Gmail API Limits 2026: Quotas, Sending Caps, Pricing
The Gmail API meters calls in quota units: 1,200,000 per minute per Cloud project and 6,000 per minute per user. A messages.send costs 100 units and a messages.get costs 20. On top of that sits the account’s own sending cap, 500 emails a day on personal Gmail and 2,000 on Google Workspace, shared with every other way that account sends mail.
Google rewrote these numbers on May 1, 2026. Reading a message now costs four times what it did and the per-user budget fell from 15,000 units a minute, so most guides you’ll find are out of date. Every figure below comes from Google’s own developer and help pages, checked October 2, 2026.
The quick answer: the API is free below 80 million quota units per project per day. The money goes on the mailbox (a Workspace seat, from $7 a user a month) and, if your server reads mail, on Google’s restricted-scope review plus an annual security assessment you pay a lab for. If you’re building an AI agent, every one of these limits belongs to a human’s account, and Google’s rules against bot-run accounts apply to it. Give the agent its own inbox on CarlyEmail instead: one API call creates the address, there’s no OAuth review, received mail never counts against your sending quota, and it’s free for 3 inboxes and 1,000 emails a month.
Gmail API limits at a glance
| Limit | Value | Notes |
|---|---|---|
| Quota per project | 1,200,000 units a minute | Shared by every user of your Cloud project |
| Quota per user | 6,000 units a minute | Was 15,000. Projects that used the API between November 2025 and April 2026 keep their previous quota for now |
| Daily billing threshold | 80,000,000 units per project a day | Free below it. Google plans to charge above it, hasn’t published a price, and won’t raise the threshold |
| Recipients per message | 500 | To, Cc and Bcc combined |
| Sending, personal Gmail | 500 emails a day | Or 500 recipients on one email. Sending comes back in 1 to 24 hours |
| Sending, Google Workspace | 2,000 messages per user a day | 1,500 for mail merge, 500 on trial accounts. Counted over a rolling 24 hours |
| Recipients, Google Workspace | 10,000 a day | 3,000 external, and 3,000 unique recipients (2,000 of them external) |
| Receiving, Google Workspace | 60 a minute, 3,600 an hour, 86,400 a day | Over it, new mail bounces for about 24 hours and can’t be recovered |
| Push notifications | 1 event a second per mailbox | Extra events are dropped. watch must be renewed at least every 7 days |
| Concurrent requests | Per-user cap, number not published | Returns 429 “Too many concurrent requests for user” |
What each Gmail API method costs in quota units
Every call spends units from both the per-user and per-project budgets. The methods an app or agent actually uses:
| Method | Quota units | Before May 2026 | Max calls per user per minute |
|---|---|---|---|
getProfile, labels.list | 1 | 1 | 6,000 |
history.list | 2 | 2 | 3,000 |
messages.list, messages.modify | 5 | 5 | 1,200 |
threads.list, drafts.create | 10 | 10 | 600 |
messages.get | 20 | 5 | 300 |
messages.attachments.get | 20 | 5 | 300 |
drafts.get, messages.trash | 20 | 5 | 300 |
threads.get | 40 | 10 | 150 |
messages.batchModify | 50 | 50 | 120 |
messages.send, drafts.send | 100 | 100 | 60 |
watch | 100 | 100 | 60 |
What that means in practice:
- Reads took the hit. A user could fetch 3,000 full messages a minute under the old table (15,000 ÷ 5). Now it’s 300 (6,000 ÷ 20), ten times fewer. Backfilling a 10,000-message mailbox costs 200,000 units, about 33 minutes per user at the new rate, against under 4 minutes before.
- Batching doesn’t save quota. Google counts a batch of n requests as n requests, and caps a batch at 100 calls. It saves HTTP round trips, nothing else.
- For sending, the per-minute quota rarely binds first. 60 sends a minute would use up a personal account’s 500 for the day in about 8 minutes. The daily cap is the wall you’ll hit.
