{
  "data": {
    "similar": [
      {
        "grade": "A",
        "json": "https://www.anchorterminal.com/tools/nylas-email.json",
        "name": "Nylas Email API",
        "score": 78.7,
        "shared": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync",
          "email.threads"
        ],
        "slug": "nylas-email"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/gmail-api.json",
        "name": "Gmail API",
        "score": 77.8,
        "shared": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync"
        ],
        "slug": "gmail-api"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/emailengine.json",
        "name": "EmailEngine",
        "score": 71.4,
        "shared": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync"
        ],
        "slug": "emailengine"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/outlook-mail-graph.json",
        "name": "Outlook Mail (Microsoft Graph)",
        "score": 66.3,
        "shared": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync"
        ],
        "slug": "outlook-mail-graph"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/unipile.json",
        "name": "Unipile",
        "score": 58.4,
        "shared": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync"
        ],
        "slug": "unipile"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/fastmail.json",
        "name": "Fastmail API (JMAP)",
        "score": 54.1,
        "shared": [
          "mailbox.read",
          "mailbox.search",
          "mailbox.send",
          "mailbox.drafts",
          "mailbox.sync"
        ],
        "slug": "fastmail"
      }
    ],
    "tool": {
      "slug": "aurinko-email",
      "name": "Aurinko Email API",
      "vendor": "Yoxel, Inc.",
      "vendorUrl": "https://www.aurinko.io",
      "kind": "http-api",
      "category": "mailbox-access",
      "summary": "Unified email REST API from Yoxel, Inc. It reads, searches, drafts and sends mail in a user's own mailbox on Gmail, Office 365, Outlook.com, Exchange, Zoho Mail, iCloud and IMAP, with delta sync, open and reply tracking and webhooks.",
      "url": "https://www.anchorterminal.com/tools/aurinko-email",
      "markdownUrl": "https://www.anchorterminal.com/tools/aurinko-email.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/aurinko-email.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/aurinko-email.json",
      "license": "Proprietary service under Yoxel's Terms of Services Agreement",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.aurinko.io",
      "packages": [],
      "auth": "oauth",
      "authNotes": "Self-serve. A developer signs up at app.aurinko.io and gets a client ID and secret for each application. Each mailbox owner connects through Aurinko's OAuth flow at `/v1/auth/authorize`, and the resulting account access token is sent as a Bearer token. Mail scopes are `Mail.Read`, `Mail.ReadWrite`, `Mail.Send` and `Mail.Drafts`. IMAP, iCloud and Exchange accounts connect with a password or app password. Gmail access needs the developer's own Google OAuth app, since Aurinko's default registration excludes Google email, and production Office 365 needs an Azure registration.",
      "pricing": "paid",
      "pricingNotes": "$1.50 an active account a month for Email (non-IMAP) with up to 1 GB of traffic, and $2 for any number of APIs including IMAP with unlimited traffic, per the billing FAQ. A 14-day trial gives full API access, and requests are blocked when it ends without a card on file. No free tier or sandbox beyond the trial (https://docs.aurinko.io/faq/how-does-aurinko-billing-work).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI description or the pricing page (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.aurinko.io/unified-apis/email-api",
      "llmsTxt": "https://docs.aurinko.io/llms.txt",
      "openapi": "https://apirefs.aurinko.io/assets/swagger.json",
      "capabilities": [
        "mailbox.read",
        "mailbox.search",
        "mailbox.send",
        "mailbox.drafts",
        "mailbox.sync",
        "email.threads"
      ],
      "tags": [
        "hosted",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "closed-source",
        "free-trial"
      ],
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 44.2,
        "grade": "E",
        "agentReady": false,
        "rank": 878,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 49,
          "maintenance": 13,
          "payments": 40,
          "reliability": 40,
          "schema": 67,
          "security": 42,
          "transparency": 44
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 40,
            "points": 8,
            "reason": "Graded as a hosted API. No status page is linked from the home page, the docs index or the description file (0). With no readable incident history the record scores 5. The description file gives a limit of 250 requests a second (15). It advises exponential backoff on 429 and 5xx and a retry on 408, and declares a `Retry-After` header only on the 408 of the get-message call. Sending takes no idempotency key (10). No SLA found, and the terms supply the service as is (0). The API is at `/v1` with no beta label (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 67,
            "points": 10.89,
            "reason": "Public OpenAPI 3.0.0 description with 154 operations, 43 of them for email, read once from the file the reference page loads (25). `llms.txt` and a Markdown copy of every docs page (10). Every email operation has a summary but only 2 of 43 have a description. 61 of 85 parameters are described, and the guide has a table of 17 search operators with provider caveats (9). The scope list and `responseType` are enums, with few required fields marked (8). 34 of 43 email operations carry a cURL sample and the Errors section shows the JSON body, while operations declare little beyond 401 and a default response (10). `/v1` in the path and version 1.0.0, with no changelog found (5)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 49,
            "points": 7.96,
            "reason": "Graded on the REST API. `bodyType`, `stripQuoted` and `returnIds` shape responses, but message lists take no field selection and no page-size parameter (10). `pageToken` on lists, `q` search with 17 operators, a per-folder list, and delta tokens for updated and deleted mail (15). Errors carry `code`, `message`, `requestId` and the provider's `originalError`, with retry advice per status (14). No idempotency key on send, reply or draft send. Reads and delta sync are safe to repeat, and delete moves a message to Trash (4). Few required parameters, but no official SDK was found (6)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 42,
            "points": 7.35,
            "reason": "Per-user OAuth with four mail scopes and `DELETE /v1/account/token` to revoke a token and the provider grant. The application's client ID and secret, sent as Basic auth with `X-Aurinko-Account-Id`, reach every connected account. The implicit grant is still supported though not recommended, returning the token in a URL fragment, and IMAP accounts give Aurinko a mailbox or app password (22). `Mail.Read` allows no writes and `Mail.Send` no reads, with no confirmation step for sends or deletes (13). Mail from third parties is returned with no injection guidance (0). No operator audit or request log found in the docs. Portal roles are documented (0). A security statement with a reporting address, security@yoxel.com, and penetration tests claimed. SOC 2 is not yet held, with no bug bounty and no security.txt (7)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 40,
            "points": 5,
            "reason": "No x402, MPP or L402 (0). Prices per active account a month published without login, $1.50 for email and $2 for all APIs, though the pricing page and the billing FAQ define the tiers differently (20). A 14-day trial, with a card asked for only when it ends (20). Signup is in a browser at app.aurinko.io, and each mailbox needs its owner's consent or password (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 13,
            "points": 1.14,
            "reason": "No changelog or release notes found, so no API change can be dated. The docs sitemap dates the IMAP connection guide 22 September 2026 and the Email API guide 18 August 2026, counted as partial evidence of activity and not as a release (10). No dated changelog entries (0). Support is by email, with no public forum or issue tracker linked (3). No official SDK named in the docs (0). No public package or repository is linked from the pages read (0)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 44,
            "points": 3.85,
            "note": "editorial 27, provenance 60",
            "reason": "Closed service under a Terms of Services Agreement naming Yoxel, Inc. of California, last updated 11 August 2022 (15). The docs say message contents are passed through and never stored, with only IDs and thread relations cached, and the privacy policy commits to Google's Limited Use requirements. The policy gives no retention period, and no DPA was found (12). No deprecation policy or dated notices found (0). No sub-processor list or data location. The security statement names no cloud provider (0)."
