{
  "data": {
    "a": {
      "slug": "fastmail",
      "name": "Fastmail API (JMAP)",
      "vendor": "Fastmail Pty Ltd",
      "vendorUrl": "https://www.fastmail.com",
      "kind": "http-api",
      "category": "mailbox-access",
      "summary": "Fastmail is a paid email, calendar and contacts host from Fastmail Pty Ltd in Melbourne. Agents reach a customer's mailbox through JMAP at api.fastmail.com, the open IETF protocol, or through the company's own MCP server.",
      "url": "https://www.anchorterminal.com/tools/fastmail",
      "markdownUrl": "https://www.anchorterminal.com/tools/fastmail.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/fastmail.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/fastmail.json",
      "repo": "https://github.com/fastmail/JMAP-Samples",
      "license": "Proprietary service under Fastmail's API Terms of Service and API Developer Policy. JMAP is an open IETF standard, and the sample code on GitHub is MIT",
      "transports": [
        "http"
      ],
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is self-serve for the account owner. An API token is made in Settings, Privacy \u0026 Security, Manage API tokens, as type JMAP or MCP, with scopes for read-only access, Email, Email submission, Contacts and Masked Email, and is sent as `Authorization: Bearer`. Tokens are not available on Basic plans. An app distributed to other users needs OAuth 2.0 (authorisation code grant, PKCE S256, rotating refresh tokens), and the developer page says clients are registered by hand through the partnerships team. The MCP server takes OAuth or an MCP-type token, and the authorisation server metadata lists a registration endpoint.",
      "pricing": "paid",
      "pricingNotes": "API access is part of a mailbox plan, with no per-call charge. Individual is $6 a month or $60 a year, Business Standard $6 a user a month and Professional $10. Basic, at $4, has no API tokens. A trial of up to 30 days needs no card, so an agent's owner can start without a contract, with sending capped at 120 messages a day (https://www.fastmail.com/pricing/us/, checked 2026-10-08).",
      "priceSummary": "$6 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 on the developer page, the pricing page or the 401 responses from api.fastmail.com (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 123,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.fastmail.com/dev/",
      "capabilities": [
        "mailbox.read",
        "mailbox.search",
        "mailbox.send",
        "mailbox.drafts",
        "mailbox.sync"
      ],
      "tags": [
        "hosted",
        "paid",
        "trial",
        "jmap",
        "open-standard",
        "oauth",
        "api-key",
        "mcp",
        "email",
        "contacts",
        "masked-email",
        "status-page",
        "bug-bounty",
        "eu-data-residency"
      ],
      "lastRelease": "2026-04-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 54.1,
        "grade": "C",
        "agentReady": false,
        "rank": 694,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 26,
          "payments": 30,
          "reliability": 54,
          "schema": 52,
          "security": 60,
          "transparency": 74
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "A mailbox API built on the open JMAP standard, with read-only tokens, six OAuth scopes and an MCP server that separates read, write and send access. Fastmail publishes no OpenAPI file, SDK, API changelog, request rate limit or SLA, and its customer terms forbid programmatically generated email to addresses outside the account.",
        "bestFor": "An agent working in its owner's own Fastmail mailbox, where JMAP gives batched reads, structured search and state-based sync on an open standard, and MCP gives a ready connection with read, write and send levels.",
        "strengths": [
          "JMAP is an IETF standard (RFC 8620, 8621 and 9610), so requests, types and errors are specified in public and not tied to one vendor",
          "API tokens can be read-only or limited to mail, sending, contacts or Masked Email, and are revocable in settings",
          "OAuth 2.0 requires PKCE with S256, rotates refresh tokens on every use and revokes the grant if an old one is replayed",
          "The MCP server at `https://api.fastmail.com/mcp`, launched 22 April 2026, has separate read, write and send levels chosen on the consent screen",
          "`properties`, `limit`, `bodyProperties` and `maxBodyValueBytes` size responses, and several calls batch into one request with back-references",
