{
  "data": {
    "a": {
      "slug": "gmail-api",
      "name": "Gmail API",
      "vendor": "Google",
      "vendorUrl": "https://developers.google.com/workspace/gmail",
      "kind": "http-api",
      "category": "mailbox-access",
      "summary": "Google's REST API for Gmail mailboxes. It searches and reads messages and threads, writes drafts, sends mail, manages labels and settings, and reports mailbox changes through history records and Cloud Pub/Sub push notifications. Access is by OAuth 2.0.",
      "url": "https://www.anchorterminal.com/tools/gmail-api",
      "markdownUrl": "https://www.anchorterminal.com/tools/gmail-api.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/gmail-api.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/gmail-api.json",
      "repo": "https://github.com/googleapis/google-api-nodejs-client",
      "license": "Apache-2.0 (client libraries)",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://gmail.googleapis.com/gmail/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "@googleapis/gmail"
        },
        {
          "registry": "pypi",
          "name": "google-api-python-client"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 access token as a Bearer header, from a Google Cloud project with the Gmail API enabled and an OAuth consent screen. Self-serve for personal use, testing and apps internal to one Workspace organisation. A public app that requests any of the eight restricted scopes, which include `gmail.readonly` and `gmail.metadata`, needs Google's restricted-scope verification, and a CASA security assessment every 12 months if it reaches the data from or through a server. Workspace domains can use a service account with domain-wide delegation. The MCP server needs your own OAuth client ID and secret, the `gmail.readonly` and `gmail.compose` scopes, and Developer Preview Programme membership.",
      "pricing": "free",
      "pricingNotes": "All standard use is at no extra cost, and a free Google account and Cloud project are enough to start, with no card or contract. Limits are 1,200,000 quota units a minute per project, 6,000 a minute per user and a daily threshold of 80,000,000 units per project. Google says use above the daily threshold is planned to be charged to the Cloud billing account later in 2026, with details and at least 90 days' notice still to come (https://developers.google.com/workspace/gmail/api/reference/quota). A security assessment for restricted scopes is paid to a third-party assessor, at a cost Google's pages don't state.",
      "priceSummary": "Free",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Gmail API guides, the quota page or the discovery document (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 23,
      "popularity": {
        "githubStars": 12262,
        "npmWeekly": 1091106,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developers.google.com/workspace/gmail/api/guides",
      "capabilities": [
        "mailbox.read",
        "mailbox.search",
        "mailbox.send",
        "mailbox.drafts",
        "mailbox.sync"
      ],
      "tags": [
        "hosted",
        "official",
        "free-tier",
        "mcp",
        "webhooks",
        "oauth",
        "typescript",
        "python",
        "enterprise"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 77.8,
        "grade": "BB",
        "agentReady": true,
        "rank": 19,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 82,
          "maintenance": 85,
          "payments": 35,
          "reliability": 90,
          "schema": 82,
          "security": 81,
          "transparency": 82
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Fourteen OAuth scopes separate labels, sending, metadata and read-only access, and the quota page gives every method a unit cost. Eight of the scopes are restricted, read-only and metadata among them, so a public app that reads mail needs Google's verification and an annual third-party security assessment. Gmail mailboxes only.",
        "bestFor": "An agent working in a Gmail or Google Workspace user's own mailbox, with search, threads, drafts, labels and incremental sync at no per-account fee.",
        "strengths": [
          "14 OAuth scopes, with `gmail.labels` non-sensitive, `gmail.send` sensitive and permanent delete reserved for the full `https://mail.google.com/` scope",
          "Quota published per method, 5 units for `messages.list`, 20 for `messages.get` and 100 for `messages.send`, against 6,000 units a minute per user",