          }
        ],
        "assessment": {
          "date": "2026-10-09",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Graded on the REST API. `bodyType`, `stripQuoted` and `returnIds` shape responses, but message lists take no field selection and no page-size parameter (10). `pageToken` on lists, `q` search with 17 operators, a per-folder list, and delta tokens for updated and deleted mail (15). Errors carry `code`, `message`, `requestId` and the provider's `originalError`, with retry advice per status (14). No idempotency key on send, reply or draft send. Reads and delta sync are safe to repeat, and delete moves a message to Trash (4). Few required parameters, but no official SDK was found (6).",
            "maintenance": "No changelog or release notes found, so no API change can be dated. The docs sitemap dates the IMAP connection guide 22 September 2026 and the Email API guide 18 August 2026, counted as partial evidence of activity and not as a release (10). No dated changelog entries (0). Support is by email, with no public forum or issue tracker linked (3). No official SDK named in the docs (0). No public package or repository is linked from the pages read (0).",
            "payments": "No x402, MPP or L402 (0). Prices per active account a month published without login, $1.50 for email and $2 for all APIs, though the pricing page and the billing FAQ define the tiers differently (20). A 14-day trial, with a card asked for only when it ends (20). Signup is in a browser at app.aurinko.io, and each mailbox needs its owner's consent or password (0).",
            "reliability": "Graded as a hosted API. No status page is linked from the home page, the docs index or the description file (0). With no readable incident history the record scores 5. The description file gives a limit of 250 requests a second (15). It advises exponential backoff on 429 and 5xx and a retry on 408, and declares a `Retry-After` header only on the 408 of the get-message call. Sending takes no idempotency key (10). No SLA found, and the terms supply the service as is (0). The API is at `/v1` with no beta label (10).",
            "schema": "Public OpenAPI 3.0.0 description with 154 operations, 43 of them for email, read once from the file the reference page loads (25). `llms.txt` and a Markdown copy of every docs page (10). Every email operation has a summary but only 2 of 43 have a description. 61 of 85 parameters are described, and the guide has a table of 17 search operators with provider caveats (9). The scope list and `responseType` are enums, with few required fields marked (8). 34 of 43 email operations carry a cURL sample and the Errors section shows the JSON body, while operations declare little beyond 401 and a default response (10). `/v1` in the path and version 1.0.0, with no changelog found (5).",
            "security": "Per-user OAuth with four mail scopes and `DELETE /v1/account/token` to revoke a token and the provider grant. The application's client ID and secret, sent as Basic auth with `X-Aurinko-Account-Id`, reach every connected account. The implicit grant is still supported though not recommended, returning the token in a URL fragment, and IMAP accounts give Aurinko a mailbox or app password (22). `Mail.Read` allows no writes and `Mail.Send` no reads, with no confirmation step for sends or deletes (13). Mail from third parties is returned with no injection guidance (0). No operator audit or request log found in the docs. Portal roles are documented (0). A security statement with a reporting address, security@yoxel.com, and penetration tests claimed. SOC 2 is not yet held, with no bug bounty and no security.txt (7).",
            "transparency": "Closed service under a Terms of Services Agreement naming Yoxel, Inc. of California, last updated 11 August 2022 (15). The docs say message contents are passed through and never stored, with only IDs and thread relations cached, and the privacy policy commits to Google's Limited Use requirements. The policy gives no retention period, and no DPA was found (12). No deprecation policy or dated notices found (0). No sub-processor list or data location. The security statement names no cloud provider (0)."
          },
          "sources": [
            {
              "what": "OpenAPI description file the reference page loads (read in place of the rendered page), errors and rate limits",
              "url": "https://apirefs.aurinko.io/assets/swagger.json",
              "seen": "2026-10-09"
            },
            {
              "what": "API reference page, a Redoc viewer over the description file",
              "url": "https://apirefs.aurinko.io/",
              "seen": "2026-10-09"
            },
            {
              "what": "docs index for agents",
              "url": "https://docs.aurinko.io/llms.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "Email API guide, sync, tracking and search operators",
              "url": "https://docs.aurinko.io/unified-apis/email-api.md",
              "seen": "2026-10-09"
            },
            {
              "what": "data handling statement",
              "url": "https://docs.aurinko.io/getting-started/readme.md",
              "seen": "2026-10-09"
            },
            {
              "what": "authentication scopes",
              "url": "https://docs.aurinko.io/authentication/authentication-scopes.md",
              "seen": "2026-10-09"
            },
            {
              "what": "account OAuth flow",
              "url": "https://docs.aurinko.io/authentication/oauth-flow/account-oauth-flow.md",
              "seen": "2026-10-09"
            },
            {
              "what": "IMAP connections and passwords",
              "url": "https://docs.aurinko.io/authentication/configuring-imap-provider-connections-in-aurinko.md",
              "seen": "2026-10-09"
            },
            {
              "what": "webhooks",
              "url": "https://docs.aurinko.io/unified-apis/webhooks-api.md",
              "seen": "2026-10-09"
            },
            {
              "what": "webhook signature validation",
              "url": "https://docs.aurinko.io/unified-apis/webhooks-api/authentication.md",
              "seen": "2026-10-09"
            },
            {
              "what": "billing FAQ and price tiers",
              "url": "https://docs.aurinko.io/faq/how-does-aurinko-billing-work.md",
              "seen": "2026-10-09"
            },
            {
              "what": "trial and subscription",
              "url": "https://docs.aurinko.io/getting-started/subscribe-to-aurinko.md",
              "seen": "2026-10-09"
            },
            {
              "what": "developer keys and test accounts",
              "url": "https://docs.aurinko.io/getting-started/get-your-developer-api-keys.md",
              "seen": "2026-10-09"
            },
            {
              "what": "shared Google OAuth app FAQ",
              "url": "https://docs.aurinko.io/faq/does-aurinko-provide-a-shared-verified-google-oauth-application.md",
              "seen": "2026-10-09"
            },
            {
              "what": "portal team roles",
              "url": "https://docs.aurinko.io/team-members-and-roles-in-applications.md",
              "seen": "2026-10-09"
            },
            {
              "what": "Direct API pass-through",
              "url": "https://docs.aurinko.io/unified-apis/direct-api.md",
              "seen": "2026-10-09"
            },
            {
              "what": "docs sitemap with page dates",
              "url": "https://docs.aurinko.io/sitemap-pages.xml",
              "seen": "2026-10-09"
            },
            {
              "what": "Email API product page",
              "url": "https://www.aurinko.io/email-api/",
              "seen": "2026-10-09"
            },
            {
              "what": "pricing page",
              "url": "https://www.aurinko.io/pricing/",
              "seen": "2026-10-09"
            },
            {
              "what": "terms of services agreement",
              "url": "https://www.aurinko.io/terms/",
              "seen": "2026-10-09"
            },
            {
              "what": "privacy policy",
              "url": "https://www.aurinko.io/privacy/",
              "seen": "2026-10-09"
            },
            {
              "what": "security statement",
              "url": "https://www.aurinko.io/certifications/",
              "seen": "2026-10-09"
            },
            {
              "what": "security.txt, 404",
              "url": "https://www.aurinko.io/.well-known/security.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "robots.txt, one User-agent line and no rules",
              "url": "https://www.aurinko.io/robots.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "robots.txt, allows all with ai-input=yes",
              "url": "https://docs.aurinko.io/robots.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "robots.txt, 404",
              "url": "https://apirefs.aurinko.io/robots.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.identitydigital.services/rdap/domain/aurinko.io",
              "seen": "2026-10-09"
            }
          ],
          "openQuestions": [
