# Zoho Mail API (slim) > Zoho Mail is Zoho's hosted business email service. Its REST API lets an application read, search, send and organise mail in a Zoho Mail account and administer an organisation's users, domains, groups and policies, with OAuth 2.0 access. - Full: https://www.anchorterminal.com/tools/zoho-mail.md (~8,750 tokens) · this version ~2,130 tokens · JSON https://www.anchorterminal.com/tools/zoho-mail.json · canonical https://www.anchorterminal.com/tools/zoho-mail - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **D · 53.8/100 · rank #626 of 842 · #7 in Mailbox access · not agent-ready · confidence medium** Assessment: A REST API over a Zoho Mail mailbox with OAuth scopes that narrow to one resource and one operation, plus an MCP server launched in 2026. Zoho publishes no OpenAPI file, SDK, request rate limit or API changelog, and its usage policy bars automated email. ## Facts - Kind: HTTP API · vendor: Zoho · category: Mailbox access · legal entity: Zoho Corporation Private Limited · provenance 95/100 - Local only (HTTP) - Auth: OAuth · pricing: Freemium · x402: no · licence: Proprietary service under the Zoho Terms of Service and the Zoho Mail usage policy. No source repository was found - Probe metrics: not measured yet (probes haven't run) - Surface graded: The REST API at `https://mail.zoho.com/api` (US). Zoho Mail MCP is described and counted where a checklist line covers it. IMAP, POP and SMTP also exist on paid plans - Mailbox calls: Send, send with attachment, upload attachment, save draft or template, reply, list a folder, search, read headers, content, original message, metadata and attachments, mark read or unread, move, flag, label, archive, mark spam and delete. Thread calls flag, move, label and mark a whole conversation - Administration calls: Organisation, domains (MX, SPF and DKIM checks, aliases, catch-all), groups and moderation, users, mail policies, storage, allowed IP ranges, anti-spam lists and logs. These need an administrator's token - Credentials: OAuth 2.0. Authorisation code for server apps, authorisation code with PKCE for mobile apps, implicit or PKCE for browser apps, device authorisation for tools without a browser, and a self client for one's own account. Access tokens last one hour (https://www.zoho.com/mail/help/api/using-oauth-2.html) - Auth scopes: `ZohoMail..` with operations ALL, READ, CREATE, UPDATE and DELETE. Resources include `accounts`, `folders`, `tags`, `messages`, `tasks`, and `organization.accounts`, `organization.domains`, `organization.groups`, `organization.policy`, `organization.audit` and `partner.organization` - Rate limits: No request rate published. Sending is 50 to 500 external emails an hour by reputation, 1,000 internal, 150 recipients a message on paid accounts and 100 on free. Incoming mail is capped at 100 messages a minute. Folder creation is limited to 40 an hour - Pagination: `start` and `limit` on list and search, with `limit` from 1 to 200 and a default of 10. List filters by folder, read status, flag, label, thread and attachment, and sorts by date, message ID or size - Search: `GET /api/accounts/{accountId}/messages/search` with a `searchKey` written in Zoho Mail's search syntax and an optional `receivedTime` cut-off. By default it returns mail received more than two minutes ago - Errors: A `status` object with a code and description and a `data.moreInfo` message. The reference lists 200, 201, 400, 401, 403, 404 and 500 - Events: Outgoing webhooks post incoming emails, tasks or Streams posts that match a filter to a URL. They are set up in Settings, Integrations, Developer Space, not through the API (https://www.zoho.com/mail/help/dev-platform/webhook.html) - MCP server: Zoho Mail tools are added to a server in the Zoho MCP console, by hand or from a pre-configured template. Authorisation is OAuth 2.1 per user, or one shared connection approved by the Super Admin. Works with ChatGPT, Gemini, Claude, Cursor, Windsurf, VS Code and Cline per the docs. Tool count not published - Data centres: US, Europe, India, Australia, Japan, Canada, China, UAE and Saudi Arabia, each with its own API host such as `mail.zoho.eu`, `mail.zoho.in` and `mail.zohocloud.ca` - SDKs: No REST SDK found. A Java command line tool (ZMail CLI) and a widget SDK for extensions inside the Zoho Mail web client exist - Free tier: Mail Free, up to five users, one domain, 5 GB a user, no card, no IMAP, POP or ActiveSync, in some regions only. 15-day trial of the highest paid edition with no card - Audit: Logs API for login history, admin audit records and SMTP logs. Admin console audit logs can be sent to a SIEM tool - Certifications: ISO/IEC 27001, SOC 2 Type II, ISO 22301 and ISO 9001 per the Zoho Mail compliance page. Bug bounty at bugbounty.zohocorp.com - Status: status.zoho.com redirects to us.zohostatus.com, with components for Zoho Mail, mail listing, IMAP, POP, SMTP, the MX host and Zoho MCP - Prices: Mail Lite, 5 GB $1 per seat per month; Workplace Standard $3 per seat per month; Mail Premium $4 per seat per month; Workplace Professional $6 per seat per month - Scores: Reliability 63, Performance pending, Schema & documentation 45, Agent ergonomics 56, Security & auth 67, Payments & pricing 30, Task success pending, Maintenance & community 33, Transparency & trust 73 · total over the 7 assessed categories - Why: Reliability, Graded on the REST API, read with the hosted lines. · Schema & documentation, Graded on the REST API. · Agent ergonomics, Graded on the REST API. · Security & auth, OAuth 2.0 with scopes down to one resource and one operation, one-hour access tokens, revocable refresh tokens, PKCE for mobile and browser… · Payments & pricing, No x402, MPP or L402 (0 of 40). · Maintenance & community, Zoho keeps no API changelog, so recency rests on what could be dated. · Transparency & trust, The editorial half. - Sources: 38, open questions: 10, both in the full twin - Capabilities: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync - JSON: https://www.anchorterminal.com/api/v1/tools/zoho-mail.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/zoho-mail.svg` or a link to https://www.anchorterminal.com/tools/zoho-mail from a page on zoho.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `Authorization: Zoho-oauthtoken `, not `Bearer`. The token response says `Bearer`, but the OAuth guide says the Mail API requires the Zoho prefix. 2. Use the host for the account's data centre, such as `mail.zoho.eu` or `mail.zoho.in`. Call `GET /api/accounts` first for the `accountId` every mailbox call needs. 3. Reading a message body needs both `folderId` and `messageId`. List and search calls return a summary only, 10 messages by default and 200 at most. 4. Request `ZohoMail.messages.READ` alone for a reading agent. Add `CREATE` only when it must send, and leave `DELETE` out unless required. 5. Refresh the access token every hour, and post OAuth parameters in the request body where the server accepts it, to keep secrets out of URLs. ## Connect ```bash curl "https://mail.zoho.com/api/accounts" \ -X GET \ -H "Accept: application/json" \ -H "Authorization: Zoho-oauthtoken $ZOHO_ACCESS_TOKEN" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/zoho-mail ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Nylas Email API | A | 78.7 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/nylas-email.min.md | | Gmail API | BB | 77.8 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/gmail-api.min.md | | EmailEngine | BB | 71.4 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/emailengine.min.md | | Outlook Mail (Microsoft Graph) | B | 66.3 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/outlook-mail-graph.min.md | | Unipile | C | 58.4 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/unipile.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)