{
  "data": {
    "a": {
      "slug": "himalaya",
      "name": "Himalaya",
      "vendor": "Pimalaya",
      "vendorUrl": "https://pimalaya.org",
      "kind": "sdk",
      "category": "mailbox-access",
      "summary": "Himalaya is an open-source command-line email client from the Pimalaya project. It lists, searches, reads, composes and sends mail over IMAP, SMTP, JMAP, the Gmail API, Microsoft Graph and local stores, with JSON output for scripts and agents.",
      "url": "https://www.anchorterminal.com/tools/himalaya",
      "markdownUrl": "https://www.anchorterminal.com/tools/himalaya.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/himalaya.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/himalaya.json",
      "repo": "https://github.com/pimalaya/himalaya",
      "license": "MIT OR Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "cargo",
          "name": "himalaya"
        }
      ],
      "auth": "mixed",
      "authNotes": "Himalaya issues no credential of its own. It signs in to the mailbox with what the provider accepts, which is an app password or account password over SASL for IMAP and SMTP, a bearer token or basic auth for JMAP, and one OAuth 2.0 bearer token for the Gmail API or Microsoft Graph. Each secret is read from a shell command such as a password manager, or from a raw value in the config file. Version 2 ships no OAuth flow, so tokens come from an external broker such as `ortie` and an OAuth app the owner registers with Google or Microsoft.",
      "pricing": "free",
      "pricingNotes": "Free software with nothing to buy, and the sponsor page states there is no paid tier. An agent can start with the binary and a mailbox credential. Pimalaya sells optional partnerships, from EUR 3,000 a year for email providers and EUR 5,000 for integrators, and describes a EUR 12 a year sign-in service for Gmail and Microsoft 365 as planned and not built (checked 2026-10-09).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the source or pimalaya.org (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 7412,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://github.com/pimalaya/himalaya",
      "capabilities": [
        "mailbox.read",
        "mailbox.search",
        "mailbox.send",
        "mailbox.drafts"
      ],
      "tags": [
        "open-source",
        "local",
        "cli",
        "rust",
        "free",
        "no-card",
        "imap",
        "smtp",
        "jmap",
        "gmail",
        "microsoft-graph",
        "json-output"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.5,
        "grade": "B",
        "agentReady": false,
        "rank": 348,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 88,
          "payments": 60,
          "reliability": 84,
          "schema": 70,
          "security": 43,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -3,
        "negativeNotes": [
          "2 October 2026. Until 2.2.1, `message send` passed the `Bcc:` header through SMTP unchanged, so every recipient could see the blind recipients. Issue #747 reported it against 2.1.0 on 12 September 2026, the fix was committed on 26 September and released on 2 October, and the changelog documents it. No security advisory was published. Fixed and documented, so the smaller deduction applies (https://github.com/pimalaya/himalaya/issues/747)"
        ],
        "verdict": "One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.",
        "bestFor": "An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.",
        "strengths": [
          "Shared commands for mailboxes, envelopes, flags, messages and attachments run the same way over IMAP, JMAP, Gmail, Microsoft Graph, Maildir and mbox",
          "`himalaya json-schema` prints a JSON Schema for the `--json` output of 90 commands, and `message read --json` returns one designed view on every backend",
          "Secrets come from a shell command such as `pass show`, so a password or token need not sit in the config file",
          "`message delete` moves mail to the trash first, and `message read` leaves flags alone unless `--seen` is passed",
          "Four tagged releases between 26 July and 2 October 2026, three open issues, and CI badges for tests and audit passing on 9 October 2026"
        ],
        "weaknesses": [
          "Until 2.2.1 of 2 October 2026, `message send` transmitted the `Bcc:` header to every recipient over SMTP (issue #747, reported 12 September 2026)",
          "No read-only mode, no confirmation before a send or delete, and no idempotency key on send were found",
