{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "unipile",
    "name": "Unipile",
    "vendor": "UNIPILE SAS",
    "vendorUrl": "https://www.unipile.com",
    "kind": "http-api",
    "category": "mailbox-access",
    "summary": "Unipile is a hosted API from Unipile SAS in France that connects to accounts people already have. It reads, searches, sends and files mail in Gmail, Outlook and IMAP mailboxes, and also covers calendars, LinkedIn, WhatsApp, Instagram and Telegram.",
    "url": "https://www.anchorterminal.com/tools/unipile",
    "markdownUrl": "https://www.anchorterminal.com/tools/unipile.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/unipile.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/unipile.json",
    "repo": "https://github.com/unipile/unipile-node-sdk",
    "license": "Proprietary service under Unipile's terms of use. The v1 Node SDK repository and the unipile-mcp repository carry an MIT licence file",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://developer.unipile.com/mcp?branch=v1.0",
    "packages": [
      {
        "registry": "npm",
        "name": "unipile-node-sdk"
      }
    ],
    "auth": "api-key",
    "authNotes": "Self-serve. A person signs up at dashboard.unipile.com, copies the account's DSN (host and port) and generates an access token, which goes in the `X-API-KEY` header. A v1 token reaches every connected account and has no scopes. Mailboxes are connected by the end user through Google or Microsoft OAuth, using an OAuth app the customer registers and has verified, or with IMAP and SMTP credentials. The v2 beta adds keys limited to a Scope of accounts.",
    "pricing": "paid",
    "pricingNotes": "55 dollars (49 euros) a month covers up to 10 connected accounts, then 5.50 dollars an account a month, falling to 3.50 above 5,000. No charge per request or message. A 7-day trial needs no card, and there is no free tier after it. An SLA needs a custom plan (checked 2026-10-08).",
    "priceSummary": "$55 / mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI spec or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 5,
    "popularity": {
      "githubStars": 48,
      "npmWeekly": 82529,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developer.unipile.com",
    "llmsTxt": "https://developer.unipile.com/llms.txt",
    "openapi": "https://api1.unipile.com/api-json?port=13111",
    "registryName": "com.unipile/unipile-mcp",
    "capabilities": [
      "mailbox.read",
      "mailbox.search",
      "mailbox.send",
      "mailbox.drafts",
      "mailbox.sync",
      "calendar.read",
      "calendar.write",
      "calendar.webhooks",
      "messaging.whatsapp",
      "messaging.inbound"
    ],
    "tags": [
      "hosted",
      "paid",
      "free-trial",
      "no-card",
      "api-key",
      "openapi",
      "llms-txt",
      "mcp",
      "webhooks",
      "gmail",
      "outlook",
      "imap",
      "calendar",
      "linkedin",
      "whatsapp",
      "typescript",
      "eu",
      "soc2",
      "status-page",
      "closed-source"
    ],
    "lastRelease": "2026-09-02",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 58.4,
      "grade": "C",
      "agentReady": false,
      "rank": 402,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 5,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 73,
        "maintenance": 59,
        "payments": 40,
        "reliability": 56,
        "schema": 77,
        "security": 37,
        "transparency": 71
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 56,
          "points": 11.2,
          "reason": "Graded on the v1 REST API with the hosted lines. Status page at status.unipile.com on OpenStatus with components per provider and an events history, though no public uptime monitors (20). Since 10 July 2026 the history shows a database incident at the hosting provider on 21 July that affected the v1 dashboard and hosted auth for about two and a half hours, a day of timeouts and failed requests on 30 July, and one API node unavailable for 70 minutes on 20 August, plus provider-side and v2 beta incidents. We scored between one major and several (5). Unipile states no request limit of its own on v1, and the docs give provider figures such as 500 emails a day for Gmail and 5,000 recipients a day for Microsoft 365 (8). 429 is typed `errors/too_many_requests` and passes on the provider's refusal with no Retry-After documented for v1. Sends accept an `Idempotency-Key`, and webhooks retry five times (8). The terms say an SLA is available only under a custom agreement, with no published figure (5). v1 is generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 77,
