{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "nylas-email",
    "name": "Nylas Email API",
    "vendor": "Nylas",
    "vendorUrl": "https://www.nylas.com",
    "kind": "http-api",
    "category": "mailbox-access",
    "summary": "Unified email API from Nylas for reading, searching, drafting and sending mail in a person's existing Gmail, Microsoft 365, Exchange, Yahoo, iCloud or IMAP mailbox, with webhooks for new mail. A hosted MCP server exposes the same data.",
    "url": "https://www.anchorterminal.com/tools/nylas-email",
    "markdownUrl": "https://www.anchorterminal.com/tools/nylas-email.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/nylas-email.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/nylas-email.json",
    "repo": "https://github.com/nylas/nylas-nodejs",
    "license": "Proprietary service under Nylas's terms. The SDKs are MIT",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://api.us.nylas.com/v3",
    "packages": [
      {
        "registry": "npm",
        "name": "nylas"
      },
      {
        "registry": "pypi",
        "name": "nylas"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. Sign in to the Dashboard or run `nylas init` (Google, Microsoft or GitHub SSO in a browser), then create an API key and send it as a Bearer token. Each mailbox is a grant, created when its owner completes Nylas hosted OAuth, and addressed as /v3/grants/\u003cgrant_id\u003e. Production Google and Microsoft connections need the integrator's own OAuth app as a connector. The application API key reaches every grant. IAM API keys, created in the Dashboard, are limited to one grant, workspace or application and to chosen permissions. The hosted MCP takes either key in the `Authorization` header.",
    "pricing": "freemium",
    "pricingNotes": "Free $0 with 5 email and calendar connected accounts and no card, so an agent's operator can start without a contract. Essentials $15 a month with 10 accounts, then $2.25 each. Pro $49 a month, or $43 billed annually, with 25 accounts, then $2.00 or $1.75 each. Enterprise is custom with volume bands, a HIPAA BAA and an uptime SLA. No per-call charge (https://www.nylas.com/pricing/, checked 2026-10-08).",
    "priceSummary": "$15 / mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in llms.txt, the OpenAPI spec or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 38,
    "popularity": {
      "githubStars": 181,
      "npmWeekly": 289344,
      "pypiWeekly": 90308,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developer.nylas.com/docs/v3/email/",
    "llmsTxt": "https://developer.nylas.com/llms.txt",
    "openapi": "https://developer.nylas.com/openapi.json",
    "capabilities": [
      "mailbox.read",
      "mailbox.search",
      "mailbox.send",
      "mailbox.drafts",
      "mailbox.sync",
      "email.threads"
    ],
    "tags": [
      "hosted",
      "freemium",
      "free-tier",
      "no-card",
      "mcp",
      "llms-txt",
      "openapi",
      "webhooks",
      "oauth",
      "typescript",
      "python",
      "ruby",
      "java",
      "enterprise",
      "eu",
      "status-page",
      "soc2",
      "closed-source"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 78.7,
      "grade": "A",
      "agentReady": true,
      "rank": 12,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 1,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 81,
        "maintenance": 88,
        "payments": 40,
        "reliability": 77,
        "schema": 93,
        "security": 87,
        "transparency": 81
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 77,
          "points": 15.4,
          "reason": "Atlassian Statuspage at status-v3.nylas.com with US and EU components (20). In the 90 days to 8 October 2026 the history feed lists eight incidents on email, each limited to a provider or function. They are missing EU message webhooks on 24 July (about five hours), 500 errors on IMAP message reads on 6 August (about four hours), sync latency on 11 August, EWS attachment errors on 14 August, delayed or missing webhooks on all providers on 19 August (about five hours), Microsoft send and read errors from 31 August to 1 September that Nylas attributes to Exchange Online, IMAP retrieval and webhook degradation on 10 September (about six hours) and IMAP 404s on 17 September. None since. No full outage, but several partial ones over an hour on the functions this listing covers (10). 200 requests a second per grant for messages and JSON send, 10 a second for multipart send, 50 a second per application for admin endpoints (15). 429s separate Nylas limits from provider limits by `error.type`, pass on `Retry-After` where the provider sends one, and send accepts an `Idempotency-Key` (15). The product page shows a 99.99 per cent uptime SLA and the pricing page lists it under Enterprise only, with no SLA document found (7). GA (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 93,
          "points": 15.11,