            "unchecked: whether a status page exists under an address the site does not link. None is linked from the home page, the docs index or the description file",
            "unchecked: the portal at app.aurinko.io behind login, so key rotation, team roles in practice, any request log and whether the trial asks for a card at signup were not seen",
            "unchecked: the vendor's GitHub organisation and any npm package. No page read links either, so no SDK, repository or download figure is recorded",
            "unchecked: the Follow-up Rules API guide, the Gmail Pub/Sub guide and the Google and Office 365 OAuth setup guides, which were not read",
            "The terms forbid robots, data mining and similar data extraction or gathering methods in connection with the Services. Recorded as a fact with no deduction. It matters before any probe is run",
            "Whether the SOC 2 Type I examination targeted for Q3 2026 has been completed. The security statement was last updated 18 June 2026",
            "Which of the two published descriptions of the $1.50 tier applies, and whether an email-only customer on IMAP pays $2",
            "Whether 429 responses carry a Retry-After header, and what page size message lists return. The description file does not say",
            "Maintenance is 13 here and 20 on aurinko-calendar. This dossier counts docs page dates as 10 for recency and records no repository, because none is linked"
          ]
        },
        "negative": 0,
        "verdict": "One REST interface covers message search with 17 query operators, drafts, sending, folders and delta sync across seven mailbox types, at $1.50 an active account a month and with send-only and read-only scopes. No status page, SLA, changelog, idempotency key on send or official SDK was found, and SOC 2 is not yet held.",
        "bestFor": "A product that connects many users' Gmail and Microsoft mailboxes and wants one schema, delta sync, tracking and webhooks at a low price per account.",
        "strengths": [
          "Public OpenAPI 3.0 description at `apirefs.aurinko.io/assets/swagger.json`, with 43 email operations, 34 of them carrying a cURL sample",
          "Four mail scopes. `Mail.Read` allows no writes, `Mail.Send` allows sending with no read access, and `Mail.ReadWrite` excludes send",
          "The `q` parameter takes 17 search operators, with a table in the docs saying where IMAP and Exchange support is partial",
          "Prices published per active account a month ($1.50 for email, $2 for all APIs with IMAP), with a 14-day trial",
          "Docs state that message contents are passed through and never stored, with only IDs and thread relations cached for sync"
        ],
        "weaknesses": [
          "No status page, incident history or SLA found, and the terms supply the service as is",
          "No idempotency key on `POST /v1/email/messages`, so a retried send can deliver twice",
          "No changelog, deprecation policy or official SDK found in the docs or on the site",
          "The application's client ID and secret, sent as Basic auth, reach every connected mailbox, and IMAP accounts hand Aurinko a mailbox password",
          "The terms of 11 August 2022 forbid robots and data extraction methods in connection with the Services. This matters before any probe is run"
        ],
        "agentNotes": [
          "Use `https://api.aurinko.io/v1`. Several cURL examples in the docs print `https:/api.aurinko.io` with one slash, and one search example names the host `asti.aurinko.io`",
          "Do not retry `POST /v1/email/messages` blindly after a timeout. There is no idempotency key, so check Sent mail with `q=rfc822msgid:` or by subject first",
          "Call `POST /v1/email/sync` until `ready` is true, then page `/v1/email/sync/updated` with `pageToken` until a `nextDeltaToken` appears and store it",
          "Check the `omitted` array on message lists. Full bodies come only from Google and Office 365, and other providers return a snippet",
          "Request `Mail.Read` plus `Mail.Send` for read and send without modify rights. The docs example names `Mail.ReadOnly`, which is not in the scope list"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 44.2
          }
        ],
        "editorialScores": {
          "ergonomics": 49,
          "maintenance": 13,
          "payments": 40,
          "reliability": 40,
          "schema": 67,
          "security": 42,
          "transparency": 27
        },
        "provenanceScore": 60
      },
      "connect": {
        "http": "curl -H 'Authorization: Bearer \u003caccess_token\u003e' \\\n  -G https://api.aurinko.io/v1/email/messages \\\n  -d q='from:alexey'"
      },
      "letme": {
        "capability": "https://letme.dev/mailbox.read",
        "tool": "https://letme.dev/aurinko-email"
      },
      "sameCompany": [
        "aurinko-calendar"
      ],
      "notable": [
        "The description file is OpenAPI 3.0.0, titled Aurinko.io API 1.0.0, with 112 paths and 154 operations, 43 of them in the Email group (Messages 10, EmailTracking 10, FollowUpRobot 9, EmailFolders 6, Drafts 5, EmailSync 3) (https://apirefs.aurinko.io/assets/swagger.json)",
        "The billing FAQ prices Email (non-IMAP) at $1.50 an active account a month up to 1 GB of traffic, and puts IMAP in the $2 Full Platform tier. An account is active above 10 API calls or 1 MB in a billing month (https://docs.aurinko.io/faq/how-does-aurinko-billing-work)",
        "The pricing page describes the same three prices by data transfer alone, $1 under 1 GB, $1.50 under 5 GB and $2 unlimited, which differs from the FAQ (https://www.aurinko.io/pricing/)",
        "The docs describe the API as mainly a pass-through that caches IDs and thread-message relations and never stores the contents of emails (https://docs.aurinko.io/getting-started/readme)",
        "Until a developer registers their own Google OAuth app, Aurinko's default registration is used with limited permissions and Google email is not available. Aurinko says it chooses not to run a shared verified Google app (https://docs.aurinko.io/getting-started/get-your-developer-api-keys)",
        "Sending accepts a `tracking` object for opens and thread replies, with a tracking pixel on Aurinko's domain or a custom alias, and `/email/tracking` is a webhook resource (https://docs.aurinko.io/unified-apis/email-api)",
        "The security statement, last updated 18 June 2026, says Yoxel is preparing for a SOC 2 Type I examination targeted for Q3 2026 with Secureframe, and takes vulnerability reports at security@yoxel.com (https://www.aurinko.io/certifications/)",
        "The Terms of Services Agreement says users may not use any robots, data mining, or similar data extraction or gathering methods in connection with the Services (https://www.aurinko.io/terms/)"
      ],
      "area": "communication",
      "details": [
        {
          "label": "Surface graded",
          "value": "The REST API at https://api.aurinko.io/v1. No MCP server was found in the docs or on the site"
        },
        {
          "label": "Providers",
          "value": "Gmail, Office 365, Outlook.com, MS Exchange, Zoho Mail, iCloud and IMAP per the Email API guide. The product page also names Yahoo"
        },
        {
          "label": "Email endpoints",
          "value": "`/v1/email/messages` (list, send, get, raw, delete to Trash, status, reply, attachments), `/v1/email/conversations/{threadId}`, `/v1/email/drafts` (create, update, get, delete, send with `sendTime`), `/v1/email/folders` and `/v1/email/sync`"
        },
        {
          "label": "Search",
          "value": "`q` on message lists with 17 operators, among them `from:`, `to:`, `subject:`, `after:`, `before:`, `has:`, `is:`, `label:` (Gmail only) and `rfc822msgid:`. Date operators are partly supported on IMAP and Exchange"
        },
        {
          "label": "Sync",
          "value": "`POST /v1/email/sync` with `daysWithin`, then `/v1/email/sync/updated` and `/v1/email/sync/deleted` with `deltaToken` and `pageToken`. A 410 response is declared on both delta calls"
        },
        {
          "label": "Tracking and follow-ups",
          "value": "Open and reply tracking on sent mail, 10 operations under `/v1/email/tracking` and `/v1/email/draftTracking`, and 9 follow-up rule operations under `/v1/followup`"
        },
        {
          "label": "Credentials",
          "value": "Account access token (Bearer) from the OAuth flow, client ID and secret (Basic) for application-level calls, or a user session in `X-Aurinko-Session` or a cookie. IMAP accounts connect with an app password or the mailbox password"
        },
        {
          "label": "Scopes",
          "value": "`Mail.Read`, `Mail.ReadWrite` (no send), `Mail.Send` (send only), `Mail.Drafts`, and `Mail.All` in the description file only, beside six calendar, contacts and tasks scopes"
        },
        {
          "label": "Rate limits",
          "value": "250 requests a second for API calls, per the description file. Provider limits behind the API can also return 429"
        },
        {
          "label": "Errors",
          "value": "JSON body with `code`, `message`, `requestId` and the provider's `originalError`. The description file advises exponential backoff on 429 and 5xx, a retry on 408, and no retry on 404"
        },
        {
          "label": "Webhooks",
