Zoho CRM's API v8 lives at https://www.zohoapis.com/crm/v8 (.eu, .in, .com.au for other data centers). Reading records requires a fields parameter.
Zoho uses OAuth. For testing, create a Self Client in the Zoho API Console and generate a token with CRM scopes. Send it as Authorization: Zoho-oauthtoken <token> — not Bearer. In the examples it's written {{ZOHO_ACCESS_TOKEN}}.
Full reference: https://www.zoho.com/crm/developer/docs/api/v8/
curl "https://www.zohoapis.com/crm/v8/Leads?fields=Last_Name,Email,Company&per_page=10" \
-H "Authorization: Zoho-oauthtoken {{ZOHO_ACCESS_TOKEN}}"
curl "https://www.zohoapis.com/crm/v8/Contacts/search?email=jenny%40example.com" \
-H "Authorization: Zoho-oauthtoken {{ZOHO_ACCESS_TOKEN}}"
curl -X POST https://www.zohoapis.com/crm/v8/Leads \
-H "Authorization: Zoho-oauthtoken {{ZOHO_ACCESS_TOKEN}}" \
-H "Content-Type: application/json" \
-d '{"data": [{"Last_Name": "Rosen", "First_Name": "Jenny", "Company": "PostTaco", "Email": "[email protected]"}]}'