          "reason": "Graded on the REST API. OpenAPI 3.1 spec at developer.nylas.com/openapi.json with 120 paths and 213 operations, read on 8 October (25). llms.txt with instructions for agents, llms-full.txt and a Markdown copy of every page (10). Guides and llms.txt say which grant type and endpoint to use and where provider behaviour differs (16). Typed query parameters on message lists, with defaults and limits in the reference (13). Curl and SDK examples on each guide, an error type table and a JSON error shape with `type`, `message`, `provider_error` and `request_id` (14). v3 in the path and a dated changelog with an RSS feed (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 81,
          "points": 13.16,
          "reason": "`limit`, `select` field selection and a clean-messages endpoint that returns plain text or Markdown size responses on the REST API. The hosted MCP server loads 38 tools, 14 of them for email, with no toolsets found (15). Cursor pagination with `next_cursor`, 50 by default and 200 at most, filters by sender, subject, folder, date and unread state, and `search_query_native`, which on Google and Microsoft combines only with `in`, `limit` and `page_token` (19). Typed errors with a request ID, the provider error passed through and retry guidance on the 202, 502 and 504 responses, with 429 handling on the rate limits page (18). `Idempotency-Key` on send with documented 409 and replay behaviour, and a confirmation call before MCP sends. Draft and folder writes take no key and we couldn't read tool annotations (14). Official SDKs for Node.js, Python, Ruby and Kotlin or Java (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 87,
          "points": 15.23,
          "reason": "IAM API keys, announced on 6 October 2026, inherit one principal's resource binding (a grant, workspace, application or organisation) and permissions, can expire, and can be disabled or replaced. End users connect by OAuth with scopes the application picks, down to `gmail.readonly` or `Mail.Read`. The application API key still reaches every grant, and IAM is managed only in the Dashboard (27). Read-only permissions and provider scopes, 403 on anything outside the binding, and a confirmation call before MCP sends (17). The MCP and agent security pages warn about hidden instructions in mail and list mitigations, which are left to the integrator (13). IAM Access Activity records allowed and denied API and MCP requests for 400 days and links to request logs, and Dashboard logs are kept 14 days. Requests made with an application key appear only in the logs (13). SOC 2 Type II, ISO 27001 and 27701, CSA STAR, a vulnerability disclosure programme, a private bug bounty, an annual penetration test and a security.txt on developer.nylas.com valid to 1 August 2027. www.nylas.com has none (17)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 (0). Per-account prices published without login, $2.25 an extra email and calendar account a month on Essentials and $2.00 on Pro (20). Free plan with 5 connected accounts and no card (20). An account needs a browser sign-in through Google, Microsoft or GitHub, and each mailbox needs its owner to complete OAuth (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 88,
          "points": 7.7,
          "reason": "Changelog entry on 7 October 2026 with message sync fixes (30). More than 30 dated changelog entries since 10 July (20). Public dated changelog with RSS, support, and SDK repositories pushed on 30 September and 3 October (15). Current official SDKs. The only Nylas entry in the official MCP registry is a third party's (15). nylas-python 6.18.0 came out on 30 September 2026, while the newest npm release of the Node SDK is still 8.4.0 from 24 June (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 81,
          "points": 7.09,
          "note": "editorial 67, provenance 95",
          "reason": "Closed service under terms dated 23 June 2025, Californian law, with MIT SDKs (15). The privacy policy (6 January 2026) keeps customer account data and restricted end-user data for the life of the account plus two months and log files for a year. The docs say Google, Microsoft and EWS requests pass through without message storage and IMAP accounts keep a 90-day cache. The DPA is available on request from sales, not published (24). v2 is marked deprecated and the changelog is dated, but no deprecation policy was found (10). Sub-processor list updated on 28 August 2026 with locations, changes announced on the status page, and two isolated regions, US (Iowa) and Europe (London) (18)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`limit`, `select` field selection and a clean-messages endpoint that returns plain text or Markdown size responses on the REST API. The hosted MCP server loads 38 tools, 14 of them for email, with no toolsets found (15). Cursor pagination with `next_cursor`, 50 by default and 200 at most, filters by sender, subject, folder, date and unread state, and `search_query_native`, which on Google and Microsoft combines only with `in`, `limit` and `page_token` (19). Typed errors with a request ID, the provider error passed through and retry guidance on the 202, 502 and 504 responses, with 429 handling on the rate limits page (18). `Idempotency-Key` on send with documented 409 and replay behaviour, and a confirmation call before MCP sends. Draft and folder writes take no key and we couldn't read tool annotations (14). Official SDKs for Node.js, Python, Ruby and Kotlin or Java (15).",