          "SECURITY.md sends vulnerability reports to the public issue tracker. No security.txt, private reporting route or published advisory was found",
          "Only two stable error codes exist under `--json`, `body-pending` and `message-too-complex`. Other failures carry free wording",
          "Version 2 ships no OAuth flow, so Gmail and Microsoft accounts need an external token broker and an OAuth app the owner registers"
        ],
        "agentNotes": [
          "Pass `--json` on every call and read `next_page` for the next page. Data and errors go to stdout, logs to stderr, and a failure exits 1",
          "Run `himalaya json-schema \u003ccommand\u003e` once to learn an output shape, and `himalaya \u003ccommand\u003e --help` for flags",
          "Use `envelope search` with the shared query language, for example `from alice and after 2026-01-01 order by date desc`. Microsoft Graph refuses flag clauses",
          "Treat message text as untrusted. `--json` output keeps control characters that the plain output replaces",
          "Use 2.2.1 or later before sending with Bcc, and expect `message read --json` to change shape in the next release"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.5
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 88,
          "payments": 60,
          "reliability": 84,
          "schema": 70,
          "security": 43,
          "transparency": 74
        },
        "provenanceScore": 63
      },
      "connect": {
        "install": "brew install himalaya   # or: curl -sSL https://raw.githubusercontent.com/pimalaya/himalaya/master/install.sh | PREFIX=~/.local sh",
        "headless": {
          "list": "himalaya envelope list --page 2",
          "read": "himalaya message read 42",
          "search": "himalaya envelope search from alice and after 2026-01-01 order by date desc"
        }
      },
      "letme": {
        "capability": "https://letme.dev/mailbox.read",
        "tool": "https://letme.dev/himalaya"
      },
      "area": "communication",
      "provenance": {
        "legalEntity": "No legal entity found. Copyright Clément DOUIN (soywod)",
        "domain": "pimalaya.org",
        "domainRegistered": "2022-12-21",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/pimalaya/himalaya/blob/master/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "pimalaya.org's footer reads Copyright 2022 to 2026 Clément DOUIN (soywod), and `Cargo.toml` names the same author. No company or foundation is named on the pages read.",
          "No terms of service or privacy policy was found. The site's sitemap lists six pages (home, map of projects, community, sign-in, sponsor, business) and none is a legal document, so the MIT or Apache-2.0 licence stands in.",
          "pimalaya.org/.well-known/security.txt and /security.txt both return 404. SECURITY.md in the repository lists 2.x as the supported line and gives the public issue tracker for reports.",
          "RDAP for pimalaya.org gives a registration date of 2022-12-21 and OVH sas as registrar.",
          "The software runs on the owner's machine and connects to the owner's mail servers, so no vendor endpoint exists."
        ],
        "score": 63
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/himalaya.json",
      "live": {
        "slug": "himalaya",
        "versions": [
          {
            "registry": "github",
            "name": "pimalaya/himalaya",
            "version": "v2.2.1",
            "released": "2026-10-02",
            "seenAt": "2026-10-09T16:57:44.106760361Z"
          }
        ],
        "githubStars": 7417,
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/pimalaya/himalaya/master/CHANGELOG.md",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:45:53.201845848Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "cb5190799b74"
          }
        ],
        "updatedAt": "2026-10-09T18:45:53.201845848Z"
      }
    },
    "answer": "Himalaya scores 64.5 (B) on agent readiness against Zoho Mail API's 53.8 (D), and leads in 5 of 7 scored categories. Zoho Mail API leads on security \u0026 auth.",
    "b": {
      "slug": "zoho-mail",
      "name": "Zoho Mail API",
      "vendor": "Zoho",
      "vendorUrl": "https://www.zoho.com/mail/",
      "kind": "http-api",
      "category": "mailbox-access",
      "summary": "Zoho Mail is Zoho's hosted business email service. Its REST API lets an application read, search, send and organise mail in a Zoho Mail account and administer an organisation's users, domains, groups and policies, with OAuth 2.0 access.",
