Set-up guide

Connect a CalDAV calendar or CardDAV contacts, with one address.

Fastmail, iCloud, Nextcloud, StackMail, Zoho, or a server of your own. If it publishes a CalDAV or CardDAV address, a mailbox that signs in with a password can have its diary and its address book connected to Claude, ChatGPT or any MCP client. This page has the addresses, the one password trap that costs people an afternoon, and what is never stored.

  • Time About 2 minutes each
  • You will need Address and password
  • Contacts stored here None, ever

The short version

Connect the mailbox first, then open its Connection tab in the control panel and paste the CalDAV address into the calendar card and the CardDAV address into the address book card, with an app password where the provider wants one. Each server is opened before anything is saved; a refusal stores nothing and says which of the address and the password was the problem. The tools then appear on the connector already in your AI client.

Before you start

What you need: a password mailbox, an address and an app password

A calendar and an address book are separate services from the mail, with credentials of their own, so connecting the mailbox connects neither. This is the second step, and the shorter one.

  • A mailbox that signs in with a password Gmail by app password, or any IMAP host
  • The address of the calendar or contacts server from your provider, or below
  • An app password for that server on the hosted providers that want one
  • A second account with us nothing
  • A second connector in your AI client nothing
  • Anything installed nothing

The route on this page is for a mailbox that signs in with a password: Gmail by app password, or any IMAP host. A Microsoft 365 mailbox gets its calendar on the same sign-in as its mail and cannot take an address book yet. A Google diary takes a Google sign-in of its own, on any mailbox, from the Gmail page. Everything else, which is most of the market, connects here.

Where to look

Find your CalDAV and CardDAV address: Fastmail, iCloud, Nextcloud, StackMail, Zoho

Most searches for how to connect CalDAV calendar or CardDAV contacts servers to an AI end on a page of addresses; the addresses are here, and so is the reason they get refused. It is the server on its own, filed under calendar sharing, CalDAV or CardDAV in your provider's settings, not the webmail address. These are the addresses for the 5 hosts most people will need, read off the provider's own page where one exists, and each hosted bare host opened from this product without a credential to confirm it answers as a working server does; the sources say which is which. Some hosts publish the address as a path rather than a bare host, with your own mailbox address in it in place of the example one; the table says which.

Provider Calendar (CalDAV) Address book (CardDAV) Password it wants
Fastmail https://caldav.fastmail.com/ https://carddav.fastmail.com/ App password
iCloud https://caldav.icloud.com/ https://contacts.icloud.com/ App-specific password
Nextcloud https://your-server/remote.php/dav/ https://your-server/remote.php/dav/ Account or app password
StackMail https://calendar.stackmail.com/calendars/you@example.com/default/ https://calendar.stackmail.com/addressbooks/you@example.com/default/ Mailbox password, on premium
Zoho https://calendar.zoho.com/ https://contacts.zoho.com/ Account or app password

Which password each one wants

  • Fastmail. An app password, made under Settings, Privacy & Security, with the Calendars and Contacts scopes ticked. The account password is refused.
  • iCloud. An app-specific password, made at account.apple.com under Sign-In and Security, which Apple issues only on an account with two-factor authentication on (the default on most Apple Accounts). The username is the full Apple Account email address.
  • Nextcloud. Your Nextcloud password, or an app password made under Settings, Security, which a server with two-factor authentication on requires.
  • StackMail. The mailbox password, once the mailbox is upgraded to premium in the hosting control panel; a standard mailbox refuses the correct address with a 401.
  • Zoho. Your Zoho password, or an application-specific password where two-factor authentication is on. The host differs by data centre: .eu, .in, .com.au and others.

A self-hosted server: Nextcloud, Baikal, Radicale

A Nextcloud server publishes both under https://your-server/remote.php/dav/; the form its manual gives a phone is that path with principals/users/<username>/ on the end. Baikal and Radicale publish one address for both protocols too, and any server that follows RFC 6764 can be given its bare host: we ask for /.well-known/caldav or /.well-known/carddav and follow the redirect.

If your host is not on the list

Search the provider's help for its name and "CalDAV" or "CardDAV", or copy the address out of an app that already syncs with it. With a web host or a domain registrar it is very often the mail hostname with the word calendar in front of it, and a guess costs you seconds.

The trap

The app password trap: a 401 is the account password working as designed

Most people's first go: copy the CalDAV address off the provider's help page, paste it in with the password you sign in to webmail with, and get a 401. Check the address, try the password again, and 20 minutes later conclude the thing is broken. Nothing is broken. Fastmail and iCloud refuse the account password on purpose and want an app password instead, and Zoho does the same once two-factor authentication is on; a 401 from one of them is that rule working as the provider designed it.

