# Fastmail API (JMAP) (slim) > Fastmail is a paid email, calendar and contacts host from Fastmail Pty Ltd in Melbourne. Agents reach a customer's mailbox through JMAP at api.fastmail.com, the open IETF protocol, or through the company's own MCP server. - Full: https://www.anchorterminal.com/tools/fastmail.md (~8,850 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/fastmail.json · canonical https://www.anchorterminal.com/tools/fastmail - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 54.1/100 · rank #620 of 842 · #6 in Mailbox access · not agent-ready · confidence medium** Assessment: A mailbox API built on the open JMAP standard, with read-only tokens, six OAuth scopes and an MCP server that separates read, write and send access. Fastmail publishes no OpenAPI file, SDK, API changelog, request rate limit or SLA, and its customer terms forbid programmatically generated email to addresses outside the account. ## Facts - Kind: HTTP API · vendor: Fastmail Pty Ltd · category: Mailbox access · legal entity: Fastmail Pty Ltd, ACN 142 646 580, PO Box 234, Collins Street West, VIC 8007, Australia · provenance 86/100 - Local only (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under Fastmail's API Terms of Service and API Developer Policy. JMAP is an open IETF standard, and the sample code on GitHub is MIT - Probe metrics: not measured yet (probes haven't run) - Graded surface: The JMAP API at api.fastmail.com with an API token or OAuth. The MCP server at https://api.fastmail.com/mcp is described and counted where a checklist line covers it - Protocols: JMAP for mail, sending and contacts (RFC 8620, 8621, 9610), plus IMAP, POP, SMTP, CardDAV, CalDAV and WebDAV with app passwords. Calendars are not yet open over JMAP (https://www.fastmail.com/dev/) - Session: GET https://api.fastmail.com/jmap/session with `Authorization: Bearer `. CORS is enabled. Without a token the endpoint answers 401 and names its resource metadata - API tokens: Created in Settings, Privacy & Security, Manage API tokens, as type JMAP or MCP. JMAP scopes are read-only access, Email, Email submission, Contacts and Masked Email. Not available on Basic plans (https://www.fastmail.help/hc/en-us/articles/5254602856719-API-tokens) - OAuth: Authorisation code grant with PKCE S256 at `/oauth/authorize` and `/oauth/refresh`, revocation at `/oauth/revoke`. Refresh tokens rotate on every use. Authorisation codes expire after 10 minutes - OAuth scopes: `urn:ietf:params:jmap:core`, `mail`, `submission`, `vacationresponse` and `contacts`, plus `https://www.fastmail.com/dev/maskedemail`, per the developer page - MCP server: https://api.fastmail.com/mcp, launched 22 April 2026. OAuth or an MCP-type API token, with read, write and send levels. Covers mail, contacts and calendars. No attachments. Tool list not read - Masked Email: A Fastmail JMAP extension with `MaskedEmail/get` and `MaskedEmail/set`. Pending addresses are deleted after 24 hours, and creation is rate limited with a `rateLimit` SetError - Sending limits: 8,000 messages and 2 GB a day on Individual and Standard, 16,000 on Professional, 4,000 on Basic, 120 a day on a trial. Hourly limits are half the daily figure. One message per recipient (https://www.fastmail.help/hc/en-us/articles/1500000277382-Account-limits) - Other limits: 70 MB per message, 100 messages and 100 MB a minute received, 500 logins per ten minutes per user. No API request rate published - Data location: Data centres in Philadelphia, St. Louis and Amsterdam. Since August 2026 an account chooses US or EU for its primary copy. EU accounts keep a replica, backups, logs and debug systems in the US - Samples: fastmail/JMAP-Samples, MIT, scripts in JavaScript, Python, Perl and Lua. Last commit 6 April 2026. No official SDK found - Support: Email and a support form, around the clock, with a first reply expected within 24 hours. No phone support - Prices: Individual plan, billed monthly $6 per month (plan); Individual plan, $60 billed yearly $5 per month (plan); Business Standard, billed monthly $6 per seat per month - Scores: Reliability 54, Performance pending, Schema & documentation 52, Agent ergonomics 73, Security & auth 60, Payments & pricing 30, Task success pending, Maintenance & community 26, Transparency & trust 74 · total over the 7 assessed categories - Why: Reliability, Graded on the JMAP API with the hosted lines. · Schema & documentation, Graded on the JMAP API. · Agent ergonomics, Graded on the JMAP API as RFC 8620 and 8621 specify it. · Security & auth, Graded on the JMAP API with the MCP controls counted where a line covers them. · Payments & pricing, No x402, MPP or L402 on the developer page, the pricing page or the 401 responses from api.fastmail.com (0 of 40). · Maintenance & community, Fastmail keeps no API changelog, so recency rests on what we could date. · Transparency & trust, The editorial half. - Sources: 36, open questions: 14, both in the full twin - Capabilities: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync - JSON: https://www.anchorterminal.com/api/v1/tools/fastmail.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/fastmail.svg` or a link to https://www.anchorterminal.com/tools/fastmail from a page on fastmail.com or one of its subdomains, or the README of github.com/fastmail/JMAP-Samples, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Fetch `https://api.fastmail.com/jmap/session` with `Authorization: Bearer ` first. It returns the API URL, account IDs and the request limits to stay under 2. Ask the owner for a read-only token unless the task writes. Sending needs both the Email and Email submission scopes 3. Request only the `properties` you need. Body text is not returned unless `fetchTextBodyValues` is set, and `maxBodyValueBytes` caps it 4. Sync with `Email/changes` from a stored state. On `cannotCalculateChanges`, fetch again from scratch 5. Do not send generated mail to outside recipients without the owner's review. The customer terms forbid it, and trial accounts stop at 120 messages a day ## Connect ```bash curl https://api.fastmail.com/jmap/session \ -H "Authorization: Bearer YOUR_API_TOKEN" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/fastmail ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Nylas Email API | A | 78.7 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/nylas-email.min.md | | Gmail API | BB | 77.8 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/gmail-api.min.md | | EmailEngine | BB | 71.4 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/emailengine.min.md | | Outlook Mail (Microsoft Graph) | B | 66.3 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/outlook-mail-graph.min.md | | Unipile | C | 58.4 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/unipile.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)