Aurinko Email API
by Yoxel, Inc. HTTP API in Mailbox access
Hosted
Yoxel, Inc. · aurinko.io since 2019 · who's behind it
Unified email REST API from Yoxel, Inc. It reads, searches, drafts and sends mail in a user's own mailbox on Gmail, Office 365, Outlook.com, Exchange, Zoho Mail, iCloud and IMAP, with delta sync, open and reply tracking and webhooks.
Good for A product that connects many users' Gmail and Microsoft mailboxes and wants one schema, delta sync, tracking and webhooks at a low price per account.
Is this your product? Claim this listing or verify it
More from Yoxel, Inc. Aurinko Calendar API (Scheduling)
Assessment. One REST interface covers message search with 17 query operators, drafts, sending, folders and delta sync across seven mailbox types, at $1.50 an active account a month and with send-only and read-only scopes. No status page, SLA, changelog, idempotency key on send or official SDK was found, and SOC 2 is not yet held.
Facts
- Transport
- HTTP
- Endpoint
https://api.aurinko.io- Auth
- OAuth
- Pricing
- Paid · Paid
- x402
- No
- Licence
- Proprietary service under Yoxel's Terms of Services Agreement
- llms.txt
- published
- Surface graded
- The REST API at https://api.aurinko.io/v1. No MCP server was found in the docs or on the site
- Providers
- Gmail, Office 365, Outlook.com, MS Exchange, Zoho Mail, iCloud and IMAP per the Email API guide. The product page also names Yahoo
- Email endpoints
/v1/email/messages(list, send, get, raw, delete to Trash, status, reply, attachments),/v1/email/conversations/{threadId},/v1/email/drafts(create, update, get, delete, send withsendTime),/v1/email/foldersand/v1/email/sync- Search
qon message lists with 17 operators, among themfrom:,to:,subject:,after:,before:,has:,is:,label:(Gmail only) andrfc822msgid:. Date operators are partly supported on IMAP and Exchange- Sync
POST /v1/email/syncwithdaysWithin, then/v1/email/sync/updatedand/v1/email/sync/deletedwithdeltaTokenandpageToken. A 410 response is declared on both delta calls- Tracking and follow-ups
- Open and reply tracking on sent mail, 10 operations under
/v1/email/trackingand/v1/email/draftTracking, and 9 follow-up rule operations under/v1/followup - Credentials
- Account access token (Bearer) from the OAuth flow, client ID and secret (Basic) for application-level calls, or a user session in
X-Aurinko-Sessionor a cookie. IMAP accounts connect with an app password or the mailbox password - Scopes
Mail.Read,Mail.ReadWrite(no send),Mail.Send(send only),Mail.Drafts, andMail.Allin the description file only, beside six calendar, contacts and tasks scopes- Rate limits
- 250 requests a second for API calls, per the description file. Provider limits behind the API can also return 429
- Errors
- JSON body with
code,message,requestIdand the provider'soriginalError. The description file advises exponential backoff on 429 and 5xx, a retry on 408, and no retry on 404 - Webhooks
POST /v1/subscriptionswith resource/email/messagesor/email/tracking, signed with HMAC SHA256 overv0:{timestamp}:{raw_body}inX-Aurinko-Signature. Gmail push needs the developer's own Google Pub/Sub setup- Trial
- 14 days with full API access. API requests are blocked at expiry until a card is added in the portal
- SDKs
- No official SDK is named in the docs or on the site
- Security statement
- TLS in transit and AES-256 at rest, MFA and role-based access, third-party penetration tests, SOC 2 Type I targeted for Q3 2026 (statement of 18 June 2026)
Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Public OpenAPI 3.0 description at
apirefs.aurinko.io/assets/swagger.json, with 43 email operations, 34 of them carrying a cURL sample - Four mail scopes.