          "value": "`POST /v1/subscriptions` with resource `/email/messages` or `/email/tracking`, signed with HMAC SHA256 over `v0:{timestamp}:{raw_body}` in `X-Aurinko-Signature`. Gmail push needs the developer's own Google Pub/Sub setup"
        },
        {
          "label": "Trial",
          "value": "14 days with full API access. API requests are blocked at expiry until a card is added in the portal"
        },
        {
          "label": "SDKs",
          "value": "No official SDK is named in the docs or on the site"
        },
        {
          "label": "Security statement",
          "value": "TLS in transit and AES-256 at rest, MFA and role-based access, third-party penetration tests, SOC 2 Type I targeted for Q3 2026 (statement of 18 June 2026)"
        }
      ],
      "unitPrices": [
        {
          "item": "Email API (non-IMAP)",
          "unit": "account-month",
          "usd": 1.5,
          "note": "Per active account, up to 1 GB of traffic a month"
        },
        {
          "item": "Full platform, any number of APIs including IMAP",
          "unit": "account-month",
          "usd": 2,
          "note": "Per active account, unlimited traffic"
        }
      ],
      "provenance": {
        "legalEntity": "Yoxel, Inc.",
        "domain": "aurinko.io",
        "domainRegistered": "2019-05-08",
        "endpointOnVendorDomain": true,
        "terms": "https://www.aurinko.io/terms/",
        "privacy": "https://www.aurinko.io/privacy/",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The Terms of Services Agreement, last updated 11 August 2022, names Yoxel, Inc., organised under the laws of California, and covers the API and the workspace integrations platform. Disputes go to binding arbitration under JAMS rules in San Francisco, with a 30-day opt-out.",
          "The privacy policy, last updated 11 August 2022, covers the site and the services, API included, and commits to Google's API Services User Data Policy and its Limited Use requirements.",
          "The terms forbid robots, data mining and similar data extraction or gathering methods in connection with the Services. We read a handful of public pages and sent nothing to the API host.",
          "The API answers at api.aurinko.io per the description file, with the portal at app.aurinko.io and the reference at apirefs.aurinko.io, all on the vendor's domain.",
          "www.aurinko.io/.well-known/security.txt returns 404. The security statement gives security@yoxel.com for reports.",
          "No status page or changelog is linked from the home page, the docs index or the description file.",
          "robots.txt on www.aurinko.io has one `User-agent: *` line and no rules. On docs.aurinko.io it allows every path with `Content-Signal: ai-input=yes`. apirefs.aurinko.io answered 404 for robots.txt, read as no rules.",
          "RDAP for aurinko.io gives a registration date of 2019-05-08."
        ],
        "score": 60,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Yoxel, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "aurinko.io, registered 2019-05-08 (7 years)",
            "points": 11,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.aurinko.io",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 5.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 7 of the 8 things a reader expects",
            "points": 9.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.aurinko.io/terms/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2022-08-11",
            "words": 6042,
            "points": 5.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: Aug 11, 2022",
                "says": "Last updated 2022-08-11"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "The Yoxel Site and Services are provided by, and you’re contracting with: Yoxel that is organized under the laws of the State of California, USA.",
                "says": "The law of the State of California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "Under no circumstances will Yoxel be responsible or liable to you for any indirect, punitive, incidental, special, consequential, or exemplary damages resulting from your use or inability to use the Services or for the unavailability of the Services, for lost profits, personal injury, or property damage, or for any ot…",
                "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Until you have submitted, and we have reviewed and approved, all Required Information, your Yoxel Account will be available to you on a preliminary basis only, and we may terminate it at any time and for any reason."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "If you are an existing user of our Services, the material changes to this Agreement will come into effect 10 days after we provide you with the Notice.",
                "says": "Gives 10 days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "You may not access or use our Services or Site unless you agree to abide by all the terms and conditions set in this Agreement."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "…re-publish, license, reverse engineer, or create derivative works from Service Materials, nor use any robots, data mining, or similar data extraction or gathering methods in connection with our Services.",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "use the Services and the Site in any manner to compete with Yoxel.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "We may terminate this Agreement or close your Yoxel Account at any time for any reason (including, without limitation, for any activity that may create harm or loss to the goodwill of a Payment Method) by providing you Notice."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "IMPORTANT NOTICE REGARDING ARBITRATION: WHEN YOU AGREE TO THIS AGREEMENT YOU ARE AGREEING (WITH LIMITED EXCEPTION) TO RESOLVE ANY DISPUTE BETWEEN YOU AND YOXEL THROUGH BINDING ARBITRATION RATHER THAN IN COURT."
              },
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Last Updated: Aug 11, 2022"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Liability not otherwise disclaimed is capped at the fees paid in the three months before the event behind the claim.",
                "quote": "you further agree that under no circumstances will any such liability exceed in the aggregate the amount of Fees paid by you to Yoxel during the three-month period immediately preceding the event that gave rise to your claim for damages."
              },
              {
                "date": "2026-10-08",
                "text": "On monthly plans Yoxel may change the fees at any time, and a customer who does not accept the new fees is told to cancel.",
                "quote": "We reserve the right to change the Fees at any time. If you do not accept the new Fees, you should cancel your subscription."
              },
              {
                "date": "2026-10-08",
                "text": "On termination Yoxel may delete all of the customer’s stored information but is not obliged to.",
                "quote": "we reserve the right (but have no obligation) to delete all of your information stored on our servers;"
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.aurinko.io/privacy/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2022-08-11",
            "words": 3325,
            "points": 9.3,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: Aug 11, 2022",
                "says": "Last updated 2022-08-11"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "We are committed to respecting the privacy and security of the personal information we collect."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "To determine how long we keep personal information we consider the amount, nature and sensitivity of personal information, the reasons for which we collect and process the information and applicable legal requirements."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Collected Indirectly: We and our authorized third-party service providers collect certain information by automated means using cookies and other tracking technologies."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Business Transfers: We may also share personal information with third parties whom we choose to acquire, or to whom we choose to sell, transfer, or merge parts of our business or our assets."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "This Privacy Policy («Privacy Policy») provides important information about our use of personal information and informs you of your rights."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have any questions about this Privacy Policy or our privacy practices, please contact us by email at: compliance@yoxel.com.",
                "says": "compliance@yoxel.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "old",
                "label": "Has not been updated for three years or more",
                "found": true,
                "quote": "Last Updated: Aug 11, 2022"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Personal information is shared with the third parties whose APIs are integrated, and the policy says they may use it for their own purposes.",
                "quote": "These third parties may use your personal information to operate their services and for their own purposes."
