通过托管 OAuth 读写 Zoho Recruit 的候选人、职位和面试数据。
设计与多媒体
zoho-people
试用通过托管 OAuth 读写 Zoho People 的员工、部门、考勤、休假和任意表单记录。
它能做什么
通过 Maton 代理调用 Zoho People API,使用托管 OAuth 完成鉴权,覆盖员工、部门、职级、考勤、休假以及账户中配置的任何表单(含自定义表单)。支持列表、按 ID 或邮箱搜索、新增和更新等记录操作,所有写操作必须在用户确认后才执行。HR 记录含姓名、邮箱、薪资等敏感信息,因此仅访问用户明确请求的具体记录,不做批量导出。需要网络访问、Maton API Key 以及已授权的 Zoho People 连接。
什么时候用它
- 按分页或筛选条件列出员工
- 按工号或邮箱检索员工
- 新增部门或请假记录
- 修改员工所属部门或状态
技能文档
Zoho People
Access the Zoho People API with managed OAuth authentication. Manage employees, departments, designations, attendance, leave, and custom HR forms with full CRUD operations.
Quick Start
# List all employees
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/zoho-people/people/api/forms/employee/getRecords?sIndex=1&limit=10')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Base URL
https://api.maton.ai/zoho-people/{native-api-path}
Maton proxies requests to people.zoho.com and automatically injects your OAuth token.
Authentication
All requests require the Maton API key in the Authorization header:
Authorization: Bearer $MATON_API_KEY
Environment Variable: Set your API key as MATON_API_KEY:
export MATON_API_KEY="YOUR_API_KEY"
Getting Your API Key
- Sign in or create an account at maton.ai
- Go to maton.ai/settings
- Copy your API key
Connection Management (Maton Platform)
The following endpoints are Maton platform operations for managing the OAuth connection to Zoho People — they are not part of the Zoho People API itself. Only the endpoints listed in the API Reference section below are proxied to Zoho People.
List Connections
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/connections?app=zoho-people&status=ACTIVE')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Create Connection
python <<'EOF'
import urllib.request, os, json
data = json.dumps({'app': 'zoho-people'}).encode()
req = urllib.request.Request('https://api.maton.ai/connections', data=data, method='POST')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Content-Type', 'application/json')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Get Connection
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/connections/{connection_id}')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Response:
{
"connection": {
"connection_id": "{connection_id}",
"status": "ACTIVE",
"creation_time": "2026-02-06T07:42:07.681370Z",
"last_updated_time": "2026-02-06T07:46:12.648445Z",
"url": "https://connect.maton.ai/?session_token=...",
"app": "zoho-people",
"metadata": {}
}
}
Open the returned url in a browser to complete OAuth authorization.
Delete Connection
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/connections/{connection_id}', method='DELETE')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Specifying Connection
If you have multiple Zoho People connections, specify which one to use with the Maton-Connection header:
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/zoho-people/people/api/forms')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Maton-Connection', '{connection_id}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
If you have multiple connections, always include this header to ensure requests go to the intended account.
Security & Permissions
- Access is scoped to employees, departments, designations, attendance, leave, and any form configured in the connected Zoho People account (including custom forms). The forms API can retrieve or modify records from any form by
formLinkName. - All write operations require explicit user approval. Before executing any create, update, or delete call, confirm the target resource and intended effect with the user.
- HR data is sensitive. Employee records contain personal information (names, emails, addresses, salary, etc.). Only access specific records the user explicitly requests — do not bulk-retrieve employee data without clear justification.
API Reference
Forms Operations
List All Forms
Get a list of all available forms in your Zoho People account.