The errors you get at the limit
| Response | What ran out | What to do |
|---|---|---|
403 userRateLimitExceeded | The 6,000 units per user per minute | Back off and retry. Per-user limits can’t be increased |
403 rateLimitExceeded | The project’s per-minute quota | Back off, or request a quota increase in the Cloud console |
403 dailyLimitExceeded | A daily cap set on the project | Raise it in the Cloud project’s quota settings |
429 User-rate limit exceeded (Mail sending) | The account’s daily sending limit | Wait. Google says the error can last several hours |
429 Too many concurrent requests for user | Too many parallel calls for one mailbox | Fewer parallel requests or smaller batches |
Google recommends truncated exponential backoff: wait 1, 2, 4 seconds and so on, plus up to a second of random jitter, capped at 32 or 64 seconds. One more trap from its error docs: once a user passes the sending limit, the API can take several minutes to start returning 429s, so a 200 response doesn’t prove the email was sent.
Gmail sending limits through the API
The API doesn’t get an allowance of its own. Google’s wording: sending limits “are per-user and are shared by all of the user’s clients, whether API clients, built-in or web clients, or SMTP”. If a person uses the account and an agent sends from it too, they draw from the same 500 or 2,000. Mail sent from an alias or by a delegate counts against the same user as well.
Two details trip up automated senders:
- The window rolls. Workspace counts the last 24 hours, not a calendar day, so a burst at 4 p.m. is still counted at 3 p.m. tomorrow.
- More accounts isn’t a workaround. Google’s Workspace developer policy bars Gmail API apps that “use multiple accounts to abuse Google policies, bypass Gmail account limitations, circumvent filters and spam”. Spreading an agent across ten Gmail accounts to get 5,000 sends a day is the pattern it describes.
The full per-recipient breakdown is in Gmail sending limits, and the SMTP route (app passwords, ports 465 and 587) is in sending email from Python.
Gmail API pricing: what it actually costs
Calls are free. Three other things are not.
1. Usage above 80 million units a day (not billed yet)
Google’s quota page: “All standard use of the Gmail API is available at no additional cost.” Usage over the 80,000,000-unit daily threshold “is planned to incur charges to your Google Cloud billing account later in 2026”, with at least 90 days’ notice. As of October 2, 2026, no price is published. Google also says quota increase requests will require billing to be enabled. For scale, 80 million units is 800,000 sends or 4 million message reads a day per project, so a single agent won’t reach it. A product syncing thousands of customers’ mailboxes might.
2. The mailbox
A personal Gmail account is free but capped at 500 sends a day and, as covered below, risky to hand to software. A Google Workspace seat is $7 a user a month for Business Starter, $14 for Business Standard and $22 for Business Plus, each on an annual commitment. An agent that needs its own address needs its own seat, because an alias shares its user’s sending limits.
3. Verification and the security assessment
This is the cost most tutorials leave out, and it depends on the OAuth scope you request:
| Scope | Google’s class | Lets the app | Review required |
|---|---|---|---|
gmail.labels | Non-sensitive | Read and edit labels | Basic verification |
gmail.send | Sensitive | Send only | OAuth app verification, no security assessment |
gmail.readonly, gmail.metadata, gmail.compose, gmail.modify, gmail.insert, https://mail.google.com/ | Restricted | Read, watch, draft, modify | Restricted-scope verification, plus an annual security assessment if the data reaches your server |
Read that middle row carefully, because it’s often stated wrong: gmail.send is sensitive, not restricted. A send-only app goes through verification but no paid assessment. The catch comes the moment the app needs to see a reply. watch, history.list and messages.get all require a restricted scope, so any agent that holds a conversation is in the restricted tier.
What the restricted tier involves:
- A third-party assessment you pay for. Google uses the App Defense Alliance’s CASA framework. An authorized lab tests the app, and Google, not you, decides whether it needs assurance level AL1 or the more thorough AL2, based on user count, scopes and other signals. TAC Security, one of the authorized labs, lists AL1 assessments from $675 and AL2 at $5,400.
