{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "aurinko-email",
    "name": "Aurinko Email API",
    "vendor": "Yoxel, Inc.",
    "vendorUrl": "https://www.aurinko.io",
    "kind": "http-api",
    "category": "mailbox-access",
    "summary": "Unified email REST API from Yoxel, Inc. It reads, searches, drafts and sends mail in a user's own mailbox on Gmail, Office 365, Outlook.com, Exchange, Zoho Mail, iCloud and IMAP, with delta sync, open and reply tracking and webhooks.",
    "url": "https://www.anchorterminal.com/tools/aurinko-email",
    "markdownUrl": "https://www.anchorterminal.com/tools/aurinko-email.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/aurinko-email.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/aurinko-email.json",
    "license": "Proprietary service under Yoxel's Terms of Services Agreement",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.aurinko.io",
    "packages": [],
    "auth": "oauth",
    "authNotes": "Self-serve. A developer signs up at app.aurinko.io and gets a client ID and secret for each application. Each mailbox owner connects through Aurinko's OAuth flow at `/v1/auth/authorize`, and the resulting account access token is sent as a Bearer token. Mail scopes are `Mail.Read`, `Mail.ReadWrite`, `Mail.Send` and `Mail.Drafts`. IMAP, iCloud and Exchange accounts connect with a password or app password. Gmail access needs the developer's own Google OAuth app, since Aurinko's default registration excludes Google email, and production Office 365 needs an Azure registration.",
    "pricing": "paid",
    "pricingNotes": "$1.50 an active account a month for Email (non-IMAP) with up to 1 GB of traffic, and $2 for any number of APIs including IMAP with unlimited traffic, per the billing FAQ. A 14-day trial gives full API access, and requests are blocked when it ends without a card on file. No free tier or sandbox beyond the trial (https://docs.aurinko.io/faq/how-does-aurinko-billing-work).",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs, the OpenAPI description or the pricing page (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://docs.aurinko.io/unified-apis/email-api",
    "llmsTxt": "https://docs.aurinko.io/llms.txt",
    "openapi": "https://apirefs.aurinko.io/assets/swagger.json",
    "capabilities": [
      "mailbox.read",
      "mailbox.search",
      "mailbox.send",
      "mailbox.drafts",
      "mailbox.sync",
      "email.threads"
    ],
    "tags": [
      "hosted",
      "oauth",
      "openapi",
      "llms-txt",
      "webhooks",
      "closed-source",
      "free-trial"
    ],
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 44.2,
      "grade": "E",
      "agentReady": false,
      "rank": 878,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 9,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 49,
        "maintenance": 13,
        "payments": 40,
        "reliability": 40,
        "schema": 67,
        "security": 42,
        "transparency": 44
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 40,
          "points": 8,
          "reason": "Graded as a hosted API. No status page is linked from the home page, the docs index or the description file (0). With no readable incident history the record scores 5. The description file gives a limit of 250 requests a second (15). It advises exponential backoff on 429 and 5xx and a retry on 408, and declares a `Retry-After` header only on the 408 of the get-message call. Sending takes no idempotency key (10). No SLA found, and the terms supply the service as is (0). The API is at `/v1` with no beta label (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 67,
          "points": 10.89,
          "reason": "Public OpenAPI 3.0.0 description with 154 operations, 43 of them for email, read once from the file the reference page loads (25). `llms.txt` and a Markdown copy of every docs page (10). Every email operation has a summary but only 2 of 43 have a description. 61 of 85 parameters are described, and the guide has a table of 17 search operators with provider caveats (9). The scope list and `responseType` are enums, with few required fields marked (8). 34 of 43 email operations carry a cURL sample and the Errors section shows the JSON body, while operations declare little beyond 401 and a default response (10). `/v1` in the path and version 1.0.0, with no changelog found (5)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 49,
          "points": 7.96,