          "`history.list` and Pub/Sub push notifications give incremental sync from a stored `historyId`",
          "`format=metadata`, `metadataHeaders`, `maxResults` and `fields` keep responses small",
          "No charge for standard use, up to 80,000,000 quota units a day per project"
        ],
        "weaknesses": [
          "Eight restricted scopes, including `gmail.readonly` and `gmail.metadata`, need restricted-scope verification for a public app",
          "An app that stores or transmits restricted data on servers needs a security assessment by a Google-approved assessor every 12 months",
          "No idempotency key on `messages.send`, and the error guide says a 200 response doesn't confirm the mail was sent",
          "MCP server limited to the Developer Preview Programme, with no send tool",
          "Price for use above the daily quota not yet published"
        ],
        "agentNotes": [
          "Ask for the narrowest scope. `gmail.labels` is non-sensitive and `gmail.send` is sensitive, while every scope that reads mail is restricted",
          "List with `messages.list` and `q` in Gmail search syntax, then fetch each ID with `format=metadata` or `full`. List calls return IDs only",
          "Send by posting an RFC 2822 message, base64url encoded, in `raw`. Set `threadId` and matching reply headers to stay in a thread",
          "Store the `historyId` and call `history.list`. On a 404, run a full sync. Call `watch` again at least every 7 days",
          "Back off exponentially on 403 and 429 rate errors, and keep batches to 50 requests or fewer"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 77.8
          }
        ],
        "editorialScores": {
          "ergonomics": 82,
          "maintenance": 85,
          "payments": 35,
          "reliability": 90,
          "schema": 82,
          "security": 81,
          "transparency": 69
        },
        "provenanceScore": 94
      },
      "connect": {
        "http": "curl \"https://gmail.googleapis.com/gmail/v1/users/me/messages?q=is:unread\u0026maxResults=5\" \\\n  -H \"Authorization: Bearer $GOOGLE_ACCESS_TOKEN\"",
        "config": {
          "mcpServers": {
            "gmail": {
              "oauth": {
                "clientId": "OAUTH_CLIENT_ID",
                "clientSecret": "OAUTH_CLIENT_SECRET"
              },
              "serverUrl": "https://gmailmcp.googleapis.com/mcp/v1"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/mailbox.read",
        "tool": "https://letme.dev/gmail-api"
      },
      "sameCompany": [
        "gemini-api",
        "gemini-embedding",
        "vertex-ai-tuning",
        "google-model-armor",
        "google-imagen",
        "google-veo",
        "google-lyria",
        "google-speech-to-text",
        "gemini-live",
        "google-adk",
        "google-secret-manager",
        "google-cloud-document-ai",
        "google-weather-api",
        "chrome-devtools-mcp",
        "google-maps-platform",
        "google-cloud-translation",
        "google-calendar-api",
        "firebase-cloud-messaging",
        "google-drive-api",
        "gemini-cli",
        "google-search-console",
        "google-ads-api",
        "google-forms",
        "google-sheets-api"
      ],
      "area": "communication",
      "provenance": {
        "legalEntity": "Google LLC",
        "domain": "google.com",
        "domainRegistered": "1997-09-15",
        "domainNote": "The endpoint is on gmail.googleapis.com, Google's API domain. google.com was registered in 1997.",
        "endpointOnVendorDomain": true,
        "terms": "https://developers.google.com/terms",
        "privacy": "https://policies.google.com/privacy",
        "statusPage": "https://www.google.com/appsstatus/dashboard/",
        "changelog": "https://developers.google.com/workspace/gmail/release-notes",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Google APIs Terms of Service (last modified 9 November 2021) name Google LLC, 1600 Amphitheatre Parkway, Mountain View.",
          "RDAP for google.com gives a registration date of 1997-09-15.",
          "www.google.com/.well-known/security.txt expires on 1 April 2030 and lists a contact, an encryption key and the vulnerability reward policy.",
          "The quota and scopes pages were last updated on 10 September 2026, the MCP setup guide on 18 September and the MCP reference on 21 July.",
          "Google publishes a discovery document for the API, not an OpenAPI spec.",
          "The Workspace status dashboard tracks the Gmail product, not the API on its own."
