{
  "data": {
    "a": {
      "slug": "emailengine",
      "name": "EmailEngine",
      "vendor": "Postal Systems OÜ",
      "vendorUrl": "https://emailengine.app",
      "kind": "http-api",
      "category": "mailbox-access",
      "summary": "EmailEngine is self-hosted software from Postal Systems that puts one REST API over Gmail, Microsoft 365 and IMAP mailboxes, with webhooks for new mail and a beta MCP server. The owner runs it with Redis.",
      "url": "https://www.anchorterminal.com/tools/emailengine",
      "markdownUrl": "https://www.anchorterminal.com/tools/emailengine.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/emailengine.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/emailengine.json",
      "repo": "https://github.com/postalsys/emailengine",
      "license": "Source available under the EmailEngine licence agreement, version 2.1 of 17 October 2023. Not open source. The PHP SDK is MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "emailengine-app"
        },
        {
          "registry": "oci",
          "name": "postalsys/emailengine"
        },
        {
          "registry": "packagist",
          "name": "postalsys/emailengine-php"
        }
      ],
      "auth": "api-key",
      "authNotes": "Access is granted by whoever runs the instance, with no vendor approval or app review. Every request takes a 64-character token as `Authorization: Bearer`, or in the `access_token` query parameter. Tokens are created in the admin interface, with the CLI (`emailengine tokens issue`) or through POST /v1/tokens, which only mints tokens bound to one account or narrowed by a permissions record. A token carries scopes (`*`, api, metrics, smtp, imap-proxy, mcp, mcp-manage), an optional account binding, allowlists of actions (read, write, send, destructive) and groups, an IP allowlist, an expiry and a rate limit. The beta MCP endpoint also has an optional built-in OAuth 2.1 server. Mailboxes are connected with the operator's own Google and Microsoft OAuth2 apps, service accounts or IMAP passwords, which stay inside the instance.",
      "pricing": "paid",
      "pricingNotes": "$1,450 or EUR 1,200 a year, excluding VAT, for unlimited mailboxes, instances and API calls, bought with an account at postalsys.com. Every install can start a 14-day trial with full functionality from its own dashboard, with no sign-up and no card, so an agent's owner can start without a contract. When the trial ends the instance stops processing accounts until a licence key is added. A perpetual licence is sold through sales with no public price. The owner also pays for the server and Redis (https://emailengine.app/, https://postalsys.com/plans, checked 2026-10-08).",
      "priceSummary": "$120.83 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 on emailengine.app, in the documentation or in the OpenAPI spec (checked 2026-10-08). Licences are bought by card at postalsys.com, with Stripe named as the payment processor.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 2237,
        "npmWeekly": 388,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.emailengine.app/",
      "llmsTxt": "https://emailengine.app/llms.txt",
      "openapi": "https://go.emailengine.app/swagger.json",
      "capabilities": [
        "mailbox.read",
        "mailbox.search",
        "mailbox.send",
        "mailbox.drafts",
        "mailbox.sync"
      ],
      "tags": [
        "self-hosted",
        "source-available",
        "paid",
        "trial",
        "api-key",
        "openapi",
        "llms-txt",
        "mcp",
        "webhooks",
        "imap",
        "gmail",
        "microsoft-365",
        "docker",
        "nodejs",
        "php"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 128,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 80,
          "maintenance": 81,
          "payments": 40,
          "reliability": 79,
          "schema": 91,
          "security": 71,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "27 September 2026. Version 2.81.2, a patch release, removed the `bounces` field from the message list, message details and messageNew payloads, listed under bug fixes with no earlier notice found in the changelog. The bounce still arrives through the messageBounce webhook, and the entry is documented, so the smallest deduction applies (https://github.com/postalsys/emailengine/blob/master/CHANGELOG.md)"
        ],
        "verdict": "A self-hosted REST API over Gmail, Microsoft 365 and IMAP, with a public OpenAPI 3.0 spec and tokens that can be bound to one account, limited by action and group, and rate limited. It needs a server, Redis and a $1,450 yearly licence after a 14-day trial, and the MCP endpoint is a beta, off by default.",
        "bestFor": "A team that must keep mailbox access on its own infrastructure, has many mailboxes across Gmail, Microsoft 365 and IMAP, and can run a server and Redis.",
        "strengths": [
          "Public OpenAPI 3.0 spec for version 2.82.2 with 82 operations, plus llms.txt on both sites and a capabilities.json manifest",