Mail.Readallows no writes,Mail.Sendallows sending with no read access, andMail.ReadWriteexcludes send - The
qparameter takes 17 search operators, with a table in the docs saying where IMAP and Exchange support is partial - Prices published per active account a month ($1.50 for email, $2 for all APIs with IMAP), with a 14-day trial
- Docs state that message contents are passed through and never stored, with only IDs and thread relations cached for sync
Weaknesses
- No status page, incident history or SLA found, and the terms supply the service as is
- No idempotency key on
POST /v1/email/messages, so a retried send can deliver twice - No changelog, deprecation policy or official SDK found in the docs or on the site
- The application's client ID and secret, sent as Basic auth, reach every connected mailbox, and IMAP accounts hand Aurinko a mailbox password
- The terms of 11 August 2022 forbid robots and data extraction methods in connection with the Services. This matters before any probe is run
Before you call it notes for agents
- Use
https://api.aurinko.io/v1. Several cURL examples in the docs printhttps:/api.aurinko.iowith one slash, and one search example names the hostasti.aurinko.io - Do not retry
POST /v1/email/messagesblindly after a timeout. There is no idempotency key, so check Sent mail withq=rfc822msgid:or by subject first - Call
POST /v1/email/syncuntilreadyis true, then page/v1/email/sync/updatedwithpageTokenuntil anextDeltaTokenappears and store it - Check the
omittedarray on message lists. Full bodies come only from Google and Office 365, and other providers return a snippet - Request
Mail.ReadplusMail.Sendfor read and send without modify rights. The docs example namesMail.ReadOnly, which is not in the scope list
Who's behind it provenance 60/100
- Legal entity namedYoxel, Inc.20/20
- Domain ageaurinko.io, registered 2019-05-08 (7 years)11/15
- Endpoint on the vendor's domainapi.aurinko.io15/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 2 clauses that cost points5.1/10
- Privacy policyread, states 7 of the 8 things a reader expects9.3/10
- Status pagenot found0/10
- Changelognot found0/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2022-08-11, states 6 of 7, 5 to know
TL;DR Dated 2022-08-11. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on automated access, limits on benchmarking, cut-off without notice or for any reason, arbitration or a class action waiver and no update in three years.
Restricts automated accesscosts points
…re-publish, license, reverse engineer, or create derivative works from Service Materials, nor use any robots, data mining, or similar data extraction or gathering methods in connection with our Services.
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Restricts benchmarking or competitive usecosts points
use the Services and the Site in any manner to compete with Yoxel.
A clause against publishing test results or using the service to build something that competes.
Says access can be ended without notice or for any reason
We may terminate this Agreement or close your Yoxel Account at any time for any reason (including, without limitation, for any activity that may create harm or loss to the goodwill of a Payment Method) by providing you Notice.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
IMPORTANT NOTICE REGARDING ARBITRATION: WHEN YOU AGREE TO THIS AGREEMENT YOU ARE AGREEING (WITH LIMITED EXCEPTION) TO RESOLVE ANY DISPUTE BETWEEN YOU AND YOXEL THROUGH BINDING ARBITRATION RATHER THAN IN COURT.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Has not been updated for three years or more
Last Updated: Aug 11, 2022
The date the document gives for itself is more than three years ago.
Gives the date it was last updated Last updated 2022-08-11
Last Updated: Aug 11, 2022
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
The Yoxel Site and Services are provided by, and you’re contracting with: Yoxel that is organized under the laws of the State of California, USA.
Says where a dispute would be heard and under whose law.
States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
Under no circumstances will Yoxel be responsible or liable to you for any indirect, punitive, incidental, special, consequential, or exemplary damages resulting from your use or inability to use the Services or for the unavailability of the Services, for lost profits, personal injury, or property damage, or for any ot…
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Until you have submitted, and we have reviewed and approved, all Required Information, your Yoxel Account will be available to you on a preliminary basis only, and we may terminate it at any time and for any reason.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives 10 days of notice before a change
If you are an existing user of our Services, the material changes to this Agreement will come into effect 10 days after we provide you with the Notice.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
You may not access or use our Services or Site unless you agree to abide by all the terms and conditions set in this Agreement.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Liability not otherwise disclaimed is capped at the fees paid in the three months before the event behind the claim.
you further agree that under no circumstances will any such liability exceed in the aggregate the amount of Fees paid by you to Yoxel during the three-month period immediately preceding the event that gave rise to your claim for damages.
Noted by a second reader on 2026-10-08.
On monthly plans Yoxel may change the fees at any time, and a customer who does not accept the new fees is told to cancel.
We reserve the right to change the Fees at any time. If you do not accept the new Fees, you should cancel your subscription.
Noted by a second reader on 2026-10-08.
