Someone who looks after several mailboxes of their own can now keep them all signed in in one browser and move between them from the account menu, without signing out (multi-account spec, MA-B; forum topic 75). How it holds them. The session cookie is unchanged: it is the account in front, and every request is answered with it, so nothing else in the server changes. The others ride in a second cookie, <name>_more, as a list of their own session cookies. Each session stays its own -- sealed credential, expiry and "this is my device" -- and nothing about one is read through another. At most 5 in all, all on this mail server. - Add account (account menu): with sign-in on the mail server's page it goes there with prompt=login, so the server asks again rather than reuse the first sign-in; with the password form, a small dialog asks. Refused, and the front stays, when either account's organization has addAccounts off (inbuxa:SharingPolicy), the account is on another server, or 5 are open. The same account again just comes to the front. - Switching (POST /api/auth/accounts/<id>/front) swaps it into front; the web app clears what it cached for the previous account and reloads. A message being written blocks the switch. - Sign out ends only the account in front, and the next one comes forward; Sign out of all accounts ends every one. - GET /api/auth/accounts lists them, the front first, and says whether one more may be added. Not in this change: unread counts and notifications for the accounts not in front (MA-8), which the spec puts last. The mock can sign in a second user (MOCK_SECOND_USER/PASS) and answer addAccounts false (MOCK_NO_ADD_ACCOUNTS), for the new server tests: two accounts joining, switching, the same account twice, a switch to a session it doesn't hold, signing out of one and of all, and an organization that forbids it; and the OAuth start asking prompt=login. The client tests cover listing, switching (cache cleared, reload) and both sign-outs. Checked in Chrome against the mock: add, switch, sign out of one. New strings (9, English only in the other ten catalogs): "Add account", "Sign out of all accounts", "Add an account", "Both accounts stay signed in here; switch between them from this menu.", "Working…", "That account couldn't be added.", "You can't add more accounts here.", and the other-server and organization refusals. typecheck, tests (web 1538, server 276) and build pass.
INBUXA webmail
Note
Development happens on git.coffeylabs.org/inbuxa/inbuxa-webmail; the copy on GitHub is a read-only mirror. Report issues at git.coffeylabs.org/inbuxa/inbuxa-webmail/issues, and join discussions at community.coffeylabs.org.
This repository was called
ihasmail-inbuxauntil October 2026. Container images are now published asinbuxa/inbuxa-webmail; the oldinbuxa/ihasmail-inbuxaimage stops at2026.9.26-g654d298.
The webmail of the INBUXA suite: mail, calendars, contacts, files and filters in one app that works as well on a phone as on a desktop. It talks only JMAP to the INBUXA mail server, and keeps nothing of its own: everything durable, settings included, lives on the server, so the container is disposable.
What's in it
- Mail: conversations, labels, search operators, keyboard shortcuts, scheduled and undo send, invitations and RSVP, filters made from a message.
- Calendar: month, week, day and agenda views, recurrence, attendees and free-busy.
- Contacts: address books, groups, vCard import and export.
- Files: browse, upload, move, share.
- Signature checking: S/MIME signed mail verified as you read it.
- Settings that follow the account, stored on the mail server.
- On a phone: swipe to archive or delete, pull to refresh, hold to select.
- Administration: a dashboard, accounts, groups, mailing lists, roles, tenants and domains, each shown only to an account whose role allows it. Everything else is in INBUXA Admin.
- Sign-in on the mail server's own page, two-factor included. The webmail never handles a password to sign someone in, and holds only sealed tokens.
- Eleven interface languages and twelve themes.
Configuration
| Variable | Meaning |
|---|---|
MAIL_SERVER_URL |
How this webmail reaches the mail server. |
APP_SECRET |
A long random secret for sealing sessions. Required in production. |
OAUTH_CLIENT_SECRET |
Turns on sign-in through the server's page. The secret of the confidential client the server registers for this webmail: on the server, the same value as INBUXA_WEBMAIL_CLIENT_SECRET. |
OAUTH_CLIENT_ID |
The client's id. Default ihasmail-inbuxa, which is what the server registers. |
PUBLIC_URL |
Where browsers reach the webmail, without BASE_PATH. Required with OAUTH_CLIENT_SECRET. The redirect URI, PUBLIC_URL + BASE_PATH + /api/auth/callback, must match the server's INBUXA_WEBMAIL_URL + /api/auth/callback exactly. |
MAIL_SERVERS_FILE |
Optional: several mail servers, picked by the account's domain. See mail-servers.example.json. |
ADMIN_URL |
Optional: where INBUXA Admin is, for the dashboard's link. |
APP_NAME |
What the webmail calls itself. Default INBUXA, shown as the INBUXA wordmark; any other name shows as text. |
.env.example lists the rest.
On the mail server, set INBUXA_WEBMAIL_URL to the webmail's address (with
BASE_PATH, if any) and INBUXA_WEBMAIL_CLIENT_SECRET to the shared secret.
The server registers the client on start and allows the webmail's origin for
cross-origin requests.
With one mail server, the sign-in page asks for no address, only whether this is the person's own device. The server's page asks for the rest. With several, the address comes first, since its domain picks the server.
A password change revokes the server's tokens, so it signs the person out everywhere, this session included.
Quick start (Docker)
cp .env.example .env
# edit: MAIL_SERVER_URL, APP_SECRET, and for server sign-in OAUTH_CLIENT_SECRET and PUBLIC_URL
docker compose up --build -d
# → http://localhost:8080. Put a reverse proxy in front for TLS.
Source code
INBUXA webmail is a modified ihasmail, so the AGPL's offer is this fork: https://git.coffeylabs.org/inbuxa/inbuxa-webmail. The sign-in page and Settings › About link there, beside the version, which names the commit the running build came from.
Run your own patched build and that offer becomes yours, not ours: point
SOURCE_URL at your tree and both links follow it.
Development
npm install
npm run dev:mock # the built-in mock mail server ([email protected] / demo)
npm test
The mock also answers OAuth. Start it and the webmail with
OAUTH_CLIENT_SECRET=mock-oauth-secret and a PUBLIC_URL, and its sign-in
page approves the demo user at once.
Architecture, the mock's switches and how versions are numbered are in CONTRIBUTING.md.
Built on ihasmail
The INBUXA webmail is built on ihasmail,
Coffey Labs' own webmail, which stays an independent product. The public
repository is the remote ihasmail, fetch-only, and its main is merged in to
keep up. Nothing here is pushed there.
License
Copyright (C) 2026 Coffey Labs. AGPL-3.0-or-later; see LICENSE.
