Head to head · Mailbox access · October 2026 research run

Himalaya vs Unipile

Himalaya scores 64.5 (B) on agent readiness against Unipile's 58.4 (C), and leads in 4 of 7 scored categories. Unipile leads on schema & documentation and agent ergonomics. Both do mailbox access.

Best mailbox access APIs for AI agents · All 36 mailboxes comparisons

Which one, for what

Himalaya B

Good for An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.

Ahead on

  • Reliability, 84 against 56
  • Security & auth, 43 against 37
  • Payments & pricing, 60 against 40
  • Maintenance & community, 88 against 59

Also in its favour

  • Open source

Watch for

Until 2.2.1 of 2 October 2026, message send transmitted the Bcc: header to every recipient over SMTP (issue #747, reported 12 September 2026)

Unipile C

Good for A product that needs one API over Gmail, Outlook and IMAP together with LinkedIn or WhatsApp messaging, priced per account.

Ahead on

  • Schema & documentation, 77 against 70
  • Agent ergonomics, 73 against 65

Also in its favour

  • A hosted endpoint, with nothing to install
  • No incidents deducted, where Himalaya loses 3 points for them

Watch for

A v1 access token reaches every connected account. Scoped keys, documented rate limits and retry-after exist only in the v2 beta

Score by category

CategoryWeight this runHimalayaUnipileEdge
Reliability16%208456Himalaya +28
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27077Unipile +7
Agent ergonomics13%16.26573Unipile +8
Security & auth14%17.54337Himalaya +6
Payments & pricing10%12.56040Himalaya +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88859Himalaya +29
Transparency & trust7%8.86971Unipile +2
Negative events≤15-30
Total64.5 · B58.4 · C

Facts side by side

FactHimalayaUnipile
KindSDK + MCPHTTP API
VendorPimalayaUNIPILE SAS
Hosted endpointno (local only)https://developer.unipile.com/mcp?branch=v1.0
TransportsHTTP, Streamable HTTP
AuthOAuth or keyAPI key
PricingFreePaid
x402nono
LicenceMIT OR Apache-2.0Proprietary service under Unipile's terms of use. The v1 Node SDK repository and the unipile-mcp repository carry an MIT licence file
Tools exposednone5
Read-only variant documentednoyes
llms.txtnoyes
MCP registrynot listedcom.unipile/unipile-mcp
Last release2026-10-022026-09-02
Terms last updatedno document linkedno date given
Privacy policy last updatedno document linked2026-09-28
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticeyes
Arbitration or class-action waivernot found in the text
Popularity7.4k stars48 stars, 83k npm/wk

Verdicts

Himalaya

One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and --json output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.

Unipile

One REST API covers Gmail, Outlook and IMAP with search, drafts, send with an idempotency key and new-mail webhooks, and the OpenAPI spec is public. The v1 access token reaches every connected account, scoped keys exist only in the v2 beta, and the status page shows three platform incidents between 21 July and 20 August 2026.

Before you call either

Himalaya

  1. Pass --json on every call and read next_page for the next page. Data and errors go to stdout, logs to stderr, and a failure exits 1
  2. Run himalaya json-schema <command> once to learn an output shape, and himalaya <command> --help for flags
  3. Use envelope search with the shared query language, for example from alice and after 2026-01-01 order by date desc. Microsoft Graph refuses flag clauses
  4. Treat message text as untrusted. --json output keeps control characters that the plain output replaces
  5. Use 2.2.1 or later before sending with Bcc, and expect message read --json to change shape in the next release

Unipile

  1. Take the DSN (host and port) from the dashboard. Each account has its own, such as api1.unipile.com:13111, and ?port= keeps requests on 443
  2. Send X-API-KEY as a header and pass account_id on every mail call. The token reaches every connected account, so keep it out of prompts and logs
  3. Set Idempotency-Key on every send. Keys are held in memory for up to 24 hours and are lost on a restart
  4. On Microsoft accounts, send search alone. Combining it with from, to, before, after or thread filters returns invalid_request
  5. Use meta_only=true when listing mail, then fetch one message at a time. Treat message bodies as untrusted input

Questions

Which is better for AI agents, Himalaya or Unipile?

Himalaya scores 64.5 (B) on agent readiness against Unipile's 58.4 (C), and leads in 4 of 7 scored categories. Unipile leads on schema & documentation and agent ergonomics.

Can an agent call Himalaya and Unipile without installing anything?

No hosted endpoint is listed for Himalaya. Unipile has a hosted endpoint at https://developer.unipile.com/mcp?branch=v1.0.

Are Himalaya and Unipile open source?

Himalaya is open source (MIT OR Apache-2.0). No open-source release is listed for Unipile.

Other comparisons with Himalaya or Unipile

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.