On termination Yoxel may delete all of the customer’s stored information but is not obliged to.
we reserve the right (but have no obligation) to delete all of your information stored on our servers;
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 6,042 words
Privacy policy dated 2022-08-11, states 7 of 8, 1 to know
TL;DR Dated 2022-08-11. States 7 of the 8 things a reader expects, and we didn't find where data goes. To know before relying on it, no update in three years.
Has not been updated for three years or more
Last Updated: Aug 11, 2022
The date the document gives for itself is more than three years ago.
Gives the date it was last updated Last updated 2022-08-11
Last Updated: Aug 11, 2022
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
We are committed to respecting the privacy and security of the personal information we collect.
The basic statement a privacy policy exists to make.
Says how long data is kept
To determine how long we keep personal information we consider the amount, nature and sensitivity of personal information, the reasons for which we collect and process the information and applicable legal requirements.
Says when data sent to the service is deleted.
Says who else receives the data
Collected Indirectly: We and our authorized third-party service providers collect certain information by automated means using cookies and other tracking technologies.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Business Transfers: We may also share personal information with third parties whom we choose to acquire, or to whom we choose to sell, transfer, or merge parts of our business or our assets.
A plain statement either way.
Says what rights people have over their data
This Privacy Policy («Privacy Policy») provides important information about our use of personal information and informs you of your rights.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact compliance@yoxel.com
If you have any questions about this Privacy Policy or our privacy practices, please contact us by email at: compliance@yoxel.com.
An address or officer to send a request to.
Says where data is transferred or stored
Not found in the text.
The countries data goes to and the safeguard used.
Personal information is shared with the third parties whose APIs are integrated, and the policy says they may use it for their own purposes.
These third parties may use your personal information to operate their services and for their own purposes.
Noted by a second reader on 2026-10-08.
Use and transfer of personal information received from Google Accounts is stated to follow the Google API Services User Data Policy, including its Limited Use requirements.
Our use and transfer to any other app of personal information received from Google Accounts will adhere to Google API Services User Data Policy
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 3,325 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Terms of Services Agreement, last updated 11 August 2022, names Yoxel, Inc., organised under the laws of California, and covers the API and the workspace integrations platform. Disputes go to binding arbitration under JAMS rules in San Francisco, with a 30-day opt-out.
The privacy policy, last updated 11 August 2022, covers the site and the services, API included, and commits to Google's API Services User Data Policy and its Limited Use requirements.
The terms forbid robots, data mining and similar data extraction or gathering methods in connection with the Services. We read a handful of public pages and sent nothing to the API host.
The API answers at api.aurinko.io per the description file, with the portal at app.aurinko.io and the reference at apirefs.aurinko.io, all on the vendor's domain.
www.aurinko.io/.well-known/security.txt returns 404. The security statement gives security@yoxel.com for reports.
No status page or changelog is linked from the home page, the docs index or the description file.
robots.txt on www.aurinko.io has one User-agent: * line and no rules. On docs.aurinko.io it allows every path with Content-Signal: ai-input=yes. apirefs.aurinko.io answered 404 for robots.txt, read as no rules.
RDAP for aurinko.io gives a registration date of 2019-05-08.
Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-10 00:51 UTC
Probed every five minutes at https://api.aurinko.io. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/aurinko-email.json
Notable
- The description file is OpenAPI 3.0.0, titled Aurinko.io API 1.0.0, with 112 paths and 154 operations, 43 of them in the Email group (Messages 10, EmailTracking 10, FollowUpRobot 9, EmailFolders 6, Drafts 5, EmailSync 3) source
- The billing FAQ prices Email (non-IMAP) at $1.50 an active account a month up to 1 GB of traffic, and puts IMAP in the $2 Full Platform tier. An account is active above 10 API calls or 1 MB in a billing month source
- The pricing page describes the same three prices by data transfer alone, $1 under 1 GB, $1.50 under 5 GB and $2 unlimited, which differs from the FAQ source
- The docs describe the API as mainly a pass-through that caches IDs and thread-message relations and never stores the contents of emails source
- Until a developer registers their own Google OAuth app, Aurinko's default registration is used with limited permissions and Google email is not available. Aurinko says it chooses not to run a shared verified Google app source
- Sending accepts a
trackingobject for opens and thread replies, with a tracking pixel on Aurinko's domain or a custom alias, and/email/trackingis a webhook resource source - The security statement, last updated 18 June 2026, says Yoxel is preparing for a SOC 2 Type I examination targeted for Q3 2026 with Secureframe, and takes vulnerability reports at security@yoxel.com source
- The Terms of Services Agreement says users may not use any robots, data mining, or similar data extraction or gathering methods in connection with the Services source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 8.0 | |
Graded as a hosted API. No status page is linked from the home page, the docs index or the description file (0). With no readable incident history the record scores 5. The description file gives a limit of 250 requests a second (15). It advises exponential backoff on 429 and 5xx and a retry on 408, and declares a Retry-After header only on the 408 of the get-message call. Sending takes no idempotency key (10). No SLA found, and the terms supply the service as is (0). The API is at /v1 with no beta label (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 10.9 | |
Public OpenAPI 3.0.0 description with 154 operations, 43 of them for email, read once from the file the reference page loads (25). llms.txt and a Markdown copy of every docs page (10). Every email operation has a summary but only 2 of 43 have a description. 61 of 85 parameters are described, and the guide has a table of 17 search operators with provider caveats (9). The scope list and responseType are enums, with few required fields marked (8). 34 of 43 email operations carry a cURL sample and the Errors section shows the JSON body, while operations declare little beyond 401 and a default response (10). /v1 in the path and version 1.0.0, with no changelog found (5). | |||
| Agent ergonomics | 13%16.2 | 8.0 | |
Graded on the REST API. bodyType, stripQuoted and returnIds shape responses, but message lists take no field selection and no page-size parameter (10). pageToken on lists, q search with 17 operators, a per-folder list, and delta tokens for updated and deleted mail (15). Errors carry code, message, requestId and the provider's originalError, with retry advice per status (14). No idempotency key on send, reply or draft send. Reads and delta sync are safe to repeat, and delete moves a message to Trash (4). Few required parameters, but no official SDK was found (6). | |||
| Security & auth | 14%17.5 | 7.3 | |
Per-user OAuth with four mail scopes and DELETE /v1/account/token to revoke a token and the provider grant. The application's client ID and secret, sent as Basic auth with X-Aurinko-Account-Id, reach every connected account. The implicit grant is still supported though not recommended, returning the token in a URL fragment, and IMAP accounts give Aurinko a mailbox or app password (22). Mail.Read allows no writes and Mail.Send no reads, with no confirmation step for sends or deletes (13). Mail from third parties is returned with no injection guidance (0). No operator audit or request log found in the docs. Portal roles are documented (0). A security statement with a reporting address, security@yoxel.com, and penetration tests claimed. SOC 2 is not yet held, with no bug bounty and no security.txt (7). | |||
| Payments & pricing | 10%12.5 | 5.0 | |
| No x402, MPP or L402 (0). Prices per active account a month published without login, $1.50 for email and $2 for all APIs, though the pricing page and the billing FAQ define the tiers differently (20). A 14-day trial, with a card asked for only when it ends (20). Signup is in a browser at app.aurinko.io, and each mailbox needs its owner's consent or password (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 1.1 | |
| No changelog or release notes found, so no API change can be dated. The docs sitemap dates the IMAP connection guide 22 September 2026 and the Email API guide 18 August 2026, counted as partial evidence of activity and not as a release (10). No dated changelog entries (0). Support is by email, with no public forum or issue tracker linked (3). No official SDK named in the docs (0). No public package or repository is linked from the pages read (0). | |||