      "url": "https://www.anchorterminal.com/tools/zoho-mail",
      "markdownUrl": "https://www.anchorterminal.com/tools/zoho-mail.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/zoho-mail.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/zoho-mail.json",
      "license": "Proprietary service under the Zoho Terms of Service and the Zoho Mail usage policy. No source repository was found",
      "transports": [
        "http"
      ],
      "packages": [],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 only. A person registers a client in the Zoho API console (server-based, client-based, mobile, non-browser with device authorisation, or a self client for one's own account) and approves scopes of the form `ZohoMail.\u003cresource\u003e.\u003coperation\u003e`. Registration is self-serve, with no app review or sales approval found. The access token lasts one hour and goes in `Authorization: Zoho-oauthtoken \u003ctoken\u003e`. The refresh token lasts until revoked. Organisation calls need an administrator's account. Each data centre has its own accounts host and API host.",
      "pricing": "freemium",
      "pricingNotes": "API access comes with a mailbox plan and has no per-call charge. Mail Free covers up to five users on one domain with no card and is available in some regions only. Paid plans cost $1 to $6 a user a month billed yearly, with a 15-day trial of the highest edition and no card. The API guide says plan and mail policy decide which APIs an account can call (https://www.zoho.com/mail/zohomail-pricing.html, checked 2026-10-09).",
      "priceSummary": "$1 / seat-mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API guide, the OAuth guide or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://www.zoho.com/mail/help/api/",
      "llmsTxt": "https://www.zoho.com/mail/help/llms.txt",
      "capabilities": [
        "mailbox.read",
        "mailbox.search",
        "mailbox.send",
        "mailbox.drafts",
        "mailbox.sync"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "oauth",
        "mcp",
        "webhooks",
        "free-tier",
        "no-card",
        "llms-txt",
        "email",
        "status-page",
        "bug-bounty",
        "soc2",
        "eu-data-residency"
      ],
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 53.8,
        "grade": "D",
        "agentReady": false,
        "rank": 702,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 56,
          "maintenance": 33,
          "payments": 30,
          "reliability": 63,
          "schema": 45,
          "security": 67,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "A REST API over a Zoho Mail mailbox with OAuth scopes that narrow to one resource and one operation, plus an MCP server launched in 2026. Zoho publishes no OpenAPI file, SDK, request rate limit or API changelog, and its usage policy bars automated email.",
        "bestFor": "An agent working inside its owner's Zoho Mail mailbox or administering a Zoho Mail organisation, where narrow scopes and the MCP server keep access small.",
        "strengths": [
          "OAuth scopes name one resource and one operation, such as `ZohoMail.messages.READ`, so an agent can hold read access without send or delete.",
          "Every reference page has a Markdown twin, indexed in `https://www.zoho.com/mail/help/llms.txt`, with a curl sample and a sample response.",
          "Zoho Mail MCP exposes the API methods as tools on a remote server, and the owner picks which tools a server carries.",
          "The Mail Free plan covers five users on one domain with no card, and the MCP FAQ says free and paid plans both work.",
          "Delete moves a message to Trash unless `expunge=true` is sent, and audit records, login history and SMTP logs are readable through the Logs API."
        ],
        "weaknesses": [
          "The Zoho Mail usage policy, updated 2 September 2026, lists automated, bulk and transactional emails among uses that are not allowed.",
          "No OpenAPI file, official REST SDK or dated API changelog was found. The path carries no version.",
          "The getting started guide says each API has its own rate limit and gives no numbers. The response code list has no 429.",
          "External sending is capped at 50 to 500 emails an hour by sender reputation, with a block of up to one hour once the cap is reached.",
          "The OAuth guide's token, refresh and revoke examples carry the client secret and refresh token in the URL query string."