          "reason": "Graded on the REST API. `bodyType`, `stripQuoted` and `returnIds` shape responses, but message lists take no field selection and no page-size parameter (10). `pageToken` on lists, `q` search with 17 operators, a per-folder list, and delta tokens for updated and deleted mail (15). Errors carry `code`, `message`, `requestId` and the provider's `originalError`, with retry advice per status (14). No idempotency key on send, reply or draft send. Reads and delta sync are safe to repeat, and delete moves a message to Trash (4). Few required parameters, but no official SDK was found (6)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 42,
          "points": 7.35,
          "reason": "Per-user OAuth with four mail scopes and `DELETE /v1/account/token` to revoke a token and the provider grant. The application's client ID and secret, sent as Basic auth with `X-Aurinko-Account-Id`, reach every connected account. The implicit grant is still supported though not recommended, returning the token in a URL fragment, and IMAP accounts give Aurinko a mailbox or app password (22). `Mail.Read` allows no writes and `Mail.Send` no reads, with no confirmation step for sends or deletes (13). Mail from third parties is returned with no injection guidance (0). No operator audit or request log found in the docs. Portal roles are documented (0). A security statement with a reporting address, security@yoxel.com, and penetration tests claimed. SOC 2 is not yet held, with no bug bounty and no security.txt (7)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 (0). Prices per active account a month published without login, $1.50 for email and $2 for all APIs, though the pricing page and the billing FAQ define the tiers differently (20). A 14-day trial, with a card asked for only when it ends (20). Signup is in a browser at app.aurinko.io, and each mailbox needs its owner's consent or password (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 13,
          "points": 1.14,
          "reason": "No changelog or release notes found, so no API change can be dated. The docs sitemap dates the IMAP connection guide 22 September 2026 and the Email API guide 18 August 2026, counted as partial evidence of activity and not as a release (10). No dated changelog entries (0). Support is by email, with no public forum or issue tracker linked (3). No official SDK named in the docs (0). No public package or repository is linked from the pages read (0)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 44,
          "points": 3.85,
          "note": "editorial 27, provenance 60",
          "reason": "Closed service under a Terms of Services Agreement naming Yoxel, Inc. of California, last updated 11 August 2022 (15). The docs say message contents are passed through and never stored, with only IDs and thread relations cached, and the privacy policy commits to Google's Limited Use requirements. The policy gives no retention period, and no DPA was found (12). No deprecation policy or dated notices found (0). No sub-processor list or data location. The security statement names no cloud provider (0)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Graded on the REST API. `bodyType`, `stripQuoted` and `returnIds` shape responses, but message lists take no field selection and no page-size parameter (10). `pageToken` on lists, `q` search with 17 operators, a per-folder list, and delta tokens for updated and deleted mail (15). Errors carry `code`, `message`, `requestId` and the provider's `originalError`, with retry advice per status (14). No idempotency key on send, reply or draft send. Reads and delta sync are safe to repeat, and delete moves a message to Trash (4). Few required parameters, but no official SDK was found (6).",
          "maintenance": "No changelog or release notes found, so no API change can be dated. The docs sitemap dates the IMAP connection guide 22 September 2026 and the Email API guide 18 August 2026, counted as partial evidence of activity and not as a release (10). No dated changelog entries (0). Support is by email, with no public forum or issue tracker linked (3). No official SDK named in the docs (0). No public package or repository is linked from the pages read (0).",
          "payments": "No x402, MPP or L402 (0). Prices per active account a month published without login, $1.50 for email and $2 for all APIs, though the pricing page and the billing FAQ define the tiers differently (20). A 14-day trial, with a card asked for only when it ends (20). Signup is in a browser at app.aurinko.io, and each mailbox needs its owner's consent or password (0).",
          "reliability": "Graded as a hosted API. No status page is linked from the home page, the docs index or the description file (0). With no readable incident history the record scores 5. The description file gives a limit of 250 requests a second (15). It advises exponential backoff on 429 and 5xx and a retry on 408, and declares a `Retry-After` header only on the 408 of the get-message call. Sending takes no idempotency key (10). No SLA found, and the terms supply the service as is (0). The API is at `/v1` with no beta label (10).",