        ],
        "score": 94
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/gmail-api.json",
      "live": {
        "slug": "gmail-api",
        "probe": {
          "target": "https://gmail.googleapis.com/gmail/v1",
          "method": "get",
          "lastAt": "2026-10-10T01:37:52.731764078Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 36,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 37,
          "p95ms24h": 86,
          "samples24h": 250,
          "samples30d": 360,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 93,
              "ok": 93
            },
            {
              "date": "2026-10-09",
              "probes": 250,
              "ok": 250
            },
            {
              "date": "2026-10-10",
              "probes": 17,
              "ok": 17
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.google.com/appsstatus/dashboard",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:50:37.53265668Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "googleapis/google-api-nodejs-client",
            "version": "workspaceevents-v17.0.0",
            "released": "2026-10-08",
            "seenAt": "2026-10-09T16:55:11.880993418Z"
          },
          {
            "registry": "npm",
            "name": "@googleapis/gmail",
            "version": "22.0.1",
            "seenAt": "2026-10-09T16:55:10.879608242Z"
          },
          {
            "registry": "pypi",
            "name": "google-api-python-client",
            "version": "2.201.0",
            "released": "2026-09-30",
            "seenAt": "2026-10-09T16:55:11.728627007Z"
          }
        ],
        "githubStars": 12266,
        "npmWeekly": 876516,
        "pypiWeekly": 31366337,
        "securityTxt": {
          "url": "https://google.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2030-04-01T00:00:00z",
          "checkedAt": "2026-10-09T15:39:28.443612679Z"
        },
        "pages": [
          {
            "url": "https://developers.google.com/workspace/gmail/release-notes",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:36:05.421734208Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4656378123eb"
          },
          {
            "url": "https://developers.google.com/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:49.55137795Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2eb11136bf24"
          }
        ],
        "updatedAt": "2026-10-10T01:37:52.731764078Z"
      }
    },
    "answer": "Gmail API scores 77.8 (BB) on agent readiness against Himalaya's 64.5 (B), and leads in 5 of 7 scored categories. Himalaya leads on payments \u0026 pricing.",
    "b": {
      "slug": "himalaya",
      "name": "Himalaya",
      "vendor": "Pimalaya",
      "vendorUrl": "https://pimalaya.org",
      "kind": "sdk",
      "category": "mailbox-access",
      "summary": "Himalaya is an open-source command-line email client from the Pimalaya project. It lists, searches, reads, composes and sends mail over IMAP, SMTP, JMAP, the Gmail API, Microsoft Graph and local stores, with JSON output for scripts and agents.",
      "url": "https://www.anchorterminal.com/tools/himalaya",
      "markdownUrl": "https://www.anchorterminal.com/tools/himalaya.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/himalaya.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/himalaya.json",
      "repo": "https://github.com/pimalaya/himalaya",
      "license": "MIT OR Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "cargo",
          "name": "himalaya"
        }
      ],
      "auth": "mixed",
      "authNotes": "Himalaya issues no credential of its own. It signs in to the mailbox with what the provider accepts, which is an app password or account password over SASL for IMAP and SMTP, a bearer token or basic auth for JMAP, and one OAuth 2.0 bearer token for the Gmail API or Microsoft Graph. Each secret is read from a shell command such as a password manager, or from a raw value in the config file. Version 2 ships no OAuth flow, so tokens come from an external broker such as `ortie` and an OAuth app the owner registers with Google or Microsoft.",
      "pricing": "free",
      "pricingNotes": "Free software with nothing to buy, and the sponsor page states there is no paid tier. An agent can start with the binary and a mailbox credential. Pimalaya sells optional partnerships, from EUR 3,000 a year for email providers and EUR 5,000 for integrators, and describes a EUR 12 a year sign-in service for Gmail and Microsoft 365 as planned and not built (checked 2026-10-09).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the source or pimalaya.org (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 7412,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://github.com/pimalaya/himalaya",
      "capabilities": [
        "mailbox.read",
        "mailbox.search",
        "mailbox.send",
        "mailbox.drafts"
      ],
      "tags": [
        "open-source",
        "local",
        "cli",
        "rust",
        "free",
        "no-card",
        "imap",
        "smtp",
        "jmap",
        "gmail",
        "microsoft-graph",
        "json-output"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.5,