          "Tokens can be bound to one account, narrowed by action and group, limited by IP range, expiry and rate, and are stored only as SHA-256 hashes",
          "Idempotency-Key header on both send routes, and 429 responses carry Retry-After and a ttl field",
          "Ten tagged releases between 7 September and 5 October 2026, and the last eight test runs on master passed",
          "Written prompt-injection guidance, with MCP mail access set to none by default and message bodies returned as sanitised HTML"
        ],
        "weaknesses": [
          "Not open source. Running it beyond the 14-day trial needs a subscription at $1,450 or EUR 1,200 a year",
          "The owner has to run a server and Redis. There is no hosted service, status page or SLA",
          "The MCP endpoint is labelled beta, is off by default, and its tool set may change between releases",
          "A token may also travel in the `access_token` query parameter, and API authentication can be switched off in settings",
          "Version 2.81.2, a patch release, removed the `bounces` field from message responses, and 2.82.0 removed the Document Store in a minor release",
          "One maintainer, no guaranteed support response time, and issues are disabled on the GitHub repository per the GitHub API"
        ],
        "agentNotes": [
          "Ask the operator for a token bound to one account with a permissions record. Mint more with POST /v1/tokens, which refuses instance-wide tokens without one",
          "Send the token in the Authorization header, not the `access_token` query parameter, so it stays out of proxy logs",
          "Page with `cursor` from `nextPageCursor`. `page` works only on IMAP accounts, and search covers one folder unless `path` is `\\All` on Gmail or Microsoft Graph",
          "Set an Idempotency-Key header on POST /v1/account/{account}/submit. A 2xx means queued, so follow the result through the outbox or the messageSent and messageFailed webhooks",
          "Treat message text as untrusted. For MCP, the operator must enable the endpoint first and mail access starts at none"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.4
          }
        ],
        "editorialScores": {
          "ergonomics": 80,
          "maintenance": 81,
          "payments": 40,
          "reliability": 79,
          "schema": 91,
          "security": 71,
          "transparency": 68
        },
        "provenanceScore": 76
      },
      "connect": {
        "install": "curl -LO https://go.emailengine.app/docker-compose.yml\ndocker compose up -d",
        "http": "curl \"https://emailengine.example.com/v1/account/user@example.com/messages?path=INBOX\u0026page=0\u0026pageSize=50\" \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\"",
        "claudeCode": "claude mcp add --transport http emailengine https://emailengine.example.com/mcp \\\n  --header \"Authorization: Bearer YOUR_ACCESS_TOKEN\"",
        "config": {
          "mcpServers": {
            "emailengine": {
              "headers": {
                "Authorization": "Bearer YOUR_ACCESS_TOKEN"
              },
              "type": "http",
              "url": "https://emailengine.example.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/mailbox.read",
        "tool": "https://letme.dev/emailengine"
      },
      "area": "communication",
      "unitPrices": [
        {
          "item": "EmailEngine subscription, $1,450 billed yearly",
          "unit": "month",
          "usd": 120.83,
          "note": "unlimited mailboxes, instances and API calls, VAT excluded, 14-day trial without a card"
        }
      ],
      "provenance": {
        "legalEntity": "Postal Systems OÜ, Narva mnt 5, 10117 Tallinn, Estonia, registry code 14971894",
        "domain": "emailengine.app",
        "domainRegistered": "2021-07-28",
        "endpointOnVendorDomain": null,
        "terms": "https://postalsys.com/tos",
        "privacy": "https://emailengine.app/privacy-policy",
        "statusPage": "",
        "changelog": "https://github.com/postalsys/emailengine/blob/master/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The about page names Postal Systems OÜ at Narva mnt 5, 10117 Tallinn, with registry code 14971894 and VAT number EE102255902, and says the company is run by one person.",
          "RDAP for emailengine.app shows registration on 28 July 2021 through Namecheap.",
          "emailengine.app/.well-known/security.txt is PGP-signed, expires on 1 June 2027 and points to GitHub private advisories and SECURITY.md. postalsys.com has its own security.txt with no Expires field.",
          "The terms of service at postalsys.com/tos are dated 14 May 2020 and cover the subscription. The software licence is the EmailEngine licence agreement, version 2.1 of 17 October 2023, governed by Estonian law.",
          "The privacy policy at emailengine.app/privacy-policy has an effective date of 29 July 2026 and covers the website and the licence account, with Stripe named for payments.",
          "The API runs on the owner's instance, so there is no vendor endpoint and no status page."