          "schema": "Public OpenAPI 3.0.0 description with 154 operations, 43 of them for email, read once from the file the reference page loads (25). `llms.txt` and a Markdown copy of every docs page (10). Every email operation has a summary but only 2 of 43 have a description. 61 of 85 parameters are described, and the guide has a table of 17 search operators with provider caveats (9). The scope list and `responseType` are enums, with few required fields marked (8). 34 of 43 email operations carry a cURL sample and the Errors section shows the JSON body, while operations declare little beyond 401 and a default response (10). `/v1` in the path and version 1.0.0, with no changelog found (5).",
          "security": "Per-user OAuth with four mail scopes and `DELETE /v1/account/token` to revoke a token and the provider grant. The application's client ID and secret, sent as Basic auth with `X-Aurinko-Account-Id`, reach every connected account. The implicit grant is still supported though not recommended, returning the token in a URL fragment, and IMAP accounts give Aurinko a mailbox or app password (22). `Mail.Read` allows no writes and `Mail.Send` no reads, with no confirmation step for sends or deletes (13). Mail from third parties is returned with no injection guidance (0). No operator audit or request log found in the docs. Portal roles are documented (0). A security statement with a reporting address, security@yoxel.com, and penetration tests claimed. SOC 2 is not yet held, with no bug bounty and no security.txt (7).",
          "transparency": "Closed service under a Terms of Services Agreement naming Yoxel, Inc. of California, last updated 11 August 2022 (15). The docs say message contents are passed through and never stored, with only IDs and thread relations cached, and the privacy policy commits to Google's Limited Use requirements. The policy gives no retention period, and no DPA was found (12). No deprecation policy or dated notices found (0). No sub-processor list or data location. The security statement names no cloud provider (0)."
        },
        "sources": [
          {
            "what": "OpenAPI description file the reference page loads (read in place of the rendered page), errors and rate limits",
            "url": "https://apirefs.aurinko.io/assets/swagger.json",
            "seen": "2026-10-09"
          },
          {
            "what": "API reference page, a Redoc viewer over the description file",
            "url": "https://apirefs.aurinko.io/",
            "seen": "2026-10-09"
          },
          {
            "what": "docs index for agents",
            "url": "https://docs.aurinko.io/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "Email API guide, sync, tracking and search operators",
            "url": "https://docs.aurinko.io/unified-apis/email-api.md",
            "seen": "2026-10-09"
          },
          {
            "what": "data handling statement",
            "url": "https://docs.aurinko.io/getting-started/readme.md",
            "seen": "2026-10-09"
          },
          {
            "what": "authentication scopes",
            "url": "https://docs.aurinko.io/authentication/authentication-scopes.md",
            "seen": "2026-10-09"
          },
          {
            "what": "account OAuth flow",
            "url": "https://docs.aurinko.io/authentication/oauth-flow/account-oauth-flow.md",
            "seen": "2026-10-09"
          },
          {
            "what": "IMAP connections and passwords",
            "url": "https://docs.aurinko.io/authentication/configuring-imap-provider-connections-in-aurinko.md",
            "seen": "2026-10-09"
          },
          {
            "what": "webhooks",
            "url": "https://docs.aurinko.io/unified-apis/webhooks-api.md",
            "seen": "2026-10-09"
          },
          {
            "what": "webhook signature validation",
            "url": "https://docs.aurinko.io/unified-apis/webhooks-api/authentication.md",
            "seen": "2026-10-09"
          },
          {
            "what": "billing FAQ and price tiers",
            "url": "https://docs.aurinko.io/faq/how-does-aurinko-billing-work.md",
            "seen": "2026-10-09"
          },
          {
            "what": "trial and subscription",
            "url": "https://docs.aurinko.io/getting-started/subscribe-to-aurinko.md",
            "seen": "2026-10-09"
          },
          {
            "what": "developer keys and test accounts",
            "url": "https://docs.aurinko.io/getting-started/get-your-developer-api-keys.md",
            "seen": "2026-10-09"
