# Got Your Back (GYB): a Gmail backup CLI that writes your mail to local disk

> GYB is a Python command line tool that pulls Gmail messages down to your own computer through Gmail's API, and the repository ships separate sample folders for Takeout, GYB-format, historic public mbox and Vault export mbox files. The install path is a one line shell script on Linux and macOS, an MSI on Windows, and the documentation lives in a wiki rather than the README.

**GAM-team/got-your-back** — Got Your Back (GYB) is a command line tool for backing up your Gmail messages to your computer using Gmail's API over HTTPS.

- Repository: https://github.com/GAM-team/got-your-back
- Website: https://github.com/GAM-team/got-your-back/wiki
- Stars: 3,128 · Forks: 248
- Language: Python
- License: Apache-2.0
- Published: 2026-09-24 · Updated: 2026-09-24 · Language: en
- Canonical page: https://hysenlabs.com/projects/gam-team-got-your-back

## What GYB backs up and who ends up running it

GYB stands for Got Your Back. The README describes it as "a command line tool for backing up your Gmail messages to your local computer", and it reaches Gmail through the Gmail API over HTTPS rather than through IMAP or POP. That choice matters: the API is the same surface Google exposes to its own clients, so labels, message identifiers and threading metadata travel with the messages instead of being flattened into a plain mbox on the way down.

The audience is narrow by design. There is no server component, no web interface and no scheduler in the repository listing. The top level holds gyb.py, a Windows batch file, an MSI definition (windows-gyb.wxs), an installer script (install-gyb.sh) and a requirements file. Someone who wants a mailbox copy on a machine they control, and who is comfortable running a Python program from a terminal, is the intended user. Someone who wants a hosted backup service is not.

## How GYB talks to Gmail: API credentials and the four sample formats

The dependency list in requirements.txt tells you most of the architecture. GYB builds on google-api-python-client, google-auth, google-auth-httplib2 and google-auth-oauthlib, with httplib2 as the transport. In practice that means an OAuth flow: the tool authenticates as a user, receives a token, and then issues Gmail API calls to enumerate and fetch messages. The repository also carries cacerts.pem and an openssl.props file, which indicates the tool manages its own certificate bundle for the HTTPS connection rather than relying purely on the system store.

The samples/ directory is the most informative part of the tree for judging scope. It contains four subfolders: google-takeout, gyb-format, historic-public-mbox and vault-export-mbox. Four import shapes are therefore anticipated, from Google's own Takeout export, through GYB's native format, to mbox files produced by Google Vault and by public archives. labellang.py and fmbox.py sit alongside gyb.py, which suggests label handling and mbox formatting are separate concerns in the codebase rather than being buried in one script.

What the README does not document is the restore direction. It points to the wiki for documentation and stops there. If your reason for backing up is recovery, the README alone will not tell you how to put the messages back.

## Installing GYB on Linux or macOS and taking a first backup

The README gives a single command for Linux and macOS. It downloads GYB, installs it and starts setup:

```bash
bash <(curl -s -S -L https://gyb-shortn.jaylee.us/gyb-install)
```

Running that script is where the OAuth setup happens, so you should expect a browser step or a credential prompt rather than a silent install. On Windows the README directs you to the MSI installer on the GitHub Releases page: install it, and the setup is triggered for you. There is no documented pip install, and requirements.txt is a dependency manifest for the tool's own environment, not a package specification you would install by name.

Once setup completes, the entry point is gyb.py. The README does not print a usage example, so treat the wiki as the source for command syntax and for the backup and restore subcommands. What the repository does give you is the format question: before a first run, decide which of the four sample layouts you are targeting, because the folder names under samples/ are the project's own statement of what it can read and write.

## Where GYB stops being the right answer

The most obvious limitation is that GYB is a run-it-yourself tool. Nothing in the repository listing suggests a daemon, a cron definition or a scheduled task. If you do not run it, no backup exists. A mailbox that changes daily needs a person or an external scheduler to invoke it on a cadence, and the README does not describe how to wire that up.

Storage is the second constraint, and it is easy to underestimate. A full Gmail account with years of attachments becomes a large local directory, and GYB writes to your computer, not to object storage. There is no documented deduplication or compression step in the README, and no incremental backup claim is made there either.

