Zoho CPaaS (formerly ZeptoMail)

by Zoho Corporation HTTP API in Email delivery APIs

Hosted

Zoho Corporation · zoho.com since 2004 · status page · who's behind it

Transactional email service from Zoho, renamed from ZeptoMail to Zoho CPaaS in September 2026. It sends application email through a REST API or SMTP relay, with templates, domain management, suppression lists, logs and webhooks.

Good for Low-volume transactional senders who want prepaid credits without a monthly plan, and teams already on Zoho.

Is this your product? Claim this listing or verify it

More from Zoho Corporation Zoho Books (Accounting) · Zoho CRM (CRM) · Zoho Recruit (Recruiting) · Zoho People (HR)

Assessment. A public OpenAPI 3.0 file covers all 42 operations, and each Agent has its own send-only key. Email costs $2.50 per 10,000 with the first credit free. No API rate limit, 429 handling, idempotency key or SLA was found in the reviewed documentation, and new accounts wait for a manual review.

Facts

Transport
HTTP
Endpoint
https://cpaas.zoho.com/v1.1
Auth
OAuth or key
Pricing
Pay per use · $30 / mo
x402
No
Licence
Proprietary service under the Zoho CPaaS terms of use. The Node SDK on npm is MIT
Packages
npm zeptomail
llms.txt
published
npm / week
40k
Rename
ZeptoMail became Zoho CPaaS in September 2026, adding SMS (India only), WhatsApp and voice, all three marked beta. zoho.com/zeptomail redirects to zoho.com/cpaas. api.zeptomail.com still answered on 8 October 2026
API
REST, version 1.1, 42 operations in one OpenAPI 3.0.3 file. 33 cover email (send, batch, templates, file cache, logs, domains, agents, suppressions), 9 cover voice, SMS and WhatsApp
Regions
Six data centres with their own base URL. US cpaas.zoho.com, EU cpaas.zoho.eu, India cpaas.zoho.in, Australia cpaas.zoho.com.au, Japan cpaas.zoho.jp, China cpaas.zoho.com.cn
Credentials
Send key per Agent and per channel in the Authorization header with the prefix Zoho-enczapikey. Zoho OAuth 2.0 (authorisation code grant, one-hour access tokens, refresh tokens) for management calls, with scopes such as Zeptomail.Domains.READ
SMTP
smtp.zeptomail.com on port 587 (TLS) or 465 (SSL), username emailapikey, TLS 1.2
Limits
500 addresses per to, cc or bcc field, 60 attachments, 15 MB per attachment, 500 characters in a subject. No request rate limit found. An owner can set a daily blocking limit per Agent
Free allowance
First credit free, 10,000 emails. Unreviewed accounts have a daily sending limit and can't buy credits
Sandbox
Up to 2 sandbox Agents, 10,000 emails a day each, nothing sent to recipients, simulated bounces and webhooks
Logs
Email logs kept 60 days and readable by API with offset, limit and 13 filters. Content is stored only if the owner opts in. Account activity logs kept one year
Webhooks
Soft bounce, hard bounce, open, click and feedback loop events per Agent
Inbound
None
Dedicated IP
$30 a month, billed annually, in some data centres
SDK
Node package zeptomail 8.0.1 (29 May 2026, MIT, Node 20 or later, TypeScript types). Code samples for curl, C#, Python, PHP and Java, and a Postman collection
Certifications
Zoho lists SOC 2 Type II, SOC 1 Type II, ISO/IEC 27001, 27701, 27017 and 27018 on its compliance page, and runs a bug bounty at bugbounty.zohocorp.com

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Public OpenAPI 3.0.3 file with 42 operations, plus llms.txt and a Markdown copy of every help page
  • Send keys are per Agent and per channel and can only send. Management calls use OAuth with READ, CREATE, UPDATE and DELETE scopes per resource
  • Published price of $2.50 per credit of 10,000 emails, valid six months, with the first credit free
  • IP allow lists for sending, the REST API and the web console, and activity logs kept for one year
  • The terms commit to a six-month deprecation period for a retired API version

