# Zoho People
> Cloud HR system from Zoho covering employee records, leave, attendance, timesheets, onboarding, performance and learning. Agents reach it through a REST API with OAuth 2.0, available on paid plans.
- Canonical: https://www.anchorterminal.com/tools/zoho-people
- Markdown: https://www.anchorterminal.com/tools/zoho-people.md (~8,000 tokens)
- Slim: https://www.anchorterminal.com/tools/zoho-people.min.md (~1,780 tokens, same facts, less prose, for token-sensitive contexts)
- JSON: https://www.anchorterminal.com/tools/zoho-people.json (this page as data, same URL with Accept: application/json)
- Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt)
- API: https://www.anchorterminal.com/api/v1/index.json
- Updated: 2026-10-08
## Overview
**Grade C · 55/100 · rank #523 of 722 · #6 in HR & employee operations · not agent-ready · confidence medium**
More from Zoho, listed separately because each is its own product: [Zoho Books](https://www.anchorterminal.com/tools/zoho-books.md) (Accounting & invoicing), [Zoho CPaaS (formerly ZeptoMail)](https://www.anchorterminal.com/tools/zoho-zeptomail.md) (Email delivery APIs), [Zoho CRM](https://www.anchorterminal.com/tools/zoho-crm.md) (CRM & customer platforms), [Zoho Recruit](https://www.anchorterminal.com/tools/zoho-recruit.md) (Recruiting & applicant tracking).
## Assessment
The REST API covers employee forms, leave, attendance, timesheets, files and learning, with per-endpoint rate limits and Markdown docs listed in an llms.txt. No OpenAPI spec, official SDK or dated API changelog was found, the Free plan has no API access, and several scopes come only as ALL.
## Facts
| Field | Value |
| --- | --- |
| Vendor | Zoho (https://www.zoho.com/people/) |
| Kind | HTTP API |
| Category | HR & employee operations (https://www.anchorterminal.com/categories/hr) |
| Transport | HTTP |
| Endpoint | `https://people.zoho.com/api` |
| Auth | OAuth · OAuth 2.0 only in the current docs. A person registers a client in the Zoho API console (web, mobile, JavaScript, non-browser or a self client for one organisation) and approves scopes of the form `ZOHOPEOPLE..`. The access token lasts one hour and goes in `Authorization: Zoho-oauthtoken `. The refresh token lasts until revoked. Each data centre (US, EU, India, Australia, Japan, China) has its own accounts host. Registration is self-serve, with no app review or sales approval for use inside one's own organisation. The authentication page still links to a legacy authentication token page, which returns 404. |
| Pricing | Paid ($1.25 / seat-mo) · Paid plans only for the API. Essential HR, Professional, Premium and Enterprise cost $1.25, $2, $3 and $4.50 a user a month billed yearly ($1.50, $2.50, $3.50 and $5 monthly), with a five-user minimum. A separate United States plan set costs $3 to $8 a user a month billed yearly. The Free plan covers five users and has no API access. A 30-day trial of any paid plan is self-serve, and the account drops to Free when it ends. Prices come from the feed the pricing page loads (https://www.zoho.com/people/zohopeople-pricing.html, checked 2026-10-08). |
| x402 | No · No x402, MPP or L402 in the API docs, the pricing pages or the terms (checked 2026-10-08). |
| Licence | Proprietary service under the Zoho Terms of Service |
| Docs | https://www.zoho.com/people/api/overview.html |
| llms.txt | https://www.zoho.com/people/api/llms.txt |
| Last release | 2026-08-01 |
| API | REST over HTTPS at https://people.zoho.com (US) in three styles. Form endpoints under `/people/api/forms/`, a v2 leave endpoint, and v3 endpoints under `/api/v3/` for leave, attendance, files, shifts, organisation structure, performance and variables. JSON or XML responses |
| Coverage | 339 reference pages in the docs index. Forms and employee records, leave, attendance, shifts, timesheets and time tracking (44 pages), files, announcements, cases, onboarding, organisation structure, performance, compensation and the learning system (110 pages). 89 pages are v3 |
| Credentials | OAuth 2.0 authorisation code grant, or a self client for one organisation. Grant token two minutes, access token one hour, refresh token until revoked. At most 10 access tokens per refresh token in 10 minutes |