              },
              {
                "date": "2026-10-08",
                "text": "Use and transfer of personal information received from Google Accounts is stated to follow the Google API Services User Data Policy, including its Limited Use requirements.",
                "quote": "Our use and transfer to any other app of personal information received from Google Accounts will adhere to Google API Services User Data Policy"
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/aurinko-email.json",
      "live": {
        "slug": "aurinko-email",
        "probe": {
          "target": "https://api.aurinko.io",
          "method": "get",
          "lastAt": "2026-10-10T01:37:43.835229901Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 236,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 120,
          "p95ms24h": 287,
          "samples24h": 102,
          "samples30d": 102,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 17,
              "ok": 17
            }
          ]
        },
        "updatedAt": "2026-10-10T01:37:43.835229901Z"
      }
    },
    "verify": {
      "accepts": "a page on aurinko.io or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/aurinko-email.svg",
      "body": {
        "slug": "aurinko-email",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/aurinko-email",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/aurinko-email\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/aurinko-email.svg\" alt=\"Aurinko Email API on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Aurinko Email API on Anchor Terminal](https://www.anchorterminal.com/badges/aurinko-email.svg)](https://www.anchorterminal.com/tools/aurinko-email)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/aurinko-email\"\u003eAurinko Email API on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/aurinko-email",
    "json": "https://www.anchorterminal.com/tools/aurinko-email.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/aurinko-email.md",
    "slim": "https://www.anchorterminal.com/tools/aurinko-email.min.md"
  },
  "markdown": "## Overview\n\n**Grade E · 44.2/100 · rank #878 of 950 · #9 in Mailbox access · not agent-ready · confidence medium**\n\n\nMore from Yoxel, Inc., listed separately because each is its own product: [Aurinko Calendar API](https://www.anchorterminal.com/tools/aurinko-calendar.md) (Calendars \u0026 scheduling).\n\n## Assessment\n\nOne REST interface covers message search with 17 query operators, drafts, sending, folders and delta sync across seven mailbox types, at $1.50 an active account a month and with send-only and read-only scopes. No status page, SLA, changelog, idempotency key on send or official SDK was found, and SOC 2 is not yet held.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Yoxel, Inc. (https://www.aurinko.io) |\n| Kind | HTTP API |\n| Category | Mailbox access (https://www.anchorterminal.com/categories/mailbox-access) |\n| Transport | HTTP |\n| Endpoint | `https://api.aurinko.io` |\n| Auth | OAuth · Self-serve. A developer signs up at app.aurinko.io and gets a client ID and secret for each application. Each mailbox owner connects through Aurinko's OAuth flow at `/v1/auth/authorize`, and the resulting account access token is sent as a Bearer token. Mail scopes are `Mail.Read`, `Mail.ReadWrite`, `Mail.Send` and `Mail.Drafts`. IMAP, iCloud and Exchange accounts connect with a password or app password. Gmail access needs the developer's own Google OAuth app, since Aurinko's default registration excludes Google email, and production Office 365 needs an Azure registration. |\n| Pricing | Paid (Paid) · $1.50 an active account a month for Email (non-IMAP) with up to 1 GB of traffic, and $2 for any number of APIs including IMAP with unlimited traffic, per the billing FAQ. A 14-day trial gives full API access, and requests are blocked when it ends without a card on file. No free tier or sandbox beyond the trial (https://docs.aurinko.io/faq/how-does-aurinko-billing-work). |\n| x402 | No · No x402, MPP or L402 in the docs, the OpenAPI description or the pricing page (checked 2026-10-09). |\n| Licence | Proprietary service under Yoxel's Terms of Services Agreement |\n| Docs | https://docs.aurinko.io/unified-apis/email-api |\n| llms.txt | https://docs.aurinko.io/llms.txt |\n| Surface graded | The REST API at https://api.aurinko.io/v1. No MCP server was found in the docs or on the site |\n| Providers | Gmail, Office 365, Outlook.com, MS Exchange, Zoho Mail, iCloud and IMAP per the Email API guide. The product page also names Yahoo |\n| Email endpoints | `/v1/email/messages` (list, send, get, raw, delete to Trash, status, reply, attachments), `/v1/email/conversations/{threadId}`, `/v1/email/drafts` (create, update, get, delete, send with `sendTime`), `/v1/email/folders` and `/v1/email/sync` |\n| Search | `q` on message lists with 17 operators, among them `from:`, `to:`, `subject:`, `after:`, `before:`, `has:`, `is:`, `label:` (Gmail only) and `rfc822msgid:`. Date operators are partly supported on IMAP and Exchange |\n| Sync | `POST /v1/email/sync` with `daysWithin`, then `/v1/email/sync/updated` and `/v1/email/sync/deleted` with `deltaToken` and `pageToken`. A 410 response is declared on both delta calls |\n| Tracking and follow-ups | Open and reply tracking on sent mail, 10 operations under `/v1/email/tracking` and `/v1/email/draftTracking`, and 9 follow-up rule operations under `/v1/followup` |\n| Credentials | Account access token (Bearer) from the OAuth flow, client ID and secret (Basic) for application-level calls, or a user session in `X-Aurinko-Session` or a cookie. IMAP accounts connect with an app password or the mailbox password |\n| Scopes | `Mail.Read`, `Mail.ReadWrite` (no send), `Mail.Send` (send only), `Mail.Drafts`, and `Mail.All` in the description file only, beside six calendar, contacts and tasks scopes |\n| Rate limits | 250 requests a second for API calls, per the description file. Provider limits behind the API can also return 429 |\n| Errors | JSON body with `code`, `message`, `requestId` and the provider's `originalError`. The description file advises exponential backoff on 429 and 5xx, a retry on 408, and no retry on 404 |\n| Webhooks | `POST /v1/subscriptions` with resource `/email/messages` or `/email/tracking`, signed with HMAC SHA256 over `v0:{timestamp}:{raw_body}` in `X-Aurinko-Signature`. Gmail push needs the developer's own Google Pub/Sub setup |\n| Trial | 14 days with full API access. API requests are blocked at expiry until a card is added in the portal |\n| SDKs | No official SDK is named in the docs or on the site |\n| Security statement | TLS in transit and AES-256 at rest, MFA and role-based access, third-party penetration tests, SOC 2 Type I targeted for Q3 2026 (statement of 18 June 2026) |\n| Capabilities | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync, email.threads |\n| Tags | hosted, oauth, openapi, llms-txt, webhooks, closed-source, free-trial |\n| JSON | https://www.anchorterminal.com/api/v1/tools/aurinko-email.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 40 | 8.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 67 | 10.9 |\n| Agent ergonomics | 13% | 16.2 | 49 | 8.0 |\n| Security \u0026 auth | 14% | 17.5 | 42 | 7.3 |\n| Payments \u0026 pricing | 10% | 12.5 | 40 | 5.