          "maintenance": "Changelog entry on 7 October 2026 with message sync fixes (30). More than 30 dated changelog entries since 10 July (20). Public dated changelog with RSS, support, and SDK repositories pushed on 30 September and 3 October (15). Current official SDKs. The only Nylas entry in the official MCP registry is a third party's (15). nylas-python 6.18.0 came out on 30 September 2026, while the newest npm release of the Node SDK is still 8.4.0 from 24 June (8).",
          "payments": "No x402, MPP or L402 (0). Per-account prices published without login, $2.25 an extra email and calendar account a month on Essentials and $2.00 on Pro (20). Free plan with 5 connected accounts and no card (20). An account needs a browser sign-in through Google, Microsoft or GitHub, and each mailbox needs its owner to complete OAuth (0).",
          "reliability": "Atlassian Statuspage at status-v3.nylas.com with US and EU components (20). In the 90 days to 8 October 2026 the history feed lists eight incidents on email, each limited to a provider or function. They are missing EU message webhooks on 24 July (about five hours), 500 errors on IMAP message reads on 6 August (about four hours), sync latency on 11 August, EWS attachment errors on 14 August, delayed or missing webhooks on all providers on 19 August (about five hours), Microsoft send and read errors from 31 August to 1 September that Nylas attributes to Exchange Online, IMAP retrieval and webhook degradation on 10 September (about six hours) and IMAP 404s on 17 September. None since. No full outage, but several partial ones over an hour on the functions this listing covers (10). 200 requests a second per grant for messages and JSON send, 10 a second for multipart send, 50 a second per application for admin endpoints (15). 429s separate Nylas limits from provider limits by `error.type`, pass on `Retry-After` where the provider sends one, and send accepts an `Idempotency-Key` (15). The product page shows a 99.99 per cent uptime SLA and the pricing page lists it under Enterprise only, with no SLA document found (7). GA (10).",
          "schema": "Graded on the REST API. OpenAPI 3.1 spec at developer.nylas.com/openapi.json with 120 paths and 213 operations, read on 8 October (25). llms.txt with instructions for agents, llms-full.txt and a Markdown copy of every page (10). Guides and llms.txt say which grant type and endpoint to use and where provider behaviour differs (16). Typed query parameters on message lists, with defaults and limits in the reference (13). Curl and SDK examples on each guide, an error type table and a JSON error shape with `type`, `message`, `provider_error` and `request_id` (14). v3 in the path and a dated changelog with an RSS feed (15).",
          "security": "IAM API keys, announced on 6 October 2026, inherit one principal's resource binding (a grant, workspace, application or organisation) and permissions, can expire, and can be disabled or replaced. End users connect by OAuth with scopes the application picks, down to `gmail.readonly` or `Mail.Read`. The application API key still reaches every grant, and IAM is managed only in the Dashboard (27). Read-only permissions and provider scopes, 403 on anything outside the binding, and a confirmation call before MCP sends (17). The MCP and agent security pages warn about hidden instructions in mail and list mitigations, which are left to the integrator (13). IAM Access Activity records allowed and denied API and MCP requests for 400 days and links to request logs, and Dashboard logs are kept 14 days. Requests made with an application key appear only in the logs (13). SOC 2 Type II, ISO 27001 and 27701, CSA STAR, a vulnerability disclosure programme, a private bug bounty, an annual penetration test and a security.txt on developer.nylas.com valid to 1 August 2027. www.nylas.com has none (17).",
          "transparency": "Closed service under terms dated 23 June 2025, Californian law, with MIT SDKs (15). The privacy policy (6 January 2026) keeps customer account data and restricted end-user data for the life of the account plus two months and log files for a year. The docs say Google, Microsoft and EWS requests pass through without message storage and IMAP accounts keep a 90-day cache. The DPA is available on request from sales, not published (24). v2 is marked deprecated and the changelog is dated, but no deprecation policy was found (10). Sub-processor list updated on 28 August 2026 with locations, changes announced on the status page, and two isolated regions, US (Iowa) and Europe (London) (18)."