Weaknesses

  • No API rate limit, 429 behaviour or Retry-After was found in the reviewed documentation or the OpenAPI file
  • No idempotency key on send. client_reference is a tracking label only
  • Every new account is reviewed by Zoho staff, which the docs say takes two business days, before credits can be bought
  • The only official SDK found is the Node package, last published on 29 May 2026 and still named zeptomail
  • The OAuth guide puts the client secret and refresh token in the token URL's query string
  • No inbound email, and no SLA was found

Before you call it notes for agents

  1. Call the base URL for the account's region (cpaas.zoho.com, .eu, .in, .com.au, .jp or .com.cn). A key from one region fails on another
  2. Send with Authorization: Zoho-enczapikey <key>. Logs, domains, templates, agents and suppressions need a Zoho OAuth token as Authorization: Zoho-oauthtoken <token>
  3. Post OAuth client secrets and refresh tokens in the request body, not the query string the guide shows, so they stay out of logs
  4. Don't retry a timed-out send blindly. There is no idempotency key, so look the message up by client_reference in the email logs first
  5. Count one email per recipient, including cc and bcc, and keep each address field to 500 entries and each attachment to 15 MB
  6. Use a sandbox Agent for tests. It accepts up to 10,000 emails a day and sends none of them

Who's behind it provenance 94/100

  • Legal entity namedZoho Corporation20/20
  • Domain agezoho.com, registered 2004-01-16 (22 years)15/15
  • Endpoint on the vendor's domaincpaas.zoho.com15/15
  • Terms of serviceread, states 2 of the 7 things a reader expects5.7/10
  • Privacy policyread, states 8 of the 8 things a reader expects, and has 1 clause that costs points8/10
  • Status pageus.zohostatus.com10/10
  • Changelogpublished10/10
  • security.txtvalid10/10

Terms and privacy, as read

Terms of service gives no date, states 2 of 7, 1 to know

TL;DR Gives no date. States 2 of the 7 things a reader expects, and we didn't find the governing law, a liability limit, how changes are announced or a service level. To know before relying on it, cut-off without notice or for any reason.

Says access can be ended without notice or for any reason
If your use of Zoho CPaaS is found to be in violation of these Terms, Zoho may, in its sole discretion, take appropriate action against you, which may include suspension or permanent termination of your access to the relevant Channel or to your user account, without any prior notification.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version they agreed to.

Names the governing law or courts

Not found in the text.

Says where a dispute would be heard and under whose law.

States a limit on its liability

Not found in the text.

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
If your use of Zoho CPaaS is found to be in violation of these Terms, Zoho may, in its sole discretion, take appropriate action against you, which may include suspension or permanent termination of your access to the relevant Channel or to your user account, without any prior notification.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced

Not found in the text.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
By using Zoho CPaaS, you agree that you will not use the Service to:

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment

Not found in the text.

Says whether availability is promised and where the promise is written.

Zoho may monitor account activity and email content, manually and with automated tools, and may throttle emails.
In order to prevent spam and to detect possible violation of these Terms, Zoho reserves the right to monitor your account activities and email content both manually and through automated tools.

Noted by a second reader on 2026-10-08.

The customer must not try to reach any API functionality that the API documentation does not expose.
You must not try to access any functionality that is not exposed in the documentation for the API.

Noted by a second reader on 2026-10-08.

Unused credits are not refunded when the customer closes the account, and credits used without authorisation are not refunded.
Zoho shall not provide any refund for (i) any unauthorized use of your service credits, either knowingly or unknowingly; and (ii) unused credits in your Zoho CPaaS account in the event of your closure of your Zoho CPaaS account

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 1,947 words

Privacy policy dated 2025-12-22, states 8 of 8, 1 to know

TL;DR Dated 2025-12-22. States all 8 things a reader expects. To know before relying on it, model training with no opt-out found.

Says it may use customer content to train or improve models, and no opt-out was foundcosts points
In keeping with Zoho's promise not to exploit your data in a way that is not respectful of your privacy and confidentiality expectations, we make only the following limited use of service data for these technologies: (i) using anonymized crops of service data to improve accuracy of the algorithms;

Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.

Gives the date it was last updated Last updated 2025-12-22
Last updated on: 22nd Dec 2025.

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
This policy tells you what information we collect from you, what we do with it, who can access it, and what you can do about it.

The basic statement a privacy policy exists to make.

Says how long data is kept Names a period of 6 months
After you terminate your account, your data will be automatically deleted from our active database within 6 months and from our backups within 3 months after that.