          "30-day trial with no card, a privacy policy with stated retention periods and a published list of 36 subprocessors"
        ],
        "weaknesses": [
          "The customer terms forbid programmatically generated email to addresses outside the account, and say the service is not for machine-to-machine workflows",
          "No OpenAPI file, llms.txt, official SDK or API changelog. The developer page points to the RFCs and four sample scripts",
          "No request rate limit, Retry-After guidance or SLA was found, and the API terms allow backwards-incompatible changes with notice only promised as an attempt",
          "Three partial outages between 25 August and 7 October 2026 blocked access for some users for 8 hours 16 minutes, 1 hour 8 minutes and 5 hours 23 minutes",
          "API tokens are not available on Basic plans, and the developer page says OAuth clients are registered by hand through the partnerships team",
          "No idempotency key on `EmailSubmission/set`, no confirmation step for delete or send, and no per-call access log",
          "Fastmail says it has not pursued SOC certification, and no ISO 27001 certificate was found"
        ],
        "agentNotes": [
          "Fetch `https://api.fastmail.com/jmap/session` with `Authorization: Bearer \u003ctoken\u003e` first. It returns the API URL, account IDs and the request limits to stay under",
          "Ask the owner for a read-only token unless the task writes. Sending needs both the Email and Email submission scopes",
          "Request only the `properties` you need. Body text is not returned unless `fetchTextBodyValues` is set, and `maxBodyValueBytes` caps it",
          "Sync with `Email/changes` from a stored state. On `cannotCalculateChanges`, fetch again from scratch",
          "Do not send generated mail to outside recipients without the owner's review. The customer terms forbid it, and trial accounts stop at 120 messages a day"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 54.1
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 26,
          "payments": 30,
          "reliability": 54,
          "schema": 52,
          "security": 60,
          "transparency": 62
        },
        "provenanceScore": 86
      },
      "connect": {
        "http": "curl https://api.fastmail.com/jmap/session \\\n  -H \"Authorization: Bearer YOUR_API_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/mailbox.read",
        "tool": "https://letme.dev/fastmail"
      },
      "area": "communication",
      "unitPrices": [
        {
          "item": "Individual plan, billed monthly",
          "unit": "month",
          "usd": 6,
          "note": "one mailbox, API tokens included, 30-day trial without a card"
        },
        {
          "item": "Individual plan, $60 billed yearly",
          "unit": "month",
          "usd": 5,
          "note": "one mailbox, API tokens included"
        },
        {
          "item": "Business Standard, billed monthly",
          "unit": "seat-month",
          "usd": 6,
          "note": "per user, API tokens included. Basic at $4 has none"
        }
      ],
      "provenance": {
        "legalEntity": "Fastmail Pty Ltd, ACN 142 646 580, PO Box 234, Collins Street West, VIC 8007, Australia",
        "domain": "fastmail.com",
        "domainRegistered": "1994-12-09",
        "endpointOnVendorDomain": true,
        "terms": "https://www.fastmail.com/policies/api-terms-of-service/",
        "privacy": "https://www.fastmail.com/policies/privacy/",
        "statusPage": "https://fastmailstatus.com/",
        "changelog": "",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The privacy policy names Fastmail Pty Ltd with ABN 31 142 646 580, and the terms of service give ACN 142 646 580, both at PO Box 234, Collins Street West, VIC 8007.",
          "RDAP for fastmail.com shows registration on 9 December 1994 and expiry on 8 December 2034.",
          "www.fastmail.com/.well-known/security.txt expires on 24 June 2027 and points to the bug bounty page for contact and policy.",
          "The API Terms of Service and the API Developer Policy together form the contract for API use, governed by the law of Victoria, Australia. The customer Terms of Service, last changed 10 October 2025 per its version list, govern the account the API reaches.",
          "The privacy policy lists versions back to 25 May 2020, the latest dated 2 July 2026.",
          "JMAP, OAuth and MCP all answer on api.fastmail.com. The status page is on fastmailstatus.com, hosted by Instatus.",
          "No API changelog was found."