          "points": 12.51,
          "reason": "OpenAPI 3.0 spec with 94 operations, served without a key, and embedded in each reference page (25). llms.txt and a Markdown copy of every page (10). Operation descriptions are one line, such as \"Returns a list of emails\", though parameter notes cover provider differences (10). Query parameters are typed and `limit` is bounded at 1 to 250, but the send and draft bodies are multipart with nested objects the reference marks as not working in the interactive docs (10). Guides carry curl and SDK examples, and each status code lists typed errors (12). v1 is in the path and a changelog exists, with seven entries since 2024 and the latest on 29 June 2026 (10)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 73,
          "points": 11.86,
          "reason": "`meta_only` drops bodies from mail lists and `limit` sizes the page. The MCP server has 5 compact tools (20). Cursor pagination, a full-text `search` and filters for folder, sender, recipient, thread and date (18). Errors carry `title`, `detail` and a typed `type`, with no retry guidance per type (14). `Idempotency-Key` on send only, not on drafts or updates. The MCP tools carry readOnlyHint and destructiveHint (14). Only `account_id` is required to list mail. The v1 SDK is Node only, and the Python client is for the v2 beta (7)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 37,
          "points": 6.48,
          "reason": "One access token in `X-API-KEY` reaches every connected account, with no scopes in v1. End users connect Gmail and Outlook through OAuth on the customer's own app. We took 5 off because the MCP page says headers can be passed as query parameters (15). Google's `gmail.modify` scope can be left out and hosted auth accepts custom scopes, but there is no read-only token or confirmation step. Scoped keys are in the v2 beta only (6). Mail bodies are untrusted content and no injection guidance was found in the v1 docs. The v2 MCP page tells users to give the client a scoped key (2). The security page mentions records of processing activity. No per-request log for the operator was found in the v1 docs (2). SOC 2 Type II, an annual third-party penetration test and Google's CASA, with no security.txt, disclosure policy or bug bounty found (12)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 (0). Per-account prices are public, from 55 dollars a month for up to 10 accounts down to 3.50 dollars an account above 5,000, with no charge per request (20). A 7-day trial with no card (20). A person has to sign up in a browser and connect each mailbox (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 59,
          "points": 5.16,
          "reason": "The latest dated change to the v1 mail docs is 2 September 2026, 36 days before the check, and the v1 changelog's latest entry is 29 June (20). The v1 changelog has no entry in the last 90 days. We gave half for dated v1 docs updates on 20 August, 28 August and 2 September and six tags of the v2 beta SDK since 13 July (10). A Slack community, live chat and detailed status updates, for a closed service (10). Listed in the official MCP registry as com.unipile/unipile-mcp since 29 September 2026 (15). The v1 Node SDK's last npm release is 1.9.3 from 21 May 2025, with Dependabot added in May 2026 (4)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 71,
          "points": 6.21,
          "note": "editorial 59, provenance 82",
          "reason": "Closed service with public terms under French law. The SDK and MCP repositories carry MIT licence files (15). The privacy policy of 28 September 2026 gives storage by API version and channel, deletion within 30 days of termination and a DPA on request. The security page says no data leaves the EU while the policy lists proxy sub-processors in the United States and Singapore, so the statements don't fully agree (20). The docs say v1 has no deprecation date, and no deprecation policy was found. The terms let changes take effect on publication (6). Eight sub-processors listed with country, data location and transfer safeguard, and hosting named as Scaleway and OVH in France (18)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`meta_only` drops bodies from mail lists and `limit` sizes the page. The MCP server has 5 compact tools (20). Cursor pagination, a full-text `search` and filters for folder, sender, recipient, thread and date (18). Errors carry `title`, `detail` and a typed `type`, with no retry guidance per type (14). `Idempotency-Key` on send only, not on drafts or updates. The MCP tools carry readOnlyHint and destructiveHint (14). Only `account_id` is required to list mail. The v1 SDK is Node only, and the Python client is for the v2 beta (7).",