        "grade": "B",
        "agentReady": false,
        "rank": 348,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 88,
          "payments": 60,
          "reliability": 84,
          "schema": 70,
          "security": 43,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -3,
        "negativeNotes": [
          "2 October 2026. Until 2.2.1, `message send` passed the `Bcc:` header through SMTP unchanged, so every recipient could see the blind recipients. Issue #747 reported it against 2.1.0 on 12 September 2026, the fix was committed on 26 September and released on 2 October, and the changelog documents it. No security advisory was published. Fixed and documented, so the smaller deduction applies (https://github.com/pimalaya/himalaya/issues/747)"
        ],
        "verdict": "One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.",
        "bestFor": "An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.",
        "strengths": [
          "Shared commands for mailboxes, envelopes, flags, messages and attachments run the same way over IMAP, JMAP, Gmail, Microsoft Graph, Maildir and mbox",
          "`himalaya json-schema` prints a JSON Schema for the `--json` output of 90 commands, and `message read --json` returns one designed view on every backend",
          "Secrets come from a shell command such as `pass show`, so a password or token need not sit in the config file",
          "`message delete` moves mail to the trash first, and `message read` leaves flags alone unless `--seen` is passed",
          "Four tagged releases between 26 July and 2 October 2026, three open issues, and CI badges for tests and audit passing on 9 October 2026"
        ],
        "weaknesses": [
          "Until 2.2.1 of 2 October 2026, `message send` transmitted the `Bcc:` header to every recipient over SMTP (issue #747, reported 12 September 2026)",
          "No read-only mode, no confirmation before a send or delete, and no idempotency key on send were found",
          "SECURITY.md sends vulnerability reports to the public issue tracker. No security.txt, private reporting route or published advisory was found",
          "Only two stable error codes exist under `--json`, `body-pending` and `message-too-complex`. Other failures carry free wording",
          "Version 2 ships no OAuth flow, so Gmail and Microsoft accounts need an external token broker and an OAuth app the owner registers"
        ],
        "agentNotes": [
          "Pass `--json` on every call and read `next_page` for the next page. Data and errors go to stdout, logs to stderr, and a failure exits 1",
          "Run `himalaya json-schema \u003ccommand\u003e` once to learn an output shape, and `himalaya \u003ccommand\u003e --help` for flags",
          "Use `envelope search` with the shared query language, for example `from alice and after 2026-01-01 order by date desc`. Microsoft Graph refuses flag clauses",
          "Treat message text as untrusted. `--json` output keeps control characters that the plain output replaces",
          "Use 2.2.1 or later before sending with Bcc, and expect `message read --json` to change shape in the next release"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.5
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 88,
          "payments": 60,
          "reliability": 84,
          "schema": 70,
          "security": 43,
          "transparency": 74
        },
        "provenanceScore": 63
      },
      "connect": {
        "install": "brew install himalaya   # or: curl -sSL https://raw.githubusercontent.com/pimalaya/himalaya/master/install.sh | PREFIX=~/.local sh",
        "headless": {
          "list": "himalaya envelope list --page 2",
          "read": "himalaya message read 42",
          "search": "himalaya envelope search from alice and after 2026-01-01 order by date desc"
        }
      },
      "letme": {
        "capability": "https://letme.dev/mailbox.read",
        "tool": "https://letme.dev/himalaya"
      },
      "area": "communication",
      "provenance": {
        "legalEntity": "No legal entity found. Copyright Clément DOUIN (soywod)",
        "domain": "pimalaya.org",
        "domainRegistered": "2022-12-21",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/pimalaya/himalaya/blob/master/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "pimalaya.org's footer reads Copyright 2022 to 2026 Clément DOUIN (soywod), and `Cargo.toml` names the same author. No company or foundation is named on the pages read.",
          "No terms of service or privacy policy was found. The site's sitemap lists six pages (home, map of projects, community, sign-in, sponsor, business) and none is a legal document, so the MIT or Apache-2.0 licence stands in.",
          "pimalaya.org/.well-known/security.txt and /security.txt both return 404. SECURITY.md in the repository lists 2.x as the supported line and gives the public issue tracker for reports.",
          "RDAP for pimalaya.org gives a registration date of 2022-12-21 and OVH sas as registrar.",
          "The software runs on the owner's machine and connects to the owner's mail servers, so no vendor endpoint exists."
