Head to head · Mailbox access · October 2026 research run

Gmail API vs Himalaya

Gmail API scores 77.8 (BB) on agent readiness against Himalaya's 64.5 (B), and leads in 5 of 7 scored categories. Himalaya leads on payments & pricing. Both do mailbox access.

Best mailbox access APIs for AI agents · All 36 mailboxes comparisons

Which one, for what

Gmail API BB

Good for An agent working in a Gmail or Google Workspace user's own mailbox, with search, threads, drafts, labels and incremental sync at no per-account fee.

Ahead on

  • Reliability, 90 against 84
  • Schema & documentation, 82 against 70
  • Agent ergonomics, 82 against 65
  • Security & auth, 81 against 43
  • Transparency & trust, 82 against 69

Also in its favour

  • Agent-ready, a grade of BB or better
  • A hosted endpoint, with nothing to install
  • No incidents deducted, where Himalaya loses 3 points for them

Watch for

Eight restricted scopes, including gmail.readonly and gmail.metadata, need restricted-scope verification for a public app

Himalaya B

Good for An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.

Ahead on

  • Payments & pricing, 60 against 35

Also in its favour

  • Free to start without a card
  • Open source

Watch for

Until 2.2.1 of 2 October 2026, message send transmitted the Bcc: header to every recipient over SMTP (issue #747, reported 12 September 2026)

Score by category

CategoryWeight this runGmail APIHimalayaEdge
Reliability16%209084Gmail API +6
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28270Gmail API +12
Agent ergonomics13%16.28265Gmail API +17
Security & auth14%17.58143Gmail API +38
Payments & pricing10%12.53560Himalaya +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88588Himalaya +3
Transparency & trust7%8.88269Gmail API +13
Negative events≤150-3
Total77.8 · BB64.5 · B

Facts side by side

FactGmail APIHimalaya
KindHTTP APISDK + MCP
VendorGooglePimalaya
Hosted endpointhttps://gmail.googleapis.com/gmail/v1no (local only)
TransportsHTTP, Streamable HTTP
AuthOAuthOAuth or key
PricingFreeFree
x402nono
LicenceApache-2.0 (client libraries)MIT OR Apache-2.0
Tools exposed23none
Read-only variant documentednono
llms.txtnono
Last release2026-09-232026-10-02
Terms last updated2021-11-09no document linked
Privacy policy last updated2026-10-01no document linked
Customer content may train modelsyes
Terms restrict automated accessyes
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity12k stars, 1.1M npm/wk7.4k stars

Verdicts

Gmail API

Fourteen OAuth scopes separate labels, sending, metadata and read-only access, and the quota page gives every method a unit cost. Eight of the scopes are restricted, read-only and metadata among them, so a public app that reads mail needs Google's verification and an annual third-party security assessment. Gmail mailboxes only.

Himalaya

One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and --json output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.

Before you call either

Gmail API

  1. Ask for the narrowest scope. gmail.labels is non-sensitive and gmail.send is sensitive, while every scope that reads mail is restricted
  2. List with messages.list and q in Gmail search syntax, then fetch each ID with format=metadata or full. List calls return IDs only
  3. Send by posting an RFC 2822 message, base64url encoded, in raw. Set threadId and matching reply headers to stay in a thread
  4. Store the historyId and call history.list. On a 404, run a full sync. Call watch again at least every 7 days
  5. Back off exponentially on 403 and 429 rate errors, and keep batches to 50 requests or fewer

Himalaya

  1. Pass --json on every call and read next_page for the next page. Data and errors go to stdout, logs to stderr, and a failure exits 1
  2. Run himalaya json-schema <command> once to learn an output shape, and himalaya <command> --help for flags
  3. Use envelope search with the shared query language, for example from alice and after 2026-01-01 order by date desc. Microsoft Graph refuses flag clauses
  4. Treat message text as untrusted. --json output keeps control characters that the plain output replaces
  5. Use 2.2.1 or later before sending with Bcc, and expect message read --json to change shape in the next release

Questions

Which is better for AI agents, Gmail API or Himalaya?

Gmail API scores 77.8 (BB) on agent readiness against Himalaya's 64.5 (B), and leads in 5 of 7 scored categories. Himalaya leads on payments & pricing.

Can an agent call Gmail API and Himalaya without installing anything?

Gmail API has a hosted endpoint at https://gmail.googleapis.com/gmail/v1. No hosted endpoint is listed for Himalaya.

Are Gmail API and Himalaya open source?

No open-source release is listed for Gmail API. Himalaya is open source (MIT OR Apache-2.0).

Other comparisons with Gmail API or Himalaya

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.