We measured it rather than read about it. On 2 September 2026 a probe of https://caldav.fastmail.com/ with the account password answered 401, and about a minute later Fastmail emailed the account to say a third-party calendar app had just tried to sign in and failed because the regular password does not work with third-party apps. Fastmail's own server-names page says the same: you cannot use your regular password. iCloud's app-specific password is the same rule, and Apple issues one only on an account with two-factor authentication on, the default on most Apple Accounts in Apple's words. The address was never the problem.

What a CalDAV app password is, and where it comes from

An app password is a second password the provider issues for one app, made in the account's security settings and revocable there without touching the password you sign in with; where each host keeps the setting is in the list under the address table, and on Fastmail tick the Calendars and Contacts scopes. It is the kind of password you will already have made to connect a Gmail mailbox, without Google's habit of hiding the setting: the hosted providers here that want one all offer it.

401 and 403 are 2 different answers

The connect form tells you which of the address and the password was refused, and the 2 codes behind that sentence want 2 different fixes. 401 means the credential was refused: make an app password, or check that you used it rather than the account one. 403 means the credential worked and was not allowed in: the app password was made without the calendar or contacts scope, so make another with the scope ticked. The same sentence reaches you later, too: a credential the server stops accepting after it was stored marks the card, emails you once, and opens the sign-in details for the new one. A few hosts only switch CalDAV and CardDAV on for a paid mailbox tier, and answer 401 on the correct address until then, which looks exactly like a wrong password.

Why Gmail is not on this page

Google's calendar and contacts endpoints take OAuth 2.0 and nothing else; Google's own CardDAV documentation says so in one sentence: it does not support any other authentication method. So a Gmail app password, which opens the mail over IMAP, is refused on Google Calendar and Google Contacts, which is why a Google diary has a route of its own and Google contacts are not reached at all. A Gmail mailbox can still take a CardDAV address book at another host.

An app password for a CalDAV or CardDAV server: the robot holding a key out on an open palm, a closed mailbox behind him with its cable unplugged and coiled on the ground.
A second key, made for one app, and revoked on its own

The diary

The CalDAV calendar: one address, and the tools your server answers for

IMAP is a mail protocol with no diary inside it. What most hosts run beside the mail server is a calendar server speaking CalDAV, defined by RFC 4791 in 2007 as a store of iCalendar entries, with an address of its own, and giving us that address is the whole job. No second account, no second connector, nothing extra to pay.

What you get is decided by asking the server rather than by us. CalDAV is 2 specifications 5 years apart, the store and the scheduling RFC 6638 added in 2012, and a server with only the first will accept a meeting with people invited, answer that it worked, and tell nobody. So at the moment the calendar connects we ask what it implements and hand your assistant only the tools it answered for: a store-only calendar gets reading, searching and your own time, and one that implements scheduling gets the meeting tools as well. The calendar card shows the list your server gave, and Check it now asks again.

CalDAV is the route for a diary on any host but Google and Microsoft. Against Google's route it needs an address and an app password rather than a sign-in; against Microsoft 365 its tool list is measured rather than complete, since the structured counter-proposal, the ranked meeting suggestions and the out-of-office are Microsoft's alone. Which of the 3 calendar routes is yours and what an assistant can be trusted with once a diary is connected are each a guide of their own.

A CalDAV calendar connected beside a mailbox: the robot pointing at one of 3 days blocked out in blue on an open desk calendar, a reminder bell on the page, a mailbox on its post behind him.
The diary as well as the post, by the address of the server that holds it

The contacts

The CardDAV address book: looked up where it lives, never copied

The same servers usually hold an address book too, speaking CardDAV, the sister protocol RFC 6352 defined in 2011 for contacts in vCard form. The address book card sits beside the calendar card and takes the same one field. On Fastmail and iCloud one app password covers mail, calendar and contacts, so the sign-in details can usually be left alone (on iCloud the username is the full Apple Account address, so open them where that is not the mailbox address).

Until a book is connected, your assistant resolves a person's address from the mailbox's own history, ranking somebody you have written to above somebody who merely wrote to you. That stays. What the address book adds is the people you put there yourself, with every address, the phone numbers, the employer and the job title on the card, ranked above anything the mail turned up. Ask what Bob's number is and the answer comes off his card.

The address book this connects to is the CardDAV one, the list a phone or a desktop client syncs to. Some webmail programs keep their own contacts list inside webmail, separate from it, and that list is not read; if yours does, export it as a vCard file and import it through a CardDAV client, and the assistant still finds people from your mail history either way.

Nothing about a contact is written down here. A card is fetched from your own server to answer the question asked, held in memory for about 10 minutes so the next question about the same person is quick, and forgotten. Thunderbird keeps a copy of a CardDAV book on the device, the right design for an offline client; at least one mainstream AI mail client states in its privacy policy that it syncs a copy of your Google Contacts to its servers. This is neither. It is the relationship a mail client's address lookup has with a company directory, and nobody thinks the directory has been copied.