| Auth scopes | `ZOHOPEOPLE..`. forms (ALL, CREATE, READ, UPDATE), leave (ALL, READ, CREATE, UPDATE), and employee, dashboard, automation, timetracker and attendance (ALL). Reference pages also name `ZOHOPEOPLE.leave.DELETE`, `ZOHOPEOPLE.attendance.READ` and `ZOHOPEOPLE.orgstructure.CREATE` |
| Rate limits | Daily. Essential HR 250 calls a user licence, at most 5,000. Professional at most 10,000. Premium at most 15,000. Enterprise 500 a licence, at most 25,000. Per endpoint, a threshold of 30 to 400 calls a minute with a five-minute lock period |
| Pagination | Form records by `sIndex` and `limit`, at most 200 a call. v3 lists by `offset` and `limit`, with `sort` on leave. `modifiedtime` returns records added or changed after a timestamp |
| Filtering | `searchParams` with a field, an operator (Is, Contains, Between, Last_30_Days and about 40 more) and AND or OR. v3 leave filters by date range, employee, department, location, leave type and approval status |
| Errors | Form endpoints return numeric codes (7011 invalid form name, 7038 permission denied to add records, 7052 missing mandatory fields) with a published list. v3 and learning endpoints return a named code, a message and the field. 429 for the daily or concurrency limit |
| Webhooks | Listed as an automation on every plan in the plan comparison, the Free plan included. Not covered in the API reference |
| Data centres | Accounts hosts for US, EU, India, Australia, Japan and China. The token response returns `api_domain` |
| SDKs | None found. Reference pages carry samples in Java, JavaScript, Python, curl and Deluge |
| Free tier and trial | Free plan for five users without API access. 30-day trial of any paid plan, after which the account moves to Free |
| Capabilities | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents |
| Tags | hosted, closed-source, paid, free-trial, oauth, llms-txt, webhooks, status-page, bug-bounty, soc2 |
| JSON | https://www.anchorterminal.com/api/v1/tools/zoho-people.json |
## Score breakdown (methodology v0.4, October 2026 research run)
Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points.
| Category | Weight | This run | Score (0–100) | Points |
| --- | --- | --- | --- | --- |
| Reliability | 16% | 20 | 77 | 15.4 |
| Performance | 10% | pending | pending | n/a |
| Schema & documentation | 13% | 16.2 | 43 | 7.0 |
| Agent ergonomics | 13% | 16.2 | 48 | 7.8 |
| Security & auth | 14% | 17.5 | 60 | 10.5 |
| Payments & pricing | 10% | 12.5 | 30 | 3.8 |
| Task success | 10% | pending | pending | n/a |
| Maintenance & community | 7% | 8.8 | 48 | 4.2 |
| Transparency & trust (editorial 51, provenance 95) | 7% | 8.8 | 73 | 6.4 |
| Negative events | up to −15 | up to −15 | none recorded | 0 |
| **Total** | | | | **55 → C** |
### Why each score
- Reliability 77: Graded on the REST API, read as a hosted service. status.zoho.com redirects to us.zohostatus.com, which lists Zoho People as a component with status and incident history (20). The status feed shows the People component last changed state on 28 March 2026, and the page's seven days of incident history name only a mail component. The older incident list loads by script and wasn't read, and only the US page was read (25 of 30). Daily caps per plan and a per-minute threshold on each reference page are published with numbers (15). 429 is documented for the daily and concurrency limits, and each page states a five-minute lock period after the threshold. No Retry-After header, backoff guidance or idempotency key was found (7 of 15). No SLA found (0). The API is the current documented surface, with no beta label (10).
- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.
- Schema & documentation 43: No OpenAPI or other machine-readable contract was found in the docs or under Zoho's GitHub organisation (0). An llms.txt at `/people/api/llms.txt` lists 339 reference pages, each served as Markdown (10). Each page opens with a one-line purpose and few say when to use one endpoint over another, such as the form, v2 and v3 routes to leave records (9 of 20). v3 pages have parameter tables with types, allowed values and defaults. Form endpoints take an `inputData` JSON string keyed by form label names, and search is a string grammar (7 of 15). Pages carry sample requests in up to five languages, sample responses and error tables, plus global lists of status and error codes. One curl sample includes session cookies (12 of 15). Versions sit in the path for v2 and v3, and no dated API changelog was found (5 of 15).