        ],
        "score": 63
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/himalaya.json",
      "live": {
        "slug": "himalaya",
        "versions": [
          {
            "registry": "github",
            "name": "pimalaya/himalaya",
            "version": "v2.2.1",
            "released": "2026-10-02",
            "seenAt": "2026-10-09T16:57:44.106760361Z"
          }
        ],
        "githubStars": 7417,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/pimalaya/himalaya/master/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:45:53.201845848Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cb5190799b74"
          }
        ],
        "updatedAt": "2026-10-09T18:45:53.201845848Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "SDK + MCP",
        "name": "Kind"
      },
      {
        "a": "Google",
        "b": "Pimalaya",
        "name": "Vendor"
      },
      {
        "a": "https://gmail.googleapis.com/gmail/v1",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0 (client libraries)",
        "b": "MIT OR Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "23",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-23",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "2021-11-09",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2026-10-01",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "12k stars, 1.1M npm/wk",
        "b": "7.4k stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Gmail API scores 77.8 (BB) on agent readiness against Himalaya's 64.5 (B), and leads in 5 of 7 scored categories. Himalaya leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Gmail API or Himalaya?"
      },
      {
        "answer": "Gmail API has a hosted endpoint at https://gmail.googleapis.com/gmail/v1. No hosted endpoint is listed for Himalaya.",
        "question": "Can an agent call Gmail API and Himalaya without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Gmail API. Himalaya is open source (MIT OR Apache-2.0).",
        "question": "Are Gmail API and Himalaya open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 90 against 84",
          "Schema \u0026 documentation, 82 against 70",
          "Agent ergonomics, 82 against 65",
          "Security \u0026 auth, 81 against 43",
          "Transparency \u0026 trust, 82 against 69"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where Himalaya loses 3 points for them"
        ],
        "goodFor": "An agent working in a Gmail or Google Workspace user's own mailbox, with search, threads, drafts, labels and incremental sync at no per-account fee.",
        "slug": "gmail-api",
        "watchFor": "Eight restricted scopes, including `gmail.readonly` and `gmail.metadata`, need restricted-scope verification for a public app"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 60 against 35"
        ],
        "also": [
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.",
        "slug": "himalaya",
        "watchFor": "Until 2.2.1 of 2 October 2026, `message send` transmitted the `Bcc:` header to every recipient over SMTP (issue #747, reported 12 September 2026)"
      }
    ],
    "job": {
      "capability": "mailbox.read",
      "name": "Mailbox access"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aurinko-email-vs-gmail-api.json",
        "title": "Aurinko Email API vs Gmail API",
        "url": "https://www.anchorterminal.com/compare/aurinko-email-vs-gmail-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aurinko-email-vs-himalaya.json",
        "title": "Aurinko Email API vs Himalaya",
        "url": "https://www.anchorterminal.com/compare/aurinko-email-vs-himalaya"
      },
      {
        "json": "https://www.anchorterminal.com/compare/emailengine-vs-gmail-api.json",
        "title": "EmailEngine vs Gmail API",
        "url": "https://www.anchorterminal.com/compare/emailengine-vs-gmail-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/emailengine-vs-himalaya.json",
        "title": "EmailEngine vs Himalaya",
        "url": "https://www.anchorterminal.com/compare/emailengine-vs-himalaya"