        ],
        "agentNotes": [
          "Send `Authorization: Zoho-oauthtoken \u003ctoken\u003e`, not `Bearer`. The token response says `Bearer`, but the OAuth guide says the Mail API requires the Zoho prefix.",
          "Use the host for the account's data centre, such as `mail.zoho.eu` or `mail.zoho.in`. Call `GET /api/accounts` first for the `accountId` every mailbox call needs.",
          "Reading a message body needs both `folderId` and `messageId`. List and search calls return a summary only, 10 messages by default and 200 at most.",
          "Request `ZohoMail.messages.READ` alone for a reading agent. Add `CREATE` only when it must send, and leave `DELETE` out unless required.",
          "Refresh the access token every hour, and post OAuth parameters in the request body where the server accepts it, to keep secrets out of URLs."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 53.8
          }
        ],
        "editorialScores": {
          "ergonomics": 56,
          "maintenance": 33,
          "payments": 30,
          "reliability": 63,
          "schema": 45,
          "security": 67,
          "transparency": 51
        },
        "provenanceScore": 95
      },
      "connect": {
        "http": "curl \"https://mail.zoho.com/api/accounts\" \\\n  -X GET \\\n  -H \"Accept: application/json\" \\\n  -H \"Authorization: Zoho-oauthtoken $ZOHO_ACCESS_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/mailbox.read",
        "tool": "https://letme.dev/zoho-mail"
      },
      "sameCompany": [
        "zoho-books",
        "zoho-zeptomail",
        "zoho-crm",
        "zoho-desk",
        "zoho-recruit",
        "zoho-people"
      ],
      "area": "communication",
      "unitPrices": [
        {
          "item": "Mail Lite, 5 GB",
          "unit": "seat-month",
          "usd": 1,
          "note": "billed yearly, no monthly plan. $1.25 for 10 GB"
        },
        {
          "item": "Workplace Standard",
          "unit": "seat-month",
          "usd": 3,
          "note": "billed yearly. $4 billed monthly. 30 GB mailbox plus the office suite"
        },
        {
          "item": "Mail Premium",
          "unit": "seat-month",
          "usd": 4,
          "note": "billed yearly, no monthly plan. 50 GB mailbox with retention and eDiscovery"
        },
        {
          "item": "Workplace Professional",
          "unit": "seat-month",
          "usd": 6,
          "note": "billed yearly. 100 GB mailbox"
        }
      ],
      "provenance": {
        "legalEntity": "Zoho Corporation Private Limited",
        "domain": "zoho.com",
        "domainRegistered": "2004-01-16",
        "endpointOnVendorDomain": true,
        "terms": "https://www.zoho.com/terms.html",
        "privacy": "https://www.zoho.com/privacy.html",
        "statusPage": "https://status.zoho.com",
        "changelog": "https://www.zoho.com/mail/whats-new.html",
        "securityTxt": "valid",
        "checked": "2026-10-09",
        "notes": [
          "The Terms of Service (last updated 2 March 2022) are the service agreement for Zoho's online services. The contracting entity depends on the customer's region, Zoho Corporation Private Limited for India and Zoho Corporation for the United States (https://www.zoho.com/legal/zoho-contracting-entities.html).",
          "The Zoho Mail usage policy at https://www.zoho.com/mail/help/usage-policy.html, last updated 2 September 2026, adds rules for the mail service and bars automated and bulk email.",
          "The privacy policy was last updated on 22 December 2025. Part II covers data Zoho processes on a customer's behalf.",
          "security.txt at www.zoho.com gives a bug bounty contact, security@zohocorp.com, a policy link and an expiry of 30 June 2028.",
          "What's New is a product changelog dated by month, with the latest entries under August 2026. No API changelog was found.",
          "The US API answers on mail.zoho.com. Other data centres use mail.zoho.eu, mail.zoho.in, mail.zoho.com.au, mail.zoho.jp, mail.zohocloud.ca, mail.zoho.com.cn, mail.zoho.ae and mail.zoho.sa. OAuth runs on accounts.zoho.com.",
          "RDAP for zoho.com gives a registration date of 2004-01-16 and expiry on 2031-01-16."