          },
          {
            "what": "shared Google OAuth app FAQ",
            "url": "https://docs.aurinko.io/faq/does-aurinko-provide-a-shared-verified-google-oauth-application.md",
            "seen": "2026-10-09"
          },
          {
            "what": "portal team roles",
            "url": "https://docs.aurinko.io/team-members-and-roles-in-applications.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Direct API pass-through",
            "url": "https://docs.aurinko.io/unified-apis/direct-api.md",
            "seen": "2026-10-09"
          },
          {
            "what": "docs sitemap with page dates",
            "url": "https://docs.aurinko.io/sitemap-pages.xml",
            "seen": "2026-10-09"
          },
          {
            "what": "Email API product page",
            "url": "https://www.aurinko.io/email-api/",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing page",
            "url": "https://www.aurinko.io/pricing/",
            "seen": "2026-10-09"
          },
          {
            "what": "terms of services agreement",
            "url": "https://www.aurinko.io/terms/",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy",
            "url": "https://www.aurinko.io/privacy/",
            "seen": "2026-10-09"
          },
          {
            "what": "security statement",
            "url": "https://www.aurinko.io/certifications/",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt, 404",
            "url": "https://www.aurinko.io/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "robots.txt, one User-agent line and no rules",
            "url": "https://www.aurinko.io/robots.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "robots.txt, allows all with ai-input=yes",
            "url": "https://docs.aurinko.io/robots.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "robots.txt, 404",
            "url": "https://apirefs.aurinko.io/robots.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.identitydigital.services/rdap/domain/aurinko.io",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: whether a status page exists under an address the site does not link. None is linked from the home page, the docs index or the description file",
          "unchecked: the portal at app.aurinko.io behind login, so key rotation, team roles in practice, any request log and whether the trial asks for a card at signup were not seen",
          "unchecked: the vendor's GitHub organisation and any npm package. No page read links either, so no SDK, repository or download figure is recorded",
          "unchecked: the Follow-up Rules API guide, the Gmail Pub/Sub guide and the Google and Office 365 OAuth setup guides, which were not read",
          "The terms forbid robots, data mining and similar data extraction or gathering methods in connection with the Services. Recorded as a fact with no deduction. It matters before any probe is run",
          "Whether the SOC 2 Type I examination targeted for Q3 2026 has been completed. The security statement was last updated 18 June 2026",
          "Which of the two published descriptions of the $1.50 tier applies, and whether an email-only customer on IMAP pays $2",
          "Whether 429 responses carry a Retry-After header, and what page size message lists return. The description file does not say",
          "Maintenance is 13 here and 20 on aurinko-calendar. This dossier counts docs page dates as 10 for recency and records no repository, because none is linked"
        ]
      },
      "negative": 0,
      "verdict": "One REST interface covers message search with 17 query operators, drafts, sending, folders and delta sync across seven mailbox types, at $1.50 an active account a month and with send-only and read-only scopes. No status page, SLA, changelog, idempotency key on send or official SDK was found, and SOC 2 is not yet held.",
      "bestFor": "A product that connects many users' Gmail and Microsoft mailboxes and wants one schema, delta sync, tracking and webhooks at a low price per account.",
      "strengths": [
        "Public OpenAPI 3.0 description at `apirefs.aurinko.io/assets/swagger.json`, with 43 email operations, 34 of them carrying a cURL sample",
        "Four mail scopes. `Mail.Read` allows no writes, `Mail.Send` allows sending with no read access, and `Mail.ReadWrite` excludes send",
        "The `q` parameter takes 17 search operators, with a table in the docs saying where IMAP and Exchange support is partial",
        "Prices published per active account a month ($1.50 for email, $2 for all APIs with IMAP), with a 14-day trial",
        "Docs state that message contents are passed through and never stored, with only IDs and thread relations cached for sync"