Says when data sent to the service is deleted.

Says who else receives the data
If you ask about our products through one of our referral programs or reselling partners, or sign in to one of our products through an authentication service provider like LinkedIn or Google, they'll pass on your contact information to us.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising
We share your information only in the ways that are described in this Privacy Policy, and only with parties who adopt appropriate confidentiality and security measures.

A plain statement either way.

Says what rights people have over their data
The European Economic Area (EEA) provides certain rights to data subjects (including access, rectification, erasure, restriction of processing, data portability, and the right to object and to complain).

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact privacy@zohocorp.com
If you wish to update or delete your testimonial, you can contact us at privacy@zohocorp.com

An address or officer to send a request to.

Says where data is transferred or stored Data goes to the United States
…or otherwise providing personal information or service data to us, you understand that the processing, transfer, and storage of your personal information or Service Data within the United States of America, the European Economic Area (EEA) and other countries where Zoho operates.

The countries data goes to and the safeguard used.

Zoho employees and contractors may open service data to resolve errors and to check by hand emails reported as spam and scanned images.
so that they can (i) identify, analyze and resolve errors, (ii) manually verify emails reported as spam to improve spam detection, or (iii) manually verify scanned images that you submit to us to verify the accuracy of optical character recognition.

Noted by a second reader on 2026-10-08.

Zoho says it uses an organisation's data to develop models specific to that organisation.
(ii) using your organization's data for developing models specific for your organization.

Noted by a second reader on 2026-10-08.

After an account is terminated, data leaves the active database at a clean-up run once every six months and leaves backups three months later.
Once you terminate your Zoho user account, your data will eventually get deleted from active database during the next clean-up that occurs once in 6 months.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 6,377 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The Zoho CPaaS terms of use name the contracting party as the Zoho entity for the customer's region. That is Zoho Corporation for the United States and Zoho Corporation Private Limited for India (https://www.zoho.com/legal/zoho-contracting-entities.html).

The privacy field points at Zoho's privacy policy, last updated 22 December 2025, whose Part II covers the data customers process through Zoho services. Zoho CPaaS has no privacy policy of its own.

status.zoho.com redirects to us.zohostatus.com, which lists Zepto Mail, Zepto Mail-SMTP and Zepto Mail-SMTP (PORT:465) under the old name. Other regions have their own status sites.

www.zoho.com/.well-known/security.txt names security@zohocorp.com and the bug bounty, and expires on 30 June 2028. cpaas.zoho.com/.well-known/security.txt returns 403.

RDAP for zoho.com gives a registration date of 2004-01-16.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 19:53 UTC

Right nowUpHTTP 403 · 459 ms · 3 minutes ago
Uptime 24h100.0%27 probes
Uptime 30 days100.0%27 probes
p50 24h433 msget
p95 24h590 msanswers, asks for auth

Probed every five minutes at https://cpaas.zoho.com/v1.1. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.

  • Vendor status page unknown, no machine-readable status found · 16 minutes ago

Pages we watch

PageKindLast checkedLast changed
www.zoho.com/cpaas/whats-new.htmlchangelog1 hour ago · 200no change seen
www.zoho.com/cpaas/pricing.htmlpricing1 hour ago · 200no change seen
www.zoho.com/cpaas/terms.htmlterms1 hour ago · 200no change seen