| Transparency & trusteditorial 27, provenance 60 | 7%8.8 | 3.9 | |
| Closed service under a Terms of Services Agreement naming Yoxel, Inc. of California, last updated 11 August 2022 (15). The docs say message contents are passed through and never stored, with only IDs and thread relations cached, and the privacy policy commits to Google's Limited Use requirements. The policy gives no retention period, and no DPA was found (12). No deprecation policy or dated notices found (0). No sub-processor list or data location. The security statement names no cloud provider (0). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 44.2 · E | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 22 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Aurinko Email API, or have the agent fetch /fixes/aurinko-email.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Aurinko Email API From Anchor Terminal's listing at https://www.anchorterminal.com/tools/aurinko-email, the October 2026 research run, assessed 9 October 2026. Grade E, 44.2 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Aurinko Email API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 40 out of 100, up to 12 more on the total Why it scored 40: Graded as a hosted API. No status page is linked from the home page, the docs index or the description file (0). With no readable incident history the record scores 5. The description file gives a limit of 250 requests a second (15). It advises exponential backoff on 429 and 5xx and a retry on 408, and declares a `Retry-After` header only on the 408 of the get-message call. Sending takes no idempotency key (10). No SLA found, and the terms supply the service as is (0). The API is at `/v1` with no beta label (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Security & auth, 42 out of 100, up to 10.1 more on the total Why it scored 42: Per-user OAuth with four mail scopes and `DELETE /v1/account/token` to revoke a token and the provider grant. The application's client ID and secret, sent as Basic auth with `X-Aurinko-Account-Id`, reach every connected account. The implicit grant is still supported though not recommended, returning the token in a URL fragment, and IMAP accounts give Aurinko a mailbox or app password (22). `Mail.Read` allows no writes and `Mail.Send` no reads, with no confirmation step for sends or deletes (13). Mail from third parties is returned with no injection guidance (0). No operator audit or request log found in the docs. Portal roles are documented (0). A security statement with a reporting address, security@yoxel.com, and penetration tests claimed. SOC 2 is not yet held, with no bug bounty and no security.txt (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 3. Agent ergonomics, 49 out of 100, up to 8.3 more on the total Why it scored 49: Graded on the REST API. `bodyType`, `stripQuoted` and `returnIds` shape responses, but message lists take no field selection and no page-size parameter (10). `pageToken` on lists, `q` search with 17 operators, a per-folder list, and delta tokens for updated and deleted mail (15). Errors carry `code`, `message`, `requestId` and the provider's `originalError`, with retry advice per status (14). No idempotency key on send, reply or draft send. Reads and delta sync are safe to repeat, and delete moves a message to Trash (4). Few required parameters, but no official SDK was found (6). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 4. Maintenance & community, 13 out of 100, up to 7.6 more on the total Why it scored 13: No changelog or release notes found, so no API change can be dated. The docs sitemap dates the IMAP connection guide 22 September 2026 and the Email API guide 18 August 2026, counted as partial evidence of activity and not as a release (10). No dated changelog entries (0). Support is by email, with no public forum or issue tracker linked (3). No official SDK named in the docs (0). No public package or repository is linked from the pages read (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 5. Payments & pricing, 40 out of 100, up to 7.5 more on the total Why it scored 40: No x402, MPP or L402 (0). Prices per active account a month published without login, $1.50 for email and $2 for all APIs, though the pricing page and the billing FAQ define the tiers differently (20). A 14-day trial, with a card asked for only when it ends (20). Signup is in a browser at app.aurinko.io, and each mailbox needs its owner's consent or password (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 6. Schema & documentation, 67 out of 100, up to 5.4 more on the total Why it scored 67: Public OpenAPI 3.0.0 description with 154 operations, 43 of them for email, read once from the file the reference page loads (25). `llms.txt` and a Markdown copy of every docs page (10). Every email operation has a summary but only 2 of 43 have a description. 61 of 85 parameters are described, and the guide has a table of 17 search operators with provider caveats (9). The scope list and `responseType` are enums, with few required fields marked (8). 