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 13 | 1.1 |\n| Transparency \u0026 trust (editorial 27, provenance 60) | 7% | 8.8 | 44 | 3.9 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **44.2 → E** |\n\n### Why each score\n\n- Reliability 40: Graded as a hosted API. No status page is linked from the home page, the docs index or the description file (0). With no readable incident history the record scores 5. The description file gives a limit of 250 requests a second (15). It advises exponential backoff on 429 and 5xx and a retry on 408, and declares a `Retry-After` header only on the 408 of the get-message call. Sending takes no idempotency key (10). No SLA found, and the terms supply the service as is (0). The API is at `/v1` with no beta label (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 67: Public OpenAPI 3.0.0 description with 154 operations, 43 of them for email, read once from the file the reference page loads (25). `llms.txt` and a Markdown copy of every docs page (10). Every email operation has a summary but only 2 of 43 have a description. 61 of 85 parameters are described, and the guide has a table of 17 search operators with provider caveats (9). The scope list and `responseType` are enums, with few required fields marked (8). 34 of 43 email operations carry a cURL sample and the Errors section shows the JSON body, while operations declare little beyond 401 and a default response (10). `/v1` in the path and version 1.0.0, with no changelog found (5).\n- Agent ergonomics 49: Graded on the REST API. `bodyType`, `stripQuoted` and `returnIds` shape responses, but message lists take no field selection and no page-size parameter (10). `pageToken` on lists, `q` search with 17 operators, a per-folder list, and delta tokens for updated and deleted mail (15). Errors carry `code`, `message`, `requestId` and the provider's `originalError`, with retry advice per status (14). No idempotency key on send, reply or draft send. Reads and delta sync are safe to repeat, and delete moves a message to Trash (4). Few required parameters, but no official SDK was found (6).\n- Security \u0026 auth 42: Per-user OAuth with four mail scopes and `DELETE /v1/account/token` to revoke a token and the provider grant. The application's client ID and secret, sent as Basic auth with `X-Aurinko-Account-Id`, reach every connected account. The implicit grant is still supported though not recommended, returning the token in a URL fragment, and IMAP accounts give Aurinko a mailbox or app password (22). `Mail.Read` allows no writes and `Mail.Send` no reads, with no confirmation step for sends or deletes (13). Mail from third parties is returned with no injection guidance (0). No operator audit or request log found in the docs. Portal roles are documented (0). A security statement with a reporting address, security@yoxel.com, and penetration tests claimed. SOC 2 is not yet held, with no bug bounty and no security.txt (7).\n- Payments \u0026 pricing 40: No x402, MPP or L402 (0). Prices per active account a month published without login, $1.50 for email and $2 for all APIs, though the pricing page and the billing FAQ define the tiers differently (20). A 14-day trial, with a card asked for only when it ends (20). Signup is in a browser at app.aurinko.io, and each mailbox needs its owner's consent or password (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 13: No changelog or release notes found, so no API change can be dated. The docs sitemap dates the IMAP connection guide 22 September 2026 and the Email API guide 18 August 2026, counted as partial evidence of activity and not as a release (10). No dated changelog entries (0). Support is by email, with no public forum or issue tracker linked (3). No official SDK named in the docs (0). No public package or repository is linked from the pages read (0).\n- Transparency \u0026 trust 44: Closed service under a Terms of Services Agreement naming Yoxel, Inc. of California, last updated 11 August 2022 (15). The docs say message contents are passed through and never stored, with only IDs and thread relations cached, and the privacy policy commits to Google's Limited Use requirements. The policy gives no retention period, and no DPA was found (12). No deprecation policy or dated notices found (0). No sub-processor list or data location. The security statement names no cloud provider (0).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (22 items): https://www.anchorterminal.com/fixes/aurinko-email.md (JSON https://www.anchorterminal.com/fixes/aurinko-email.json)\n\n### What we couldn't check\n\n- unchecked: whether a status page exists under an address the site does not link. None is linked from the home page, the docs index or the description file\n- unchecked: the portal at app.aurinko.io behind login, so key rotation, team roles in practice, any request log and whether the trial asks for a card at signup were not seen\n- unchecked: the vendor's GitHub organisation and any npm package. No page read links either, so no SDK, repository or download figure is recorded\n- unchecked: the Follow-up Rules API guide, the Gmail Pub/Sub guide and the Google and Office 365 OAuth setup guides, which were not read\n- The terms forbid robots, data mining and similar data extraction or gathering methods in connection with the Services. Recorded as a fact with no deduction. It matters before any probe is run\n- Whether the SOC 2 Type I examination targeted for Q3 2026 has been completed. The security statement was last updated 18 June 2026\n- Which of the two published descriptions of the $1.50 tier applies, and whether an email-only customer on IMAP pays $2\n- Whether 429 responses carry a Retry-After header, and what page size message lists return. The description file does not say\n- Maintenance is 13 here and 20 on aurinko-calendar. This dossier counts docs page dates as 10 for recency and records no repository, because none is linked\n\n### Sources\n\n- OpenAPI description file the reference page loads (read in place of the rendered page), errors and rate limits: \u003chttps://apirefs.aurinko.io/assets/swagger.json\u003e (seen 2026-10-09)\n- API reference page, a Redoc viewer over the description file: \u003chttps://apirefs.aurinko.io/\u003e (seen 2026-10-09)\n- docs index for agents: \u003chttps://docs.aurinko.io/llms.txt\u003e (seen 2026-10-09)\n- Email API guide, sync, tracking and search operators: \u003chttps://docs.aurinko.io/unified-apis/email-api.md\u003e (seen 2026-10-09)\n- data handling statement: \u003chttps://docs.aurinko.io/getting-started/readme.md\u003e (seen 2026-10-09)\n- authentication scopes: \u003chttps://docs.aurinko.io/authentication/authentication-scopes.md\u003e (seen 2026-10-09)\n- account OAuth flow: \u003chttps://docs.aurinko.io/authentication/oauth-flow/account-oauth-flow.md\u003e (seen 2026-10-09)\n- IMAP connections and passwords: \u003chttps://docs.aurinko.io/authentication/configuring-imap-provider-connections-in-aurinko.md\u003e (seen 2026-10-09)\n- webhooks: \u003chttps://docs.aurinko.io/unified-apis/webhooks-api.md\u003e (seen 2026-10-09)\n- webhook signature validation: \u003chttps://docs.aurinko.io/unified-apis/webhooks-api/authentication.md\u003e (seen 2026-10-09)\n- billing FAQ and price tiers: \u003chttps://docs.aurinko.io/faq/how-does-aurinko-billing-work.md\u003e (seen 2026-10-09)\n- trial and subscription: \u003chttps://docs.aurinko.io/getting-started/subscribe-to-aurinko.md\u003e (seen 2026-10-09)\n- developer keys and test accounts: \u003chttps://docs.aurinko.io/getting-started/get-your-developer-api-keys.md\u003e (seen 2026-10-09)\n- shared Google OAuth app FAQ: \u003chttps://docs.aurinko.io/faq/does-aurinko-provide-a-shared-verified-google-oauth-application.md\u003e (seen 2026-10-09)\n- portal team roles: \u003chttps://docs.aurinko.io/team-members-and-roles-in-applications.md\u003e (seen 2026-10-09)\n- Direct API pass-through: \u003chttps://docs.aurinko.io/unified-apis/direct-api.md\u003e (seen 2026-10-09)\n- docs sitemap with