      },
      {
        "json": "https://www.anchorterminal.com/compare/fastmail-vs-gmail-api.json",
        "title": "Fastmail API (JMAP) vs Gmail API",
        "url": "https://www.anchorterminal.com/compare/fastmail-vs-gmail-api"
      },
      {
        "json": "https://www.anchorterminal.com/compare/fastmail-vs-himalaya.json",
        "title": "Fastmail API (JMAP) vs Himalaya",
        "url": "https://www.anchorterminal.com/compare/fastmail-vs-himalaya"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gmail-api-vs-nylas-email.json",
        "title": "Gmail API vs Nylas Email API",
        "url": "https://www.anchorterminal.com/compare/gmail-api-vs-nylas-email"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gmail-api-vs-outlook-mail-graph.json",
        "title": "Gmail API vs Outlook Mail (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/gmail-api-vs-outlook-mail-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gmail-api-vs-unipile.json",
        "title": "Gmail API vs Unipile",
        "url": "https://www.anchorterminal.com/compare/gmail-api-vs-unipile"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gmail-api-vs-zoho-mail.json",
        "title": "Gmail API vs Zoho Mail API",
        "url": "https://www.anchorterminal.com/compare/gmail-api-vs-zoho-mail"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-nylas-email.json",
        "title": "Himalaya vs Nylas Email API",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-nylas-email"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-outlook-mail-graph.json",
        "title": "Himalaya vs Outlook Mail (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-outlook-mail-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-unipile.json",
        "title": "Himalaya vs Unipile",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-unipile"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail.json",
        "title": "Himalaya vs Zoho Mail API",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail"
      }
    ],
    "scores": [
      {
        "by": 6,
        "edge": "gmail-api",
        "gmail-api": 90,
        "himalaya": 84,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "edge": "gmail-api",
        "gmail-api": 82,
        "himalaya": 70,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 17,
        "edge": "gmail-api",
        "gmail-api": 82,
        "himalaya": 65,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 38,
        "edge": "gmail-api",
        "gmail-api": 81,
        "himalaya": 43,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 25,
        "edge": "himalaya",
        "gmail-api": 35,
        "himalaya": 60,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 3,
        "edge": "himalaya",
        "gmail-api": 85,
        "himalaya": 88,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 13,
        "edge": "gmail-api",
        "gmail-api": 82,
        "himalaya": 69,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Gmail API scores 77.8 (BB) on agent readiness against Himalaya's 64.5 (B), and leads in 5 of 7 scored categories. Himalaya leads on payments \u0026 pricing. Both do mailbox access.",
    "verdicts": {
      "gmail-api": "Fourteen OAuth scopes separate labels, sending, metadata and read-only access, and the quota page gives every method a unit cost. Eight of the scopes are restricted, read-only and metadata among them, so a public app that reads mail needs Google's verification and an annual third-party security assessment. Gmail mailboxes only.",
      "himalaya": "One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/gmail-api-vs-himalaya",
    "json": "https://www.anchorterminal.com/compare/gmail-api-vs-himalaya.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/gmail-api-vs-himalaya.md",
    "slim": "https://www.anchorterminal.com/compare/gmail-api-vs-himalaya.min.md"
  },