34 of 43 email operations carry a cURL sample and the Errors section shows the JSON body, while operations declare little beyond 401 and a default response (10). `/v1` in the path and version 1.0.0, with no changelog found (5). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 7. Transparency & trust, 44 out of 100, up to 4.9 more on the total Made of editorial 27, provenance 60. Why it scored 44: Closed service under a Terms of Services Agreement naming Yoxel, Inc. of California, last updated 11 August 2022 (15). The docs say message contents are passed through and never stored, with only IDs and thread relations cached, and the privacy policy commits to Google's Limited Use requirements. The policy gives no retention period, and no DPA was found (12). No deprecation policy or dated notices found (0). No sub-processor list or data location. The security statement names no cloud provider (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: aurinko.io, registered 2019-05-08 (7 years) (11 of 15) - Terms of service: read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points (5.1 of 10) - Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10) - Status page: not found (0 of 10) - Changelog: not found (0 of 10) - security.txt: not found (0 of 10) ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: whether a status page exists under an address the site does not link. None is linked from the home page, the docs index or the description file - unchecked: the portal at app.aurinko.io behind login, so key rotation, team roles in practice, any request log and whether the trial asks for a card at signup were not seen - unchecked: the vendor's GitHub organisation and any npm package. No page read links either, so no SDK, repository or download figure is recorded - unchecked: the Follow-up Rules API guide, the Gmail Pub/Sub guide and the Google and Office 365 OAuth setup guides, which were not read - The terms forbid robots, data mining and similar data extraction or gathering methods in connection with the Services. Recorded as a fact with no deduction. It matters before any probe is run - Whether the SOC 2 Type I examination targeted for Q3 2026 has been completed. The security statement was last updated 18 June 2026 - Which of the two published descriptions of the $1.50 tier applies, and whether an email-only customer on IMAP pays $2 - Whether 429 responses carry a Retry-After header, and what page size message lists return. The description file does not say - Maintenance is 13 here and 20 on aurinko-calendar. This dossier counts docs page dates as 10 for recency and records no repository, because none is linked ## Weaknesses - No status page, incident history or SLA found, and the terms supply the service as is - No idempotency key on `POST /v1/email/messages`, so a retried send can deliver twice - No changelog, deprecation policy or official SDK found in the docs or on the site - The application's client ID and secret, sent as Basic auth, reach every connected mailbox, and IMAP accounts hand Aurinko a mailbox password - The terms of 11 August 2022 forbid robots and data extraction methods in connection with the Services. This matters before any probe is run ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Use `https://api.aurinko.io/v1`. Several cURL examples in the docs print `https:/api.aurinko.io` with one slash, and one search example names the host `asti.aurinko.io` - Do not retry `POST /v1/email/messages` blindly after a timeout. There is no idempotency key, so check Sent mail with `q=rfc822msgid:` or by subject first - Call `POST /v1/email/sync` until `ready` is true, then page `/v1/email/sync/updated` with `pageToken` until a `nextDeltaToken` appears and store it - Check the `omitted` array on message lists. Full bodies come only from Google and Office 365, and other providers return a snippet - Request `Mail.Read` plus `Mail.Send` for read and send without modify rights. The docs example names `Mail.ReadOnly`, which is not in the scope list ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: whether a status page exists under an address the site does not link. None is linked from the home page, the docs index or the description file
- unchecked: the portal at app.aurinko.io behind login, so key rotation, team roles in practice, any request log and whether the trial asks for a card at signup were not seen
- unchecked: the vendor's GitHub organisation and any npm package. No page read links either, so no SDK, repository or download figure is recorded
- unchecked: the Follow-up Rules API guide, the Gmail Pub/Sub guide and the Google and Office 365 OAuth setup guides, which were not read
- The terms forbid robots, data mining and similar data extraction or gathering methods in connection with the Services. Recorded as a fact with no deduction. It matters before any probe is run
- Whether the SOC 2 Type I examination targeted for Q3 2026 has been completed. The security statement was last updated 18 June 2026
- Which of the two published descriptions of the $1.50 tier applies, and whether an email-only customer on IMAP pays $2
- Whether 429 responses carry a Retry-After header, and what page size message lists return. The description file does not say
- Maintenance is 13 here and 20 on aurinko-calendar. This dossier counts docs page dates as 10 for recency and records no repository, because none is linked