        ],
        "score": 76
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/emailengine.json",
      "live": {
        "slug": "emailengine",
        "versions": [
          {
            "registry": "github",
            "name": "postalsys/emailengine",
            "version": "v2.83.1",
            "released": "2026-10-08",
            "seenAt": "2026-10-09T16:51:53.89216043Z"
          },
          {
            "registry": "npm",
            "name": "emailengine-app",
            "version": "2.83.1",
            "seenAt": "2026-10-09T16:51:52.899054872Z"
          }
        ],
        "githubStars": 2238,
        "npmWeekly": 635,
        "securityTxt": {
          "url": "https://emailengine.app/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-06-01T00:00:00.000Z",
          "checkedAt": "2026-10-09T15:39:42.849079277Z"
        },
        "llmsTxt": {
          "url": "https://emailengine.app/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:01:52.760550973Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/postalsys/emailengine/master/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:45:57.369645087Z",
            "changedAt": "2026-10-09T18:45:57.369645087Z",
            "fingerprint": "bad92b1dd95d"
          },
          {
            "url": "https://emailengine.app/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-09T18:39:03.761468001Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "bf031c33ef50"
          },
          {
            "url": "https://postalsys.com/tos",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-09T18:43:42.3890862Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cb7a76a9cb6a"
          }
        ],
        "updatedAt": "2026-10-09T18:45:57.369645087Z"
      }
    },
    "answer": "EmailEngine scores 71.4 (BB) on agent readiness against Himalaya's 64.5 (B), and leads in 4 of 7 scored categories. Himalaya leads on reliability, payments \u0026 pricing and maintenance \u0026 community.",
    "b": {
      "slug": "himalaya",
      "name": "Himalaya",
      "vendor": "Pimalaya",
      "vendorUrl": "https://pimalaya.org",
      "kind": "sdk",
      "category": "mailbox-access",
      "summary": "Himalaya is an open-source command-line email client from the Pimalaya project. It lists, searches, reads, composes and sends mail over IMAP, SMTP, JMAP, the Gmail API, Microsoft Graph and local stores, with JSON output for scripts and agents.",
      "url": "https://www.anchorterminal.com/tools/himalaya",
      "markdownUrl": "https://www.anchorterminal.com/tools/himalaya.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/himalaya.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/himalaya.json",
      "repo": "https://github.com/pimalaya/himalaya",
      "license": "MIT OR Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "cargo",
          "name": "himalaya"
        }
      ],
      "auth": "mixed",
      "authNotes": "Himalaya issues no credential of its own. It signs in to the mailbox with what the provider accepts, which is an app password or account password over SASL for IMAP and SMTP, a bearer token or basic auth for JMAP, and one OAuth 2.0 bearer token for the Gmail API or Microsoft Graph. Each secret is read from a shell command such as a password manager, or from a raw value in the config file. Version 2 ships no OAuth flow, so tokens come from an external broker such as `ortie` and an OAuth app the owner registers with Google or Microsoft.",
      "pricing": "free",
      "pricingNotes": "Free software with nothing to buy, and the sponsor page states there is no paid tier. An agent can start with the binary and a mailbox credential. Pimalaya sells optional partnerships, from EUR 3,000 a year for email providers and EUR 5,000 for integrators, and describes a EUR 12 a year sign-in service for Gmail and Microsoft 365 as planned and not built (checked 2026-10-09).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the source or pimalaya.org (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 7412,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://github.com/pimalaya/himalaya",
      "capabilities": [
        "mailbox.read",
        "mailbox.search",
        "mailbox.send",
        "mailbox.drafts"
      ],
      "tags": [
        "open-source",
        "local",
        "cli",
        "rust",
        "free",
        "no-card",
        "imap",
        "smtp",
        "jmap",
        "gmail",
        "microsoft-graph",
        "json-output"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.5,
        "grade": "B",
        "agentReady": false,
        "rank": 348,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 88,
          "payments": 60,
          "reliability": 84,
          "schema": 70,
          "security": 43,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -3,
        "negativeNotes": [