        ],
        "score": 86
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/fastmail.json",
      "live": {
        "slug": "fastmail",
        "vendorStatus": {
          "page": "https://fastmailstatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:50:33.514978799Z"
        },
        "githubStars": 123,
        "securityTxt": {
          "url": "https://fastmail.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-06-24T00:00:00.000Z",
          "checkedAt": "2026-10-09T15:40:02.699489243Z"
        },
        "pages": [
          {
            "url": "https://www.fastmail.com/pricing/us/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:50:06.55208356Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f82655a263b3"
          },
          {
            "url": "https://www.fastmail.com/policies/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:50:04.525742369Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "46e72082b1b3"
          },
          {
            "url": "https://www.fastmail.com/policies/api-terms-of-service/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:50:02.423137198Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f73a69f7e8ec"
          }
        ],
        "updatedAt": "2026-10-10T00:50:33.514978799Z"
      }
    },
    "answer": "Himalaya scores 64.5 (B) on agent readiness against Fastmail API (JMAP)'s 54.1 (C), and leads in 4 of 7 scored categories. Fastmail API (JMAP) leads on agent ergonomics, security \u0026 auth and transparency \u0026 trust.",
    "b": {
      "slug": "himalaya",
      "name": "Himalaya",
      "vendor": "Pimalaya",
      "vendorUrl": "https://pimalaya.org",
      "kind": "sdk",
      "category": "mailbox-access",
      "summary": "Himalaya is an open-source command-line email client from the Pimalaya project. It lists, searches, reads, composes and sends mail over IMAP, SMTP, JMAP, the Gmail API, Microsoft Graph and local stores, with JSON output for scripts and agents.",
      "url": "https://www.anchorterminal.com/tools/himalaya",
      "markdownUrl": "https://www.anchorterminal.com/tools/himalaya.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/himalaya.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/himalaya.json",
      "repo": "https://github.com/pimalaya/himalaya",
      "license": "MIT OR Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "cargo",
          "name": "himalaya"
        }
      ],
      "auth": "mixed",
      "authNotes": "Himalaya issues no credential of its own. It signs in to the mailbox with what the provider accepts, which is an app password or account password over SASL for IMAP and SMTP, a bearer token or basic auth for JMAP, and one OAuth 2.0 bearer token for the Gmail API or Microsoft Graph. Each secret is read from a shell command such as a password manager, or from a raw value in the config file. Version 2 ships no OAuth flow, so tokens come from an external broker such as `ortie` and an OAuth app the owner registers with Google or Microsoft.",
      "pricing": "free",
      "pricingNotes": "Free software with nothing to buy, and the sponsor page states there is no paid tier. An agent can start with the binary and a mailbox credential. Pimalaya sells optional partnerships, from EUR 3,000 a year for email providers and EUR 5,000 for integrators, and describes a EUR 12 a year sign-in service for Gmail and Microsoft 365 as planned and not built (checked 2026-10-09).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the source or pimalaya.org (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 7412,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://github.com/pimalaya/himalaya",
      "capabilities": [
        "mailbox.read",
        "mailbox.search",
        "mailbox.send",
        "mailbox.drafts"
      ],
      "tags": [
        "open-source",
        "local",
        "cli",
        "rust",
        "free",
        "no-card",
        "imap",
        "smtp",
        "jmap",
        "gmail",
        "microsoft-graph",
        "json-output"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.5,
        "grade": "B",
        "agentReady": false,
        "rank": 348,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 88,
          "payments": 60,
          "reliability": 84,
          "schema": 70,
          "security": 43,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -3,
        "negativeNotes": [