Sources 27
- OpenAPI description file the reference page loads (read in place of the rendered page), errors and rate limits apirefs.aurinko.io · seen 2026-10-09
- API reference page, a Redoc viewer over the description file apirefs.aurinko.io · seen 2026-10-09
- docs index for agents docs.aurinko.io · seen 2026-10-09
- Email API guide, sync, tracking and search operators docs.aurinko.io · seen 2026-10-09
- data handling statement docs.aurinko.io · seen 2026-10-09
- authentication scopes docs.aurinko.io · seen 2026-10-09
- account OAuth flow docs.aurinko.io · seen 2026-10-09
- IMAP connections and passwords docs.aurinko.io · seen 2026-10-09
- webhooks docs.aurinko.io · seen 2026-10-09
- webhook signature validation docs.aurinko.io · seen 2026-10-09
- billing FAQ and price tiers docs.aurinko.io · seen 2026-10-09
- trial and subscription docs.aurinko.io · seen 2026-10-09
- developer keys and test accounts docs.aurinko.io · seen 2026-10-09
- shared Google OAuth app FAQ docs.aurinko.io · seen 2026-10-09
- portal team roles docs.aurinko.io · seen 2026-10-09
- Direct API pass-through docs.aurinko.io · seen 2026-10-09
- docs sitemap with page dates docs.aurinko.io · seen 2026-10-09
- Email API product page aurinko.io · seen 2026-10-09
- pricing page aurinko.io · seen 2026-10-09
- terms of services agreement aurinko.io · seen 2026-10-09
- privacy policy aurinko.io · seen 2026-10-09
- security statement aurinko.io · seen 2026-10-09
- security.txt, 404 aurinko.io · seen 2026-10-09
- robots.txt, one User-agent line and no rules aurinko.io · seen 2026-10-09
- robots.txt, allows all with ai-input=yes docs.aurinko.io · seen 2026-10-09
- robots.txt, 404 apirefs.aurinko.io · seen 2026-10-09
- domain registration rdap.identitydigital.services · seen 2026-10-09
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Paid Paid $1.50 an active account a month for Email (non-IMAP) with up to 1 GB of traffic, and $2 for any number of APIs including IMAP with unlimited traffic, per the billing FAQ. A 14-day trial gives full API access, and requests are blocked when it ends without a card on file. No free tier or sandbox beyond the trial (https://docs.aurinko.io/faq/how-does-aurinko-billing-work).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Email API (non-IMAP) | $1.50 | per connected account per month | Per active account, up to 1 GB of traffic a month |
| Full platform, any number of APIs including IMAP | $2 | per connected account per month | Per active account, unlimited traffic |
Compared across listings on the price index.
Recent changes
- No changes recorded yet.
Follow them as a feed at /feeds/tools/aurinko-email.xml, or this listing's score history at history.json.
Connect
First request
curl -H 'Authorization: Bearer <access_token>' \
-G https://api.aurinko.io/v1/email/messages \
-d q='from:alexey'
Through letme picks today, calling later
GET https://letme.dev/aurinko-email
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Alternatives to Aurinko Email API
#9 of 9 in Best mailbox access APIs for AI agents · All 36 mailboxes comparisons
Nylas Email API AGmail API BBEmailEngine BBOutlook Mail (Microsoft Graph) BUnipile CFastmail API (JMAP) C
Head to head Aurinko Email API vs EmailEngine · Aurinko Email API vs Fastmail API (JMAP) · Aurinko Email API vs Gmail API · Aurinko Email API vs Himalaya · Aurinko Email API vs Nylas Email API · Aurinko Email API vs Outlook Mail (Microsoft Graph) · Aurinko Email API vs Unipile · Aurinko Email API vs Zoho Mail API
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Nylas Email API Nylas | A | 78.7 | mailbox.read mailbox.search mailbox.send mailbox.drafts mailbox.sync email.threads | no |
| Gmail API Google | BB | 77.8 | mailbox.read mailbox.search mailbox.send mailbox.drafts mailbox.sync | no |
| EmailEngine Postal Systems OÜ | BB | 71.4 | mailbox.read mailbox.search mailbox.send mailbox.drafts mailbox.sync | no |
| Outlook Mail (Microsoft Graph) Microsoft | B | 66.3 | mailbox.read mailbox.search mailbox.send mailbox.drafts mailbox.sync | no |
| Unipile UNIPILE SAS | C | 58.4 | mailbox.read mailbox.search mailbox.send mailbox.drafts mailbox.sync | no |
| Fastmail API (JMAP) Fastmail Pty Ltd | C | 54.1 | mailbox.read mailbox.search mailbox.send mailbox.drafts mailbox.sync | no |
Machine-readable
- JSON
/api/v1/tools/aurinko-email.json· historyhistory.json· badge/badges/aurinko-email.svg· changes feed/feeds/tools/aurinko-email.xml - Markdown
/tools/aurinko-email.md· slim/tools/aurinko-email.min.md(or sendAccept: text/markdown) - Fix list
/fixes/aurinko-email.md·/fixes/aurinko-email.json - From a terminal
anchor tool aurinko-email --md(the CLI) · over MCPget_tool {"slug": "aurinko-email"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/aurinko-email"><img src="https://www.anchorterminal.com/badges/aurinko-email.svg" alt="Aurinko Email API on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/aurinko-email)<a href="https://www.anchorterminal.com/tools/aurinko-email">Aurinko Email API on Anchor Terminal</a>It counts on a page on aurinko.io or one of its subdomains.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "aurinko-email", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


