com/compare/attio-vs-zoho-crm.md): B 63.1 vs BB 70.8\n- [Capsule CRM vs Zoho CRM](https://www.anchorterminal.com/compare/capsule-crm-vs-zoho-crm.md): C 55.7 vs BB 70.8\n- [Close API + MCP vs Zoho CRM](https://www.anchorterminal.com/compare/close-vs-zoho-crm.md): B 66.7 vs BB 70.8\n- [Copper API vs Zoho CRM](https://www.anchorterminal.com/compare/copper-vs-zoho-crm.md): D 46.7 vs BB 70.8\n- [Microsoft Dynamics 365 Sales vs Zoho CRM](https://www.anchorterminal.com/compare/dynamics-365-sales-vs-zoho-crm.md): B 69.7 vs BB 70.8\n- [folk API + MCP vs Zoho CRM](https://www.anchorterminal.com/compare/folk-vs-zoho-crm.md): C 60.8 vs BB 70.8\n- [Freshsales API vs Zoho CRM](https://www.anchorterminal.com/compare/freshsales-vs-zoho-crm.md): E 40.6 vs BB 70.8\n- [HubSpot API + MCP vs Zoho CRM](https://www.anchorterminal.com/compare/hubspot-mcp-vs-zoho-crm.md): BB 71.5 vs BB 70.8\n- [Nutshell vs Zoho CRM](https://www.anchorterminal.com/compare/nutshell-vs-zoho-crm.md): D 49.6 vs BB 70.8\n- [Pipedrive API + MCP vs Zoho CRM](https://www.anchorterminal.com/compare/pipedrive-vs-zoho-crm.md): C 60.5 vs BB 70.8\n- [Salesforce API + MCP vs Zoho CRM](https://www.anchorterminal.com/compare/salesforce-vs-zoho-crm.md): C 60.5 vs BB 70.8\n- [Streak API + MCP vs Zoho CRM](https://www.anchorterminal.com/compare/streak-vs-zoho-crm.md): D 46.4 vs BB 70.8\n- [Twenty API + MCP vs Zoho CRM](https://www.anchorterminal.com/compare/twenty-vs-zoho-crm.md): B 65.9 vs BB 70.8\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on zoho.com or one of its subdomains, or the README of github.com/zoho/crm-oas. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"zoho-crm\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/zoho-crm\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/zoho-crm.svg\" alt=\"Zoho CRM on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Zoho CRM on Anchor Terminal](https://www.anchorterminal.com/badges/zoho-crm.svg)](https://www.anchorterminal.com/tools/zoho-crm)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/zoho-crm\"\u003eZoho CRM on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Zoho CRM is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/zoho-crm-dark.png\n- Light: https://www.anchorterminal.com/assets/share/zoho-crm-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "CRM \u0026 customer platforms",
        "url": "https://www.anchorterminal.com/categories/crm"
      },
      {
        "name": "Zoho CRM",
        "url": ""
      }
    ],
    "description": "Zoho CRM is a hosted sales CRM from Zoho. Agents reach it through the REST API v8, with record, search, query, bulk and notification endpoints behind OAuth 2.0, or through four pre-built remote MCP servers.",
    "facts": [
      "rank #128 of 722",
      "OAuth auth",
      "0 desk reviews"
    ],
    "h1": "Zoho CRM",
    "image": "https://www.anchorterminal.com/assets/og/tools-zoho-crm.png",
    "path": "/tools/zoho-crm",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Zoho CRM review for AI agents, grade BB (70.8/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/zoho-crm"
  },
  "tokens": {
    "markdown": 8300,
    "slim": 1980
  },
  "version": 1
}