The third issue is the documentation split. The README is a quick start and a set of links. Anything beyond installation and the pointer to the wiki is undocumented in the repository root. Questions such as how a partial backup resumes, what happens when a token expires mid-run, or how to verify a completed backup are not answered by the README, and the README is silent on rollback entirely.

## GYB compared with Google Takeout

The natural alternative is Google Takeout, Google's own export service, and the repository acknowledges it by shipping a samples/google-takeout folder. The difference in approach is who drives the transfer. Takeout is a server side job: you request an export, Google assembles it, and you download an archive on Google's schedule. GYB is client side: your machine makes the API calls, and you control when the run starts and what it targets.

That distinction has practical consequences. A Takeout archive is a one time snapshot in Google's chosen layout, which is why GYB needs a dedicated importer for it. GYB's own format, by contrast, is designed to be written and read by the same tool, and the samples/gyb-format folder exists to describe it. If you already have Takeout archives and only want to read them, GYB's value is the import path, not the backup path. If you want repeated backups under your own scheduling, Takeout's request-and-wait model is the wrong shape for the job.

## Maintenance, releases and what Apache-2.0 means here

The repository is not archived, and the last push was on 2026-09-11, which is recent enough that the project is being touched. The release history shows v1.93, v1.94 and v1.95 all published within September 2025, so versioning is active rather than stalled. Note that the v1.94 release is labelled "GAM 1.94" in the release list while v1.93 and v1.95 are labelled GYB, which reflects the shared maintenance lineage between GYB and the GAM project.

Upgrade cost is low in the sense that the tool is a script plus Python dependencies, and the Linux and macOS installer re-runs the same way it first ran. It is higher in the sense that the pinned ranges in requirements.txt (google-api-python-client>=2.0, google-auth>=1.11.2, google-auth-oauthlib>=0.4.1, httplib2>=0.17.0) are lower bounds, not locks, so a fresh install can pull newer Google client libraries than a previous one did. If you keep a working environment, pin it yourself.

The licence is Apache-2.0, which permits commercial and private use and modification with the usual notice and attribution conditions. That is a statement about the repository's LICENSE file, not legal advice; if you redistribute GYB inside a product, read the licence text and the NOTICE requirements yourself.

## Conclusion

GYB fits an administrator or power user who already keeps a machine with enough free disk for a full mailbox and wants a local copy it can restore from. It is the wrong tool for someone who wants continuous, background protection with a web console, and for anyone unwilling to run a Python tool from a terminal. Before trusting it, verify two things in the repository itself: that the sample directories under samples/ match the format you intend to import, and that your own Gmail API credentials are accepted by the setup step. The wiki, not the README, is where the restore procedure is documented.

## FAQ

### What is Got Your Back (GYB)?

It is a command line tool for backing up Gmail messages to your local computer, using Gmail's API over HTTPS. It is written in Python and distributed through an installer script on Linux and macOS and an MSI on Windows.

### How do I install Got Your Back on Linux or macOS?

The README gives a single command: bash <(curl -s -S -L https://gyb-shortn.jaylee.us/gyb-install). The script downloads GYB, installs it and starts setup. On Windows, the README directs you to the MSI installer on the GitHub Releases page.

### Does Got Your Back document how to restore messages?

The README does not. It points to the GitHub Wiki for documentation, so the restore procedure has to be read there rather than in the repository root.

### What Python packages does Got Your Back depend on?

requirements.txt lists httplib2>=0.17.0, google-api-python-client>=2.0, google-auth>=1.11.2, google-auth-httplib2 and google-auth-oauthlib>=0.4.1. These are lower bounds, not pinned versions.

## Sources

- [GAM-team/got-your-back on GitHub](https://github.com/GAM-team/got-your-back)
- [License: Apache-2.0](https://github.com/GAM-team/got-your-back/blob/main/LICENSE)
- [Project website](https://github.com/GAM-team/got-your-back/wiki)
- [README](https://github.com/GAM-team/got-your-back/blob/main/README.md)
- [Releases](https://github.com/GAM-team/got-your-back/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/gam-team-got-your-back