          "2 October 2026. Until 2.2.1, `message send` passed the `Bcc:` header through SMTP unchanged, so every recipient could see the blind recipients. Issue #747 reported it against 2.1.0 on 12 September 2026, the fix was committed on 26 September and released on 2 October, and the changelog documents it. No security advisory was published. Fixed and documented, so the smaller deduction applies (https://github.com/pimalaya/himalaya/issues/747)"
        ],
        "verdict": "One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.",
        "bestFor": "An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.",
        "strengths": [
          "Shared commands for mailboxes, envelopes, flags, messages and attachments run the same way over IMAP, JMAP, Gmail, Microsoft Graph, Maildir and mbox",
          "`himalaya json-schema` prints a JSON Schema for the `--json` output of 90 commands, and `message read --json` returns one designed view on every backend",
          "Secrets come from a shell command such as `pass show`, so a password or token need not sit in the config file",
          "`message delete` moves mail to the trash first, and `message read` leaves flags alone unless `--seen` is passed",
          "Four tagged releases between 26 July and 2 October 2026, three open issues, and CI badges for tests and audit passing on 9 October 2026"
        ],
        "weaknesses": [
          "Until 2.2.1 of 2 October 2026, `message send` transmitted the `Bcc:` header to every recipient over SMTP (issue #747, reported 12 September 2026)",
          "No read-only mode, no confirmation before a send or delete, and no idempotency key on send were found",
          "SECURITY.md sends vulnerability reports to the public issue tracker. No security.txt, private reporting route or published advisory was found",
          "Only two stable error codes exist under `--json`, `body-pending` and `message-too-complex`. Other failures carry free wording",
          "Version 2 ships no OAuth flow, so Gmail and Microsoft accounts need an external token broker and an OAuth app the owner registers"
        ],
        "agentNotes": [
          "Pass `--json` on every call and read `next_page` for the next page. Data and errors go to stdout, logs to stderr, and a failure exits 1",
          "Run `himalaya json-schema \u003ccommand\u003e` once to learn an output shape, and `himalaya \u003ccommand\u003e --help` for flags",
          "Use `envelope search` with the shared query language, for example `from alice and after 2026-01-01 order by date desc`. Microsoft Graph refuses flag clauses",
          "Treat message text as untrusted. `--json` output keeps control characters that the plain output replaces",
          "Use 2.2.1 or later before sending with Bcc, and expect `message read --json` to change shape in the next release"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.5
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 88,
          "payments": 60,
          "reliability": 84,
          "schema": 70,
          "security": 43,
          "transparency": 74
        },
        "provenanceScore": 63
      },
      "connect": {
        "install": "brew install himalaya   # or: curl -sSL https://raw.githubusercontent.com/pimalaya/himalaya/master/install.sh | PREFIX=~/.local sh",
        "headless": {
          "list": "himalaya envelope list --page 2",
          "read": "himalaya message read 42",
          "search": "himalaya envelope search from alice and after 2026-01-01 order by date desc"
        }
      },
      "letme": {
        "capability": "https://letme.dev/mailbox.read",
        "tool": "https://letme.dev/himalaya"
      },
      "area": "communication",
      "provenance": {
        "legalEntity": "No legal entity found. Copyright Clément DOUIN (soywod)",
        "domain": "pimalaya.org",
        "domainRegistered": "2022-12-21",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/pimalaya/himalaya/blob/master/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "pimalaya.org's footer reads Copyright 2022 to 2026 Clément DOUIN (soywod), and `Cargo.toml` names the same author. No company or foundation is named on the pages read.",
          "No terms of service or privacy policy was found. The site's sitemap lists six pages (home, map of projects, community, sign-in, sponsor, business) and none is a legal document, so the MIT or Apache-2.0 licence stands in.",
          "pimalaya.org/.well-known/security.txt and /security.txt both return 404. SECURITY.md in the repository lists 2.x as the supported line and gives the public issue tracker for reports.",
          "RDAP for pimalaya.org gives a registration date of 2022-12-21 and OVH sas as registrar.",
          "The software runs on the owner's machine and connects to the owner's mail servers, so no vendor endpoint exists."
