Explicit routes, visible tradeoffs
Choose the route that matches your account.
Corresync never guesses capability from a logo. Discovery gathers credential-free evidence; you select mail and calendar routes before authentication begins.
Will it work with my address?
Check your address — without sending it anywhere.
Type the email address you want to connect. Your browser keeps the address to itself and asks our lookup service about only the domain—the part after the @.
Only the domain leaves your browser. Everything before the @ stays on
this page—it is never sent, stored, logged, or placed in the address bar. The lookup
service reads public DNS records, keeps nothing, and never starts a sign-in. Prefer to
skip it entirely? corr account discover you@example.com runs credential-free
discovery locally.
Microsoft routes
Use the browser you already trust—or opt into Graph.
Outlook Web is browser-owned. Microsoft Graph is a separate, explicitly configured public OAuth client and is never an automatic fallback.
Browser-owned
Outlook Web
- Read, compose, organize, and reviewed destructive actions
- Calendar
- Selectable calendars and provider-supported Teams join links
- Sign-in
- Dedicated visible browser profile
SSO, MFA, Conditional Access, and organization notices remain inside the browser.
Explicit OAuth
Microsoft Graph
- Read, compose, organize, and reviewed destructive actions
- Calendar
- Selectable calendars and typed Teams join-link creation
- Sign-in
- Your authorized public client; grant stored in the OS keyring
Graph is offered only as an explicit choice or for an authorization you already granted.
Apple iCloud
Set up iCloud Mail and Calendar in one guided flow.
corr setup recognises Apple’s documented address families and complete
verified service records for custom iCloud domains. It proposes Apple’s published
IMAP, SMTP, and CalDAV endpoints, then lets you review every identity and route before
adding the account.
Available now · guided preset
iCloud Mail + Calendar
- IMAP reads and organization, with SMTP composition and sending
- Calendar
- CalDAV calendar discovery, reads, and reviewed writes
- Sign-in
- Apple app-specific password entered directly into the OS credential store
Corresync passes only a fixed service name and reviewed handle to the system prompt; it never reads the password. The last-authenticated Mail and Calendar status is shown independently without reading message or event content.
Apple Account requirement
Two-factor authentication
Enable two-factor authentication, then create an app-specific password on Apple’s account page. The guided flow opens that page only when you explicitly choose it, after the reviewed local account has been added.
Check Apple’s official iCloud Mail settings and app-specific password guide. This preset has synthetic contract coverage and remains live-unobserved until an opt-in observation is recorded.
Google routes
Gmail, Calendar, and Tasks work with your own Google OAuth client.
Create a Desktop OAuth client in a Google Cloud project you control, then import its JSON during guided setup. Corresync-managed OAuth stays dormant; your own client opens the normal Google browser flow. The route is synthetic-contract covered and live-unobserved.
Available with setup · user-owned OAuth
Google API route
- Gmail API labels, search, selected reads, composition, send, and organization; move to Trash instead of permanent delete
- Calendar
- Selectable calendars and Google Meet when the calendar advertises it
- Tasks
- Date-only due dates, subtasks, ordering, source links, and safe polling
- Sign-in
- Your Desktop OAuth client; its credential and the account-scoped grant stay in separate OS-keyring entries
The normal browser owns OAuth. Gmail, Calendar, Meet, and Tasks use pinned Google APIs. See every Google Cloud screen and setup step.
Available now
Google Workspace MCP
- Provider
- Remote MCP servers operated by Google
- Status
- Google Developer Preview
- Setup
- Google Cloud and OAuth configuration are required
Follow Google’s official Workspace MCP setup guide.
Task routes
Connect the task service you already use.
Task routes are selected independently from mail and calendar. Their authorization, capabilities, cursors, and reviewed writes stay isolated per account.
Available now · explicit OAuth
Microsoft To Do
Task lists, typed create and update, complete and reopen, delete, recurrence, checklists, categories, and bounded Graph delta sync.
Uses a Microsoft Graph public client you are authorized to register and select.
Available now · explicit OAuth
Todoist
Task projects, typed writes and state, reminders, recurrence, subtasks, labels, assignment, exact date and time meanings, and bounded sync-token changes.
Uses your public OAuth client with PKCE; plan-dependent features remain visible.
Available now · explicit OAuth
TickTick
Projects and Inbox, search, create, update, complete, delete, recurrence, checklists, labels, one assignee, ordering, and bounded polling.
Uses your confidential OAuth client. Its secret stays in an approved credential store; reopen and reminder replacement are not claimed.
Open standards
Mix the services your provider actually exposes.
Standards routes use valid TLS and an OS-keyring entry or one explicitly approved absolute credential-helper reference.
JMAP
Mail reads, drafts, submission where advertised, moves, state changes, and reviewed deletion through typed RFC 8620 contracts.
A read-only account or missing Submission capability stays explicitly unavailable.
IMAP / SMTP
IMAP folders, reads, MIME, drafts, safe moves, and SMTP submission with a resolvable Sent-mailbox outcome.
Operations that need UIDPLUS or a Sent mailbox fail before unsafe emulation.
Calendar · Tasks
CalDAV
Separate VEVENT calendars and VTODO task lists, with bounded reads, recurrence, sync tokens, and reviewed conditional WebDAV/iCalendar writes.
Calendar scheduling and task capabilities are observed independently after sign-in.
One account, two routes
Mail and calendar do not have to come from the same protocol.
Pair IMAP/SMTP with CalDAV or configure a mail-only or calendar-only account today. The unified Google route uses your Desktop OAuth client. Stable account identity keeps profiles, credentials, cursors, previews, and audit context isolated.
$ corr account discover reader@example.invalid
evidence DNS · well-known · provider metadata
action none — discovery never authenticates
$ corr account add reader@example.invalid --help
choose one mail route and one calendar route
No hidden fallback
A missing capability stays missing.
See the plain-language feature tour for the actions agents can take and how partial provider support is shown.
- Provider limitations are returned as typed capabilities or degradations.
- Automatic discovery never starts Google OAuth; only explicit local login may open it.
- Graph authorization never starts from automatic discovery.
- Meeting links are requested only from the selected calendar route when it reports support.
- Unknown write outcomes require reconciliation and are never retried automatically.
Choose deliberately
Start with evidence, then authenticate.
Discovery reads no credentials and adds no account.