GET /zoho-people/people/api/forms
Example:
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/zoho-people/people/api/forms')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Response:
{
"response": {
"result": [
{
"componentId": 943596000000035679,
"iscustom": false,
"displayName": "Employee",
"formLinkName": "employee",
"PermissionDetails": {
"Add": 3,
"Edit": 3,
"View": 3
},
"isVisible": true,
"viewDetails": {
"view_Id": 943596000000035705,
"view_Name": "P_EmployeeView"
}
}
],
"message": "Data fetched successfully",
"status": 0
}
}
Employee Operations
List Employees (Bulk Records)
GET /zoho-people/people/api/forms/employee/getRecords?sIndex={startIndex}&limit={limit}
Query Parameters:
| Parameter | Type | Default | Description |
|---|---|---|---|
sIndex | integer | 1 | Starting index (1-based) |
limit | integer | 200 | Number of records (max 200) |
SearchColumn | string | - | EMPLOYEEID or EMPLOYEEMAILALIAS |
SearchValue | string | - | Value to search for |
modifiedtime | long | - | Timestamp in milliseconds for modified records |
Example:
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/zoho-people/people/api/forms/employee/getRecords?sIndex=1&limit=10')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Response:
{
"response": {
"result": [
{
"943596000000294355": [
{
"FirstName": "Christopher",
"LastName": "Brown",
"EmailID": "christopherbrown@zylker.com",
"EmployeeID": "S20",
"Department": "Management",
"Designation": "Administration",
"Employeestatus": "Active",
"Gender": "Male",
"Date_of_birth": "02-Feb-1987",
"Zoho_ID": 943596000000294355
}
]
}
],
"message": "Data fetched successfully",
"status": 0
}
}
List Employees (View-based)
GET /zoho-people/api/forms/{viewName}/records?rec_limit={limit}
Example:
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/zoho-people/api/forms/P_EmployeeView/records?rec_limit=10')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Search Employee by ID
GET /zoho-people/people/api/forms/employee/getRecords?SearchColumn=EMPLOYEEID&SearchValue={employeeId}
Example:
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/zoho-people/people/api/forms/employee/getRecords?SearchColumn=EMPLOYEEID&SearchValue=S20')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Search Employee by Email
GET /zoho-people/people/api/forms/employee/getRecords?SearchColumn=EMPLOYEEMAILALIAS&SearchValue={email}
Department Operations
List Departments
GET /zoho-people/people/api/forms/department/getRecords?sIndex={startIndex}&limit={limit}
Example:
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/zoho-people/people/api/forms/department/getRecords?sIndex=1&limit=50')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Response:
{
"response": {
"result": [
{
"943596000000294315": [
{
"Department": "IT",
"Department_Lead": "",
"Parent_Department": "",
"Zoho_ID": 943596000000294315
}
]
}
],
"message": "Data fetched successfully",
"status": 0
}
}
Designation Operations
List Designations
GET /zoho-people/people/api/forms/designation/getRecords?sIndex={startIndex}&limit={limit}
Example:
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/zoho-people/people/api/forms/designation/getRecords?sIndex=1&limit=50')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Response:
{
"response": {
"result": [
{
"943596000000294399": [
{
"Designation": "Team Member",
"EEO_Category": "Professionals",
"Zoho_ID": 943596000000294399
}
]
}
],
"message": "Data fetched successfully",
"status": 0
}
}
Insert Record
Add a new record to any form.
POST /zoho-people/people/api/forms/json/{formLinkName}/insertRecord
Content-Type: application/x-www-form-urlencoded
inputData={field1:'value1',field2:'value2'}
Example - Create Department:
python <<'EOF'
import urllib.request, os, json
from urllib.parse import urlencode
inputData = json.dumps({"Department": "Engineering"})
data = urlencode({"inputData": inputData}).encode()
req = urllib.request.Request('https://api.maton.ai/zoho-people/people/api/forms/json/department/insertRecord', data=data, method='POST')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Content-Type', 'application/x-www-form-urlencoded')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Response:
{
"response": {
"result": {
"pkId": "943596000000300001",
"message": "Successfully Added"
},
"message": "Data added successfully",
"status": 0
}
}
Update Record
Modify an existing record.
POST /zoho-people/people/api/forms/json/{formLinkName}/updateRecord
Content-Type: application/x-www-form-urlencoded
inputData={field1:'newValue'}&recordId={recordId}
Example - Update Employee:
python <<'EOF'
import urllib.request, os, json
from urllib.parse import urlencode
inputData = json.dumps({"Department": "Engineering"})
data = urlencode({
"inputData": inputData,
"recordId": "943596000000294355"
}).encode()
req = urllib.request.Request('https://api.maton.ai/zoho-people/people/api/forms/json/employee/updateRecord', data=data, method='POST')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Content-Type', 'application/x-www-form-urlencoded')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Leave Operations
List Leave Records
GET /zoho-people/people/api/forms/leave/getRecords?sIndex={startIndex}&limit={limit}
Add Leave
POST /zoho-people/people/api/forms/json/leave/insertRecord
Content-Type: application/x-www-form-urlencoded
inputData={Employee_ID:'EMP001',Leavetype:'123456',From:'01-Feb-2026',To:'02-Feb-2026'}
Attendance Operations
Note: Attendance endpoints require additional OAuth scopes.