page dates: \u003chttps://docs.aurinko.io/sitemap-pages.xml\u003e (seen 2026-10-09)\n- Email API product page: \u003chttps://www.aurinko.io/email-api/\u003e (seen 2026-10-09)\n- pricing page: \u003chttps://www.aurinko.io/pricing/\u003e (seen 2026-10-09)\n- terms of services agreement: \u003chttps://www.aurinko.io/terms/\u003e (seen 2026-10-09)\n- privacy policy: \u003chttps://www.aurinko.io/privacy/\u003e (seen 2026-10-09)\n- security statement: \u003chttps://www.aurinko.io/certifications/\u003e (seen 2026-10-09)\n- security.txt, 404: \u003chttps://www.aurinko.io/.well-known/security.txt\u003e (seen 2026-10-09)\n- robots.txt, one User-agent line and no rules: \u003chttps://www.aurinko.io/robots.txt\u003e (seen 2026-10-09)\n- robots.txt, allows all with ai-input=yes: \u003chttps://docs.aurinko.io/robots.txt\u003e (seen 2026-10-09)\n- robots.txt, 404: \u003chttps://apirefs.aurinko.io/robots.txt\u003e (seen 2026-10-09)\n- domain registration: \u003chttps://rdap.identitydigital.services/rdap/domain/aurinko.io\u003e (seen 2026-10-09)\n\n## Who's behind it (provenance 60/100, checked 2026-10-09)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Yoxel, Inc. | 20/20 |\n| Domain age | aurinko.io, registered 2019-05-08 (7 years) | 11/15 |\n| Endpoint on the vendor's domain | api.aurinko.io | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 |\n| Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 |\n| Status page | not found | 0/10 |\n| Changelog | not found | 0/10 |\n| security.txt | not found | 0/10 |\n\nThe Terms of Services Agreement, last updated 11 August 2022, names Yoxel, Inc., organised under the laws of California, and covers the API and the workspace integrations platform. Disputes go to binding arbitration under JAMS rules in San Francisco, with a 30-day opt-out.\n\nThe privacy policy, last updated 11 August 2022, covers the site and the services, API included, and commits to Google's API Services User Data Policy and its Limited Use requirements.\n\nThe terms forbid robots, data mining and similar data extraction or gathering methods in connection with the Services. We read a handful of public pages and sent nothing to the API host.\n\nThe API answers at api.aurinko.io per the description file, with the portal at app.aurinko.io and the reference at apirefs.aurinko.io, all on the vendor's domain.\n\nwww.aurinko.io/.well-known/security.txt returns 404. The security statement gives security@yoxel.com for reports.\n\nNo status page or changelog is linked from the home page, the docs index or the description file.\n\nrobots.txt on www.aurinko.io has one `User-agent: *` line and no rules. On docs.aurinko.io it allows every path with `Content-Signal: ai-input=yes`. apirefs.aurinko.io answered 404 for robots.txt, read as no rules.\n\nRDAP for aurinko.io gives a registration date of 2019-05-08.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.aurinko.io/terms/), read 2026-10-08, dated 2022-08-11, states 6 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"…re-publish, license, reverse engineer, or create derivative works from Service Materials, nor use any robots, data mining, or similar data extraction or gathering methods in connection with our Services.\"\n- To know. Restricts benchmarking or competitive use (costs points). \"use the Services and the Site in any manner to compete with Yoxel.\"\n- To know. Says access can be ended without notice or for any reason. \"We may terminate this Agreement or close your Yoxel Account at any time for any reason (including, without limitation, for any activity that may create harm or loss to the goodwill of a Payment Method) by providing you Notice.\"\n- To know. Requires arbitration or waives class actions. \"IMPORTANT NOTICE REGARDING ARBITRATION: WHEN YOU AGREE TO THIS AGREEMENT YOU ARE AGREEING (WITH LIMITED EXCEPTION) TO RESOLVE ANY DISPUTE BETWEEN YOU AND YOXEL THROUGH BINDING ARBITRATION RATHER THAN IN COURT.\"\n- To know. Has not been updated for three years or more. \"Last Updated: Aug 11, 2022\"\n- Gives the date it was last updated. Last updated 2022-08-11.\n- Names the governing law or courts. The law of the State of California.\n- States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence.\n- Says how changes to the terms are announced. Gives 10 days of notice before a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Liability not otherwise disclaimed is capped at the fees paid in the three months before the event behind the claim. \"you further agree that under no circumstances will any such liability exceed in the aggregate the amount of Fees paid by you to Yoxel during the three-month period immediately preceding the event that gave rise to your claim for damages.\"\n- Also in the text (2026-10-08). On monthly plans Yoxel may change the fees at any time, and a customer who does not accept the new fees is told to cancel. \"We reserve the right to change the Fees at any time. If you do not accept the new Fees, you should cancel your subscription.\"\n- Also in the text (2026-10-08). On termination Yoxel may delete all of the customer’s stored information but is not obliged to. \"we reserve the right (but have no obligation) to delete all of your information stored on our servers;\"\n\n**Privacy policy** (https://www.aurinko.io/privacy/), read 2026-10-08, dated 2022-08-11, states 7 of the 8 things a reader expects.\n\n- To know. Has not been updated for three years or more. \"Last Updated: Aug 11, 2022\"\n- Gives the date it was last updated. Last updated 2022-08-11.\n- Gives a privacy contact. compliance@yoxel.com.\n- Not found in the text. Says where data is transferred or stored.\n- Also in the text (2026-10-08). Personal information is shared with the third parties whose APIs are integrated, and the policy says they may use it for their own purposes. \"These third parties may use your personal information to operate their services and for their own purposes.\"\n- Also in the text (2026-10-08). Use and transfer of personal information received from Google Accounts is stated to follow the Google API Services User Data Policy, including its Limited Use requirements. \"Our use and transfer to any other app of personal information received from Google Accounts will adhere to Google API Services User Data Policy\"\n\n## Live (updated 2026-10-10 01:37 UTC)\n\n- Right now: up, HTTP 404, 236 ms, checked 2026-10-10 01:37 UTC (get on `https://api.aurinko.io`)\n- Uptime 24h 100.0% (102 probes) · 30 days 100.0% (102 probes) · p50 120 ms · p95 287 ms\n- Always current: https://www.anchorterminal.com/api/v1/live/aurinko-email.