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/zoho-zeptomail.json

Notable

  • ZeptoMail was renamed Zoho CPaaS in September 2026, and existing agents, domains, templates and settings carry over unchanged source
  • Send, batch, template and file-cache calls take a per-Agent send key, while logs, domains, agents, templates and suppressions take Zoho OAuth with scopes per resource and operation source
  • The OpenAPI 3.0.3 file lists 42 operations, 33 of them for email source
  • One email credit covers 10,000 emails for six months, usage is counted per recipient, and the first credit is free source
  • Every new account is reviewed by Zoho staff through a customer validation form, and credits can't be bought until then source
  • The terms allow only transactional email and set limits of 5 per cent bounces and 0.1 per cent spam complaints, above which Zoho may close the account without notice source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 8.2
Graded on the hosted email API with the hosted lines. Zoho's status site at us.zohostatus.com lists three Zepto Mail components with status and incident history sections (20). The history loads by script and we couldn't read it. The site's RSS feed shows Zepto Mail and Zepto Mail-SMTP last changed status on 29 July 2026, in the same minute as several other Zoho services, with no duration, so this line is scored as no readable history (5). No request rate limit was found. The docs give payload caps (500 addresses a field, 60 attachments, 15 MB each) and the sandbox allowance of 10,000 emails a day (6). No 429 handling, Retry-After or idempotency key found in the docs or the OpenAPI file, whose email operations document only 200, 400 and 404 (0). No SLA found (0). The email channel is generally available, while SMS, WhatsApp and voice are marked beta (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 12.7
One public OpenAPI 3.0.3 file with 42 operations, linked from the docs without a login (25). llms.txt at zoho.com/cpaas/llms.txt and a second for the help centre, with a Markdown copy of each page (10). Every operation has a description, most of them one sentence, with nothing on when not to use it (10). Request bodies name required fields and length caps, with 9 enums across the file, but log filters take dates as free strings and responses are typed as a bare JSON object (10). Sample requests and responses on every page and an error-code table of 24 rows with remedies. The 401 body we got from the live endpoint has a different shape from the documented sample (11). Version 1.1 in the path and a What's New page dated by month only (12).
Agent ergonomics 13%16.2 8.9
Send responses are small, and the logs endpoint takes offset and limit, with no field selection (15). Thirteen filters on email logs, among them recipient, subject, date range, client_reference and bounce or delivery state (16). Errors carry a code, a sub-code and a message, and the docs pair each with a fix (16). No idempotency key and no guidance on retrying a send (0). A send needs only from, to and subject. The one official SDK found is for Node, and managing the account needs a second credential type (8).
Security & auth 14%17.5 13.3
Send keys are per Agent and per channel, can be created, listed and deleted by API, and can only send and upload attachments. Management calls use Zoho OAuth 2.0 with READ, CREATE, UPDATE and DELETE scopes per resource and one-hour access tokens. That earns 30, less 10 because the OAuth guide documents the client secret and refresh token in the token URL's query string (20). Read-only scopes, send-only keys, sandbox Agents and IP allow lists for sending, the REST API and the web console. No approval step for deletes (15). No inbound mail, so responses hold only the account's own logs and settings (10). Activity logs per user kept one year with export, and email logs for 60 days that show the triggering IP (13). security.txt valid until 30 June 2028, a bug bounty, and SOC 2 Type II and ISO/IEC 27001 on Zoho's compliance page. No public advisory feed found (18).
Payments & pricing 10%12.5 5.0
No x402, MPP or L402 (0). $2.50 per credit of 10,000 emails and $30 a month for a dedicated IP, public without a login (20). The first credit is free, and the documented signup asks for a phone verification and no payment details (20). Signup is a browser form with phone verification, and Zoho staff review each new account, so there is no autonomous route (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 6.5
The What's New page dates entries by month. The newest is the September 2026 rename with new SMS, WhatsApp and voice endpoints, and help pages carry dates up to 6 October 2026, so we counted it as within 30 days (30). Entries for September, August and July 2026 fall in the last 90 days, though the July one may predate 10 July (20). A public changelog, a support address and a contact page that says support runs around the clock. We saw no public forum replies (10). The Node SDK zeptomail 8.0.1 is from 29 May 2026 with about 40,000 weekly downloads, and it is the only official SDK found (10). The npm package names no source repository, so CI and dependency health couldn't be read (4).
Transparency & trusteditorial 69, provenance 94 7%8.8 7.2
Closed service with its own published terms of use, and an MIT Node SDK (20). Zoho's privacy policy of 22 December 2025 covers service data, and the CPaaS pages say content is stored only on opt-in for 60 days and logs for 60 days. The pages disagree on deletion. The GDPR page says account data is deleted within 24 hours of a 48-hour grace period, the privacy policy says a clean-up every six months with backups three months later, and the April 2026 changelog entry says content can be kept up to 50 days (18). The terms commit to a six-month deprecation period after a service announcement, with no dated notices to check it against (16). Six data centre regions are named with their hosts, and Zoho publishes a sub-processor directory by service that loads by script and that we couldn't read (15).
Negative events≤15None recorded0
Total61.8 · C