          "2 October 2026. Until 2.2.1, `message send` passed the `Bcc:` header through SMTP unchanged, so every recipient could see the blind recipients. Issue #747 reported it against 2.1.0 on 12 September 2026, the fix was committed on 26 September and released on 2 October, and the changelog documents it. No security advisory was published. Fixed and documented, so the smaller deduction applies (https://github.com/pimalaya/himalaya/issues/747)"
        ],
        "verdict": "One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.",
        "bestFor": "An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.",
        "strengths": [
          "Shared commands for mailboxes, envelopes, flags, messages and attachments run the same way over IMAP, JMAP, Gmail, Microsoft Graph, Maildir and mbox",
          "`himalaya json-schema` prints a JSON Schema for the `--json` output of 90 commands, and `message read --json` returns one designed view on every backend",
          "Secrets come from a shell command such as `pass show`, so a password or token need not sit in the config file",
          "`message delete` moves mail to the trash first, and `message read` leaves flags alone unless `--seen` is passed",
          "Four tagged releases between 26 July and 2 October 2026, three open issues, and CI badges for tests and audit passing on 9 October 2026"
        ],
        "weaknesses": [
          "Until 2.2.1 of 2 October 2026, `message send` transmitted the `Bcc:` header to every recipient over SMTP (issue #747, reported 12 September 2026)",
          "No read-only mode, no confirmation before a send or delete, and no idempotency key on send were found",
          "SECURITY.md sends vulnerability reports to the public issue tracker. No security.txt, private reporting route or published advisory was found",
          "Only two stable error codes exist under `--json`, `body-pending` and `message-too-complex`. Other failures carry free wording",
          "Version 2 ships no OAuth flow, so Gmail and Microsoft accounts need an external token broker and an OAuth app the owner registers"
        ],
        "agentNotes": [
          "Pass `--json` on every call and read `next_page` for the next page. Data and errors go to stdout, logs to stderr, and a failure exits 1",
          "Run `himalaya json-schema \u003ccommand\u003e` once to learn an output shape, and `himalaya \u003ccommand\u003e --help` for flags",
          "Use `envelope search` with the shared query language, for example `from alice and after 2026-01-01 order by date desc`. Microsoft Graph refuses flag clauses",
          "Treat message text as untrusted. `--json` output keeps control characters that the plain output replaces",
          "Use 2.2.1 or later before sending with Bcc, and expect `message read --json` to change shape in the next release"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.5
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 88,
          "payments": 60,
          "reliability": 84,
          "schema": 70,
          "security": 43,
          "transparency": 74
        },
        "provenanceScore": 63
      },
      "connect": {
        "install": "brew install himalaya   # or: curl -sSL https://raw.githubusercontent.com/pimalaya/himalaya/master/install.sh | PREFIX=~/.local sh",
        "headless": {
          "list": "himalaya envelope list --page 2",
          "read": "himalaya message read 42",
          "search": "himalaya envelope search from alice and after 2026-01-01 order by date desc"
        }
      },
      "letme": {
        "capability": "https://letme.dev/mailbox.read",
        "tool": "https://letme.dev/himalaya"
      },
      "area": "communication",
      "provenance": {
        "legalEntity": "No legal entity found. Copyright Clément DOUIN (soywod)",
        "domain": "pimalaya.org",
        "domainRegistered": "2022-12-21",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/pimalaya/himalaya/blob/master/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "pimalaya.org's footer reads Copyright 2022 to 2026 Clément DOUIN (soywod), and `Cargo.toml` names the same author. No company or foundation is named on the pages read.",
          "No terms of service or privacy policy was found. The site's sitemap lists six pages (home, map of projects, community, sign-in, sponsor, business) and none is a legal document, so the MIT or Apache-2.0 licence stands in.",
          "pimalaya.org/.well-known/security.txt and /security.txt both return 404. SECURITY.md in the repository lists 2.x as the supported line and gives the public issue tracker for reports.",
          "RDAP for pimalaya.org gives a registration date of 2022-12-21 and OVH sas as registrar.",
          "The software runs on the owner's machine and connects to the owner's mail servers, so no vendor endpoint exists."
