# Gmail API (slim) > Google's REST API for Gmail mailboxes. It searches and reads messages and threads, writes drafts, sends mail, manages labels and settings, and reports mailbox changes through history records and Cloud Pub/Sub push notifications. Access is by OAuth 2.0. - Full: https://www.anchorterminal.com/tools/gmail-api.md (~9,150 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/gmail-api.json · canonical https://www.anchorterminal.com/tools/gmail-api - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 77.8/100 · rank #17 of 629 · #2 in Mailbox access · agent-ready · confidence medium** Assessment: Fourteen OAuth scopes separate labels, sending, metadata and read-only access, and the quota page gives every method a unit cost. Eight of the scopes are restricted, read-only and metadata among them, so a public app that reads mail needs Google's verification and an annual third-party security assessment. Gmail mailboxes only. ## Facts - Kind: HTTP API · vendor: Google · category: Mailbox access · legal entity: Google LLC · provenance 94/100 - Endpoint: `https://gmail.googleapis.com/gmail/v1` (HTTP, Streamable HTTP) - Auth: OAuth · pricing: Free · x402: no · licence: Apache-2.0 (client libraries) - Probe metrics: not measured yet (probes haven't run) - Surface graded: The REST API at https://gmail.googleapis.com/gmail/v1, generally available, discovery revision 20260928 with 79 methods. The MCP server is a developer preview and is described but not the basis of the grade - Free tier: All standard use, up to 80,000,000 quota units a day per project - Rate limits: 1,200,000 quota units a minute per project and 6,000 a minute per user per project. `messages.list` 5 units, `messages.get` 20, `threads.get` 40, `messages.send` 100, `history.list` 2 - Planned charges: Use above the daily threshold to be billed to the Cloud billing account later in 2026, with at least 90 days' notice. No price published - Scopes: 14. Non-sensitive `gmail.labels` and two add-on scopes. Sensitive `gmail.send` and two add-on scopes. Restricted `https://mail.google.com/`, `gmail.readonly`, `gmail.compose`, `gmail.insert`, `gmail.modify`, `gmail.metadata`, `gmail.settings.basic` and `gmail.settings.sharing` - App verification: Restricted scopes need restricted-scope verification for a public app, plus a CASA security assessment every 12 months when data is reached from or through a server. Google says the process can take several weeks. Personal, test, internal and domain-wide installed apps are exempt - Sending: `messages.send` and `drafts.send` take an RFC 2822 message, base64url encoded, up to 36,700,160 bytes by upload and 500 recipients a message. The user's Gmail daily sending limit applies, 2,000 messages a day on paid Workspace and 500 on trial accounts - Sync: `history.list` from a stored `historyId`, with records typically kept for at least a week and a 404 when the ID is too old. Push notifications through Cloud Pub/Sub, renewed with `watch` at least every 7 days - Batching: Up to 100 calls a batch request, with 50 or fewer recommended. Each call counts against quota separately - MCP server: gmailmcp.googleapis.com/mcp/v1, streamable HTTP, own OAuth client with `gmail.readonly` and `gmail.compose`, Developer Preview Programme members only. 23 tools on 8 October 2026, drafts but no send and no permanent delete, each with readOnlyHint, destructiveHint and idempotentHint annotations - Audit: Workspace OAuth log events record the API name, the API method, the OAuth client ID and scopes. The security investigation tool needs Enterprise, Frontline, Education Standard or Plus, or Cloud Identity Premium editions - Client libraries: @googleapis/gmail 22.0.1 (23 September 2026, Node 22 or later) and google-api-python-client 2.201.0 (30 September 2026), Apache-2.0, plus Google's generated clients for other languages - Scores: Reliability 90, Performance pending, Schema & documentation 82, Agent ergonomics 82, Security & auth 81, Payments & pricing 35, Task success pending, Maintenance & community 85, Transparency & trust 82 · total over the 7 assessed categories - Why: Reliability, Graded on the REST API with the hosted lines. · Schema & documentation, Google publishes a discovery document, not OpenAPI, which is a machine-readable contract all the same, at revision 20260928 with 79 methods… · Agent ergonomics, Responses size with `format=minimal` or `metadata`, `metadataHeaders`, `maxResults` and Google's standard `fields` partial responses. · Security & auth, OAuth 2.0 with 14 scopes and revocable tokens, from `gmail.labels` and `gmail.send` up to the full `https://mail.google.com/` scope. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, @googleapis/gmail 22.0.1 on 23 September 2026, and discovery revision 20260928 (30). · Transparency & trust, Closed service under the Google APIs Terms of Service (last modified 9 November 2021), with Apache-2.0 client libraries (15). - Sources: 30, open questions: 11, both in the full twin - Capabilities: mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync - JSON: https://www.anchorterminal.com/api/v1/tools/gmail-api.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/gmail-api.svg` or a link to https://www.anchorterminal.com/tools/gmail-api from a page on google.com or one of its subdomains, or the README of github.com/googleapis/google-api-nodejs-client, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Ask for the narrowest scope. `gmail.labels` is non-sensitive and `gmail.send` is sensitive, while every scope that reads mail is restricted 2. List with `messages.list` and `q` in Gmail search syntax, then fetch each ID with `format=metadata` or `full`. List calls return IDs only 3. Send by posting an RFC 2822 message, base64url encoded, in `raw`. Set `threadId` and matching reply headers to stay in a thread 4. Store the `historyId` and call `history.list`. On a 404, run a full sync. Call `watch` again at least every 7 days 5. Back off exponentially on 403 and 429 rate errors, and keep batches to 50 requests or fewer ## Connect ```bash curl "https://gmail.googleapis.com/gmail/v1/users/me/messages?q=is:unread&maxResults=5" \ -H "Authorization: Bearer $GOOGLE_ACCESS_TOKEN" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/gmail-api ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Nylas Email API | A | 78.7 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/nylas-email.min.md | | EmailEngine | BB | 71.4 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/emailengine.min.md | | Outlook Mail (Microsoft Graph) | B | 66.3 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/outlook-mail-graph.min.md | | Unipile | C | 58.4 | mailbox.read, mailbox.search, mailbox.send, mailbox.drafts, mailbox.sync | https://www.anchorterminal.com/tools/unipile.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)