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 19 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Zoho CPaaS (formerly ZeptoMail), or have the agent fetch /fixes/zoho-zeptomail.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Zoho CPaaS (formerly ZeptoMail)

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/zoho-zeptomail, the October 2026 research run, assessed 8 October 2026. Grade C, 61.8 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Zoho CPaaS (formerly ZeptoMail): work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Reliability, 41 out of 100, up to 11.8 more on the total

Why it scored 41: Graded on the hosted email API with the hosted lines. Zoho's status site at us.zohostatus.com lists three Zepto Mail components with status and incident history sections (20). The history loads by script and we couldn't read it. The site's RSS feed shows Zepto Mail and Zepto Mail-SMTP last changed status on 29 July 2026, in the same minute as several other Zoho services, with no duration, so this line is scored as no readable history (5). No request rate limit was found. The docs give payload caps (500 addresses a field, 60 attachments, 15 MB each) and the sandbox allowance of 10,000 emails a day (6). No 429 handling, Retry-After or idempotency key found in the docs or the OpenAPI file, whose email operations document only 200, 400 and 404 (0). No SLA found (0). The email channel is generally available, while SMS, WhatsApp and voice are marked beta (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 2. Payments & pricing, 40 out of 100, up to 7.5 more on the total

Why it scored 40: No x402, MPP or L402 (0). $2.50 per credit of 10,000 emails and $30 a month for a dedicated IP, public without a login (20). The first credit is free, and the documented signup asks for a phone verification and no payment details (20). Signup is a browser form with phone verification, and Zoho staff review each new account, so there is no autonomous route (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 3. Agent ergonomics, 55 out of 100, up to 7.3 more on the total

Why it scored 55: Send responses are small, and the logs endpoint takes offset and limit, with no field selection (15). Thirteen filters on email logs, among them recipient, subject, date range, `client_reference` and bounce or delivery state (16). Errors carry a code, a sub-code and a message, and the docs pair each with a fix (16). No idempotency key and no guidance on retrying a send (0). A send needs only from, to and subject. The one official SDK found is for Node, and managing the account needs a second credential type (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 4. Security & auth, 76 out of 100, up to 4.2 more on the total

Why it scored 76: Send keys are per Agent and per channel, can be created, listed and deleted by API, and can only send and upload attachments. Management calls use Zoho OAuth 2.0 with READ, CREATE, UPDATE and DELETE scopes per resource and one-hour access tokens. That earns 30, less 10 because the OAuth guide documents the client secret and refresh token in the token URL's query string (20). Read-only scopes, send-only keys, sandbox Agents and IP allow lists for sending, the REST API and the web console. No approval step for deletes (15). No inbound mail, so responses hold only the account's own logs and settings (10). Activity logs per user kept one year with export, and email logs for 60 days that show the triggering IP (13). security.txt valid until 30 June 2028, a bug bounty, and SOC 2 Type II and ISO/IEC 27001 on Zoho's compliance page. No public advisory feed found (18).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 5. Schema & documentation, 78 out of 100, up to 3.6 more on the total

Why it scored 78: One public OpenAPI 3.0.3 file with 42 operations, linked from the docs without a login (25). llms.txt at zoho.com/cpaas/llms.txt and a second for the help centre, with a Markdown copy of each page (10). Every operation has a description, most of them one sentence, with nothing on when not to use it (10). Request bodies name required fields and length caps, with 9 enums across the file, but log filters take dates as free strings and responses are typed as a bare JSON object (10). Sample requests and responses on every page and an error-code table of 24 rows with remedies. The 401 body we got from the live endpoint has a different shape from the documented sample (11). Version 1.1 in the path and a What's New page dated by month only (12).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 6. Maintenance & community, 74 out of 100, up to 2.3 more on the total

Why it scored 74: The What's New page dates entries by month. The newest is the September 2026 rename with new SMS, WhatsApp and voice endpoints, and help pages carry dates up to 6 October 2026, so we counted it as within 30 days (30). Entries for September, August and July 2026 fall in the last 90 days, though the July one may predate 10 July (20). A public changelog, a support address and a contact page that says support runs around the clock. We saw no public forum replies (10). The Node SDK zeptomail 8.0.1 is from 29 May 2026 with about 40,000 weekly downloads, and it is the only official SDK found (10). The npm package names no source repository, so CI and dependency health couldn't be read (4).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 7. Transparency & trust, 82 out of 100, up to 1.6 more on the total

Made of editorial 69, provenance 94.