        },
        "sources": [
          {
            "what": "Email API product page",
            "url": "https://www.nylas.com/products/email-api/",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt",
            "url": "https://developer.nylas.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI spec",
            "url": "https://developer.nylas.com/openapi.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Messages API guide",
            "url": "https://developer.nylas.com/docs/v3/email/messages/",
            "seen": "2026-10-08"
          },
          {
            "what": "idempotent send",
            "url": "https://developer.nylas.com/docs/v3/email/idempotent-send/",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits",
            "url": "https://developer.nylas.com/docs/dev-guide/platform/rate-limits/",
            "seen": "2026-10-08"
          },
          {
            "what": "errors",
            "url": "https://developer.nylas.com/docs/api/errors/",
            "seen": "2026-10-08"
          },
          {
            "what": "Nylas IAM",
            "url": "https://developer.nylas.com/docs/v3/auth/nylas-iam/",
            "seen": "2026-10-08"
          },
          {
            "what": "security for AI agents",
            "url": "https://developer.nylas.com/docs/v3/getting-started/agent-security/",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth scopes",
            "url": "https://developer.nylas.com/docs/dev-guide/scopes/",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server docs",
            "url": "https://developer.nylas.com/docs/dev-guide/mcp/",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks",
            "url": "https://developer.nylas.com/docs/v3/notifications/",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog feed",
            "url": "https://developer.nylas.com/atom-changelogs.xml",
            "seen": "2026-10-08"
          },
          {
            "what": "status history feed",
            "url": "https://status-v3.nylas.com/history.rss",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.nylas.com/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://www.nylas.com/security/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt on the docs host",
            "url": "https://developer.nylas.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.nylas.com/privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "terms",
            "url": "https://www.nylas.com/legal/terms/",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://www.nylas.com/security/subprocessors/",
            "seen": "2026-10-08"
          },
          {
            "what": "data residency",
            "url": "https://developer.nylas.com/docs/dev-guide/platform/data-residency/",
            "seen": "2026-10-08"
          },
          {
            "what": "CLI quickstart",
            "url": "https://developer.nylas.com/docs/v3/getting-started/cli/",
            "seen": "2026-10-08"
          },
          {
            "what": "npm latest for nylas",
            "url": "https://registry.npmjs.org/nylas/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI nylas",
            "url": "https://pypi.org/pypi/nylas/json",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=nylas",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the list of IAM permissions and system roles, which is shown only in the Dashboard",
          "unchecked: whether the MCP tools carry readOnlyHint or destructiveHint, since listing them needs an API key",
          "Whether a published SLA document backs the 99.99 per cent figure on the product page",
          "nylas-calendar records securityTxt as none. A valid file is on developer.nylas.com, and www.nylas.com still returns 404",
          "nylas-calendar's security note predates Nylas IAM (6 October 2026) and says keys can't be scoped",
          "Whether IAM is included on every plan. The pricing page doesn't list it",
          "No deprecation policy found in the docs or terms"
        ]
      },
      "negative": 0,
      "verdict": "One REST schema covers Gmail, Microsoft 365, Exchange, Yahoo, iCloud and IMAP, and IAM API keys launched on 6 October 2026 can be bound to a single mailbox with chosen permissions. The status page lists eight email incidents between 24 July and 17 September 2026, most on IMAP sync and webhooks.",
      "bestFor": "Products that act in their users' own mailboxes across several providers and want one schema, webhooks and OAuth handled.",