        ],
        "score": 63
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/himalaya.json",
      "live": {
        "slug": "himalaya",
        "versions": [
          {
            "registry": "github",
            "name": "pimalaya/himalaya",
            "version": "v2.2.1",
            "released": "2026-10-02",
            "seenAt": "2026-10-09T16:57:44.106760361Z"
          }
        ],
        "githubStars": 7417,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/pimalaya/himalaya/master/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:45:53.201845848Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cb5190799b74"
          }
        ],
        "updatedAt": "2026-10-09T18:45:53.201845848Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "SDK + MCP",
        "name": "Kind"
      },
      {
        "a": "Postal Systems OÜ",
        "b": "Pimalaya",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Source available under the EmailEngine licence agreement, version 2.1 of 17 October 2023. Not open source. The PHP SDK is MIT",
        "b": "MIT OR Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-05",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "2.2k stars, 388 npm/wk",
        "b": "7.4k stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "EmailEngine scores 71.4 (BB) on agent readiness against Himalaya's 64.5 (B), and leads in 4 of 7 scored categories. Himalaya leads on reliability, payments \u0026 pricing and maintenance \u0026 community.",
        "question": "Which is better for AI agents, EmailEngine or Himalaya?"
      },
      {
        "answer": "No hosted endpoint is listed for EmailEngine. No hosted endpoint is listed for Himalaya.",
        "question": "Can an agent call EmailEngine and Himalaya without installing anything?"
      },
      {
        "answer": "No open-source release is listed for EmailEngine. Himalaya is open source (MIT OR Apache-2.0).",
        "question": "Are EmailEngine and Himalaya open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 91 against 70",
          "Agent ergonomics, 80 against 65",
          "Security \u0026 auth, 71 against 43"
        ],
        "also": [
          "Agent-ready, a grade of BB or better"
        ],
        "goodFor": "A team that must keep mailbox access on its own infrastructure, has many mailboxes across Gmail, Microsoft 365 and IMAP, and can run a server and Redis.",
        "slug": "emailengine",
        "watchFor": "Not open source. Running it beyond the 14-day trial needs a subscription at $1,450 or EUR 1,200 a year"
      },
      {
        "aheadOn": [
          "Reliability, 84 against 79",
          "Payments \u0026 pricing, 60 against 40",
          "Maintenance \u0026 community, 88 against 81"
        ],
        "also": [
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.",
        "slug": "himalaya",
        "watchFor": "Until 2.2.1 of 2 October 2026, `message send` transmitted the `Bcc:` header to every recipient over SMTP (issue #747, reported 12 September 2026)"
      }
    ],
    "job": {
      "capability": "mailbox.read",
      "name": "Mailbox access"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aurinko-email-vs-emailengine.json",
        "title": "Aurinko Email API vs EmailEngine",
        "url": "https://www.anchorterminal.com/compare/aurinko-email-vs-emailengine"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aurinko-email-vs-himalaya.json",
        "title": "Aurinko Email API vs Himalaya",
        "url": "https://www.anchorterminal.com/compare/aurinko-email-vs-himalaya"
      },
      {
        "json": "https://www.anchorterminal.com/compare/emailengine-vs-fastmail.json",
        "title": "EmailEngine vs Fastmail API (JMAP)",
        "url": "https://www.anchorterminal.com/compare/emailengine-vs-fastmail"
      },
      {
        "json": "https://www.anchorterminal.com/compare/emailengine-vs-gmail-api.json",
        "title": "EmailEngine vs Gmail API",
        "url": "https://www.anchorterminal.com/compare/emailengine-vs-gmail-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/emailengine-vs-nylas-email.json",