Why it scored 82: Closed service with its own published terms of use, and an MIT Node SDK (20). Zoho's privacy policy of 22 December 2025 covers service data, and the CPaaS pages say content is stored only on opt-in for 60 days and logs for 60 days. The pages disagree on deletion. The GDPR page says account data is deleted within 24 hours of a 48-hour grace period, the privacy policy says a clean-up every six months with backups three months later, and the April 2026 changelog entry says content can be kept up to 50 days (18). The terms commit to a six-month deprecation period after a service announcement, with no dated notices to check it against (16). Six data centre regions are named with their hosts, and Zoho publishes a sub-processor directory by service that loads by script and that we couldn't read (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: read, states 2 of the 7 things a reader expects (5.7 of 10)
- Privacy policy: read, states 8 of the 8 things a reader expects, and has 1 clause that costs points (8 of 10)

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- The lead named the product Zoho ZeptoMail. It was renamed Zoho CPaaS in September 2026, and the API host in the docs is now cpaas.zoho.com
- unchecked: incident history on us.zohostatus.com, which loads by script. Only the RSS feed's last status change (29 July 2026) was read
- unchecked: Zoho's sub-processor directory entries for Zoho CPaaS, which load by script
- unchecked: whether the Zoho MCP product listed on the status page exposes Zoho CPaaS. Nothing in the CPaaS docs mentions an MCP server
- Whether a request rate limit exists and what a throttled call returns
- Whether signup ever asks for a card. The documented steps don't
- The day in September 2026 of the rename, and whether the July 2026 changelog entry falls inside the last 90 days
- Whether bounced or rejected sends use credit
- No data processing addendum was looked for beyond the GDPR page
- `lastRelease` is left empty because the newest changelog entry is dated September 2026 with no day. The newest release with a full date is the Node SDK 8.0.1 on 29 May 2026

## Weaknesses

- No API rate limit, 429 behaviour or Retry-After was found in the reviewed documentation or the OpenAPI file
- No idempotency key on send. `client_reference` is a tracking label only
- Every new account is reviewed by Zoho staff, which the docs say takes two business days, before credits can be bought
- The only official SDK found is the Node package, last published on 29 May 2026 and still named zeptomail
- The OAuth guide puts the client secret and refresh token in the token URL's query string
- No inbound email, and no SLA was found

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Call the base URL for the account's region (cpaas.zoho.com, .eu, .in, .com.au, .jp or .com.cn). A key from one region fails on another
- Send with `Authorization: Zoho-enczapikey <key>`. Logs, domains, templates, agents and suppressions need a Zoho OAuth token as `Authorization: Zoho-oauthtoken <token>`
- Post OAuth client secrets and refresh tokens in the request body, not the query string the guide shows, so they stay out of logs
- Don't retry a timed-out send blindly. There is no idempotency key, so look the message up by `client_reference` in the email logs first
- Count one email per recipient, including cc and bcc, and keep each address field to 500 entries and each attachment to 15 MB
- Use a sandbox Agent for tests. It accepts up to 10,000 emails a day and sends none of them

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • The lead named the product Zoho ZeptoMail. It was renamed Zoho CPaaS in September 2026, and the API host in the docs is now cpaas.zoho.com
  • unchecked: incident history on us.zohostatus.com, which loads by script. Only the RSS feed's last status change (29 July 2026) was read
  • unchecked: Zoho's sub-processor directory entries for Zoho CPaaS, which load by script
  • unchecked: whether the Zoho MCP product listed on the status page exposes Zoho CPaaS. Nothing in the CPaaS docs mentions an MCP server
  • Whether a request rate limit exists and what a throttled call returns
  • Whether signup ever asks for a card. The documented steps don't
  • The day in September 2026 of the rename, and whether the July 2026 changelog entry falls inside the last 90 days
  • Whether bounced or rejected sends use credit
  • No data processing addendum was looked for beyond the GDPR page
  • lastRelease is left empty because the newest changelog entry is dated September 2026 with no day. The newest release with a full date is the Node SDK 8.0.1 on 29 May 2026