      ],
      "weaknesses": [
        "No status page, incident history or SLA found, and the terms supply the service as is",
        "No idempotency key on `POST /v1/email/messages`, so a retried send can deliver twice",
        "No changelog, deprecation policy or official SDK found in the docs or on the site",
        "The application's client ID and secret, sent as Basic auth, reach every connected mailbox, and IMAP accounts hand Aurinko a mailbox password",
        "The terms of 11 August 2022 forbid robots and data extraction methods in connection with the Services. This matters before any probe is run"
      ],
      "agentNotes": [
        "Use `https://api.aurinko.io/v1`. Several cURL examples in the docs print `https:/api.aurinko.io` with one slash, and one search example names the host `asti.aurinko.io`",
        "Do not retry `POST /v1/email/messages` blindly after a timeout. There is no idempotency key, so check Sent mail with `q=rfc822msgid:` or by subject first",
        "Call `POST /v1/email/sync` until `ready` is true, then page `/v1/email/sync/updated` with `pageToken` until a `nextDeltaToken` appears and store it",
        "Check the `omitted` array on message lists. Full bodies come only from Google and Office 365, and other providers return a snippet",
        "Request `Mail.Read` plus `Mail.Send` for read and send without modify rights. The docs example names `Mail.ReadOnly`, which is not in the scope list"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "E",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 44.2
        }
      ],
      "editorialScores": {
        "ergonomics": 49,
        "maintenance": 13,
        "payments": 40,
        "reliability": 40,
        "schema": 67,
        "security": 42,
        "transparency": 27
      },
      "provenanceScore": 60
    },
    "connect": {
      "http": "curl -H 'Authorization: Bearer \u003caccess_token\u003e' \\\n  -G https://api.aurinko.io/v1/email/messages \\\n  -d q='from:alexey'"
    },
    "letme": {
      "capability": "https://letme.dev/mailbox.read",
      "tool": "https://letme.dev/aurinko-email"
    },
    "sameCompany": [
      "aurinko-calendar"
    ],
    "notable": [
      "The description file is OpenAPI 3.0.0, titled Aurinko.io API 1.0.0, with 112 paths and 154 operations, 43 of them in the Email group (Messages 10, EmailTracking 10, FollowUpRobot 9, EmailFolders 6, Drafts 5, EmailSync 3) (https://apirefs.aurinko.io/assets/swagger.json)",
      "The billing FAQ prices Email (non-IMAP) at $1.50 an active account a month up to 1 GB of traffic, and puts IMAP in the $2 Full Platform tier. An account is active above 10 API calls or 1 MB in a billing month (https://docs.aurinko.io/faq/how-does-aurinko-billing-work)",
      "The pricing page describes the same three prices by data transfer alone, $1 under 1 GB, $1.50 under 5 GB and $2 unlimited, which differs from the FAQ (https://www.aurinko.io/pricing/)",
      "The docs describe the API as mainly a pass-through that caches IDs and thread-message relations and never stores the contents of emails (https://docs.aurinko.io/getting-started/readme)",
      "Until a developer registers their own Google OAuth app, Aurinko's default registration is used with limited permissions and Google email is not available. Aurinko says it chooses not to run a shared verified Google app (https://docs.aurinko.io/getting-started/get-your-developer-api-keys)",
      "Sending accepts a `tracking` object for opens and thread replies, with a tracking pixel on Aurinko's domain or a custom alias, and `/email/tracking` is a webhook resource (https://docs.aurinko.io/unified-apis/email-api)",
      "The security statement, last updated 18 June 2026, says Yoxel is preparing for a SOC 2 Type I examination targeted for Q3 2026 with Secureframe, and takes vulnerability reports at security@yoxel.com (https://www.aurinko.io/certifications/)",
      "The Terms of Services Agreement says users may not use any robots, data mining, or similar data extraction or gathering methods in connection with the Services (https://www.aurinko.io/terms/)"
    ],
    "area": "communication",
    "details": [
      {
        "label": "Surface graded",
        "value": "The REST API at https://api.aurinko.io/v1. No MCP server was found in the docs or on the site"
      },
      {
        "label": "Providers",
        "value": "Gmail, Office 365, Outlook.com, MS Exchange, Zoho Mail, iCloud and IMAP per the Email API guide. The product page also names Yahoo"
      },
      {
        "label": "Email endpoints",
        "value": "`/v1/email/messages` (list, send, get, raw, delete to Trash, status, reply, attachments), `/v1/email/conversations/{threadId}`, `/v1/email/drafts` (create, update, get, delete, send with `sendTime`), `/v1/email/folders` and `/v1/email/sync`"