- Agent ergonomics 48: Graded on the REST API. `limit` caps a page at 200 records and views narrow the columns, but no field selection parameter was found and form records return their tabular sections (12 of 25). `sIndex` and `limit` on forms, `offset`, `limit` and `sort` on v3, `searchParams` with about 50 operators, and `modifiedtime` for changes since a timestamp. Parameter names differ between the three URL styles (16 of 20). Form endpoints return numeric codes with a published cause list, and v3 returns a named code, a message and the field at fault. The two formats coexist (13 of 20). No idempotency key or documented safe-retry method for writes (2 of 20). No official SDK found. The one-hour token, per-region hosts and the lookup of form and field label names add setup (5 of 15).
- Security & auth 60: OAuth 2.0 with scopes by area and operation, one-hour access tokens and refresh tokens that last until revoked (30). Less 10 because the documented refresh call carries the refresh token and client secret in the URL query string (20 of 30). READ scopes exist for forms and leave. Employee, attendance, time tracker, dashboard and automation scopes are listed only as ALL. Permission errors (7037 to 7040) show calls are bound by the user's access, and no approval step for deletes was found (11 of 20). Records hold text written by employees and candidates, and no prompt-injection guidance was found (3 of 15). The product has activity logs and field audit history. Whether API calls appear in them isn't stated (6 of 15). security.txt valid to 30 June 2028, a bug bounty, SOC 2 Type 2 and ISO/IEC 27001, 27701, 27017 and 27018 (20).
- Payments & pricing 30: No x402, MPP or L402 (0). Plan prices are public in the pricing page's own feed, $1.25 to $4.50 a user a month billed yearly, and the daily API allowance per plan is published. There's no per-call price, so we scored it between plan-only and per-unit (15). A 30-day trial of any paid plan is self-serve. The Free plan has no API, and no page read says whether signup needs a card. The signup form's script asks for name, email and phone only (15 of 20). A person signs up in a browser, registers an OAuth client in the API console and approves scopes (0).
- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.
- Maintenance & community 48: Closed service, read from the product's What's New page, which is dated by month. The newest entries are for August 2026, between 38 and 68 days before this check (20). August lists nine entries and July ten (20). No API changelog. Support is by email on every plan, and a community forum exists on help.zoho.com, which we did not test for replies (8 of 25). No official SDK for Zoho People was found (0 of 15). No packages to assess (0 of 10).
- Transparency & trust 73: Closed service under the Zoho Terms of Service, last updated 2 March 2022 (15 of 30). The privacy policy of 22 December 2025 says Zoho does not sell personal information, and that data is deleted from the active database within six months of account termination and from backups three months later. A Zoho People privacy notice covers facial recognition and location data. The DPA is sent on request through a form (24 of 30). No API deprecation policy or dated notices found, and the legacy authentication token page linked from the docs returns 404 with no notice (0). A sub-processor page exists, but its directory loads by script and we could not read the list. The OAuth page names six data centre regions (12 of 20).
Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (22 items): https://www.anchorterminal.com/fixes/zoho-people.md (JSON https://www.anchorterminal.com/fixes/zoho-people.json)
### What we couldn't check
- unchecked: the incident list on us.zohostatus.com beyond the seven days shown. It loads by script, so the 90-day record rests on the status feed's last state change for Zoho People (28 March 2026)
- unchecked: status pages for data centres other than the US
- unchecked: the sub-processor directory, which loads by script
- unchecked: whether the trial signup asks for a card. No page read says either way
- unchecked: whether Zoho MCP has Zoho People tools. The MCP home page names Zoho People and the MCP pricing page's supported services list does not
- unchecked: replies on the Zoho People community forum at help.zoho.com
- unchecked: API hosts for regions other than the US. The docs use people.zoho.com throughout and people.zoho.in once
- The price feed also holds entries named `zapi-addon` ($750 a month) and `zus-api-addon` ($375 a month). No page read explains them, so they are not on the listing
- The United States plan prices ($3 Essential HR, $5 Workforce, $5 Talent, $8 Enterprise, billed yearly) are matched to plan names by their order on the pricing page
- What's New entries carry a month, not a day, and none is listed for September 2026. `lastRelease` is set to the first day of August 2026
- Whether API calls appear in the product's activity logs. Not found in the reviewed documentation
- The lead was right about OAuth and employee and form records. It had not read the leave endpoints, which exist in v2 and v3. It did not mention that the Free plan has no API
- No terms specific to the API were found. The Zoho Terms of Service govern the product
### Sources
- API overview and plan availability: (seen 2026-10-08)
- API reference index (llms.txt): (seen 2026-10-08)
- daily API limits per plan: (seen 2026-10-08)
- OAuth scopes: (seen 2026-10-08)
- OAuth steps, accounts hosts and refresh call: (seen 2026-10-08)
- token validity: (seen 2026-10-08)
- status codes: (seen 2026-10-08)
- error codes: (seen 2026-10-08)
- Get Bulk Records, paging and threshold: (seen 2026-10-08)
- Search Records operators: (seen 2026-10-08)
- Get Leave Requests v3: (seen 2026-10-08)
- Create Organisation Structure v3, error format: (seen 2026-10-08)
- Trigger Onboarding API: (seen 2026-10-08)
- Fetch Forms, curl sample: (seen 2026-10-08)
- pricing page and trial terms: (seen 2026-10-08)
- price feed the pricing page loads: (seen 2026-10-08)
- plan comparison, API and webhooks rows: (seen 2026-10-08)
- What's New 2026: (seen 2026-10-08)
- status page (US): (seen 2026-10-08)
- status feed: (seen 2026-10-08)
- Terms of Service: (seen 2026-10-08)
- contracting entities: (seen 2026-10-08)
- privacy policy: (seen 2026-10-08)
- Zoho People privacy notice: (seen 2026-10-08)
- Zoho People security and privacy page: (seen 2026-10-08)
- compliance certificates: (seen 2026-10-08)
- sub-processor page: (seen 2026-10-08)
- security.txt: (seen 2026-10-08)
- Zoho MCP home page: (seen 2026-10-08)
- Zoho MCP pricing and supported services: (seen 2026-10-08)
- RDAP for zoho.com: (seen 2026-10-08)
## Who's behind it (provenance 95/100, checked 2026-10-08)
| Check | Finding | Points |
| --- | --- | --- |
| Legal entity named | Zoho Corporation Private Limited | 20/20 |
| Domain age | zoho.com, registered 2004-01-16 (22 years) | 15/15 |
| Endpoint on the vendor's domain | people.zoho.com | 15/15 |
| Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 |
| Privacy policy | read, states 8 of the 8 things a reader expects, and has 1 clause that costs points | 8/10 |
| Status page | status.zoho.com | 10/10 |
| Changelog | published | 10/10 |
| security.txt | valid | 10/10 |
The Terms of Service (last updated 2 March 2022) are the service agreement for Zoho's online services. The contracting entity depends on the customer's region, Zoho Corporation Private Limited for India and Zoho Corporation for the United States (https://www.zoho.com/legal/zoho-contracting-entities.html).
The privacy policy was last updated on 22 December 2025. Its Part II covers data customers store in Zoho services. A separate Zoho People privacy notice at https://www.zoho.com/people/privacy-policy.html adds terms for facial recognition and location data in attendance.
API calls go to people.zoho.com and its regional equivalents, on Zoho's own domains. OAuth runs on accounts.zoho.com.
status.zoho.com redirects to us.zohostatus.com, which lists Zoho People as a component.
security.txt at www.zoho.com gives a bug bounty contact, security@zohocorp.com, a policy link and an expiry of 30 June 2028.
What's New is a product changelog dated by month, newest August 2026. No API changelog was found.
RDAP for zoho.com gives a registration date of 2004-01-16.
### Terms and privacy, as read
A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.
**Terms of service** (https://www.zoho.com/terms.html), read 2026-10-08, dated 2022-03-02, states 6 of the 7 things a reader expects.
- To know. Restricts benchmarking or competitive use (costs points). "use the Services for any form of competitive or benchmarking purposes"
- To know. Has not been updated for three years or more. "Last updated on: 2nd March 2022."
- Gives the date it was last updated. Last updated 2022-03-02.
- States a limit on its liability. Capped at the fees paid in the 12 months before the claim or $1000.
- Says how changes to the terms are announced. Gives 30 days of notice before a change.