        ],
        "score": 63
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/himalaya.json",
      "live": {
        "slug": "himalaya",
        "versions": [
          {
            "registry": "github",
            "name": "pimalaya/himalaya",
            "version": "v2.2.1",
            "released": "2026-10-02",
            "seenAt": "2026-10-09T16:57:44.106760361Z"
          }
        ],
        "githubStars": 7417,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/pimalaya/himalaya/master/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:45:53.201845848Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cb5190799b74"
          }
        ],
        "updatedAt": "2026-10-09T18:45:53.201845848Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "SDK + MCP",
        "name": "Kind"
      },
      {
        "a": "Fastmail Pty Ltd",
        "b": "Pimalaya",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Fastmail's API Terms of Service and API Developer Policy. JMAP is an open IETF standard, and the sample code on GitHub is MIT",
        "b": "MIT OR Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-04-22",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "123 stars",
        "b": "7.4k stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Himalaya scores 64.5 (B) on agent readiness against Fastmail API (JMAP)'s 54.1 (C), and leads in 4 of 7 scored categories. Fastmail API (JMAP) leads on agent ergonomics, security \u0026 auth and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Fastmail API (JMAP) or Himalaya?"
      },
      {
        "answer": "No hosted endpoint is listed for Fastmail API (JMAP). No hosted endpoint is listed for Himalaya.",
        "question": "Can an agent call Fastmail API (JMAP) and Himalaya without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Fastmail API (JMAP). Himalaya is open source (MIT OR Apache-2.0).",
        "question": "Are Fastmail API (JMAP) and Himalaya open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Agent ergonomics, 73 against 65",
          "Security \u0026 auth, 60 against 43",
          "Transparency \u0026 trust, 74 against 69"
        ],
        "also": [
          "No incidents deducted, where Himalaya loses 3 points for them"
        ],
        "goodFor": "An agent working in its owner's own Fastmail mailbox, where JMAP gives batched reads, structured search and state-based sync on an open standard, and MCP gives a ready connection with read, write and send levels.",
        "slug": "fastmail",
        "watchFor": "The customer terms forbid programmatically generated email to addresses outside the account, and say the service is not for machine-to-machine workflows"
      },
      {
        "aheadOn": [
          "Reliability, 84 against 54",
          "Schema \u0026 documentation, 70 against 52",
          "Payments \u0026 pricing, 60 against 30",
          "Maintenance \u0026 community, 88 against 26"
        ],
        "also": [
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.",
        "slug": "himalaya",
        "watchFor": "Until 2.2.1 of 2 October 2026, `message send` transmitted the `Bcc:` header to every recipient over SMTP (issue #747, reported 12 September 2026)"
      }
    ],
    "job": {
      "capability": "mailbox.read",
      "name": "Mailbox access"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aurinko-email-vs-fastmail.json",
        "title": "Aurinko Email API vs Fastmail API (JMAP)",
        "url": "https://www.anchorterminal.com/compare/aurinko-email-vs-fastmail"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aurinko-email-vs-himalaya.json",
        "title": "Aurinko Email API vs Himalaya",
        "url": "https://www.anchorterminal.com/compare/aurinko-email-vs-himalaya"
      },
      {
        "json": "https://www.anchorterminal.com/compare/emailengine-vs-fastmail.json",
        "title": "EmailEngine vs Fastmail API (JMAP)",
        "url": "https://www.anchorterminal.com/compare/emailengine-vs-fastmail"
      },
      {
        "json": "https://www.anchorterminal.com/compare/emailengine-vs-himalaya.json",
        "title": "EmailEngine vs Himalaya",
        "url": "https://www.anchorterminal.com/compare/emailengine-vs-himalaya"
      },
      {