      },
      {
        "label": "Search",
        "value": "`q` on message lists with 17 operators, among them `from:`, `to:`, `subject:`, `after:`, `before:`, `has:`, `is:`, `label:` (Gmail only) and `rfc822msgid:`. Date operators are partly supported on IMAP and Exchange"
      },
      {
        "label": "Sync",
        "value": "`POST /v1/email/sync` with `daysWithin`, then `/v1/email/sync/updated` and `/v1/email/sync/deleted` with `deltaToken` and `pageToken`. A 410 response is declared on both delta calls"
      },
      {
        "label": "Tracking and follow-ups",
        "value": "Open and reply tracking on sent mail, 10 operations under `/v1/email/tracking` and `/v1/email/draftTracking`, and 9 follow-up rule operations under `/v1/followup`"
      },
      {
        "label": "Credentials",
        "value": "Account access token (Bearer) from the OAuth flow, client ID and secret (Basic) for application-level calls, or a user session in `X-Aurinko-Session` or a cookie. IMAP accounts connect with an app password or the mailbox password"
      },
      {
        "label": "Scopes",
        "value": "`Mail.Read`, `Mail.ReadWrite` (no send), `Mail.Send` (send only), `Mail.Drafts`, and `Mail.All` in the description file only, beside six calendar, contacts and tasks scopes"
      },
      {
        "label": "Rate limits",
        "value": "250 requests a second for API calls, per the description file. Provider limits behind the API can also return 429"
      },
      {
        "label": "Errors",
        "value": "JSON body with `code`, `message`, `requestId` and the provider's `originalError`. The description file advises exponential backoff on 429 and 5xx, a retry on 408, and no retry on 404"
      },
      {
        "label": "Webhooks",
        "value": "`POST /v1/subscriptions` with resource `/email/messages` or `/email/tracking`, signed with HMAC SHA256 over `v0:{timestamp}:{raw_body}` in `X-Aurinko-Signature`. Gmail push needs the developer's own Google Pub/Sub setup"
      },
      {
        "label": "Trial",
        "value": "14 days with full API access. API requests are blocked at expiry until a card is added in the portal"
      },
      {
        "label": "SDKs",
        "value": "No official SDK is named in the docs or on the site"
      },
      {
        "label": "Security statement",
        "value": "TLS in transit and AES-256 at rest, MFA and role-based access, third-party penetration tests, SOC 2 Type I targeted for Q3 2026 (statement of 18 June 2026)"
      }
    ],
    "unitPrices": [
      {
        "item": "Email API (non-IMAP)",
        "unit": "account-month",
        "usd": 1.5,
        "note": "Per active account, up to 1 GB of traffic a month"
      },
      {
        "item": "Full platform, any number of APIs including IMAP",
        "unit": "account-month",
        "usd": 2,
        "note": "Per active account, unlimited traffic"
      }
    ],
    "provenance": {
      "legalEntity": "Yoxel, Inc.",
      "domain": "aurinko.io",
      "domainRegistered": "2019-05-08",
      "endpointOnVendorDomain": true,
      "terms": "https://www.aurinko.io/terms/",
      "privacy": "https://www.aurinko.io/privacy/",
      "statusPage": "",
      "changelog": "",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The Terms of Services Agreement, last updated 11 August 2022, names Yoxel, Inc., organised under the laws of California, and covers the API and the workspace integrations platform. Disputes go to binding arbitration under JAMS rules in San Francisco, with a 30-day opt-out.",
        "The privacy policy, last updated 11 August 2022, covers the site and the services, API included, and commits to Google's API Services User Data Policy and its Limited Use requirements.",
        "The terms forbid robots, data mining and similar data extraction or gathering methods in connection with the Services. We read a handful of public pages and sent nothing to the API host.",
        "The API answers at api.aurinko.io per the description file, with the portal at app.aurinko.io and the reference at apirefs.aurinko.io, all on the vendor's domain.",
        "www.aurinko.io/.well-known/security.txt returns 404. The security statement gives security@yoxel.com for reports.",
        "No status page or changelog is linked from the home page, the docs index or the description file.",
        "robots.txt on www.aurinko.io has one `User-agent: *` line and no rules. On docs.aurinko.io it allows every path with `Content-Signal: ai-input=yes`. apirefs.aurinko.io answered 404 for robots.txt, read as no rules.",
        "RDAP for aurinko.io gives a registration date of 2019-05-08."