          "maintenance": "The latest dated change to the v1 mail docs is 2 September 2026, 36 days before the check, and the v1 changelog's latest entry is 29 June (20). The v1 changelog has no entry in the last 90 days. We gave half for dated v1 docs updates on 20 August, 28 August and 2 September and six tags of the v2 beta SDK since 13 July (10). A Slack community, live chat and detailed status updates, for a closed service (10). Listed in the official MCP registry as com.unipile/unipile-mcp since 29 September 2026 (15). The v1 Node SDK's last npm release is 1.9.3 from 21 May 2025, with Dependabot added in May 2026 (4).",
          "payments": "No x402, MPP or L402 (0). Per-account prices are public, from 55 dollars a month for up to 10 accounts down to 3.50 dollars an account above 5,000, with no charge per request (20). A 7-day trial with no card (20). A person has to sign up in a browser and connect each mailbox (0).",
          "reliability": "Graded on the v1 REST API with the hosted lines. Status page at status.unipile.com on OpenStatus with components per provider and an events history, though no public uptime monitors (20). Since 10 July 2026 the history shows a database incident at the hosting provider on 21 July that affected the v1 dashboard and hosted auth for about two and a half hours, a day of timeouts and failed requests on 30 July, and one API node unavailable for 70 minutes on 20 August, plus provider-side and v2 beta incidents. We scored between one major and several (5). Unipile states no request limit of its own on v1, and the docs give provider figures such as 500 emails a day for Gmail and 5,000 recipients a day for Microsoft 365 (8). 429 is typed `errors/too_many_requests` and passes on the provider's refusal with no Retry-After documented for v1. Sends accept an `Idempotency-Key`, and webhooks retry five times (8). The terms say an SLA is available only under a custom agreement, with no published figure (5). v1 is generally available (10).",
          "schema": "OpenAPI 3.0 spec with 94 operations, served without a key, and embedded in each reference page (25). llms.txt and a Markdown copy of every page (10). Operation descriptions are one line, such as \"Returns a list of emails\", though parameter notes cover provider differences (10). Query parameters are typed and `limit` is bounded at 1 to 250, but the send and draft bodies are multipart with nested objects the reference marks as not working in the interactive docs (10). Guides carry curl and SDK examples, and each status code lists typed errors (12). v1 is in the path and a changelog exists, with seven entries since 2024 and the latest on 29 June 2026 (10).",
          "security": "One access token in `X-API-KEY` reaches every connected account, with no scopes in v1. End users connect Gmail and Outlook through OAuth on the customer's own app. We took 5 off because the MCP page says headers can be passed as query parameters (15). Google's `gmail.modify` scope can be left out and hosted auth accepts custom scopes, but there is no read-only token or confirmation step. Scoped keys are in the v2 beta only (6). Mail bodies are untrusted content and no injection guidance was found in the v1 docs. The v2 MCP page tells users to give the client a scoped key (2). The security page mentions records of processing activity. No per-request log for the operator was found in the v1 docs (2). SOC 2 Type II, an annual third-party penetration test and Google's CASA, with no security.txt, disclosure policy or bug bounty found (12).",
          "transparency": "Closed service with public terms under French law. The SDK and MCP repositories carry MIT licence files (15). The privacy policy of 28 September 2026 gives storage by API version and channel, deletion within 30 days of termination and a DPA on request. The security page says no data leaves the EU while the policy lists proxy sub-processors in the United States and Singapore, so the statements don't fully agree (20). The docs say v1 has no deprecation date, and no deprecation policy was found. The terms let changes take effect on publication (6). Eight sub-processors listed with country, data location and transfer safeguard, and hosting named as Scaleway and OVH in France (18)."
