# Aurinko Email API (slim) > Unified email REST API from Yoxel, Inc. It reads, searches, drafts and sends mail in a user's own mailbox on Gmail, Office 365, Outlook.com, Exchange, Zoho Mail, iCloud and IMAP, with delta sync, open and reply tracking and webhooks. - Full: https://www.anchorterminal.com/tools/aurinko-email.md (~7,850 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/aurinko-email.json · canonical https://www.anchorterminal.com/tools/aurinko-email - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 **E · 44.2/100 · rank #878 of 950 · #9 in Mailbox access · not agent-ready · confidence medium** Assessment: One REST interface covers message search with 17 query operators, drafts, sending, folders and delta sync across seven mailbox types, at $1.50 an active account a month and with send-only and read-only scopes. No status page, SLA, changelog, idempotency key on send or official SDK was found, and SOC 2 is not yet held. ## Facts - Kind: HTTP API · vendor: Yoxel, Inc. · category: Mailbox access · legal entity: Yoxel, Inc. · provenance 60/100 - Endpoint: `https://api.aurinko.io` (HTTP) - Auth: OAuth · pricing: Paid · x402: no · licence: Proprietary service under Yoxel's Terms of Services Agreement - Probe metrics: not measured yet (probes haven't run) - Surface graded: The REST API at https://api.aurinko.io/v1. No MCP server was found in the docs or on the site - Providers: Gmail, Office 365, Outlook.com, MS Exchange, Zoho Mail, iCloud and IMAP per the Email API guide. The product page also names Yahoo - Email endpoints: `/v1/email/messages` (list, send, get, raw, delete to Trash, status, reply, attachments), `/v1/email/conversations/{threadId}`, `/v1/email/drafts` (create, update, get, delete, send with `sendTime`), `/v1/email/folders` and `/v1/email/sync` - Search: `q` on message lists with 17 operators, among them `from:`, `to:`, `subject:`, `after:`, `before:`, `has:`, `is:`, `label:` (Gmail only) and `rfc822msgid:`. Date operators are partly supported on IMAP and Exchange - Sync: `POST /v1/email/sync` with `daysWithin`, then `/v1/email/sync/updated` and `/v1/email/sync/deleted` with `deltaToken` and `pageToken`. A 410 response is declared on both delta calls - Tracking and follow-ups: Open and reply tracking on sent mail, 10 operations under `/v1/email/tracking` and `/v1/email/draftTracking`, and 9 follow-up rule operations under `/v1/followup` - Credentials: Account access token (Bearer) from the OAuth flow, client ID and secret (Basic) for application-level calls, or a user session in `X-Aurinko-Session` or a cookie. IMAP accounts connect with an app password or the mailbox password - Scopes: `Mail.Read`, `Mail.ReadWrite` (no send), `Mail.Send` (send only), `Mail.Drafts`, and `Mail.All` in the description file only, beside six calendar, contacts and tasks scopes - Rate limits: 250 requests a second for API calls, per the description file. Provider limits behind the API can also return 429 - Errors: JSON body with `code`, `message`, `requestId` and the provider's `originalError`. The description file advises exponential backoff on 429 and 5xx, a retry on 408, and no retry on 404 - Webhooks: `POST /v1/subscriptions` with resource `/email/messages` or `/email/tracking`, signed with HMAC SHA256 over `v0:{timestamp}:{raw_body}` in `X-Aurinko-Signature`. Gmail push needs the developer's own Google Pub/Sub setup - Trial: 14 days with full API access. API requests are blocked at expiry until a card is added in the portal - SDKs: No official SDK is named in the docs or on the site - Security statement: TLS in transit and AES-256 at rest, MFA and role-based access, third-party penetration tests, SOC 2 Type I targeted for Q3 2026 (statement of 18 June 2026) - Prices: Email API (non-IMAP) $1.50 per connected account per month; Full platform, any number of APIs including IMAP $2 per connected account per month - Scores: Reliability 40, Performance pending, Schema & documentation 67, Agent ergonomics 49, Security & auth 42, Payments & pricing 40, Task success pending, Maintenance & community 13, Transparency & trust 44 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted API. · Schema & documentation, Public OpenAPI 3.0.0 description with 154 operations, 43 of them for email, read once from the file the reference page loads (25). · Agent ergonomics, Graded on the REST API. · Security & auth, Per-user OAuth with four mail scopes and `DELETE /v1/account/token` to revoke a token and the provider grant. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, No changelog or release notes found, so no API change can be dated. · Transparency & trust, Closed service under a Terms of Services Agreement naming Yoxel, Inc. - Sources: 27, open questions: 9, both in the full twin - Capabilities: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync, email.threads - JSON: https://www.anchorterminal.com/api/v1/tools/aurinko-email.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/aurinko-email.svg` or a link to https://www.anchorterminal.com/tools/aurinko-email from a page on aurinko.io or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Use `https://api.aurinko.io/v1`. Several cURL examples in the docs print `https:/api.aurinko.io` with one slash, and one search example names the host `asti.aurinko.io` 2. Do not retry `POST /v1/email/messages` blindly after a timeout. There is no idempotency key, so check Sent mail with `q=rfc822msgid:` or by subject first 3. Call `POST /v1/email/sync` until `ready` is true, then page `/v1/email/sync/updated` with `pageToken` until a `nextDeltaToken` appears and store it 4. Check the `omitted` array on message lists. Full bodies come only from Google and Office 365, and other providers return a snippet 5. Request `Mail.Read` plus `Mail.Send` for read and send without modify rights. The docs example names `Mail.ReadOnly`, which is not in the scope list ## Connect ```bash curl -H 'Authorization: Bearer ' \ -G https://api.aurinko.io/v1/email/messages \ -d q='from:alexey' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/aurinko-email ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Nylas Email API | A | 78.7 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync, email.threads | https://www.anchorterminal.com/tools/nylas-email.min.md | | Gmail API | BB | 77.8 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/gmail-api.min.md | | EmailEngine | BB | 71.4 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/emailengine.min.md | | Outlook Mail (Microsoft Graph) | B | 66.3 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/outlook-mail-graph.min.md | | Unipile | C | 58.4 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/unipile.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)