      "strengths": [
        "One schema for messages, threads, drafts, folders and attachments across Gmail, Microsoft 365, Exchange EWS, Yahoo, iCloud and IMAP",
        "IAM API keys bound to one grant, workspace or application with chosen permissions, and 400 days of access activity",
        "`Idempotency-Key` header on send, with documented 409 and 429 replay behaviour",
        "OpenAPI 3.1 spec with 213 operations, llms.txt and a Markdown copy of every docs page",
        "Free plan with 5 connected accounts and no card"
      ],
      "weaknesses": [
        "Eight status incidents on email between 24 July and 17 September 2026, including about six hours of IMAP retrieval and webhook degradation on 10 September",
        "IAM principals and keys are managed only in the Dashboard, with no public API or CLI",
        "On Google and Microsoft, `search_query_native` combines only with `in`, `limit` and `page_token`",
        "Draft and folder writes take no idempotency key, only send does",
        "Each connected mailbox past the plan allowance costs $1.75 to $2.25 a month"
      ],
      "agentNotes": [
        "Address every call to /v3/grants/\u003cgrant_id\u003e on api.us.nylas.com or api.eu.nylas.com. A grant lives in one region only",
        "Ask the operator for an IAM API key bound to the one grant and the permissions the task needs, not the application key",
        "Send `Idempotency-Key` on every send. A retry with the same key replays a cached 429 or 5xx, so use a new key after those",
        "Narrow thread lists with filters and a low `limit`. Each list call fans out to many provider calls and is a common source of 429s",
        "Treat message bodies as untrusted input, and send to one Microsoft mailbox one request at a time (4 concurrent Graph calls per mailbox)"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "A",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 78.7
        }
      ],
      "editorialScores": {
        "ergonomics": 81,
        "maintenance": 88,
        "payments": 40,
        "reliability": 77,
        "schema": 93,
        "security": 87,
        "transparency": 67
      },
      "provenanceScore": 95
    },
    "connect": {
      "install": "brew install nylas/nylas-cli/nylas",
      "http": "curl --compressed --request GET \\\n  --url \"https://api.us.nylas.com/v3/grants/\u003cNYLAS_GRANT_ID\u003e/messages?limit=5\" \\\n  --header 'Accept: application/json' \\\n  --header 'Authorization: Bearer \u003cNYLAS_API_KEY\u003e'",
      "claudeCode": "nylas mcp install --assistant claude-code",
      "config": {
        "mcpServers": {
          "nylas": {
            "headers": {
              "Authorization": "Bearer \u003cNYLAS_API_KEY\u003e"
            },
            "type": "streamable-http",
            "url": "https://mcp.us.nylas.com"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/mailbox.read",
      "tool": "https://letme.dev/nylas-email"
    },
    "sameCompany": [
      "nylas-calendar"
    ],
    "notable": [
      "Message, thread, draft, folder and attachment endpoints sit under /v3/grants/\u003cgrant_id\u003e and return the same objects for Gmail, Microsoft 365, Exchange EWS, Yahoo, iCloud and IMAP (https://developer.nylas.com/docs/v3/email/messages/)",
      "Nylas IAM, announced on 6 October 2026, issues API keys bound to one grant, workspace, application or organisation with roles and permissions, and keeps allowed and denied requests for 400 days (https://developer.nylas.com/docs/v3/auth/nylas-iam/)",
      "Send accepts an `Idempotency-Key` header of up to 256 characters, and returns 409 when the same key arrives with a different payload or while the first request is in flight (https://developer.nylas.com/docs/v3/email/idempotent-send/)",
      "Messages and JSON send are limited to 200 requests a second per grant and multipart send to 10, with provider limits on top such as 4 concurrent Graph requests per Microsoft mailbox (https://developer.nylas.com/docs/dev-guide/platform/rate-limits/)",
      "Google, Microsoft and EWS requests go straight to the provider without Nylas storing message data, while IMAP accounts keep a 90-day message cache, per the docs (https://developer.nylas.com/llms-full.txt)",
      "The hosted MCP server at mcp.us.nylas.com (mcp.eu.nylas.com in the EU) has 38 tools, 14 of them for email, and `send_message` and `send_draft` need a confirmation call first (https://developer.nylas.com/docs/dev-guide/mcp/)",