        },
        "sources": [
          {
            "what": "home page",
            "url": "https://www.unipile.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.unipile.com/pricing-api/",
            "seen": "2026-10-08"
          },
          {
            "what": "docs index for agents",
            "url": "https://developer.unipile.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "API usage, authentication and spec URL",
            "url": "https://developer.unipile.com/docs/api-usage.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI spec",
            "url": "https://api1.unipile.com/api-json?port=13111",
            "seen": "2026-10-08"
          },
          {
            "what": "list emails reference",
            "url": "https://developer.unipile.com/reference/mailscontroller_listmails.md",
            "seen": "2026-10-08"
          },
          {
            "what": "send email reference",
            "url": "https://developer.unipile.com/reference/mailscontroller_sendmail.md",
            "seen": "2026-10-08"
          },
          {
            "what": "provider limits",
            "url": "https://developer.unipile.com/docs/provider-limits-and-restrictions.md",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks overview",
            "url": "https://developer.unipile.com/docs/webhooks-2.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP docs (v1)",
            "url": "https://developer.unipile.com/docs/mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP tools/list reply",
            "url": "https://developer.unipile.com/mcp?branch=v1.0",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry entry",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=unipile",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://developer.unipile.com/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "v2 beta migration notice",
            "url": "https://developer.unipile.com/v2.0/docs/migration-from-v1.md",
            "seen": "2026-10-08"
          },
          {
            "what": "v2 beta API keys and rate limits",
            "url": "https://developer.unipile.com/v2.0/docs/rate-limits.md",
            "seen": "2026-10-08"
          },
          {
            "what": "status history",
            "url": "https://status.unipile.com/events",
            "seen": "2026-10-08"
          },
          {
            "what": "security and compliance",
            "url": "https://www.unipile.com/security-compliance/",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of use",
            "url": "https://www.unipile.com/terms-of-use/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.unipile.com/privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "legal notice",
            "url": "https://www.unipile.com/legal-notice/",
            "seen": "2026-10-08"
          },
          {
            "what": "v1 Node SDK on npm",
            "url": "https://registry.npmjs.org/unipile-node-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "v1 Node SDK repository",
            "url": "https://github.com/unipile/unipile-node-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "v2 Node SDK repository",
            "url": "https://github.com/unipile/unipile-node",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.verisign.com/com/v1/domain/unipile.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: how access tokens are listed, expired and revoked in the dashboard, which sits behind a login",
          "unchecked: whether the dashboard keeps a per-request log an operator can read",
          "When the v2 API leaves beta. The docs said summer 2026 and still mark it beta on 8 October 2026",
          "Whether v1 returns Retry-After on a 429. The v1 docs don't say",
          "The SOC 2 report and the DPA are available only on request and weren't read",
          "The pricing page's dollar figures come from the page's currency switch (55, 5.50, 5.00, 4.50, 4.00, 3.50). The structured data on the page is in euros"
        ]
      },
      "negative": 0,
      "verdict": "One REST API covers Gmail, Outlook and IMAP with search, drafts, send with an idempotency key and new-mail webhooks, and the OpenAPI spec is public. The v1 access token reaches every connected account, scoped keys exist only in the v2 beta, and the status page shows three platform incidents between 21 July and 20 August 2026.",
      "bestFor": "A product that needs one API over Gmail, Outlook and IMAP together with LinkedIn or WhatsApp messaging, priced per account.",
      "strengths": [
        "Public OpenAPI 3.0 spec with 94 operations, readable without a key, plus llms.txt and a Markdown copy of every docs page",
        "`POST /api/v1/emails` accepts an `Idempotency-Key` header of up to 255 characters, so a retried send returns the first result",
