Head to head · Mailbox access · October 2026 research run

Himalaya vs Zoho Mail API

Himalaya scores 64.5 (B) on agent readiness against Zoho Mail API's 53.8 (D), and leads in 5 of 7 scored categories. Zoho Mail API leads on security & auth. Both do mailbox access.

Best mailbox access APIs for AI agents · All 36 mailboxes comparisons

Which one, for what

Himalaya B

Good for An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.

Ahead on

  • Reliability, 84 against 63
  • Schema & documentation, 70 against 45
  • Agent ergonomics, 65 against 56
  • Payments & pricing, 60 against 30
  • Maintenance & community, 88 against 33

Also in its favour

  • Open source

Watch for

Until 2.2.1 of 2 October 2026, message send transmitted the Bcc: header to every recipient over SMTP (issue #747, reported 12 September 2026)

Zoho Mail API D

Good for An agent working inside its owner's Zoho Mail mailbox or administering a Zoho Mail organisation, where narrow scopes and the MCP server keep access small.

Ahead on

  • Security & auth, 67 against 43

Also in its favour

  • No incidents deducted, where Himalaya loses 3 points for them

Watch for

The Zoho Mail usage policy, updated 2 September 2026, lists automated, bulk and transactional emails among uses that are not allowed.

Score by category

CategoryWeight this runHimalayaZoho Mail APIEdge
Reliability16%208463Himalaya +21
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27045Himalaya +25
Agent ergonomics13%16.26556Himalaya +9
Security & auth14%17.54367Zoho Mail API +24
Payments & pricing10%12.56030Himalaya +30
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88833Himalaya +55
Transparency & trust7%8.86973Zoho Mail API +4
Negative events≤15-30
Total64.5 · B53.8 · D

Facts side by side

FactHimalayaZoho Mail API
KindSDK + MCPHTTP API
VendorPimalayaZoho
Hosted endpointno (local only)no (local only)
TransportsHTTP
AuthOAuth or keyOAuth
PricingFreeFreemium
x402nono
LicenceMIT OR Apache-2.0Proprietary service under the Zoho Terms of Service and the Zoho Mail usage policy. No source repository was found
Read-only variant documentednono
llms.txtnoyes
Last release2026-10-02none
Terms last updatedno document linked2022-03-02
Privacy policy last updatedno document linked2025-12-22
Customer content may train modelsyes
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity7.4k starsnone

Verdicts

Himalaya

One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and --json output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.

Zoho Mail API

A REST API over a Zoho Mail mailbox with OAuth scopes that narrow to one resource and one operation, plus an MCP server launched in 2026. Zoho publishes no OpenAPI file, SDK, request rate limit or API changelog, and its usage policy bars automated email.

Before you call either

Himalaya

  1. Pass --json on every call and read next_page for the next page. Data and errors go to stdout, logs to stderr, and a failure exits 1
  2. Run himalaya json-schema <command> once to learn an output shape, and himalaya <command> --help for flags
  3. Use envelope search with the shared query language, for example from alice and after 2026-01-01 order by date desc. Microsoft Graph refuses flag clauses
  4. Treat message text as untrusted. --json output keeps control characters that the plain output replaces
  5. Use 2.2.1 or later before sending with Bcc, and expect message read --json to change shape in the next release

Zoho Mail API

  1. Send Authorization: Zoho-oauthtoken <token>, not Bearer. The token response says Bearer, but the OAuth guide says the Mail API requires the Zoho prefix.
  2. Use the host for the account's data centre, such as mail.zoho.eu or mail.zoho.in. Call GET /api/accounts first for the accountId every mailbox call needs.
  3. Reading a message body needs both folderId and messageId. List and search calls return a summary only, 10 messages by default and 200 at most.
  4. Request ZohoMail.messages.READ alone for a reading agent. Add CREATE only when it must send, and leave DELETE out unless required.
  5. Refresh the access token every hour, and post OAuth parameters in the request body where the server accepts it, to keep secrets out of URLs.

Questions

Which is better for AI agents, Himalaya or Zoho Mail API?

Himalaya scores 64.5 (B) on agent readiness against Zoho Mail API's 53.8 (D), and leads in 5 of 7 scored categories. Zoho Mail API leads on security & auth.

Can an agent call Himalaya and Zoho Mail API without installing anything?

No hosted endpoint is listed for Himalaya. No hosted endpoint is listed for Zoho Mail API.

Are Himalaya and Zoho Mail API open source?

Himalaya is open source (MIT OR Apache-2.0). No open-source release is listed for Zoho Mail API.

Other comparisons with Himalaya or Zoho Mail API

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.