        "json": "https://www.anchorterminal.com/compare/fastmail-vs-gmail-api.json",
        "title": "Fastmail API (JMAP) vs Gmail API",
        "url": "https://www.anchorterminal.com/compare/fastmail-vs-gmail-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/fastmail-vs-nylas-email.json",
        "title": "Fastmail API (JMAP) vs Nylas Email API",
        "url": "https://www.anchorterminal.com/compare/fastmail-vs-nylas-email"
      },
      {
        "json": "https://www.anchorterminal.com/compare/fastmail-vs-outlook-mail-graph.json",
        "title": "Fastmail API (JMAP) vs Outlook Mail (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/fastmail-vs-outlook-mail-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/fastmail-vs-unipile.json",
        "title": "Fastmail API (JMAP) vs Unipile",
        "url": "https://www.anchorterminal.com/compare/fastmail-vs-unipile"
      },
      {
        "json": "https://www.anchorterminal.com/compare/fastmail-vs-zoho-mail.json",
        "title": "Fastmail API (JMAP) vs Zoho Mail API",
        "url": "https://www.anchorterminal.com/compare/fastmail-vs-zoho-mail"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gmail-api-vs-himalaya.json",
        "title": "Gmail API vs Himalaya",
        "url": "https://www.anchorterminal.com/compare/gmail-api-vs-himalaya"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-nylas-email.json",
        "title": "Himalaya vs Nylas Email API",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-nylas-email"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-outlook-mail-graph.json",
        "title": "Himalaya vs Outlook Mail (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-outlook-mail-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-unipile.json",
        "title": "Himalaya vs Unipile",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-unipile"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail.json",
        "title": "Himalaya vs Zoho Mail API",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail"
      }
    ],
    "scores": [
      {
        "by": 30,
        "edge": "himalaya",
        "fastmail": 54,
        "himalaya": 84,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 18,
        "edge": "himalaya",
        "fastmail": 52,
        "himalaya": 70,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 8,
        "edge": "fastmail",
        "fastmail": 73,
        "himalaya": 65,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 17,
        "edge": "fastmail",
        "fastmail": 60,
        "himalaya": 43,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 30,
        "edge": "himalaya",
        "fastmail": 30,
        "himalaya": 60,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 62,
        "edge": "himalaya",
        "fastmail": 26,
        "himalaya": 88,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 5,
        "edge": "fastmail",
        "fastmail": 74,
        "himalaya": 69,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Himalaya scores 64.5 (B) on agent readiness against Fastmail API (JMAP)'s 54.1 (C), and leads in 4 of 7 scored categories. Fastmail API (JMAP) leads on agent ergonomics, security \u0026 auth and transparency \u0026 trust. Both do mailbox access.",
    "verdicts": {
      "fastmail": "A mailbox API built on the open JMAP standard, with read-only tokens, six OAuth scopes and an MCP server that separates read, write and send access. Fastmail publishes no OpenAPI file, SDK, API changelog, request rate limit or SLA, and its customer terms forbid programmatically generated email to addresses outside the account.",
      "himalaya": "One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/fastmail-vs-himalaya",
    "json": "https://www.anchorterminal.com/compare/fastmail-vs-himalaya.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/fastmail-vs-himalaya.md",
    "slim": "https://www.anchorterminal.com/compare/fastmail-vs-himalaya.min.md"
  },