      "The status feed lists eight email incidents between 24 July and 17 September 2026, five of them on IMAP or webhooks, and none from 18 September to 8 October (https://status-v3.nylas.com/history.rss)"
    ],
    "area": "communication",
    "details": [
      {
        "label": "Surface graded",
        "value": "The v3 REST API at api.us.nylas.com and api.eu.nylas.com. The hosted MCP server calls the same API with the same keys"
      },
      {
        "label": "Providers",
        "value": "Gmail and Google Workspace, Microsoft 365 and Outlook, Exchange on-premises (EWS), Yahoo, iCloud and generic IMAP"
      },
      {
        "label": "Endpoints",
        "value": "Messages (list, get, update, delete, send, clean, scheduled sends, Smart Compose), threads, drafts, folders and labels, attachments. OpenAPI 3.1 spec with 120 paths and 213 operations for the whole platform"
      },
      {
        "label": "Search",
        "value": "Filters for sender, recipient, subject, folder, dates, unread, starred and attachments, plus `search_query_native` for Gmail operators and Microsoft KQL. On Google and Microsoft it combines only with `in`, `limit` and `page_token`"
      },
      {
        "label": "Sync",
        "value": "Webhooks, Google Pub/Sub or Amazon SNS for `message.created` and `message.updated`, signed with HMAC-SHA256, up to 3 delivery attempts, payloads over 1 MB truncated. Gmail changes arrive through Pub/Sub, IMAP through two IDLE connections per account"
      },
      {
        "label": "Credentials",
        "value": "Application API key (every grant) or IAM API key (one grant, workspace, application or organisation, with permissions and optional expiry). End users connect by OAuth with provider scopes such as `gmail.readonly`, `gmail.send`, `Mail.Read` and `Mail.Send`"
      },
      {
        "label": "Rate limits",
        "value": "200 requests a second per grant for messages and JSON send, 10 a second per grant for multipart send, 50 a second per application for grants, auth and webhooks. Provider limits apply on top"
      },
      {
        "label": "Pagination",
        "value": "50 items by default, `limit` up to 200, `next_cursor` passed back as `page_token`, `select` for field selection"
      },
      {
        "label": "Send limits",
        "value": "3 MB for a JSON request with inline attachments, 25 MB as multipart, 150 MB through the attachment uploads API on Microsoft grants (beta). Gmail allows 2,000 sent messages a day, Microsoft 30 a minute per mailbox"
      },
      {
        "label": "MCP server",
        "value": "Hosted at mcp.us.nylas.com and mcp.eu.nylas.com, 38 tools (14 for email), 90-second timeout per request, API key or IAM API key as Bearer"
      },
      {
        "label": "Audit",
        "value": "IAM Access Activity and Config Changes kept 400 days, filterable by principal, key, grant and request ID. Dashboard logs kept 14 days"
      },
      {
        "label": "Regions",
        "value": "US (Iowa) and Europe (London), isolated from each other. An application and its grants live in one region"
      },
      {
        "label": "Data retention",
        "value": "Life of the account plus two months for customer account data and restricted end-user data, and one year for log files, per the privacy policy of 6 January 2026"
      },
      {
        "label": "SDKs",
        "value": "Node.js (nylas 8.4.0, 24 June 2026), Python (nylas 6.18.0, 30 September 2026), Ruby, Kotlin and Java, all MIT, plus the Nylas CLI"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II, ISO 27001, ISO 27701, CSA STAR, HIPAA report and PCI DSS SAQ A per nylas.com/security. Private bug bounty and a vulnerability disclosure programme"
      }
    ],
    "unitPrices": [
      {
        "item": "Essentials",
        "unit": "month",
        "usd": 15,
        "note": "10 email and calendar connected accounts"
      },
      {
        "item": "Pro",
        "unit": "month",
        "usd": 49,
        "note": "25 email and calendar connected accounts, billed monthly"
      },
      {
        "item": "Extra email and calendar account on Essentials",
        "unit": "account-month",
        "usd": 2.25
      },
      {
        "item": "Extra email and calendar account on Pro",
        "unit": "account-month",
        "usd": 2
      }
    ],
    "provenance": {
      "legalEntity": "Nylas, Inc.",
      "domain": "nylas.com",
      "domainRegistered": "2001-11-07",
      "domainNote": "nylas.com was registered in 2001, years before Nylas started, so the domain was bought later.",