- Every year. Apps must be reassessed at least every 12 months, and Google can raise the required level as your user base grows.
- Weeks to months. Google says restricted-scope verification “can potentially take several weeks”. Its help center adds that verification “might require several months” depending on the data requested.
- Limits until you’re through. An unverified app shows users a warning screen and is capped at 100 new users. Leave it in Testing mode instead and refresh tokens expire after 7 days, so an unattended agent loses access every week.
- Rules on the data. Workspace’s developer policy forbids using Gmail data to train AI models “beyond that specific user’s personalized model”.
You can skip review if the app is only for you (or a few people you know personally), is marked Internal inside your own Workspace organization, or uses a service account that touches only its own data. That covers a personal script. It doesn’t cover a product that connects customers’ Gmail.
Why Gmail flags accounts run by AI agents
Google’s account rules don’t mention AI agents. They’re written about bots, and an agent on a Gmail account fits the description:
- Google Account Help: “Don’t use programs (called bots) to create fake accounts” and “Google automatically detects and disables accounts made for abuse.”
- Gmail Program Policies: “You are not allowed to automate the Gmail interface, whether to send, delete, or filter emails, in a manner that misleads or deceives users.”
- The Workspace developer policy’s ban on using multiple accounts to get around Gmail’s limits, quoted above.
What builders have reported this year:
- May 2026, n8n community forum. A builder created a fresh Gmail account just for automations. Google disabled it on May 10 with the notice that it “might have been created by a computer program or bot”, and scheduled it for deletion in April 2027. The poster said they hadn’t warmed the account up and had signed in from many locations. Every reply gave the same advice: don’t run automations on a new Gmail account.
- August 28, 2026, Cursor forum. People connecting personal Gmail to Grok Bot’s Gmail plugin got Google’s “This app is blocked” screen: “The app tried to access sensitive info in your Google Account.” An app update fixed it the next day. If your agent reaches Gmail through someone else’s OAuth app, its access depends on that app’s standing with Google.
A disabled account loses more than mail. Google’s help page is blunt: “your entire Google Account has been disabled”, and you “can’t sign in to Google services or use Sign in with Google.” Every service the agent signed up for with that address goes with it. Appeals exist, but for some violations Google reviews at most two.
To be fair to Gmail: an established account sending a few dozen expected messages a day through OAuth, for its own owner, is ordinary use. The risk climbs with new accounts, logins from servers in several places, many accounts run together, and mail to people who never wrote first. An agent running on a server usually checks several of them.
Give the agent its own inbox instead
The Gmail API is built to let an app act on a person’s mailbox. An agent that needs an address of its own is better served by an inbox made for software. That’s what CarlyEmail is: an email API that gives AI agents real inboxes that send, receive and reply.
| For an AI agent | Gmail API | CarlyEmail |
|---|---|---|
| A new mailbox | A Google account, or a Workspace seat at $7+ a month | One API call. The agent can sign itself up |
| Auth | OAuth consent, tokens to refresh | API key, scopable to one inbox or tenant |
| Before going live | Restricted-scope review and a paid annual assessment, to read mail | None. Until the owner confirms a 6-digit code, the account can only email its owner |
| Sending cap | 500 a day personal, 2,000 Workspace, shared with the human | 100 a day on free, no daily cap on paid plans |
| Reading mail | 20 units per message, 300 reads per user a minute | Received mail doesn’t count against the email quota |
| New-mail events | Pub/Sub topic, renew watch every 7 days, payload is a history ID | Signed webhook or WebSocket carrying the message text and thread_id |
| Replies | Build MIME, set In-Reply-To and References yourself | messages.reply lands inside the thread |
| At the limit | 403 or 429, and a 200 isn’t proof of delivery | 429 naming the cap, with a Retry-After set to the exact reset |
| Price | Free API, plus seats, plus the assessment | Free for 3 inboxes; $20 a month for 25; $200 a month for 250 |
Here’s the whole loop in TypeScript, npm install carlyemail:
import { CarlyEmail } from "carlyemail";
const carly = new CarlyEmail();
const inbox = await carly.inboxes.create({ username: "hello" });
const { messages } = await carly.messages.list(inbox.email);
await carly.messages.reply(inbox.email, messages[0].message_id, { text: "On it." });
No Cloud project, no consent screen, no Pub/Sub topic. Python works the same way (pip install carlyemail), and there’s a CLI and a hosted MCP server at https://api.carlyemail.com/mcp for agents that speak MCP. Or skip the code entirely: the box at the end of this section has the one-line prompt that lets an agent sign itself up.