        "`GET /api/v1/emails` has cursor pagination, `limit` up to 250, `meta_only`, a full-text `search` and filters for folder, sender, recipient and date",
        "Price is per connected account with no charge per request, from 55 dollars a month for up to 10 accounts, with a 7-day trial and no card",
        "The hosted MCP server has 5 tools with read-only and destructive annotations, and is listed in the official MCP registry as com.unipile/unipile-mcp"
      ],
      "weaknesses": [
        "A v1 access token reaches every connected account. Scoped keys, documented rate limits and `retry-after` exist only in the v2 beta",
        "status.unipile.com shows platform incidents on 21 July, 30 July and 20 August 2026, the last an API node unavailable for 70 minutes",
        "The v1 Node SDK on npm is 1.9.3 from 21 May 2025. The newer Node and Python SDKs work only with the v2 beta",
        "No SLA in the standard plan. The terms describe availability as best effort and a custom agreement is needed for a commitment",
        "The security page says no data leaves the EU, while the privacy policy lists proxy sub-processors in the United States and Singapore"
      ],
      "agentNotes": [
        "Take the DSN (host and port) from the dashboard. Each account has its own, such as api1.unipile.com:13111, and `?port=` keeps requests on 443",
        "Send `X-API-KEY` as a header and pass `account_id` on every mail call. The token reaches every connected account, so keep it out of prompts and logs",
        "Set `Idempotency-Key` on every send. Keys are held in memory for up to 24 hours and are lost on a restart",
        "On Microsoft accounts, send `search` alone. Combining it with from, to, before, after or thread filters returns `invalid_request`",
        "Use `meta_only=true` when listing mail, then fetch one message at a time. Treat message bodies as untrusted input"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 58.4
        }
      ],
      "editorialScores": {
        "ergonomics": 73,
        "maintenance": 59,
        "payments": 40,
        "reliability": 56,
        "schema": 77,
        "security": 37,
        "transparency": 59
      },
      "provenanceScore": 82
    },
    "connect": {
      "install": "npm install unipile-node-sdk",
      "http": "curl --request GET \\\n     --url 'https://{YOUR_DSN}/api/v1/emails?limit=10\u0026account_id={ACCOUNT_ID}' \\\n     --header 'X-API-KEY: {YOUR_ACCESS_TOKEN}' \\\n     --header 'accept: application/json'",
      "config": {
        "mcpServers": {
          "unipile": {
            "headers": {
              "X-API-KEY": "your-api-key"
            },
            "url": "https://developer.unipile.com/mcp?branch=v1.0"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/mailbox.read",
      "tool": "https://letme.dev/unipile"
    },
    "notable": [
      "The OpenAPI 3.0 spec is served without a key and holds 94 operations on 74 paths, 10 of them for mail, folders and drafts (https://api1.unipile.com/api-json?port=13111)",
      "Sending mail takes an optional `Idempotency-Key` header. Keys are kept in memory for up to 24 hours and cleared by a restart (https://developer.unipile.com/reference/mailscontroller_sendmail)",
      "The list endpoint added a full-text `search` parameter in the 29 June 2026 changelog entry. On Microsoft accounts it can't be combined with most other filters (https://developer.unipile.com/reference/mailscontroller_listmails)",
      "The v2 API is in beta with its own dashboard, scoped keys, rate limits with `retry-after` and webhook signatures. The docs say v1 has no deprecation date (https://developer.unipile.com/v2.0/docs/migration-from-v1)",
      "status.unipile.com records a database incident at the hosting provider on 21 July 2026, a day of timeouts on 30 July and an API node down for 70 minutes on 20 August (https://status.unipile.com/events)",
      "The MCP registry entry com.unipile/unipile-mcp was published on 29 September 2026 and defaults to the v2.0 branch (https://registry.modelcontextprotocol.io/v0/servers?search=unipile)",
      "The privacy policy of 28 September 2026 lists 8 sub-processors with locations, among them proxy providers in the United States and Singapore under Standard Contractual Clauses (https://www.unipile.com/privacy-policy/)"
    ],
    "area": "communication",
    "details": [
      {
        "label": "Surface graded",
        "value": "The v1 REST API at https://{YOUR_DSN}/api/v1, which is generally available, and the hosted MCP server at https://developer.unipile.com/mcp. The v2 API is in beta and has its own dashboard, keys and SDKs"
      },
      {
        "label": "Mail providers",
        "value": "Gmail and Google Workspace and Microsoft through OAuth with the customer's own OAuth app, IMAP and SMTP with credentials"