        "title": "EmailEngine vs Nylas Email API",
        "url": "https://www.anchorterminal.com/compare/emailengine-vs-nylas-email"
      },
      {
        "json": "https://www.anchorterminal.com/compare/emailengine-vs-outlook-mail-graph.json",
        "title": "EmailEngine vs Outlook Mail (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/emailengine-vs-outlook-mail-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/emailengine-vs-unipile.json",
        "title": "EmailEngine vs Unipile",
        "url": "https://www.anchorterminal.com/compare/emailengine-vs-unipile"
      },
      {
        "json": "https://www.anchorterminal.com/compare/emailengine-vs-zoho-mail.json",
        "title": "EmailEngine vs Zoho Mail API",
        "url": "https://www.anchorterminal.com/compare/emailengine-vs-zoho-mail"
      },
      {
        "json": "https://www.anchorterminal.com/compare/fastmail-vs-himalaya.json",
        "title": "Fastmail API (JMAP) vs Himalaya",
        "url": "https://www.anchorterminal.com/compare/fastmail-vs-himalaya"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gmail-api-vs-himalaya.json",
        "title": "Gmail API vs Himalaya",
        "url": "https://www.anchorterminal.com/compare/gmail-api-vs-himalaya"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-nylas-email.json",
        "title": "Himalaya vs Nylas Email API",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-nylas-email"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-outlook-mail-graph.json",
        "title": "Himalaya vs Outlook Mail (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-outlook-mail-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-unipile.json",
        "title": "Himalaya vs Unipile",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-unipile"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail.json",
        "title": "Himalaya vs Zoho Mail API",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail"
      }
    ],
    "scores": [
      {
        "by": 5,
        "edge": "himalaya",
        "emailengine": 79,
        "himalaya": 84,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 21,
        "edge": "emailengine",
        "emailengine": 91,
        "himalaya": 70,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 15,
        "edge": "emailengine",
        "emailengine": 80,
        "himalaya": 65,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 28,
        "edge": "emailengine",
        "emailengine": 71,
        "himalaya": 43,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 20,
        "edge": "himalaya",
        "emailengine": 40,
        "himalaya": 60,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 7,
        "edge": "himalaya",
        "emailengine": 81,
        "himalaya": 88,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 3,
        "edge": "emailengine",
        "emailengine": 72,
        "himalaya": 69,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "EmailEngine scores 71.4 (BB) on agent readiness against Himalaya's 64.5 (B), and leads in 4 of 7 scored categories. Himalaya leads on reliability, payments \u0026 pricing and maintenance \u0026 community. Both do mailbox access.",
    "verdicts": {
      "emailengine": "A self-hosted REST API over Gmail, Microsoft 365 and IMAP, with a public OpenAPI 3.0 spec and tokens that can be bound to one account, limited by action and group, and rate limited. It needs a server, Redis and a $1,450 yearly licence after a 14-day trial, and the MCP endpoint is a beta, off by default.",
      "himalaya": "One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/emailengine-vs-himalaya",
    "json": "https://www.anchorterminal.com/compare/emailengine-vs-himalaya.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/emailengine-vs-himalaya.md",
    "slim": "https://www.anchorterminal.com/compare/emailengine-vs-himalaya.min.md"
  },