What comes with it:
- Limits you can read in advance. Free is 3 inboxes, 1,000 emails a month and 100 a day, with a custom domain and no “sent via” footer. Startup is $20 a month for 25 inboxes and 10,000 emails, Business is $200 a month for 250 inboxes and 100,000 emails, and neither has a daily cap. Caps count sent recipients only, and the daily one resets at 00:00 UTC. The full limits page lists every number and the error code for each.
- Published review thresholds in place of a black box. CarlyEmail reviews an account at a 5% hard-bounce rate or 0.1% complaint rate, and the deliverability guide says so. SPF, DKIM and DMARC are set up for you, and bounced or complaining addresses are suppressed automatically.
- Inbound you can trust. Mail that fails SPF, DKIM or DMARC is kept and labelled
unauthenticatedrather than handed to yourmessage.receivedhandler. Mail is stored until you delete it. See the receiving guide. - One inbox per customer. Pods isolate tenants, and keys can be scoped so a
draft_createkey gets a 403 on send however the agent reasons. Gmail’s scopes have no draft-only option:gmail.composecovers drafting and sending together.
Be clear on scope. Keep the Gmail API when the job is your inbox: triaging it, drafting replies in your name. Google’s Gmail MCP server runs on the same quota system (get_thread costs 40, search_threads 10) and still has no send tool. If all you do is send receipts at volume, a transactional sender priced per message fits better; best email APIs compares them. When the agent needs an address of its own that holds a conversation, that’s CarlyEmail. More on the pattern in email APIs for AI agents and giving an agent its own identity.
FAQ
Is the Gmail API free?
Yes. Standard use costs nothing below 80,000,000 quota units per project per day. Google plans to bill usage above that threshold, with at least 90 days’ notice, and hasn’t published a price. The real costs are a Workspace seat per mailbox and, for apps that read mail on a server, an annual security assessment paid to a Google-authorized lab.
What is the Gmail API rate limit per user?
6,000 quota units per user per minute and 1,200,000 per project per minute, for Cloud projects created on or after May 1, 2026. Projects that used the API between November 2025 and April 2026 kept the previous 15,000 per user per minute. Per-user limits can’t be increased.
How many emails can I send per day with the Gmail API?
The same as the account can send any other way: 500 a day on personal Gmail and 2,000 per user a day on Google Workspace (500 on a trial), with at most 500 recipients per message. The API, the Gmail web app and SMTP all share one allowance.
How many quota units does messages.send use?
100, so one user can send at most 60 messages a minute before the per-user quota stops them. messages.get costs 20, threads.get 40, history.list 2 and watch 100.
Does a Gmail API app need a CASA security assessment?
Only if it requests a restricted scope (reading, modifying or drafting mail), the data passes through a server, and the app isn’t exempt as personal-use or internal-only. A send-only app on gmail.send needs OAuth verification but no assessment. Assessments are renewed every 12 months.
Can an AI agent have its own Gmail account?
Google’s rules prohibit creating accounts with bots, and builders report fresh accounts run by automations being disabled as possibly “created by a computer program or bot”. An agent that needs its own address is better off with an inbox built for software: CarlyEmail creates one in a single API call, and the agent can sign itself up.
Give your agent a real inbox
Your agent gets its own email address. People can email it, it answers in the same thread, and your personal inbox stays out of it. Start with 3 inboxes, no card needed.
Get startedSee the prompt
Read https://docs.carlyemail.com/llms.txt and set yourself up with an email address.