      },
      {
        "label": "Mail endpoints",
        "value": "List and search emails, retrieve an email, send or reply, create a draft, update (unread, folders, Outlook categories), delete to Trash, attachments, folders, contacts"
      },
      {
        "label": "Other channels",
        "value": "Google and Outlook calendars (7 event and calendar endpoints), LinkedIn, WhatsApp, Instagram and Telegram messaging. The docs mark X and Messenger as no longer maintained"
      },
      {
        "label": "Credentials",
        "value": "An access token from the dashboard, sent as `X-API-KEY`. No scopes in v1. The v2 beta adds Service, Global Account and Scoped Account API keys"
      },
      {
        "label": "Webhooks",
        "value": "`mail_received`, `mail_sent` and `mail_moved` events, open and click tracking, account status. Five retries when the receiver doesn't answer 200 within 30 seconds. A custom header can carry a shared secret"
      },
      {
        "label": "Limits",
        "value": "Unipile states no request limit of its own on v1. The docs give provider figures, such as 500 emails a day for Gmail, 2,000 for Google Workspace and 5,000 recipients a day for Microsoft 365"
      },
      {
        "label": "Errors",
        "value": "JSON with `title`, `detail`, `type` and `status`. Types include `errors/disconnected_account`, `errors/too_many_requests` (the provider's 429) and `errors/network_down`"
      },
      {
        "label": "MCP server",
        "value": "Hosted by ReadMe from the OpenAPI spec. Five tools, list-endpoints, get-endpoint, search-endpoints, execute-request and get-server-variables. The docs tools answer without a key"
      },
      {
        "label": "SDKs",
        "value": "For v1, unipile-node-sdk 1.9.3 on npm (21 May 2025). For the v2 beta only, @unipile/sdk v2.56.0 (6 October 2026) and a Python client installed from GitHub"
      },
      {
        "label": "Hosting",
        "value": "Scaleway data centres in France, with OVH also listed as a hosting sub-processor"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II and Google's Cloud Application Security Assessment per unipile.com/security-compliance. Report and DPA on request"
      },
      {
        "label": "Stored mail data",
        "value": "Per the privacy policy of 28 September 2026, v1 stores metadata only for Microsoft and IMAP mail and nothing for Gmail. Customer data is deleted within 30 days of termination"
      },
      {
        "label": "Status",
        "value": "status.unipile.com on OpenStatus, with components per provider and for V1, V2 and the website. No public uptime monitors"
      }
    ],
    "unitPrices": [
      {
        "item": "Minimum, up to 10 connected accounts",
        "unit": "month",
        "usd": 55,
        "note": "49 euros. Any channel counts as one account, and a Gmail or Outlook account covers mail and calendar"
      },
      {
        "item": "Connected account, 11 to 50",
        "unit": "account-month",
        "usd": 5.5,
        "note": "5.00 euros"
      },
      {
        "item": "Connected account, 51 to 200",
        "unit": "account-month",
        "usd": 5,
        "note": "4.50 euros"
      },
      {
        "item": "Connected account, 201 to 1,000",
        "unit": "account-month",
        "usd": 4.5,
        "note": "4.00 euros"
      },
      {
        "item": "Connected account, 1,001 to 5,000",
        "unit": "account-month",
        "usd": 4,
        "note": "3.50 euros"
      },
      {
        "item": "Connected account, 5,001 and above",
        "unit": "account-month",
        "usd": 3.5,
        "note": "3.00 euros"
      }
    ],
    "provenance": {
      "legalEntity": "UNIPILE SAS",
      "domain": "unipile.com",
      "domainRegistered": "2020-11-17",
      "endpointOnVendorDomain": true,
      "terms": "https://www.unipile.com/terms-of-use/",
      "privacy": "https://www.unipile.com/privacy-policy/",
      "statusPage": "https://status.unipile.com",
      "changelog": "https://developer.unipile.com/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The legal notice names UNIPILE SAS, registered with the RCS of Roanne under number 885265595, head office 168 rue de la Rotonde, 42153 Riorges, France.",
        "The API answers on a per-account host and port under unipile.com, such as api1.unipile.com:13111. The MCP server is at developer.unipile.com/mcp, a ReadMe-hosted docs site on the vendor's domain.",
        "www.unipile.com/.well-known/security.txt returns 404. No vulnerability disclosure policy or bug bounty was found on the security page.",
        "The terms are governed by French law, with the Commercial Court of Roanne as the court. They say changes take effect on publication.",
        "RDAP for unipile.com gives a registration date of 2020-11-17."