  "markdown": "Gmail API scores 77.8 (BB) on agent readiness against Himalaya's 64.5 (B), and leads in 5 of 7 scored categories. Himalaya leads on payments \u0026 pricing. Both do mailbox access.\n\n- Gmail API: grade BB, 77.8/100, rank #19 of 950. Markdown https://www.anchorterminal.com/tools/gmail-api.md · JSON https://www.anchorterminal.com/api/v1/tools/gmail-api.json\n- Himalaya: grade B, 64.5/100, rank #348 of 950. Markdown https://www.anchorterminal.com/tools/himalaya.md · JSON https://www.anchorterminal.com/api/v1/tools/himalaya.json\n- Best mailbox access APIs for AI agents: https://www.anchorterminal.com/best/mailbox-access/index.md\n- All 36 mailboxes comparisons: https://www.anchorterminal.com/compare/mailbox-access/index.md\n\n## Which one, for what\n\n### Gmail API (BB)\n\nGood for: An agent working in a Gmail or Google Workspace user's own mailbox, with search, threads, drafts, labels and incremental sync at no per-account fee.\n\nAhead on:\n- Reliability, 90 against 84\n- Schema \u0026 documentation, 82 against 70\n- Agent ergonomics, 82 against 65\n- Security \u0026 auth, 81 against 43\n- Transparency \u0026 trust, 82 against 69\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where Himalaya loses 3 points for them\n\nWatch for: Eight restricted scopes, including `gmail.readonly` and `gmail.metadata`, need restricted-scope verification for a public app\n\n### Himalaya (B)\n\nGood for: An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.\n\nAhead on:\n- Payments \u0026 pricing, 60 against 35\n\nAlso in its favour:\n- Free to start without a card\n- Open source\n\nWatch for: Until 2.2.1 of 2 October 2026, `message send` transmitted the `Bcc:` header to every recipient over SMTP (issue #747, reported 12 September 2026)\n\n\n## Score by category\n\n| Category | Weight | Gmail API | Himalaya | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 90 | 84 | Gmail API +6 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 70 | Gmail API +12 |\n| Agent ergonomics | 13% (16.2 this run) | 82 | 65 | Gmail API +17 |\n| Security \u0026 auth | 14% (17.5 this run) | 81 | 43 | Gmail API +38 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 35 | 60 | Himalaya +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 88 | Himalaya +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 82 | 69 | Gmail API +13 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **77.8 · BB** | **64.5 · B** | |\n\n## Facts side by side\n\n| Fact | Gmail API | Himalaya |\n| --- | --- | --- |\n| Kind | HTTP API | SDK + MCP |\n| Vendor | Google | Pimalaya |\n| Hosted endpoint | `https://gmail.googleapis.com/gmail/v1` | no (local only) |\n| Transports | HTTP, Streamable HTTP |  |\n| Auth | OAuth | OAuth or key |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | Apache-2.0 (client libraries) | MIT OR Apache-2.0 |\n| Tools exposed | 23 | none |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-09-23 | 2026-10-02 |\n| Terms last updated | 2021-11-09 | no document linked |\n| Privacy policy last updated | 2026-10-01 | no document linked |\n| Customer content may train models | yes |  |\n| Terms restrict automated access | yes |  |\n| Terms restrict benchmarking | not found in the text |  |\n| Terms or service can change without notice | not found in the text |  |\n| Arbitration or class-action waiver | not found in the text |  |\n| Popularity | 12k stars, 1.1M npm/wk | 7.4k stars |\n\n## Verdicts\n\n**Gmail API.** Fourteen OAuth scopes separate labels, sending, metadata and read-only access, and the quota page gives every method a unit cost. Eight of the scopes are restricted, read-only and metadata among them, so a public app that reads mail needs Google's verification and an annual third-party security assessment. Gmail mailboxes only.\n\n**Himalaya.** One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.