        ],
        "score": 95
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/zoho-mail.json",
      "live": {
        "slug": "zoho-mail",
        "securityTxt": {
          "url": "https://zoho.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2028-06-30T23:59:59.000Z",
          "checkedAt": "2026-10-09T15:40:32.838784892Z"
        },
        "llmsTxt": {
          "url": "https://www.zoho.com/mail/help/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:03:05.053121001Z"
        },
        "pages": [
          {
            "url": "https://www.zoho.com/mail/whats-new.html",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:56:15.852510636Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5dd41bf4a099"
          },
          {
            "url": "https://www.zoho.com/mail/zohomail-pricing.html",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:56:17.891172142Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0823801268d9"
          }
        ],
        "updatedAt": "2026-10-09T18:56:17.891172142Z"
      }
    },
    "facts": [
      {
        "a": "SDK + MCP",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Pimalaya",
        "b": "Zoho",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT OR Apache-2.0",
        "b": "Proprietary service under the Zoho Terms of Service and the Zoho Mail usage policy. No source repository was found",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-02",
        "b": "none",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2022-03-02",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "2025-12-22",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "7.4k stars",
        "b": "none",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Himalaya scores 64.5 (B) on agent readiness against Zoho Mail API's 53.8 (D), and leads in 5 of 7 scored categories. Zoho Mail API leads on security \u0026 auth.",
        "question": "Which is better for AI agents, Himalaya or Zoho Mail API?"
      },
      {
        "answer": "No hosted endpoint is listed for Himalaya. No hosted endpoint is listed for Zoho Mail API.",
        "question": "Can an agent call Himalaya and Zoho Mail API without installing anything?"
      },
      {
        "answer": "Himalaya is open source (MIT OR Apache-2.0). No open-source release is listed for Zoho Mail API.",
        "question": "Are Himalaya and Zoho Mail API open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 84 against 63",
          "Schema \u0026 documentation, 70 against 45",
          "Agent ergonomics, 65 against 56",
          "Payments \u0026 pricing, 60 against 30",
          "Maintenance \u0026 community, 88 against 33"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.",
        "slug": "himalaya",
        "watchFor": "Until 2.2.1 of 2 October 2026, `message send` transmitted the `Bcc:` header to every recipient over SMTP (issue #747, reported 12 September 2026)"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 67 against 43"
        ],
        "also": [
          "No incidents deducted, where Himalaya loses 3 points for them"
        ],
        "goodFor": "An agent working inside its owner's Zoho Mail mailbox or administering a Zoho Mail organisation, where narrow scopes and the MCP server keep access small.",
        "slug": "zoho-mail",
        "watchFor": "The Zoho Mail usage policy, updated 2 September 2026, lists automated, bulk and transactional emails among uses that are not allowed."
      }
    ],
    "job": {
      "capability": "mailbox.read",
      "name": "Mailbox access"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aurinko-email-vs-himalaya.json",
        "title": "Aurinko Email API vs Himalaya",
        "url": "https://www.anchorterminal.com/compare/aurinko-email-vs-himalaya"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aurinko-email-vs-zoho-mail.json",
        "title": "Aurinko Email API vs Zoho Mail API",
        "url": "https://www.anchorterminal.com/compare/aurinko-email-vs-zoho-mail"
      },
      {
        "json": "https://www.anchorterminal.com/compare/emailengine-vs-himalaya.json",
        "title": "EmailEngine vs Himalaya",
        "url": "https://www.anchorterminal.com/compare/emailengine-vs-himalaya"
      },
      {
        "json": "https://www.anchorterminal.com/compare/emailengine-vs-zoho-mail.json",