      ],
      "score": 60,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Yoxel, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "aurinko.io, registered 2019-05-08 (7 years)",
          "points": 11,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.aurinko.io",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.aurinko.io/terms/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2022-08-11",
          "words": 6042,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: Aug 11, 2022",
              "says": "Last updated 2022-08-11"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "The Yoxel Site and Services are provided by, and you’re contracting with: Yoxel that is organized under the laws of the State of California, USA.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "Under no circumstances will Yoxel be responsible or liable to you for any indirect, punitive, incidental, special, consequential, or exemplary damages resulting from your use or inability to use the Services or for the unavailability of the Services, for lost profits, personal injury, or property damage, or for any ot…",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Until you have submitted, and we have reviewed and approved, all Required Information, your Yoxel Account will be available to you on a preliminary basis only, and we may terminate it at any time and for any reason."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "If you are an existing user of our Services, the material changes to this Agreement will come into effect 10 days after we provide you with the Notice.",
              "says": "Gives 10 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You may not access or use our Services or Site unless you agree to abide by all the terms and conditions set in this Agreement."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "…re-publish, license, reverse engineer, or create derivative works from Service Materials, nor use any robots, data mining, or similar data extraction or gathering methods in connection with our Services.",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "use the Services and the Site in any manner to compete with Yoxel.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may terminate this Agreement or close your Yoxel Account at any time for any reason (including, without limitation, for any activity that may create harm or loss to the goodwill of a Payment Method) by providing you Notice."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "IMPORTANT NOTICE REGARDING ARBITRATION: WHEN YOU AGREE TO THIS AGREEMENT YOU ARE AGREEING (WITH LIMITED EXCEPTION) TO RESOLVE ANY DISPUTE BETWEEN YOU AND YOXEL THROUGH BINDING ARBITRATION RATHER THAN IN COURT."
            },
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "Last Updated: Aug 11, 2022"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Liability not otherwise disclaimed is capped at the fees paid in the three months before the event behind the claim.",
              "quote": "you further agree that under no circumstances will any such liability exceed in the aggregate the amount of Fees paid by you to Yoxel during the three-month period immediately preceding the event that gave rise to your claim for damages."
            },
            {
              "date": "2026-10-08",
              "text": "On monthly plans Yoxel may change the fees at any time, and a customer who does not accept the new fees is told to cancel.",
              "quote": "We reserve the right to change the Fees at any time. If you do not accept the new Fees, you should cancel your subscription."
            },
            {
              "date": "2026-10-08",
              "text": "On termination Yoxel may delete all of the customer’s stored information but is not obliged to.",
              "quote": "we reserve the right (but have no obligation) to delete all of your information stored on our servers;"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.aurinko.io/privacy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2022-08-11",
          "words": 3325,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: Aug 11, 2022",
              "says": "Last updated 2022-08-11"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We are committed to respecting the privacy and security of the personal information we collect."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "To determine how long we keep personal information we consider the amount, nature and sensitivity of personal information, the reasons for which we collect and process the information and applicable legal requirements."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Collected Indirectly: We and our authorized third-party service providers collect certain information by automated means using cookies and other tracking technologies."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Business Transfers: We may also share personal information with third parties whom we choose to acquire, or to whom we choose to sell, transfer, or merge parts of our business or our assets."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "This Privacy Policy («Privacy Policy») provides important information about our use of personal information and informs you of your rights."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have any questions about this Privacy Policy or our privacy practices, please contact us by email at: compliance@yoxel.com.",
              "says": "compliance@yoxel.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "Last Updated: Aug 11, 2022"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Personal information is shared with the third parties whose APIs are integrated, and the policy says they may use it for their own purposes.",
              "quote": "These third parties may use your personal information to operate their services and for their own purposes."
            },
            {
              "date": "2026-10-08",
              "text": "Use and transfer of personal information received from Google Accounts is stated to follow the Google API Services User Data Policy, including its Limited Use requirements.",
              "quote": "Our use and transfer to any other app of personal information received from Google Accounts will adhere to Google API Services User Data Policy"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/aurinko-email.json",
    "live": {
      "slug": "aurinko-email",
      "probe": {
        "target": "https://api.aurinko.io",
        "method": "get",
        "lastAt": "2026-10-10T01:37:43.835229901Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 236,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 120,
        "p95ms24h": 287,
        "samples24h": 102,
        "samples30d": 102,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 17,
            "ok": 17
          }
        ]
      },
      "updatedAt": "2026-10-10T01:37:43.835229901Z"
    }
  }
}
