Developers

Everything in Mailocity and Zappocity has an API: the same ones the web apps use. The documentation below comes from the specs the server is tested against, so it is always current.

Mailocity

Zappocity

Standard protocols

JMAP

Mail, submission, contacts, calendars, Sieve, quotas, blobs, sharing and push (RFC 8620, 8621 and the rest) at /.well-known/jmap, over HTTP and WebSocket.

CalDAV and CardDAV

Calendars and contacts for Apple, Thunderbird, DAVx⁵ and others, at /.well-known/caldav and /.well-known/carddav.

IMAP and SMTP

IMAP4rev2 on 993 and SMTP submission on 587, with ManageSieve on 4190 for filters.

Signing in

The admin API takes a platform key or a team API key (Authorization: Bearer); team keys reach their own team only. Webmail and account endpoints use the browser session with an X-CSRF-Token header. Mail apps and scripts use the account's password, an app password, or a mailbox token (cs_mt_) for JMAP and sending.