        "title": "EmailEngine vs Zoho Mail API",
        "url": "https://www.anchorterminal.com/compare/emailengine-vs-zoho-mail"
      },
      {
        "json": "https://www.anchorterminal.com/compare/fastmail-vs-himalaya.json",
        "title": "Fastmail API (JMAP) vs Himalaya",
        "url": "https://www.anchorterminal.com/compare/fastmail-vs-himalaya"
      },
      {
        "json": "https://www.anchorterminal.com/compare/fastmail-vs-zoho-mail.json",
        "title": "Fastmail API (JMAP) vs Zoho Mail API",
        "url": "https://www.anchorterminal.com/compare/fastmail-vs-zoho-mail"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gmail-api-vs-himalaya.json",
        "title": "Gmail API vs Himalaya",
        "url": "https://www.anchorterminal.com/compare/gmail-api-vs-himalaya"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gmail-api-vs-zoho-mail.json",
        "title": "Gmail API vs Zoho Mail API",
        "url": "https://www.anchorterminal.com/compare/gmail-api-vs-zoho-mail"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-nylas-email.json",
        "title": "Himalaya vs Nylas Email API",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-nylas-email"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-outlook-mail-graph.json",
        "title": "Himalaya vs Outlook Mail (Microsoft Graph)",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-outlook-mail-graph"
      },
      {
        "json": "https://www.anchorterminal.com/compare/himalaya-vs-unipile.json",
        "title": "Himalaya vs Unipile",
        "url": "https://www.anchorterminal.com/compare/himalaya-vs-unipile"
      },
      {
        "json": "https://www.anchorterminal.com/compare/nylas-email-vs-zoho-mail.json",
        "title": "Nylas Email API vs Zoho Mail API",
        "url": "https://www.anchorterminal.com/compare/nylas-email-vs-zoho-mail"
      },
      {
        "json": "https://www.anchorterminal.com/compare/outlook-mail-graph-vs-zoho-mail.json",
        "title": "Outlook Mail (Microsoft Graph) vs Zoho Mail API",
        "url": "https://www.anchorterminal.com/compare/outlook-mail-graph-vs-zoho-mail"
      },
      {
        "json": "https://www.anchorterminal.com/compare/unipile-vs-zoho-mail.json",
        "title": "Unipile vs Zoho Mail API",
        "url": "https://www.anchorterminal.com/compare/unipile-vs-zoho-mail"
      }
    ],
    "scores": [
      {
        "by": 21,
        "edge": "himalaya",
        "himalaya": 84,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16,
        "zoho-mail": 63
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 25,
        "edge": "himalaya",
        "himalaya": 70,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13,
        "zoho-mail": 45
      },
      {
        "by": 9,
        "edge": "himalaya",
        "himalaya": 65,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13,
        "zoho-mail": 56
      },
      {
        "by": 24,
        "edge": "zoho-mail",
        "himalaya": 43,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14,
        "zoho-mail": 67
      },
      {
        "by": 30,
        "edge": "himalaya",
        "himalaya": 60,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10,
        "zoho-mail": 30
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 55,
        "edge": "himalaya",
        "himalaya": 88,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7,
        "zoho-mail": 33
      },
      {
        "by": 4,
        "edge": "zoho-mail",
        "himalaya": 69,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7,
        "zoho-mail": 73
      }
    ],
    "summary": "Himalaya scores 64.5 (B) on agent readiness against Zoho Mail API's 53.8 (D), and leads in 5 of 7 scored categories. Zoho Mail API leads on security \u0026 auth. Both do mailbox access.",
    "verdicts": {
      "himalaya": "One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.",
      "zoho-mail": "A REST API over a Zoho Mail mailbox with OAuth scopes that narrow to one resource and one operation, plus an MCP server launched in 2026. Zoho publishes no OpenAPI file, SDK, request rate limit or API changelog, and its usage policy bars automated email."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail",
    "json": "https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail.md",
    "slim": "https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail.min.md"