      "endpointOnVendorDomain": true,
      "terms": "https://www.nylas.com/legal/terms/",
      "privacy": "https://www.nylas.com/privacy-policy/",
      "statusPage": "https://status-v3.nylas.com",
      "changelog": "https://developer.nylas.com/docs/changelogs/",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The terms (updated 23 June 2025) name Nylas, Inc., 2100 Geng Rd, Palo Alto, CA 94303, under Californian law with arbitration.",
        "developer.nylas.com/.well-known/security.txt is an RFC 9116 file with security@nylas.com as contact, expiring on 1 August 2027. www.nylas.com/.well-known/security.txt returns 404.",
        "The API answers at api.us.nylas.com and api.eu.nylas.com, and the status page for the v3 API is status-v3.nylas.com.",
        "RDAP for nylas.com gives a registration date of 2001-11-07.",
        "The privacy policy was last updated on 6 January 2026 and the sub-processor page on 28 August 2026."
      ],
      "score": 95,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Nylas, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "nylas.com, registered 2001-11-07 (24 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.us.nylas.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status-v3.nylas.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.nylas.com/legal/terms/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-06-23",
          "words": 5143,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: June 23, 2025",
              "says": "Last updated 2025-06-23"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "The TOU and any action related thereto will be governed by the Federal Arbitration Act, federal arbitration law, and the laws of the State of California without regard to its conflict of laws provisions.",
              "says": "The law of Federal Arbitration Act"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "IN NO EVENT WILL NYLAS’ TOTAL LIABILITY ARISING OUT OF OR IN CONNECTION WITH THE TOU OR FROM THE USE OF OR INABILITY TO USE THE SERVICES OR CONTENT EXCEED THE LESSER OF THE AMOUNT YOU HAVE PAID TO NYLAS FOR THE USE OF THEIR SERVICES IN THE TWELVE (12) MONTHS PRECEDING THE INCIDENT GIVING RISE TO THE CLAIM OR ONE HUNDR…",
              "says": "Capped at the lesser of $100 and the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If you do not, we may prevent you from receiving future updates and/or suspend or terminate your Account."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Notwithstanding the provisions of Section 1.b above, if Nylas changes any of the terms of this Section 16 after the date you first accepted the TOU (or accepted any subsequent changes to the TOU), you may reject any such change by sending us written notice (including by email to support@nylas.com) within 30 days of th…",
              "says": "Gives 30 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If you do not agree to be bound by the TOU, then, except as otherwise provided in Section 16.f (Effect of Changes on Arbitration) and except if you have entered into Terms with Nylas, you may not use the Services."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "Attempt to access or search the Services or Content or download Content from the Services using any engine, software, tool, agent, device, or mechanism (including spiders, robots, crawlers, data mining tools or the like)",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "Because our Services are evolving over time we may change or discontinue all or any part of the Services, at any time and without notice, at our sole discretion.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may terminate your access to and use of the Services, at our sole discretion, at any time and without notice to you."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "IMPORTANT NOTICE REGARDING ARBITRATION: WHEN YOU AGREE TO THE TOU YOU ARE AGREEING (WITH LIMITED EXCEPTION) TO RESOLVE ANY DISPUTE BETWEEN YOU AND NYLAS THROUGH BINDING, INDIVIDUAL ARBITRATION RATHER THAN IN COURT."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Total liability is capped at the lesser of fees paid in the preceding twelve months or 100 US dollars where there were no payment obligations.",
              "quote": "EXCEED THE LESSER OF THE AMOUNT YOU HAVE PAID TO NYLAS FOR THE USE OF THEIR SERVICES IN THE TWELVE (12) MONTHS PRECEDING THE INCIDENT GIVING RISE TO THE CLAIM OR ONE HUNDRED DOLLARS ($100), IF YOU HAVE NOT HAD ANY PAYMENT OBLIGATIONS TO NYLAS, AS APPLICABLE."