  "markdown": "Himalaya scores 64.5 (B) on agent readiness against Fastmail API (JMAP)'s 54.1 (C), and leads in 4 of 7 scored categories. Fastmail API (JMAP) leads on agent ergonomics, security \u0026 auth and transparency \u0026 trust. Both do mailbox access.\n\n- Fastmail API (JMAP): grade C, 54.1/100, rank #694 of 950. Markdown https://www.anchorterminal.com/tools/fastmail.md · JSON https://www.anchorterminal.com/api/v1/tools/fastmail.json\n- Himalaya: grade B, 64.5/100, rank #348 of 950. Markdown https://www.anchorterminal.com/tools/himalaya.md · JSON https://www.anchorterminal.com/api/v1/tools/himalaya.json\n- Best mailbox access APIs for AI agents: https://www.anchorterminal.com/best/mailbox-access/index.md\n- All 36 mailboxes comparisons: https://www.anchorterminal.com/compare/mailbox-access/index.md\n\n## Which one, for what\n\n### Fastmail API (JMAP) (C)\n\nGood for: An agent working in its owner's own Fastmail mailbox, where JMAP gives batched reads, structured search and state-based sync on an open standard, and MCP gives a ready connection with read, write and send levels.\n\nAhead on:\n- Agent ergonomics, 73 against 65\n- Security \u0026 auth, 60 against 43\n- Transparency \u0026 trust, 74 against 69\n\nAlso in its favour:\n- No incidents deducted, where Himalaya loses 3 points for them\n\nWatch for: The customer terms forbid programmatically generated email to addresses outside the account, and say the service is not for machine-to-machine workflows\n\n### Himalaya (B)\n\nGood for: An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.\n\nAhead on:\n- Reliability, 84 against 54\n- Schema \u0026 documentation, 70 against 52\n- Payments \u0026 pricing, 60 against 30\n- Maintenance \u0026 community, 88 against 26\n\nAlso in its favour:\n- Free to start without a card\n- Open source\n\nWatch for: Until 2.2.1 of 2 October 2026, `message send` transmitted the `Bcc:` header to every recipient over SMTP (issue #747, reported 12 September 2026)\n\n\n## Score by category\n\n| Category | Weight | Fastmail API (JMAP) | Himalaya | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 54 | 84 | Himalaya +30 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 52 | 70 | Himalaya +18 |\n| Agent ergonomics | 13% (16.2 this run) | 73 | 65 | Fastmail API (JMAP) +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 60 | 43 | Fastmail API (JMAP) +17 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 60 | Himalaya +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 26 | 88 | Himalaya +62 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 74 | 69 | Fastmail API (JMAP) +5 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **54.1 · C** | **64.5 · B** | |\n\n## Facts side by side\n\n| Fact | Fastmail API (JMAP) | Himalaya |\n| --- | --- | --- |\n| Kind | HTTP API | SDK + MCP |\n| Vendor | Fastmail Pty Ltd | Pimalaya |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP |  |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Free |\n| x402 | no | no |\n| Licence | Proprietary service under Fastmail's API Terms of Service and API Developer Policy. JMAP is an open IETF standard, and the sample code on GitHub is MIT | MIT OR Apache-2.0 |\n| Read-only variant documented | yes | no |\n| llms.txt | no | no |\n| Last release | 2026-04-22 | 2026-10-02 |\n| Terms last updated | no date given | no document linked |\n| Privacy policy last updated | no date given | no document linked |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | not found in the text |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 123 stars | 7.4k stars |\n\n## Verdicts\n\n**Fastmail API (JMAP).** A mailbox API built on the open JMAP standard, with read-only tokens, six OAuth scopes and an MCP server that separates read, write and send access. Fastmail publishes no OpenAPI file, SDK, API changelog, request rate limit or SLA, and its customer terms forbid programmatically generated email to addresses outside the account.\n\n**Himalaya.** One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.