Connecting a CardDAV address book and a CalDAV calendar to an AI assistant: the robot holding up a contact card and a calendar page, a glowing cable running from each of them and from the mailbox beside him into one screen.
The address book and the calendar, plugged into the same screen as the post

Walkthrough

Connect the calendar and the address book, step by step

2 cards on one tab, and the same 3 things for each: an address, a password, and a button.

  1. Find the CalDAV or CardDAV address your provider publishes

    Take it from the table above, from the provider's help pages under CalDAV or CardDAV, or from a calendar or contacts app that already syncs with the account. It starts with https://.

  2. Make an app password with the calendar and contacts scopes

    In the provider's security settings, make an app password and tick the calendar and contacts scopes where it offers them (an app-specific password, on iCloud). A host whose row in the table says the mailbox password takes that instead.

  3. Paste the calendar address into the calendar card

    In the control panel open the mailbox, then its Connection tab, and paste the CalDAV address into the calendar card. If the calendar signs in with different details from the mailbox, open My calendar signs in with different details from the mailbox and enter them there. Choose Connect the calendar, and the card lists the tools that server supports.

  4. Paste the address book address into the address book card

    Same tab, the card beside it. Paste the CardDAV address, open the sign-in details only if the book uses its own, and choose Connect the address book. The card then says how many address books it found and whether they can be written to.

  5. Check both from your AI client

    Ask your assistant what is in the diary on Thursday, then for the phone number of somebody who is in your address book and not in your mail. The second answer comes off a card, and says which book.

The calendar card on the Connection tab of the Mailbox MCP control panel, connected: a green note reading Connected to a CalDAV calendar on calendar.stackmail.com, signed in with the mailbox password; the server address in a copy field, a StackMail path with the mailbox address in it; a Change the calendar address disclosure; and a Disconnect this calendar button with a line saying the mailbox, its settings and its mail are untouched.
The calendar card, connected to a calendar given as a path, with the mailbox password. Check it now asks the server what it supports.
The address book card beside it, connected: a green note reading Connected to a CardDAV address book on carddav.example.net, signed in with the mailbox password, the assistant can look people up in it and open a card, a card is held in memory for a few minutes and then forgotten, and nothing about a contact is written down anywhere; the server address in a copy field; a Change the server address disclosure; and a Disconnect this address book button.
The address book card, connected at a bare host. Disconnecting it removes the contact tools and touches nothing in the book.

Afterwards

What your assistant can then do with the calendar and the address book

With the calendar

Read the week and search it by subject, location or organiser. Open one event with everybody invited and how each answered. Ask when a group of people are free and get back busy blocks rather than their diaries. Book your own time, move it, repeat it weekly. Where the server implements scheduling, invite people to a meeting, reschedule or cancel it and tell everybody, and answer an invitation. A recurring meeting appears on every date it falls on, the way it does in Outlook.

With the address book

Find a person by name, nickname, part of an address or employer, and get back the address to write to, the phone numbers, the employer and the job title, ranked above whatever the mail turned up. Open one card in full with read_contact: every name, every email address and phone number with its type, the note, and which book it is in. Then write to that address, or put that person in a meeting, in the same conversation.

The book does not replace the mailbox's own evidence; it sits above it. Both sources are read on every lookup, and the answer says which is which.

Where the person is found Rank What comes back
In your CardDAV address book First, where a book is connected Every address, the phone numbers, the employer, the job title, and a reference that opens the card
An address you have sent to Next The address, how often you have written to it, and when it was last seen
An address that only ever wrote to you Last The address and when it was last seen, marked as not yet confirmed

What each tool does is on the tool reference, and how a calendar connects is on the how-it-works page.

The free tier is 5 calls a day on any mailbox, enough to connect both and ask what is on Thursday and what Bob's number is.

Limits

What is never stored, and what this connection does not do yet

The address of each server and a credential for it are the whole of what is stored; everything else here is never written down or not built yet.

  • Contacts are looked up, never copied

    Your address book stays where it is. Once one is connected, which is its own step, a person is looked up in it when you ask, held in memory for about 10 minutes, and forgotten: nothing about a contact is written to a database, a file or a log of ours. Until a book is connected, addresses are resolved from the mailbox's own history. There is no file store either: an attachment is read and sent on the message it belongs to rather than kept anywhere as a document of its own.

  • The address and a credential, and nothing else

    A calendar's or an address book's address and, where you gave one, a username and password for it, encrypted as every credential is. Disconnecting either deletes its credential that minute, and revoking the app password at your provider ends access the same way. The privacy policy and the security page list it beside everything else held.

  • Photos are never read

    A card comes back as names, addresses, phone numbers, employer, job title and note. The photograph is not requested, is discarded if a server sends it anyway, and the answer says so.

