
Gmail API vs Microsoft Graph vs IMAP
When a tool connects to your inbox to read invoice emails, there are three common ways it can do that: the Gmail API, Microsoft Graph, or IMAP. They are not interchangeable, and the choice affects both security and reliability.
Gmail API
Google's REST API for Gmail. Uses OAuth 2.0 with specific scopes, including a read-only scope (gmail.readonly) that grants no send, delete, or write access. Supports push notifications through Google Cloud Pub/Sub, so a connected app can be notified of new mail almost immediately instead of checking repeatedly. Apps requesting these scopes for public use need to go through Google's OAuth verification process before general availability.
Microsoft Graph
Microsoft's unified API covering Outlook, Microsoft 365, and related services. Authenticates through an Azure AD app registration, also with OAuth 2.0 and scoped permissions. Supports delta queries and webhook-style subscriptions for near real-time updates, similar in spirit to Gmail's push notifications. Works for both Outlook.com personal accounts and Microsoft 365 business mailboxes.
IMAP
An older, universal email protocol supported by nearly every provider, not just Gmail and Outlook. Simpler to set up in some cases, sometimes using just a username and an app password instead of a full OAuth flow. The tradeoff: IMAP generally grants full mailbox access rather than fine-grained read-only scopes, and it is polling-based, meaning a connected app checks the inbox periodically instead of being notified instantly. Some organizations also restrict or disable IMAP access entirely for security reasons.
Which one actually matters for you
If an email automation tool only needs to read invoice attachments and nothing else, the access method it uses says a lot about how much trust you are extending. A tool using Gmail API or Microsoft Graph with a read-only scope can be technically limited to reading mail only, with no ability to send, delete, or modify anything, even if it wanted to. A tool relying on IMAP with full mailbox access does not have that same built-in limitation.
InboxDoc connects through the Gmail API and Microsoft Graph, using read-only scopes only. No send, write, or delete access, ever.