Explicit routes, visible tradeoffs

Choose the route that matches your account.

Corresync never guesses capability from a logo. Discovery gathers credential-free evidence; you select mail and calendar routes before authentication begins.

v0.8 evidence level: deterministic.

All routes below have synthetic provider-contract and application coverage. They remain live-unobserved until an authorized record is tied to the exact commit, provider route, and platform.

How evidence works

Microsoft routes

Use the browser you already trust—or opt into Graph.

Outlook Web is browser-owned. Microsoft Graph is a separate, explicitly configured public OAuth client and is never an automatic fallback.

Browser-owned

Outlook Web

Mail
Read, compose, organize, and reviewed destructive actions
Calendar
Selectable calendars and provider-supported Teams join links
Sign-in
Dedicated visible browser profile

SSO, MFA, Conditional Access, and organization notices remain inside the browser.

Explicit OAuth

Microsoft Graph

Mail
Read, compose, organize, and reviewed destructive actions
Calendar
Selectable calendars and typed Teams join-link creation
Sign-in
Your authorized public client; grant stored in the OS keyring

Graph is offered only as an explicit choice or for an authorization you already granted.

Google routes

Corresync’s guided Google connection is not available yet.

The transport is built and tested with synthetic contracts while the project prepares its official OAuth application for Google verification. For now, use Google’s official Workspace MCP servers with your agent.

Preparing verification

Corresync Google route

Mail
Gmail IMAP folders, search, composition, and organization; permanent delete remains disabled
Calendar
Selectable calendars and Google Meet when the calendar advertises it
Sign-in
Your authorized public client; grant stored in the OS keyring

When approval opens, the normal browser will own OAuth. Gmail uses encrypted IMAP/SMTP XOAUTH2; Calendar and Meet use the Calendar API.

Available now

Google Workspace MCP

Provider
Remote MCP servers operated by Google
Status
Google Developer Preview
Setup
Google Cloud and OAuth configuration are required

Follow Google’s official Workspace MCP setup guide.

Open standards

Mix the services your provider actually exposes.

Standards routes use valid TLS and an OS-keyring entry or one explicitly approved absolute credential-helper reference.

Mail

JMAP

Mail reads, drafts, submission where advertised, moves, state changes, and reviewed deletion through typed RFC 8620 contracts.

A read-only account or missing Submission capability stays explicitly unavailable.

Mail

IMAP / SMTP

IMAP folders, reads, MIME, drafts, safe moves, and SMTP submission with a resolvable Sent-mailbox outcome.

Operations that need UIDPLUS or a Sent mailbox fail before unsafe emulation.

Calendar

CalDAV

Calendar discovery, bounded recurrence, create, update, and cancellation with conditional WebDAV/iCalendar writes.

Attendee scheduling requires observed RFC 6638 support and schedule-tag protection.

One account, two routes

Mail and calendar do not have to come from the same protocol.

Pair IMAP/SMTP with CalDAV, use the unified Google route, or configure a mail-only or calendar-only account. Stable account identity keeps profiles, credentials, cursors, previews, and audit context isolated.

credential-free discovery
$ corr account discover reader@example.invalid
evidence  DNS · well-known · provider metadata
action    none — discovery never authenticates

$ corr account add reader@example.invalid --help
choose one mail route and one calendar route

No hidden fallback

A missing capability stays missing.

See the plain-language feature tour for the actions agents can take and how partial provider support is shown.

Choose deliberately

Start with evidence, then authenticate.

Discovery reads no credentials and adds no account.