  },
  "markdown": "Himalaya scores 64.5 (B) on agent readiness against Zoho Mail API's 53.8 (D), and leads in 5 of 7 scored categories. Zoho Mail API leads on security \u0026 auth. Both do mailbox access.\n\n- Himalaya: grade B, 64.5/100, rank #348 of 950. Markdown https://www.anchorterminal.com/tools/himalaya.md · JSON https://www.anchorterminal.com/api/v1/tools/himalaya.json\n- Zoho Mail API: grade D, 53.8/100, rank #702 of 950. Markdown https://www.anchorterminal.com/tools/zoho-mail.md · JSON https://www.anchorterminal.com/api/v1/tools/zoho-mail.json\n- Best mailbox access APIs for AI agents: https://www.anchorterminal.com/best/mailbox-access/index.md\n- All 36 mailboxes comparisons: https://www.anchorterminal.com/compare/mailbox-access/index.md\n\n## Which one, for what\n\n### Himalaya (B)\n\nGood for: An agent with a shell that must work in one person's existing mailbox on any provider, including plain IMAP hosts, without a hosted intermediary.\n\nAhead on:\n- Reliability, 84 against 63\n- Schema \u0026 documentation, 70 against 45\n- Agent ergonomics, 65 against 56\n- Payments \u0026 pricing, 60 against 30\n- Maintenance \u0026 community, 88 against 33\n\nAlso in its favour:\n- Open source\n\nWatch for: Until 2.2.1 of 2 October 2026, `message send` transmitted the `Bcc:` header to every recipient over SMTP (issue #747, reported 12 September 2026)\n\n### Zoho Mail API (D)\n\nGood for: An agent working inside its owner's Zoho Mail mailbox or administering a Zoho Mail organisation, where narrow scopes and the MCP server keep access small.\n\nAhead on:\n- Security \u0026 auth, 67 against 43\n\nAlso in its favour:\n- No incidents deducted, where Himalaya loses 3 points for them\n\nWatch for: The Zoho Mail usage policy, updated 2 September 2026, lists automated, bulk and transactional emails among uses that are not allowed.\n\n\n## Score by category\n\n| Category | Weight | Himalaya | Zoho Mail API | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 84 | 63 | Himalaya +21 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 70 | 45 | Himalaya +25 |\n| Agent ergonomics | 13% (16.2 this run) | 65 | 56 | Himalaya +9 |\n| Security \u0026 auth | 14% (17.5 this run) | 43 | 67 | Zoho Mail API +24 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 30 | Himalaya +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 88 | 33 | Himalaya +55 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 69 | 73 | Zoho Mail API +4 |\n| Negative events | ≤15 | -3 | 0 | |\n| **Total** | | **64.5 · B** | **53.8 · D** | |\n\n## Facts side by side\n\n| Fact | Himalaya | Zoho Mail API |\n| --- | --- | --- |\n| Kind | SDK + MCP | HTTP API |\n| Vendor | Pimalaya | Zoho |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  | HTTP |\n| Auth | OAuth or key | OAuth |\n| Pricing | Free | Freemium |\n| x402 | no | no |\n| Licence | MIT OR Apache-2.0 | Proprietary service under the Zoho Terms of Service and the Zoho Mail usage policy. No source repository was found |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| Last release | 2026-10-02 | none |\n| Terms last updated | no document linked | 2022-03-02 |\n| Privacy policy last updated | no document linked | 2025-12-22 |\n| Customer content may train models |  | yes |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | yes |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 7.4k stars | none |\n\n## Verdicts\n\n**Himalaya.** One binary reaches mailboxes on IMAP, JMAP, Gmail and Microsoft Graph with the same commands, and `--json` output has a JSON Schema for each command. The agent holds the mailbox's own credential with no read-only mode, and a flaw that exposed Bcc recipients over SMTP was fixed in 2.2.1 on 2 October 2026.\n\n**Zoho Mail API.** A REST API over a Zoho Mail mailbox with OAuth scopes that narrow to one resource and one operation, plus an MCP server launched in 2026. Zoho publishes no OpenAPI file, SDK, request rate limit or API changelog, and its usage policy bars automated email.