      ],
      "score": 82,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "UNIPILE SAS",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "unipile.com, registered 2020-11-17 (5 years)",
          "points": 11,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "developer.unipile.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 7.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.unipile.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.unipile.com/terms-of-use/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 4576,
          "points": 7.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "French Courts: Any dispute arising from these terms of use or related to them shall be subject to the exclusive jurisdiction of the Commercial Court of Roanne (France).",
              "says": "Disputes go to the courts of Roanne"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "Surviving Clauses: Provisions of this Agreement that by their nature should survive termination (such as limitation of liability, intellectual property, and confidentiality clauses) shall continue to apply after termination."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "In the event of refusal, they may terminate the service at any time, provided that all outstanding invoices are settled in full before the termination takes effect."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Advance Notice: Unipile agrees to inform users of any substantial modifications to the terms of use.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If you do not accept these terms, you must not use our services."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "SLA commitments and warranties are not included in our standard offering."
            }
          ],
          "toKnow": [
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "Unipile may make minor or non-substantial modifications to the terms of use without prior notice.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "If full payment is not received within 15 days from the invoice date, Unipile reserves the right to suspend all services associated with the account and delete all related data, including connected accounts, historical logs, and stored information, without prior notice."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Users grant Unipile a worldwide, transferable and sublicensable licence to use, modify, publish and display submitted content in connection with the services.",
              "quote": "However, by submitting content, the User grants Unipile a worldwide, non-exclusive, royalty-free, transferable, and sublicensable license to use, reproduce, modify, adapt, publish, and display this content in connection with providing the services."
            },
            {
              "date": "2026-10-08",
              "text": "If payment is still outstanding after 30 days, Unipile permanently deletes all data associated with the account.",
              "quote": "If payment remains outstanding after 30 days, Unipile will permanently delete all data associated with the user account."
            },
            {
              "date": "2026-10-08",
              "text": "Integrators and their end users may not use the services in a way that breaches the terms of connected messaging, email or social platforms.",
              "quote": "Using Unipile’s services in a way that violates third-party Terms of Service, especially those of connected messaging, email, or social platforms"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.unipile.com/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-28",
          "words": 2843,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: September 28, 2026",
              "says": "Last updated 2026-09-28"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": false
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "account registration data is retained for the duration of the contractual relationship and for 30 days after account deletion, without prejudice to applicable statutory retention periods;",
              "says": "Names a period of 30 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Unipile may also use service providers required for processing carried out for its own purposes, including a payment provider to process online payments."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We disclose it only where necessary to provide our services, comply with the law, defend our rights, or protect our systems and users."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "For processing for which Unipile is the controller, you may exercise your rights by writing to dpo@unipile.com or start@unipile.com."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "For processing for which Unipile is the controller, you may exercise your rights by writing to dpo@unipile.com or start@unipile.com.",
              "says": "dpo@unipile.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Standard Contractual Clauses, Module 3, and a transfer impact assessment",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Unipile says it does not use data processed on behalf of customers for its own purposes.",
              "quote": "Unipile does not use data processed on behalf of its customers for its own purposes."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/unipile.json",
    "live": {
      "slug": "unipile",
      "probe": {
        "target": "https://developer.unipile.com/mcp?branch=v1.0",
        "method": "get",
        "lastAt": "2026-10-08T19:09:01.147207455Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 37,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 55,
        "p95ms24h": 115,
        "samples24h": 42,
        "samples30d": 42,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 42,
            "ok": 42
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.unipile.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T17:51:16.923603697Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "unipile/unipile-node-sdk",
          "version": "v1.9.3",
          "released": "2025-05-21",
          "seenAt": "2026-10-08T16:33:19.750124079Z"
        },
        {
          "registry": "npm",
          "name": "unipile-node-sdk",
          "version": "1.9.3",
          "seenAt": "2026-10-08T16:33:18.965183575Z"
        }
      ],
      "githubStars": 48,
      "npmWeekly": 82529,
      "securityTxt": {
        "url": "https://unipile.com/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:38:37.558927605Z"
      },
      "pages": [
        {
          "url": "https://developer.unipile.com/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:17:20.678778332Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "14178c9246c1"
        },
        {
          "url": "https://www.unipile.com/privacy-policy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:31:12.004667145Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "cbc48f825ecc"
        },
        {
          "url": "https://www.unipile.com/terms-of-use/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:31:14.04469123Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "3d0b4ec6b8b4"
        }
      ],
      "updatedAt": "2026-10-08T19:09:01.147207455Z"
    }
  }
}