  • Nothing is written to the book yet

    Adding, correcting and deleting a contact are a later release, each written to your own contacts server so the change shows up in your phone and your mail client. Today a card is changed in your own contacts app.

  • Password mailboxes only, for now

    A Microsoft 365 mailbox cannot take an address book yet: its contacts arrive with the Microsoft sign-in in a later release, and until then its assistant resolves a person's address from the mailbox's own history. Google contacts are not reached on any mailbox, and no Google permission for them is asked for.

  • One server address each

    A mailbox holds one calendar address and one address book address, and every calendar or book that server exposes under it is read. A second server needs a second mailbox.

FAQ

Questions people ask about CalDAV and CardDAV

Does connecting a CardDAV address book copy my contacts to your servers?

No. The address book stays on your own contacts server; what we store is its address and a credential for it, encrypted as every credential is. When you ask your assistant to find somebody, our server asks your contacts server that one question, keeps the answer in memory for about 10 minutes so the next question about the same person is quick, and then forgets it. Nothing about a contact is written to a database, a file or a log of ours, and disconnecting the book deletes the credential and leaves the book untouched.

Why does my CalDAV or CardDAV server answer 401 when the password is right?

Because the account password is the wrong kind of password, and the 401 is the server working as designed. Fastmail and iCloud refuse the password you sign in to webmail with outright, and Zoho does once two-factor authentication is on; each wants an app password made in the account's security settings instead. Nothing is wrong with the address. Make an app password with the calendar and contacts scopes and paste it into the sign-in details on the connect form. A few hosts add a second cause of the same 401: they switch CalDAV and CardDAV on only for a paid mailbox tier, and until then the correct address is refused with the correct password too. A 403 means the app password worked but lacks the calendar or contacts scope.

Is the contacts list in my webmail the address book?

Not necessarily. The address book this connects to is the CardDAV one, the list a phone or a desktop client syncs to, at the address in the table. Some webmail programs keep their own contacts list inside webmail, separate from it, and that list is not read, so a name you only ever added in webmail is not in the book. If yours does, export the list as a vCard file and import it through a CardDAV client, such as the phone that syncs with the book, and it appears to your assistant from then on. The assistant still finds people from your mail history either way, ranking somebody you have written to above somebody who only wrote to you.

Does iCloud need an app-specific password for CalDAV and CardDAV?

Yes. Apple's own instructions say that a third-party app that wants your iCloud calendar or contacts signs in with an app-specific password, made at account.apple.com under Sign-In and Security, never with your Apple Account password, and Apple issues one only on an account with two-factor authentication on, its default for most accounts. The username is your full Apple Account email address, and one app-specific password covers the calendar at https://caldav.icloud.com/ and the address book at https://contacts.icloud.com/.

Can I connect my Gmail calendar or Google contacts this way?

Not over CalDAV or CardDAV: Google's own documentation says it supports no authentication method other than OAuth 2.0 on those endpoints, so a Gmail app password is refused there. A Google Calendar connects on its own route, a Google sign-in from the Gmail connect page, on any mailbox. Google contacts are not reached at all, and no permission for them is asked for. A Gmail mailbox can connect a CardDAV address book at another host, as any mailbox that signs in with a password can.

What tools appear once a calendar or an address book is connected?

For the calendar, whatever that server turned out to support: the list is measured when it connects and shown on the calendar card. For the address book it is one tool, read_contact, which opens one card in full, and a change to one that was already there: find_contact reads the book beside the mailbox's own history on every call and ranks a person from the book first. Both appear on the connector already in your AI client.

Can the assistant add, correct or delete a contact?

Not yet. Today the address book is read: a person is looked up and a card is opened, and nothing is written to the book. Adding, correcting and deleting a card are a later release, each written to your own contacts server so the change appears in your phone and your mail client as if you had typed it there. Until then, ask your assistant for the address or the number and make the change in your own contacts app.

Are contact photos read?

Never. A card comes back with the names, every email address and phone number with its type, the employer, the job title and the note, and the answer says in so many words that photos are not read; a photograph a server sends anyway is discarded. The data processing agreement states the same list of fields, with the photograph named as the one thing never requested.

Attribution

Sources

StackMail publishes no page about its CalDAV and CardDAV addresses. Both were opened from this product with a real credential, the calendar on 2 September 2026 and the address book on 16 September 2026; the premium tier and the path are the owner's own mailbox, settled the day after the first opening, rather than a document. So is the webmail contacts list the book does not hold: on 16 September 2026 that mailbox's webmail contacts page was read beside its CardDAV book, 1 entry against 0 cards, before and after the entries were edited in webmail.

Connect the calendar and the address book.

The free tier is 5 calls a day on any mailbox, and disconnecting a calendar or an address book deletes its credential and leaves your diary and your contacts exactly as they were.