# Zoho CRM (slim) > Zoho CRM is a hosted sales CRM from Zoho. Agents reach it through the REST API v8, with record, search, query, bulk and notification endpoints behind OAuth 2.0, or through four pre-built remote MCP servers. - Full: https://www.anchorterminal.com/tools/zoho-crm.md (~8,300 tokens) · this version ~1,980 tokens · JSON https://www.anchorterminal.com/tools/zoho-crm.json · canonical https://www.anchorterminal.com/tools/zoho-crm - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 70.8/100 · rank #128 of 722 · #2 in CRM & customer platforms · agent-ready · confidence medium** Assessment: A public OpenAPI 3.1 description of 644 operations and OAuth scopes down to one module and one operation suit agent use, and the Free edition includes 5,000 API credits a day. The documented token refresh puts the client secret in the URL, and no SLA, deprecation policy or dated API changelog was found. ## Facts - Kind: HTTP API · vendor: Zoho · category: CRM & customer platforms · legal entity: Zoho Corporation Private Limited · provenance 95/100 - Local only (HTTP): npm `@zohocrm/nodejs-sdk-8.0`, pypi `zohocrmsdk8-0` - Auth: OAuth · pricing: Freemium · x402: no · licence: Proprietary service under Zoho's Terms of Service. The server-side SDKs on GitHub are Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - API: REST API v8 at https://www.zohoapis.com/crm/v8 (US). Records, related records, search, COQL query, composite (five calls in one request), bulk read and write, notifications, metadata, workflow and data sharing endpoints - MCP servers: Four pre-built remote servers on zohomcp.in hosts. Data Insights (read-only, COQL queries, module and field metadata), Data Operations (record create, read, update, delete and bulk), Module Customisation, Workflow and Process Automation. OAuth sign-in in a browser on first use. Tool counts not published - Credentials: OAuth 2.0 authorisation code grant, or a self client with authorisation code or client credentials. Access tokens last one hour. Refresh tokens last until revoked - Auth scopes: `ZohoCRM...` with operations ALL, READ, CREATE, UPDATE and DELETE. Groups are users, org, settings, modules, bulk, notifications and coql. Module scopes name one module, such as `ZohoCRM.modules.leads.READ` - Rate limits: Credits per rolling 24 hours. Free 5,000. Standard 50,000 plus 250 a user licence, at most 100,000. Professional 50,000 plus 500 a licence, at most 3,000,000. Enterprise 50,000 plus 1,000 a licence, at most 5,000,000. Ultimate 50,000 plus 2,000 a licence, no maximum. Concurrency 5, 10, 15, 20 and 25 by edition, sub-concurrency 10 - Credit costs: Most calls 1. Insert, update or upsert 1 per 10 records (100 records a call). Convert Lead 5. Send Mail 20. Bulk read 50. Bulk write 500. COQL 1 to 3 by LIMIT - Read and write: Leads, Accounts, Contacts, Deals, Campaigns, Tasks, Cases, Meetings, Calls, Products, Vendors, Price Books, Quotes, Sales Orders, Purchase Orders, Invoices, Appointments, Services and custom modules - Pagination: `per_page` up to 200. `page` reaches 2,000 records, `page_token` reaches 100,000. Search returns 2,000 records at most. `fields` is mandatory on list calls, 50 names at most - Webhooks: Notification API channels per module for create, update and delete, with field conditions and an expiry time. Webhooks are also a workflow action - Data centres: US, EU, India, Australia, Japan, Canada, China and Saudi Arabia, each with its own accounts host and API domain - SDKs: Java, Python, PHP, Node.js, C# and Ruby, Apache-2.0. Node.js @zohocrm/nodejs-sdk-8.0 4.0.0 (21 September 2026), Python zohocrmsdk8-0 7.0.0 (24 July 2026) - Free tier: Free edition for three users with 5,000 API credits a day, no card at signup. 15-day trial of paid editions with the paid edition's API limits - Audit: Audit Logs in paid editions per the feature list. The API dashboard shows credits used by application and function - Certifications: SOC 2 Type 2, SOC 1 Type 2, ISO/IEC 27001, 27701 and 27017 per zoho.com/compliance.html. Bug bounty at bugbounty.zohocorp.com - Status: status.zoho.com redirects to us.zohostatus.com, with a Zoho CRM component and incident history back to November 2025 - Prices: Standard $14 per seat per month; Professional $23 per seat per month; Enterprise $40 per seat per month; Ultimate $52 per seat per month; Add-on API credits, first 25,000 a day $0.0001 per credit - Scores: Reliability 72, Performance pending, Schema & documentation 81, Agent ergonomics 81, Security & auth 67, Payments & pricing 40, Task success pending, Maintenance & community 77, Transparency & trust 75 · total over the 7 assessed categories - Why: Reliability, Graded on the REST API v8, read as a hosted service. · Schema & documentation, zoho/crm-oas on GitHub holds OpenAPI 3.1 files for 103 resources and 644 operations (25). · Agent ergonomics, Graded on the REST API. · Security & auth, OAuth 2.0 with scopes down to one module and one operation, one-hour access tokens and revocable refresh tokens (30). · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The Node.js SDK for v8 reached 4.0.0 on 21 September 2026, 17 days before this check (30). · Transparency & trust, Closed service under the Zoho Terms of Service, last updated 2 March 2022, with Apache-2.0 SDKs (15 of 30). - Sources: 42, open questions: 8, both in the full twin - Capabilities: crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks - JSON: https://www.anchorterminal.com/api/v1/tools/zoho-crm.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/zoho-crm.svg` or a link to https://www.anchorterminal.com/tools/zoho-crm from a page on zoho.com or one of its subdomains, or the README of github.com/zoho/crm-oas, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Use the `api_domain` returned with the token, since each data centre has its own host (zohoapis.com, zohoapis.eu, zohoapis.in and others) 2. Send `Authorization: Zoho-oauthtoken ` and refresh hourly. Put refresh parameters in the POST body, not the URL 3. Pass `fields` on every list call. Page with `page` up to 2,000 records, then `page_token` up to 100,000 4. Create through `/{module}/upsert` so a retry updates instead of duplicating 5. Budget credits. Convert Lead costs 5, Send Mail 20, a bulk read 50, and calls through the MCP servers draw on the same allowance ## Connect ```bash pip install zohocrmsdk8-0 ``` ```bash curl "https://www.zohoapis.com/crm/v8/Leads?fields=Last_Name,Email&per_page=5" \ -X GET -H "Authorization: Zoho-oauthtoken $ZOHO_ACCESS_TOKEN" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/zoho-crm ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | HubSpot API + MCP | BB | 71.5 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/hubspot-mcp.min.md | | Microsoft Dynamics 365 Sales | B | 69.7 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/dynamics-365-sales.min.md | | Close API + MCP | B | 66.7 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/close.min.md | | Twenty API + MCP | B | 65.9 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/twenty.min.md | | Affinity | B | 63.4 | crm.records, crm.pipeline, crm.activities, crm.search, crm.webhooks | https://www.anchorterminal.com/tools/affinity.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)