  "markdown": "EmailEngine scores 71.4 (BB) on agent readiness against Himalaya's 64.5 (B), and leads in 4 of 7 scored categories. Himalaya leads on reliability, payments \u0026 pricing and maintenance \u0026 community. Both do mailbox access.\n\n- EmailEngine: grade BB, 71.4/100, rank #128 of 950. Markdown https://www.anchorterminal.com/tools/emailengine.md · JSON https://www.anchorterminal.com/api/v1/tools/emailengine.json\n- Himalaya: grade B, 64.5/100, rank #348 of 950. Markdown https://www.anchorterminal.com/tools/himalaya.md · JSON https://www.anchorterminal.com/api/v1/tools/himalaya.json\n- Best mailbox access APIs for AI agents: https://www.anchorterminal.com/best/mailbox-access/index.md\n- All 36 mailboxes comparisons: https://www.anchorterminal.com/compare/mailbox-access/index.md\n\n## Which one, for what\n\n### EmailEngine (BB)\n\nGood for: A team that must keep mailbox access on its own infrastructure, has many mailboxes across Gmail, Microsoft 365 and IMAP, and can run a server and Redis.\n\nAhead on:\n- Schema \u0026 documentation, 91 against 70\n- Agent ergonomics, 80 against 65\n- Security \u0026 auth, 71 against 43\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n\nWatch for: Not open source. Running it beyond the 14-day trial needs a subscription at $1,450 or EUR 1,200 a year\n\n### Himalaya (B)\n\nGood for: An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.\n\nAhead on:\n- Reliability, 84 against 79\n- Payments \u0026 pricing, 60 against 40\n- Maintenance \u0026 community, 88 against 81\n\nAlso in its favour:\n- Free to start without a card\n- Open source\n\nWatch for: Until 2.2.1 of 2 October 2026, `message send` transmitted the `Bcc:` header to every recipient over SMTP (issue #747, reported 12 September 2026)\n\n\n## Score by category\n\n| Category | Weight | EmailEngine | Himalaya | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 79 | 84 | Himalaya +5 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 91 | 70 | EmailEngine +21 |\n| Agent ergonomics | 13% (16.2 this run) | 80 | 65 | EmailEngine +15 |\n| Security \u0026 auth | 14% (17.5 this run) | 71 | 43 | EmailEngine +28 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 60 | Himalaya +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 81 | 88 | Himalaya +7 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 69 | EmailEngine +3 |\n| Negative events | ≤15 | -3 | -3 | |\n| **Total** | | **71.4 · BB** | **64.5 · B** | |\n\n## Facts side by side\n\n| Fact | EmailEngine | Himalaya |\n| --- | --- | --- |\n| Kind | HTTP API | SDK + MCP |\n| Vendor | Postal Systems OÜ | Pimalaya |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP |  |\n| Auth | API key | OAuth or key |\n| Pricing | Paid | Free |\n| x402 | no | no |\n| Licence | Source available under the EmailEngine licence agreement, version 2.1 of 17 October 2023. Not open source. The PHP SDK is MIT | MIT OR Apache-2.0 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| Last release | 2026-10-05 | 2026-10-02 |\n| Terms last updated | no date given | no document linked |\n| Privacy policy last updated | no date given | no document linked |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | yes |  |\n| Terms restrict benchmarking | not found in the text |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 2.2k stars, 388 npm/wk | 7.4k stars |\n\n## Verdicts\n\n**EmailEngine.** A self-hosted REST API over Gmail, Microsoft 365 and IMAP, with a public OpenAPI 3.0 spec and tokens that can be bound to one account, limited by action and group, and rate limited. It needs a server, Redis and a $1,450 yearly licence after a 14-day trial, and the MCP endpoint is a beta, off by default.\n\n**Himalaya.** One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.