\n\n## Before you call either\n\n### Himalaya\n\n1. Pass `--json` on every call and read `next_page` for the next page. Data and errors go to stdout, logs to stderr, and a failure exits 1\n2. Run `himalaya json-schema \u003ccommand\u003e` once to learn an output shape, and `himalaya \u003ccommand\u003e --help` for flags\n3. Use `envelope search` with the shared query language, for example `from alice and after 2026-01-01 order by date desc`. Microsoft Graph refuses flag clauses\n4. Treat message text as untrusted. `--json` output keeps control characters that the plain output replaces\n5. Use 2.2.1 or later before sending with Bcc, and expect `message read --json` to change shape in the next release\n\n### Zoho Mail API\n\n1. Send `Authorization: Zoho-oauthtoken \u003ctoken\u003e`, not `Bearer`. The token response says `Bearer`, but the OAuth guide says the Mail API requires the Zoho prefix.\n2. Use the host for the account's data centre, such as `mail.zoho.eu` or `mail.zoho.in`. Call `GET /api/accounts` first for the `accountId` every mailbox call needs.\n3. Reading a message body needs both `folderId` and `messageId`. List and search calls return a summary only, 10 messages by default and 200 at most.\n4. Request `ZohoMail.messages.READ` alone for a reading agent. Add `CREATE` only when it must send, and leave `DELETE` out unless required.\n5. Refresh the access token every hour, and post OAuth parameters in the request body where the server accepts it, to keep secrets out of URLs.\n\n## Questions\n\n### Which is better for AI agents, Himalaya or Zoho Mail API?\n\nHimalaya scores 64.5 (B) on agent readiness against Zoho Mail API's 53.8 (D), and leads in 5 of 7 scored categories. Zoho Mail API leads on security \u0026 auth.\n\n### Can an agent call Himalaya and Zoho Mail API without installing anything?\n\nNo hosted endpoint is listed for Himalaya. No hosted endpoint is listed for Zoho Mail API.\n\n### Are Himalaya and Zoho Mail API open source?\n\nHimalaya is open source (MIT OR Apache-2.0). No open-source release is listed for Zoho Mail API.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail.json, and with the fewest tokens: https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"himalaya\", \"b\": \"zoho-mail\"}`. From a terminal: `anchor compare himalaya zoho-mail`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/himalaya.json and https://www.anchorterminal.com/api/v1/tools/zoho-mail.json\n\n## Other comparisons with Himalaya or Zoho Mail API\n\n- [Aurinko Email API vs Himalaya](https://www.anchorterminal.com/compare/aurinko-email-vs-himalaya.md)\n- [Aurinko Email API vs Zoho Mail API](https://www.anchorterminal.com/compare/aurinko-email-vs-zoho-mail.md)\n- [EmailEngine vs Himalaya](https://www.anchorterminal.com/compare/emailengine-vs-himalaya.md)\n- [EmailEngine vs Zoho Mail API](https://www.anchorterminal.com/compare/emailengine-vs-zoho-mail.md)\n- [Fastmail API (JMAP) vs Himalaya](https://www.anchorterminal.com/compare/fastmail-vs-himalaya.md)\n- [Fastmail API (JMAP) vs Zoho Mail API](https://www.anchorterminal.com/compare/fastmail-vs-zoho-mail.md)\n- [Gmail API vs Himalaya](https://www.anchorterminal.com/compare/gmail-api-vs-himalaya.md)\n- [Gmail API vs Zoho Mail API](https://www.anchorterminal.com/compare/gmail-api-vs-zoho-mail.md)\n- [Himalaya vs Nylas Email API](https://www.anchorterminal.com/compare/himalaya-vs-nylas-email.md)\n- [Himalaya vs Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/compare/himalaya-vs-outlook-mail-graph.md)\n- [Himalaya vs Unipile](https://www.anchorterminal.com/compare/himalaya-vs-unipile.md)\n- [Nylas Email API vs Zoho Mail API](https://www.anchorterminal.com/compare/nylas-email-vs-zoho-mail.md)\n- [Outlook Mail (Microsoft Graph) vs Zoho Mail API](https://www.anchorterminal.com/compare/outlook-mail-graph-vs-zoho-mail.md)\n- [Unipile vs Zoho Mail API](https://www.anchorterminal.com/compare/unipile-vs-zoho-mail.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Himalaya vs Zoho Mail API",
        "url": ""
      }
    ],
    "description": "Himalaya scores 64.5 (B) to Zoho Mail's 53.8 (D) for mailbox access. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Himalaya B 64.5",
      "Zoho Mail API D 53.8",
      "scores"
    ],
    "h1": "Himalaya vs Zoho Mail API",
    "image": "https://www.anchorterminal.com/assets/og/compare-himalaya-vs-zoho-mail.png",
    "path": "/compare/himalaya-vs-zoho-mail",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Himalaya vs Zoho Mail for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/himalaya-vs-zoho-mail"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 680
  },
  "version": 1
}