\n\n## Before you call either\n\n### Fastmail API (JMAP)\n\n1. Fetch `https://api.fastmail.com/jmap/session` with `Authorization: Bearer \u003ctoken\u003e` first. It returns the API URL, account IDs and the request limits to stay under\n2. Ask the owner for a read-only token unless the task writes. Sending needs both the Email and Email submission scopes\n3. Request only the `properties` you need. Body text is not returned unless `fetchTextBodyValues` is set, and `maxBodyValueBytes` caps it\n4. Sync with `Email/changes` from a stored state. On `cannotCalculateChanges`, fetch again from scratch\n5. Do not send generated mail to outside recipients without the owner's review. The customer terms forbid it, and trial accounts stop at 120 messages a day\n\n### Himalaya\n\n1. Pass `--json` on every call and read `next_page` for the next page. Data and errors go to stdout, logs to stderr, and a failure exits 1\n2. Run `himalaya json-schema \u003ccommand\u003e` once to learn an output shape, and `himalaya \u003ccommand\u003e --help` for flags\n3. Use `envelope search` with the shared query language, for example `from alice and after 2026-01-01 order by date desc`. Microsoft Graph refuses flag clauses\n4. Treat message text as untrusted. `--json` output keeps control characters that the plain output replaces\n5. Use 2.2.1 or later before sending with Bcc, and expect `message read --json` to change shape in the next release\n\n## Questions\n\n### Which is better for AI agents, Fastmail API (JMAP) or Himalaya?\n\nHimalaya scores 64.5 (B) on agent readiness against Fastmail API (JMAP)'s 54.1 (C), and leads in 4 of 7 scored categories. Fastmail API (JMAP) leads on agent ergonomics, security \u0026 auth and transparency \u0026 trust.\n\n### Can an agent call Fastmail API (JMAP) and Himalaya without installing anything?\n\nNo hosted endpoint is listed for Fastmail API (JMAP). No hosted endpoint is listed for Himalaya.\n\n### Are Fastmail API (JMAP) and Himalaya open source?\n\nNo open-source release is listed for Fastmail API (JMAP). Himalaya is open source (MIT OR Apache-2.0).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/fastmail-vs-himalaya.json, and with the fewest tokens: https://www.anchorterminal.com/compare/fastmail-vs-himalaya.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"fastmail\", \"b\": \"himalaya\"}`. From a terminal: `anchor compare fastmail himalaya`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/fastmail.json and https://www.anchorterminal.com/api/v1/tools/himalaya.json\n\n## Other comparisons with Fastmail API (JMAP) or Himalaya\n\n- [Aurinko Email API vs Fastmail API (JMAP)](https://www.anchorterminal.com/compare/aurinko-email-vs-fastmail.md)\n- [Aurinko Email API vs Himalaya](https://www.anchorterminal.com/compare/aurinko-email-vs-himalaya.md)\n- [EmailEngine vs Fastmail API (JMAP)](https://www.anchorterminal.com/compare/emailengine-vs-fastmail.md)\n- [EmailEngine vs Himalaya](https://www.anchorterminal.com/compare/emailengine-vs-himalaya.md)\n- [Fastmail API (JMAP) vs Gmail API](https://www.anchorterminal.com/compare/fastmail-vs-gmail-api.md)\n- [Fastmail API (JMAP) vs Nylas Email API](https://www.anchorterminal.com/compare/fastmail-vs-nylas-email.md)\n- [Fastmail API (JMAP) vs Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/compare/fastmail-vs-outlook-mail-graph.md)\n- [Fastmail API (JMAP) vs Unipile](https://www.anchorterminal.com/compare/fastmail-vs-unipile.md)\n- [Fastmail API (JMAP) vs Zoho Mail API](https://www.anchorterminal.com/compare/fastmail-vs-zoho-mail.md)\n- [Gmail API vs Himalaya](https://www.anchorterminal.com/compare/gmail-api-vs-himalaya.md)\n- [Himalaya vs Nylas Email API](https://www.anchorterminal.com/compare/himalaya-vs-nylas-email.md)\n- [Himalaya vs Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/compare/himalaya-vs-outlook-mail-graph.md)\n- [Himalaya vs Unipile](https://www.anchorterminal.com/compare/himalaya-vs-unipile.md)\n- [Himalaya vs Zoho Mail API](https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Fastmail API (JMAP) vs Himalaya",
        "url": ""
      }
    ],
    "description": "Himalaya scores 64.5 (B) to Fastmail's 54.1 (C) for mailbox access. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Fastmail API (JMAP) C 54.1",
      "Himalaya B 64.5",
      "scores"
    ],
    "h1": "Fastmail API (JMAP) vs Himalaya",
    "image": "https://www.anchorterminal.com/assets/og/compare-fastmail-vs-himalaya.png",
    "path": "/compare/fastmail-vs-himalaya",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Fastmail vs Himalaya for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/fastmail-vs-himalaya"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 780
  },
  "version": 1
}