            },
            {
              "date": "2026-10-08",
              "text": "The general prohibitions bar using the Services or Content for any commercial purpose or for the benefit of any third party.",
              "quote": "Use the Services or Content, or any portion thereof, for any commercial purpose or for the benefit of any third party or in any manner not permitted by the TOU;"
            },
            {
              "date": "2026-10-08",
              "text": "The terms say the system is not designed for transaction processing or other commerce-related activities, and the customer agrees not to use it for them.",
              "quote": "You acknowledge that our system is not designed for transaction processing or other commerce-related activities."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.nylas.com/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-01-06",
          "words": 6376,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: January 6, 2026",
              "says": "Last updated 2026-01-06"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Policy explains our information practices, the kinds of personal information we may collect, how we use and share that personal information, and how you can exercise the choices you may have."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Subject to the earlier exercise of your rights in your personal information, we will retain your Customer Account Data and Restricted Customer End-User Data for as long as you have an account with us, plus two months.",
              "says": "Names a period of two months"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Information We Collect Automatically: When you visit a Website, including our web forms, we and service providers acting on our behalf automatically collect certain information using tracking technologies like cookies, web beacons, and similar technologies."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We will not sell personal information of EEA Users without valid consent under the GDPR.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Subject to the earlier exercise of your rights in your personal information, we will retain your Customer Account Data and Restricted Customer End-User Data for as long as you have an account with us, plus two months."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have additional questions about our Data Privacy Framework certification, contact us at support@nylas.com.",
              "says": "support@nylas.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit Data Privacy Framework.",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "Subject to any opt-in required by applicable law, we sell, share (or have in the 12 months preceding the “Last Updated” date of this Privacy Policy) your personal information with third parties like in exchange for monetary or other valuable consideration, or process it for “targeted advertising” in the manner describ…"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Nylas may create, disclose and commercialise aggregated information derived from Customer Data for any lawful purpose, excluding encrypted restricted end-user data.",
              "quote": "Nylas may create, use, disclose, and commercialize Aggregated Information derived from operational metrics and Customer Data, excluding Restricted Customer End Data that is encrypted and inaccessible to Nylas, for any lawful purpose"
            },
            {
              "date": "2026-10-08",
              "text": "Certain subprocessors can see Customer End-User Data so that the AI Products can run.",
              "quote": "Certain subprocessors can see Customer End-User Data to provide the AI Products; those are noted in the subprocessor list."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/nylas-email.json",
    "live": {
      "slug": "nylas-email",
      "probe": {
        "target": "https://api.us.nylas.com/v3",
        "method": "get",
        "lastAt": "2026-10-08T17:36:41.59735093Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 122,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 132,
        "p95ms24h": 189,
        "samples24h": 25,
        "samples30d": 25,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 25,
            "ok": 25
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status-v3.nylas.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T17:25:24.608211988Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "nylas/nylas-nodejs",
          "version": "v8.4.0",
          "released": "2026-06-24",
          "seenAt": "2026-10-08T16:22:58.572230857Z"
        },
        {
          "registry": "npm",
          "name": "nylas",
          "version": "8.4.0",
          "seenAt": "2026-10-08T16:22:58.35348864Z"
        },
        {
          "registry": "pypi",
          "name": "nylas",
          "version": "6.18.0",
          "released": "2026-09-30",
          "seenAt": "2026-10-08T16:22:58.443340194Z"
        }
      ],
      "githubStars": 181,
      "npmWeekly": 289344,
      "pypiWeekly": 90308,
      "securityTxt": {
        "url": "https://nylas.com/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:38:57.948763904Z"
      },
      "updatedAt": "2026-10-08T17:36:41.59735093Z"
    }
  }
}