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Email API (non-IMAP) | $1.50 | per connected account per month | Per active account, up to 1 GB of traffic a month |\n| Full platform, any number of APIs including IMAP | $2 | per connected account per month | Per active account, unlimited traffic |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public OpenAPI 3.0 description at `apirefs.aurinko.io/assets/swagger.json`, with 43 email operations, 34 of them carrying a cURL sample\n- Four mail scopes. `Mail.Read` allows no writes, `Mail.Send` allows sending with no read access, and `Mail.ReadWrite` excludes send\n- The `q` parameter takes 17 search operators, with a table in the docs saying where IMAP and Exchange support is partial\n- Prices published per active account a month ($1.50 for email, $2 for all APIs with IMAP), with a 14-day trial\n- Docs state that message contents are passed through and never stored, with only IDs and thread relations cached for sync\n\n## Weaknesses\n\n- No status page, incident history or SLA found, and the terms supply the service as is\n- No idempotency key on `POST /v1/email/messages`, so a retried send can deliver twice\n- No changelog, deprecation policy or official SDK found in the docs or on the site\n- The application's client ID and secret, sent as Basic auth, reach every connected mailbox, and IMAP accounts hand Aurinko a mailbox password\n- The terms of 11 August 2022 forbid robots and data extraction methods in connection with the Services. This matters before any probe is run\n\n## Before you call it (notes for agents)\n\n1. Use `https://api.aurinko.io/v1`. Several cURL examples in the docs print `https:/api.aurinko.io` with one slash, and one search example names the host `asti.aurinko.io`\n2. Do not retry `POST /v1/email/messages` blindly after a timeout. There is no idempotency key, so check Sent mail with `q=rfc822msgid:` or by subject first\n3. Call `POST /v1/email/sync` until `ready` is true, then page `/v1/email/sync/updated` with `pageToken` until a `nextDeltaToken` appears and store it\n4. Check the `omitted` array on message lists. Full bodies come only from Google and Office 365, and other providers return a snippet\n5. Request `Mail.Read` plus `Mail.Send` for read and send without modify rights. The docs example names `Mail.ReadOnly`, which is not in the scope list\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -H 'Authorization: Bearer \u003caccess_token\u003e' \\\n  -G https://api.aurinko.io/v1/email/messages \\\n  -d q='from:alexey'\n```\n\nThrough letme (picks today, calling later): https://letme.dev/aurinko-email. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Nylas Email API | A | 78.7 | 13 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync, email.threads | no | https://www.anchorterminal.com/tools/nylas-email.md |\n| Gmail API | BB | 77.8 | 19 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | no | https://www.anchorterminal.com/tools/gmail-api.md |\n| EmailEngine | BB | 71.4 | 128 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | no | https://www.anchorterminal.com/tools/emailengine.md |\n| Outlook Mail (Microsoft Graph) | B | 66.3 | 296 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | no | https://www.anchorterminal.com/tools/outlook-mail-graph.md |\n| Unipile | C | 58.4 | 581 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | no | https://www.anchorterminal.com/tools/unipile.md |\n| Fastmail API (JMAP) | C | 54.1 | 694 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | no | https://www.anchorterminal.com/tools/fastmail.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The description file is OpenAPI 3.0.0, titled Aurinko.io API 1.0.0, with 112 paths and 154 operations, 43 of them in the Email group (Messages 10, EmailTracking 10, FollowUpRobot 9, EmailFolders 6, Drafts 5, EmailSync 3) (source: \u003chttps://apirefs.aurinko.io/assets/swagger.json\u003e)\n- The billing FAQ prices Email (non-IMAP) at $1.50 an active account a month up to 1 GB of traffic, and puts IMAP in the $2 Full Platform tier. An account is active above 10 API calls or 1 MB in a billing month (source: \u003chttps://docs.aurinko.io/faq/how-does-aurinko-billing-work\u003e)\n- The pricing page describes the same three prices by data transfer alone, $1 under 1 GB, $1.50 under 5 GB and $2 unlimited, which differs from the FAQ (source: \u003chttps://www.aurinko.io/pricing/\u003e)\n- The docs describe the API as mainly a pass-through that caches IDs and thread-message relations and never stores the contents of emails (source: \u003chttps://docs.aurinko.io/getting-started/readme\u003e)\n- Until a developer registers their own Google OAuth app, Aurinko's default registration is used with limited permissions and Google email is not available. Aurinko says it chooses not to run a shared verified Google app (source: \u003chttps://docs.aurinko.io/getting-started/get-your-developer-api-keys\u003e)\n- Sending accepts a `tracking` object for opens and thread replies, with a tracking pixel on Aurinko's domain or a custom alias, and `/email/tracking` is a webhook resource (source: \u003chttps://docs.aurinko.io/unified-apis/email-api\u003e)\n- The security statement, last updated 18 June 2026, says Yoxel is preparing for a SOC 2 Type I examination targeted for Q3 2026 with Secureframe, and takes vulnerability reports at security@yoxel.com (source: \u003chttps://www.aurinko.io/certifications/\u003e)\n- The Terms of Services Agreement says users may not use any robots, data mining, or similar data extraction or gathering methods in connection with the Services (source: \u003chttps://www.aurinko.io/terms/\u003e)\n\n- #9 of 9 in Best mailbox access APIs for AI agents: https://www.anchorterminal.com/best/mailbox-access/index.md\n- All 36 mailboxes comparisons: https://www.anchorterminal.com/compare/mailbox-access/index.md\n\n## Compare\n\n- [Aurinko Email API vs EmailEngine](https://www.anchorterminal.com/compare/aurinko-email-vs-emailengine.md): E 44.2 vs BB 71.4\n- [Aurinko Email API vs Fastmail API (JMAP)](https://www.anchorterminal.com/compare/aurinko-email-vs-fastmail.md): E 44.2 vs C 54.1\n- [Aurinko Email API vs Gmail API](https://www.anchorterminal.com/compare/aurinko-email-vs-gmail-api.md): E 44.2 vs BB 77.8\n- [Aurinko Email API vs Himalaya](https://www.anchorterminal.com/compare/aurinko-email-vs-himalaya.md): E 44.2 vs B 64.5\n- [Aurinko Email API vs Nylas Email API](https://www.anchorterminal.com/compare/aurinko-email-vs-nylas-email.md): E 44.2 vs A 78.7\n- [Aurinko Email API vs Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/compare/aurinko-email-vs-outlook-mail-graph.md): E 44.2 vs B 66.3\n- [Aurinko Email API vs Unipile](https://www.anchorterminal.com/compare/aurinko-email-vs-unipile.md): E 44.2 vs C 58.4\n- [Aurinko Email API vs Zoho Mail API](https://www.anchorterminal.com/compare/aurinko-email-vs-zoho-mail.md): E 44.2 vs D 53.8\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on aurinko.io or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"aurinko-email\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/aurinko-email\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/aurinko-email.svg\" alt=\"Aurinko Email API on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Aurinko Email API on Anchor Terminal](https://www.anchorterminal.com/badges/aurinko-email.svg)](https://www.anchorterminal.com/tools/aurinko-email)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/aurinko-email\"\u003eAurinko Email API on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Aurinko Email API is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/aurinko-email-dark.png\n- Light: https://www.anchorterminal.com/assets/share/aurinko-email-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Mailbox access",
        "url": "https://www.anchorterminal.com/categories/mailbox-access"
      },
      {
        "name": "Aurinko Email API",
        "url": ""
      }
    ],
    "description": "Unified email REST API from Yoxel, Inc. It reads, searches, drafts and sends mail in a user's own mailbox on Gmail, Office 365, Outlook.com, Exchange, Zoho Mail, iCloud and IMAP, with delta sync, open and reply tracking and webhooks.",
    "facts": [
      "rank #878 of 950",
      "OAuth auth",
      "0 desk reviews"
    ],
    "h1": "Aurinko Email API",
    "image": "https://www.anchorterminal.com/assets/og/tools-aurinko-email.png",
    "path": "/tools/aurinko-email",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Aurinko Email review (2026): pricing, alternatives and grade E",
    "toc": null,
    "updated": "2026-10-10",
    "url": "https://www.anchorterminal.com/tools/aurinko-email"
  },
  "tokens": {
    "markdown": 7850,
    "slim": 1830
  },
  "version": 1
}