\n\n## Before you call either\n\n### Gmail API\n\n1. Ask for the narrowest scope. `gmail.labels` is non-sensitive and `gmail.send` is sensitive, while every scope that reads mail is restricted\n2. List with `messages.list` and `q` in Gmail search syntax, then fetch each ID with `format=metadata` or `full`. List calls return IDs only\n3. Send by posting an RFC 2822 message, base64url encoded, in `raw`. Set `threadId` and matching reply headers to stay in a thread\n4. Store the `historyId` and call `history.list`. On a 404, run a full sync. Call `watch` again at least every 7 days\n5. Back off exponentially on 403 and 429 rate errors, and keep batches to 50 requests or fewer\n\n### Himalaya\n\n1. Pass `--json` on every call and read `next_page` for the next page. Data and errors go to stdout, logs to stderr, and a failure exits 1\n2. Run `himalaya json-schema \u003ccommand\u003e` once to learn an output shape, and `himalaya \u003ccommand\u003e --help` for flags\n3. Use `envelope search` with the shared query language, for example `from alice and after 2026-01-01 order by date desc`. Microsoft Graph refuses flag clauses\n4. Treat message text as untrusted. `--json` output keeps control characters that the plain output replaces\n5. Use 2.2.1 or later before sending with Bcc, and expect `message read --json` to change shape in the next release\n\n## Questions\n\n### Which is better for AI agents, Gmail API or Himalaya?\n\nGmail API scores 77.8 (BB) on agent readiness against Himalaya's 64.5 (B), and leads in 5 of 7 scored categories. Himalaya leads on payments \u0026 pricing.\n\n### Can an agent call Gmail API and Himalaya without installing anything?\n\nGmail API has a hosted endpoint at https://gmail.googleapis.com/gmail/v1. No hosted endpoint is listed for Himalaya.\n\n### Are Gmail API and Himalaya open source?\n\nNo open-source release is listed for Gmail API. Himalaya is open source (MIT OR Apache-2.0).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/gmail-api-vs-himalaya.json, and with the fewest tokens: https://www.anchorterminal.com/compare/gmail-api-vs-himalaya.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"gmail-api\", \"b\": \"himalaya\"}`. From a terminal: `anchor compare gmail-api himalaya`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/gmail-api.json and https://www.anchorterminal.com/api/v1/tools/himalaya.json\n\n## Other comparisons with Gmail API or Himalaya\n\n- [Aurinko Email API vs Gmail API](https://www.anchorterminal.com/compare/aurinko-email-vs-gmail-api.md)\n- [Aurinko Email API vs Himalaya](https://www.anchorterminal.com/compare/aurinko-email-vs-himalaya.md)\n- [EmailEngine vs Gmail API](https://www.anchorterminal.com/compare/emailengine-vs-gmail-api.md)\n- [EmailEngine vs Himalaya](https://www.anchorterminal.com/compare/emailengine-vs-himalaya.md)\n- [Fastmail API (JMAP) vs Gmail API](https://www.anchorterminal.com/compare/fastmail-vs-gmail-api.md)\n- [Fastmail API (JMAP) vs Himalaya](https://www.anchorterminal.com/compare/fastmail-vs-himalaya.md)\n- [Gmail API vs Nylas Email API](https://www.anchorterminal.com/compare/gmail-api-vs-nylas-email.md)\n- [Gmail API vs Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/compare/gmail-api-vs-outlook-mail-graph.md)\n- [Gmail API vs Unipile](https://www.anchorterminal.com/compare/gmail-api-vs-unipile.md)\n- [Gmail API vs Zoho Mail API](https://www.anchorterminal.com/compare/gmail-api-vs-zoho-mail.md)\n- [Himalaya vs Nylas Email API](https://www.anchorterminal.com/compare/himalaya-vs-nylas-email.md)\n- [Himalaya vs Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/compare/himalaya-vs-outlook-mail-graph.md)\n- [Himalaya vs Unipile](https://www.anchorterminal.com/compare/himalaya-vs-unipile.md)\n- [Himalaya vs Zoho Mail API](https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Gmail API vs Himalaya",
        "url": ""
      }
    ],
    "description": "Gmail scores 77.8 (BB) to Himalaya's 64.5 (B) for mailbox access. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Gmail API BB 77.8",
      "Himalaya B 64.5",
      "scores"
    ],
    "h1": "Gmail API vs Himalaya",
    "image": "https://www.anchorterminal.com/assets/og/compare-gmail-api-vs-himalaya.png",
    "path": "/compare/gmail-api-vs-himalaya",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Gmail vs Himalaya for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/gmail-api-vs-himalaya"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 730
  },
  "version": 1
}