Get Attendance Entries
GET /zoho-people/people/api/attendance/getAttendanceEntries?date={date}&dateFormat={format}
Parameters:
| Parameter | Type | Description |
|---|---|---|
date | string | Date in organization format |
dateFormat | string | Date format (e.g., dd-MMM-yyyy) |
empId | string | Employee ID (optional) |
emailId | string | Employee email (optional) |
Check-In/Check-Out
POST /zoho-people/people/api/attendance
Content-Type: application/x-www-form-urlencoded
dateFormat=dd/MM/yyyy HH:mm:ss&checkIn={datetime}&checkOut={datetime}&empId={empId}
Common Form Link Names
| Form | formLinkName | Description |
|---|---|---|
| Employee | employee | Employee records |
| Department | department | Departments |
| Designation | designation | Job titles |
| Leave | leave | Leave requests |
| Clients | P_ClientDetails | Client information |
Pagination
Zoho People uses index-based pagination:
GET /zoho-people/people/api/forms/{formLinkName}/getRecords?sIndex=1&limit=200
sIndex: Starting index (1-based)limit: Number of records per request (max 200)
For subsequent pages:
- Page 1:
sIndex=1&limit=200 - Page 2:
sIndex=201&limit=200 - Page 3:
sIndex=401&limit=200
Code Examples
JavaScript
const response = await fetch(
'https://api.maton.ai/zoho-people/people/api/forms/employee/getRecords?sIndex=1&limit=10',
{
headers: {
'Authorization': `Bearer ${process.env.MATON_API_KEY}`
}
}
);
const data = await response.json();
Python
import os
import requests
response = requests.get(
'https://api.maton.ai/zoho-people/people/api/forms/employee/getRecords',
headers={'Authorization': f'Bearer {os.environ["MATON_API_KEY"]}'},
params={'sIndex': 1, 'limit': 10}
)
data = response.json()
Notes
- Record IDs are numeric strings (e.g.,
943596000000294355) - The
Zoho_IDfield in responses contains the record ID - Maximum 200 records per GET request
- Insert/Update operations use form-urlencoded data with
inputDataJSON - Date format varies by field and organization settings
- Some endpoints (attendance, leave) require additional OAuth scopes. If you receive an
INVALID_OAUTHSCOPEerror, contact Maton support at support@maton.ai with the specific operations/APIs you need and your use-case - Response structure wraps data in
response.result[]array - IMPORTANT: When using curl commands, use
curl -gwhen URLs contain special characters - IMPORTANT: When piping curl output to
jqor other commands, environment variables like$MATON_API_KEYmay not expand correctly in some shell environments
Error Handling
| Status | Meaning |
|---|---|
| 400 | Missing Zoho People connection or invalid request |
| 401 | Invalid or missing Maton API key, or invalid OAuth scope |
| 429 | Rate limited |
| 4xx/5xx | Passthrough error from Zoho People API |
Common Error Codes
| Code | Description |
|---|---|
| 7011 | Invalid form name |
| 7012 | Invalid view name |
| 7021 | Maximum record limit exceeded (200) |
| 7024 | No records found |
| 7042 | Invalid search value |
| 7218 | Invalid OAuth scope |
Troubleshooting: API Key Issues
- Check that the
MATON_API_KEYenvironment variable is set:
echo $MATON_API_KEY
- Verify the API key is valid by listing connections:
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/connections')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF
Troubleshooting: Invalid App Name
- Ensure your URL path starts with
zoho-people. For example:
- Correct:
https://api.maton.ai/zoho-people/people/api/forms - Incorrect:
https://api.maton.ai/people/api/forms
Resources
常见问题
- OAuth 如何处理?
- 由 Maton 平台托管 OAuth 流程:调用创建连接接口后,用返回的 URL 在浏览器中完成授权,Maton 会自动向 people.zoho.com 注入访问令牌,无需自行管理 token 刷新。
- 能读写哪些数据?
- 可读取和修改员工、部门、职级、休假以及 Zoho People 账户中配置的任何表单记录,自定义表单也在范围内,按 formLinkName 定位具体表单。
- 写操作是否需要用户授权?
- 需要。新增、更新、删除等写操作在执行前都必须得到用户明确确认,因为 HR 记录通常包含姓名、邮箱、薪资等敏感个人信息。
相关技能
通过 OAuth 代理调用 Zoho Mail REST API,管理账户、文件夹、标签以及邮件收发。
通过 Maton 托管的 OAuth 代理读写 Zoho CRM 记录,所有写入操作均需用户确认。
通过托管 OAuth 网关读写 Zoho 日历的日历与事件。
通过 Maton API 代理,使用托管 OAuth 管理 Zoho Bookings 的预约、服务、员工和工作区。
通过托管 OAuth 网关读写 Zoho Projects 资源,所有写操作执行前需用户确认。