Corresync never guesses capability from a logo. Discovery gathers credential-free
evidence; you select mail and calendar routes before authentication begins.
All routes below have synthetic provider-contract and application coverage. They remain
live-unobserved until an authorized record is tied to the exact commit, provider route,
and platform.
Use the browser you already trust—or opt into Graph.
Outlook Web is browser-owned. Microsoft Graph is a separate, explicitly configured
public OAuth client and is never an automatic fallback.
OW
Browser-owned
Outlook Web
Mail
Read, compose, organize, and reviewed destructive actions
Calendar
Selectable calendars and provider-supported Teams join links
Sign-in
Dedicated visible browser profile
SSO, MFA, Conditional Access, and organization notices remain inside the browser.
G
Explicit OAuth
Microsoft Graph
Mail
Read, compose, organize, and reviewed destructive actions
Calendar
Selectable calendars and typed Teams join-link creation
Sign-in
Your authorized public client; grant stored in the OS keyring
Graph is offered only as an explicit choice or for an authorization you already
granted.
Google routes
Corresync’s guided Google connection is not available yet.
The transport is built and tested with synthetic contracts while the project prepares
its official OAuth application for Google verification. For now, use Google’s official
Workspace MCP servers with your agent.
Standards routes use valid TLS and an OS-keyring entry or one explicitly approved
absolute credential-helper reference.
J
Mail
JMAP
Mail reads, drafts, submission where advertised, moves, state changes, and reviewed
deletion through typed RFC 8620 contracts.
A read-only account or missing Submission capability stays explicitly unavailable.
IM
Mail
IMAP / SMTP
IMAP folders, reads, MIME, drafts, safe moves, and SMTP submission with a resolvable
Sent-mailbox outcome.
Operations that need UIDPLUS or a Sent mailbox fail before unsafe emulation.
C
Calendar
CalDAV
Calendar discovery, bounded recurrence, create, update, and cancellation with
conditional WebDAV/iCalendar writes.
Attendee scheduling requires observed RFC 6638 support and schedule-tag protection.
One account, two routes
Mail and calendar do not have to come from the same protocol.
Pair IMAP/SMTP with CalDAV, use the unified Google route, or configure a mail-only or
calendar-only account. Stable account identity keeps profiles, credentials, cursors,
previews, and audit context isolated.
credential-free discovery
$ corr account discover reader@example.invalid
evidence DNS · well-known · provider metadataaction none — discovery never authenticates$ corr account add reader@example.invalid --help
choose one mail route and one calendar route
No hidden fallback
A missing capability stays missing.
See the plain-language feature tour for the actions agents
can take and how partial provider support is shown.
Provider limitations are returned as typed capabilities or degradations.
Google connects only through normal-browser OAuth and the current Google route.
Graph and Google authorization never start from automatic discovery.
Meeting links are requested only from the selected calendar route when it reports
support.
Unknown write outcomes require reconciliation and are never retried automatically.
Choose deliberately
Start with evidence, then authenticate.
Discovery reads no credentials and adds no account.