- Not found in the text. Refers to a service level or uptime commitment.
- Also in the text (2026-10-08). Subscriptions renew automatically and the customer must give at least seven days' notice before the renewal date to stop renewal. "If you do not wish to renew the subscription, you must inform us at least seven days prior to the renewal date."
- Also in the text (2026-10-08). Unpaid accounts inactive for 120 continuous days may be terminated and their data deleted, with prior notice, and activity in one service does not keep another active. "We reserve the right to terminate unpaid user accounts that are inactive for a continuous period of 120 days."
- Also in the text (2026-10-08). If the customer does not answer a forwarded complaint within 10 days, Zoho may give the customer's name and contact information to the complainant. "If you do not respond to the complainant within 10 days from the date of our email to you, we may disclose your name and contact information to the complainant for enabling the complainant to take legal action against you."
**Privacy policy** (https://www.zoho.com/privacy.html), read 2026-10-08, dated 2025-12-22, states 8 of the 8 things a reader expects.
- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "In keeping with Zoho's promise not to exploit your data in a way that is not respectful of your privacy and confidentiality expectations, we make only the following limited use of service data for these technologies: (i) using anonymized crops of service data to improve accuracy of the algorithms;"
- Gives the date it was last updated. Last updated 2025-12-22.
- Says how long data is kept. Names a period of 6 months.
- Gives a privacy contact. privacy@zohocorp.com.
- Says where data is transferred or stored. Data goes to the United States.
- Also in the text (2026-10-08). Zoho employees and contractors may open service data to resolve errors and to check by hand emails reported as spam and scanned images. "so that they can (i) identify, analyze and resolve errors, (ii) manually verify emails reported as spam to improve spam detection, or (iii) manually verify scanned images that you submit to us to verify the accuracy of optical character recognition."
- Also in the text (2026-10-08). Zoho says it uses an organisation's data to develop models specific to that organisation. "(ii) using your organization's data for developing models specific for your organization."
- Also in the text (2026-10-08). After an account is terminated, data leaves the active database at a clean-up run once every six months and leaves backups three months later. "Once you terminate your Zoho user account, your data will eventually get deleted from active database during the next clean-up that occurs once in 6 months."
## Live (updated 2026-10-08 21:12 UTC)
- Right now: up, HTTP 404, 421 ms, checked 2026-10-08 21:12 UTC (get on `https://people.zoho.com/api`)
- Uptime 24h 100.0% (21 probes) · 30 days 100.0% (21 probes) · p50 431 ms · p95 460 ms
- Always current: https://www.anchorterminal.com/api/v1/live/zoho-people.json
## Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.
## Prices
| Item | Price | Unit | Note |
| --- | --- | --- | --- |
| Essential HR | $1.25 | per seat per month | billed yearly; $1.50 billed monthly; five-user minimum; API capped at 5,000 calls a day |
| Professional | $2 | per seat per month | billed yearly; $2.50 billed monthly; API capped at 10,000 calls a day |
| Premium | $3 | per seat per month | billed yearly; $3.50 billed monthly; API capped at 15,000 calls a day |
| Enterprise | $4.50 | per seat per month | billed yearly; $5 billed monthly; API capped at 25,000 calls a day |
Across all listings: https://www.anchorterminal.com/prices/index.md
## Strengths
- OAuth 2.0 scopes name an area and an operation, such as `ZOHOPEOPLE.forms.READ` and `ZOHOPEOPLE.leave.CREATE`, with one-hour access tokens
- Every reference page states a per-minute threshold and a five-minute lock period, and daily call caps are published per plan
- An llms.txt at `/people/api/llms.txt` lists 339 reference pages, each served as Markdown
- Plan prices are public, from $1.25 a user a month billed yearly, with a 30-day trial of any paid plan
- security.txt valid to 30 June 2028, a bug bounty, SOC 2 Type 2 and ISO/IEC 27001, 27701, 27017 and 27018
## Weaknesses
- No OpenAPI spec, official SDK or dated API changelog found. The product What's New page has no API entries for 2026
- The Free plan has no API access. Paid plans cap calls at 5,000 to 25,000 a day
- Employee, attendance, time tracker, dashboard and automation scopes are listed only as ALL, with no read-only form
- Three URL styles coexist (unversioned form endpoints, v2 and v3), with different parameter names, paging and error formats
- The documented token refresh call carries the refresh token and client secret in the URL query string
## Before you call it (notes for agents)
1. Use the accounts host and API host of the organisation's data centre. Tokens issued in one region fail in another
2. Stay under each page's threshold, often 30 calls a minute. Exceeding it locks that endpoint for five minutes
3. Page form records with `sIndex` and `limit`, at most 200 a call, and use `modifiedtime` to fetch only changes
4. Look up form and field label names with `/api/forms` before writing. `inputData` takes label names, and lookup fields take record IDs
5. Send the refresh token and client secret in the POST body, not the query string, and store the refresh token, which never expires
## Connect
First request:
```bash
curl --location 'https://people.zoho.com/api/forms' \
--header "Authorization: Zoho-oauthtoken $ZOHO_ACCESS_TOKEN"
```
Through letme (picks today, calling later): https://letme.dev/zoho-people. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md
## Similar tools
Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.
| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |
| --- | --- | --- | --- | --- | --- | --- |
| Deel | B | 69.1 | 168 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/deel.md |
| BambooHR | C | 61.7 | 357 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/bamboohr.md |
| Rippling | C | 60.8 | 386 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/rippling.md |
| HiBob | C | 57 | 484 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/hibob.md |
| Humaans | C | 54.4 | 529 | hr.employees, hr.time-off, hr.org, hr.documents, hr.onboarding | no | https://www.anchorterminal.com/tools/humaans.md |
| Factorial | B | 66.3 | 239 | hr.employees, hr.time-off, hr.org, hr.documents | no | https://www.anchorterminal.com/tools/factorial.md |
## Panel reviews (0)
Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .
Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md
## Notable
- The API is available on the Essential HR, Professional, Premium and Enterprise plans. The plan comparison shows no API on the Free plan (source: )
- Daily caps are 250 calls a user licence up to 5,000 (Essential HR), 10,000 (Professional) and 15,000 (Premium), and 500 a licence up to 25,000 on Enterprise (source: )
- Each reference page states a threshold of calls a minute and a lock period of five minutes. Get Leave Requests allows 30, Insert Record 100 and Get Bulk Records 400 (source: )
- The scopes page lists employee, dashboard, automation, timetracker and attendance scopes only as ALL. Forms and leave have READ, CREATE and UPDATE (source: )
- The refresh call is documented as `{Accounts_URL}/oauth/v2/token?refresh_token=...&client_secret=...`, with both secrets in the query string (source: )
- The docs' curl sample for `/api/forms` includes a Cookie header with session values, which an API client does not need (source: )
- Zoho MCP's home page names Zoho People among its integrations, and its pricing page's list of supported services does not. No People tool list was found (source: )
- What's New for July 2026 lists onboarding operations and file access through Zia, Zoho's own assistant inside the product (source: )
## Compare
- [BambooHR vs Zoho People](https://www.anchorterminal.com/compare/bamboohr-vs-zoho-people.md): C 61.7 vs C 55
- [Deel vs Zoho People](https://www.anchorterminal.com/compare/deel-vs-zoho-people.md): B 69.1 vs C 55
- [Factorial vs Zoho People](https://www.anchorterminal.com/compare/factorial-vs-zoho-people.md): B 66.3 vs C 55
- [HiBob vs Zoho People](https://www.anchorterminal.com/compare/hibob-vs-zoho-people.md): C 57 vs C 55
- [Humaans vs Zoho People](https://www.anchorterminal.com/compare/humaans-vs-zoho-people.md): C 54.4 vs C 55
- [Rippling vs Zoho People](https://www.anchorterminal.com/compare/rippling-vs-zoho-people.md): C 60.8 vs C 55
## Verify this listing
For the vendor. The badge or a plain link to this page verifies the listing, from a page on zoho.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "zoho-people", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify
HTML badge:
```html
```
Markdown badge, for a README:
```markdown
[](https://www.anchorterminal.com/tools/zoho-people)
```
Plain link:
```html
Zoho People on Anchor Terminal
```
## Share this listing
For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Zoho People is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.
- Dark: https://www.anchorterminal.com/assets/share/zoho-people-dark.png
- Light: https://www.anchorterminal.com/assets/share/zoho-people-light.png