Sources 27

  1. home page with the rename notice zoho.com · seen 2026-10-08
  2. API overview and groups zoho.com · seen 2026-10-08
  3. API index with OAuth scopes zoho.com · seen 2026-10-08
  4. authentication zoho.com · seen 2026-10-08
  5. OAuth guide zoho.com · seen 2026-10-08
  6. send email reference zoho.com · seen 2026-10-08
  7. error codes zoho.com · seen 2026-10-08
  8. OpenAPI file zohowebstatic.com · seen 2026-10-08
  9. llms.txt zoho.com · seen 2026-10-08
  10. data centres and base URLs zoho.com · seen 2026-10-08
  11. pricing zoho.com · seen 2026-10-08
  12. price values the pricing page loads zoho.com · seen 2026-10-08
  13. subscription and credits zoho.com · seen 2026-10-08
  14. getting started and account review zoho.com · seen 2026-10-08
  15. sandbox Agent zoho.com · seen 2026-10-08
  16. What's New zoho.com · seen 2026-10-08
  17. terms of use zoho.com · seen 2026-10-08
  18. Zoho privacy policy zoho.com · seen 2026-10-08
  19. GDPR page zoho.com · seen 2026-10-08
  20. IP restrictions zoho.com · seen 2026-10-08
  21. activity logs zoho.com · seen 2026-10-08
  22. status page us.zohostatus.com · seen 2026-10-08
  23. status RSS feed us.zohostatus.com · seen 2026-10-08
  24. security.txt zoho.com · seen 2026-10-08
  25. compliance page zoho.com · seen 2026-10-08
  26. npm registry record for zeptomail registry.npmjs.org · seen 2026-10-08
  27. contracting entities zoho.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Pay per use $30 / mo $2.50 per email credit of 10,000 emails ($0.25 per 1,000), valid six months, counted per recipient. The first credit is free, and a sandbox Agent accepts 10,000 test emails a day without sending them. No monthly plan. Credits can be bought only after the account review. Dedicated IP $30 a month, billed annually. Prices are filled in by script from a public JSON file (https://www.zoho.com/cpaas/pricing.html).

Prices

ItemPriceUnitNote
Email credit$0.25per 1,000 emails$2.50 per credit of 10,000 emails, valid six months, counted per recipient. First credit free
Dedicated IP$30per month (plan)Billed annually, some data centres only

Compared across listings on the price index.

Recent changes

  • No changes recorded yet.

Follow them as a feed at /feeds/tools/zoho-zeptomail.xml, or this listing's score history at history.json.

Connect

Install

npm install zeptomail

First request

curl --request POST --url https://cpaas.zoho.com/v1.1/email \
  --header 'Authorization: Zoho-enczapikey REPLACE_WITH_YOUR_KEY' \
  --header 'content-type: application/json' \
  --data '{"from":{"address":"hello@yourapp.com","name":"Your App"},"to":[{"email_address":{"address":"user@example.com","name":"User"}}],"subject":"Test Email","htmlbody":"<p>Test email sent successfully.</p>"}'

Through letme picks today, calling later

GET https://letme.dev/zoho-zeptomail

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Amazon SES Amazon Web ServicesBB75.1email.send email.templates email.domains email.analyticsno
Resend API + MCP ResendBB75.1email.send email.templates email.domains email.analyticsno
MailerSend MailerSend, Inc.B69.5email.send email.templates email.domains email.analyticsno
Mailtrap Email API + MCP Mailtrap (Railsware)B66.8email.send email.templates email.domains email.analyticsno
Postmark API + MCP Postmark (ActiveCampaign)B66.5email.send email.templates email.domains email.analyticsno
Mailgun API + MCP Mailgun (Sinch)B66.2email.send email.templates email.domains email.analyticsno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Zoho CPaaS (formerly ZeptoMail) on Anchor Terminal, C, 61.8/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/zoho-zeptomail"><img src="https://www.anchorterminal.com/badges/zoho-zeptomail.svg" alt="Zoho CPaaS (formerly ZeptoMail) on Anchor Terminal" height="20"></a>
    [![Zoho CPaaS (formerly ZeptoMail) on Anchor Terminal](https://www.anchorterminal.com/badges/zoho-zeptomail.svg)](https://www.anchorterminal.com/tools/zoho-zeptomail)

    It counts on a page on zoho.com or one of its subdomains.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "zoho-zeptomail", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.