Signatoro for Zoho Mail: admin guide
What the Signatoro install for Zoho Mail can access, what it writes, how it stores Zoho tokens, and how a person or an admin stops it.
This page is for whoever looks after Zoho Mail at a company where people install their signature with Signatoro. The steps for the person installing are in How to add a signature in Zoho Mail.
What the install does
Each person connects their own Zoho Mail from their Signatoro signature page, with "Install into my Zoho Mail", and approves access on Zoho's consent screen. Signatoro then:
- Reads the person's Zoho Mail account to find the address they send from.
- Adds a signature named "Signatoro" to their Zoho Mail settings.
- Sets it for new emails from that address, placed above the quoted text in replies.
After that, each change the person saves in Signatoro is written to the same signature in Zoho Mail. Signatoro updates the signature it created, found by its id, and leaves every other signature in the mailbox as it is.
Permissions Signatoro asks for
The Zoho consent screen lists three permissions:
| Zoho scope | Shown by Zoho as | What Signatoro uses it for |
|---|---|---|
ZohoMail.accounts.READ | View mail account related information | Finding the address the person sends from |
ZohoMail.accounts.CREATE | Create mail account | Adding the "Signatoro" signature. Zoho's add signature API requires this scope. |
ZohoMail.accounts.UPDATE | Update mail account related information | Updating that signature and setting it for new emails |
Signatoro calls only the account and signature endpoints of the Zoho Mail API, for the person who connected.
What Signatoro stores
For each connected person, Signatoro keeps:
- the address the signature is set for, and the Zoho data center of the account
- the refresh token from Zoho, encrypted with AES-256-GCM under a key used only for Zoho tokens
- the current access token, encrypted the same way, until it expires within the hour
- the id of the signature it created, and when it last wrote it
When Signatoro writes to Zoho Mail
- When the person saves their signature in Signatoro.
- Once an hour, a check writes any change that has not reached Zoho Mail yet, and retries a write that failed.
If Zoho stops accepting the token, Signatoro stops writing and asks the person to reconnect on their signature page.
How to stop it
The person clicks "Disconnect" on their Signatoro signature page. Signatoro revokes the token at Zoho and deletes what it stored. The signature stays in Zoho Mail as it is.
In Zoho, the person signs in at accounts.zoho.com, opens "Sessions", scrolls to "Connected Apps", hovers over Signatoro and clicks "Revoke Access". At its next write Signatoro finds the access revoked, shows "Reconnect" on their signature page and writes nothing more. Zoho's help covers this in Sessions.
To remove the signature itself, delete "Signatoro" in Zoho Mail under Settings > Signatures.
Questions
Write to support, or read the FAQ.
Sources
Checked against Zoho's own pages on 2026-09-29:
Was this page helpful?
Make your signature first
It is free and needs no account. Build it once, then paste it into any mail app with the steps on this page.
Make my signature