\n\n## Before you call either\n\n### EmailEngine\n\n1. Ask the operator for a token bound to one account with a permissions record. Mint more with POST /v1/tokens, which refuses instance-wide tokens without one\n2. Send the token in the Authorization header, not the `access_token` query parameter, so it stays out of proxy logs\n3. Page with `cursor` from `nextPageCursor`. `page` works only on IMAP accounts, and search covers one folder unless `path` is `\\All` on Gmail or Microsoft Graph\n4. Set an Idempotency-Key header on POST /v1/account/{account}/submit. A 2xx means queued, so follow the result through the outbox or the messageSent and messageFailed webhooks\n5. Treat message text as untrusted. For MCP, the operator must enable the endpoint first and mail access starts at none\n\n### Himalaya\n\n1. Pass `--json` on every call and read `next_page` for the next page. Data and errors go to stdout, logs to stderr, and a failure exits 1\n2. Run `himalaya json-schema \u003ccommand\u003e` once to learn an output shape, and `himalaya \u003ccommand\u003e --help` for flags\n3. Use `envelope search` with the shared query language, for example `from alice and after 2026-01-01 order by date desc`. Microsoft Graph refuses flag clauses\n4. Treat message text as untrusted. `--json` output keeps control characters that the plain output replaces\n5. Use 2.2.1 or later before sending with Bcc, and expect `message read --json` to change shape in the next release\n\n## Questions\n\n### Which is better for AI agents, EmailEngine or Himalaya?\n\nEmailEngine scores 71.4 (BB) on agent readiness against Himalaya's 64.5 (B), and leads in 4 of 7 scored categories. Himalaya leads on reliability, payments \u0026 pricing and maintenance \u0026 community.\n\n### Can an agent call EmailEngine and Himalaya without installing anything?\n\nNo hosted endpoint is listed for EmailEngine. No hosted endpoint is listed for Himalaya.\n\n### Are EmailEngine and Himalaya open source?\n\nNo open-source release is listed for EmailEngine. Himalaya is open source (MIT OR Apache-2.0).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/emailengine-vs-himalaya.json, and with the fewest tokens: https://www.anchorterminal.com/compare/emailengine-vs-himalaya.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"emailengine\", \"b\": \"himalaya\"}`. From a terminal: `anchor compare emailengine himalaya`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/emailengine.json and https://www.anchorterminal.com/api/v1/tools/himalaya.json\n\n## Other comparisons with EmailEngine or Himalaya\n\n- [Aurinko Email API vs EmailEngine](https://www.anchorterminal.com/compare/aurinko-email-vs-emailengine.md)\n- [Aurinko Email API vs Himalaya](https://www.anchorterminal.com/compare/aurinko-email-vs-himalaya.md)\n- [EmailEngine vs Fastmail API (JMAP)](https://www.anchorterminal.com/compare/emailengine-vs-fastmail.md)\n- [EmailEngine vs Gmail API](https://www.anchorterminal.com/compare/emailengine-vs-gmail-api.md)\n- [EmailEngine vs Nylas Email API](https://www.anchorterminal.com/compare/emailengine-vs-nylas-email.md)\n- [EmailEngine vs Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/compare/emailengine-vs-outlook-mail-graph.md)\n- [EmailEngine vs Unipile](https://www.anchorterminal.com/compare/emailengine-vs-unipile.md)\n- [EmailEngine vs Zoho Mail API](https://www.anchorterminal.com/compare/emailengine-vs-zoho-mail.md)\n- [Fastmail API (JMAP) vs Himalaya](https://www.anchorterminal.com/compare/fastmail-vs-himalaya.md)\n- [Gmail API vs Himalaya](https://www.anchorterminal.com/compare/gmail-api-vs-himalaya.md)\n- [Himalaya vs Nylas Email API](https://www.anchorterminal.com/compare/himalaya-vs-nylas-email.md)\n- [Himalaya vs Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/compare/himalaya-vs-outlook-mail-graph.md)\n- [Himalaya vs Unipile](https://www.anchorterminal.com/compare/himalaya-vs-unipile.md)\n- [Himalaya vs Zoho Mail API](https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "EmailEngine vs Himalaya",
        "url": ""
      }
    ],
    "description": "EmailEngine scores 71.4 (BB) to Himalaya's 64.5 (B) for mailbox access. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "EmailEngine BB 71.4",
      "Himalaya B 64.5",
      "scores"
    ],
    "h1": "EmailEngine vs Himalaya",
    "image": "https://www.anchorterminal.com/assets/og/compare-emailengine-vs-himalaya.png",
    "path": "/compare/emailengine-vs-himalaya",
    "published": "2026-10-01",
    "section": "tools",
    "title": "EmailEngine vs Himalaya for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/emailengine-vs-himalaya"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 730
  },
  "version": 1
}
