Sync Workspace contacts with CardDAV
Sync the Workspace contacts you are allowed to see with a CardDAV-capable contact app. Workspace remains the source of truth. Continue to edit contacts in Workspace; CardDAV provides a read-only view.
Prerequisites
You need permission to read people. Email addresses, phone numbers, postal addresses, company, and position appear only when you can also read the corresponding child resources. The Employees address book appears only with effective permission to read employee PII.
Create a CardDAV credential
- Open
Profile>Client credentials. - Enter a name for the device or app.
- Select the
CardDAVservice and the tenant. - Optionally set a future expiration time.
- Select
Create client credential. - Copy the username, secret, and discovery URL. Workspace displays the secret only once.
The discovery URL uses this format:
https://workspace.example.com/.well-known/carddavDo not use your normal Workspace password. You can copy the username and discovery URL again from your profile. If you lose the secret, rotate the client credential and enter the new value in the contact app. Expired and revoked credentials can no longer authenticate.
Set up Thunderbird
- Open Address Book and select
New Address Book>CardDAV Address Book. - Enter the technical username and the full discovery URL.
- Enter the one-time secret when prompted.
- Select the discovered address books and start synchronization.
Set up Android with DAVx⁵
- In DAVx⁵, select the sign-in option for URL and username.
- Enter the discovery URL, technical username, and secret.
- Enable the address books after discovery completes.
- Grant DAVx⁵ access to contacts and start synchronization.
Other CardDAV apps can use the same discovery URL. If an app asks for a server address, enter the complete URL including https://.
Address books and fields
Workspace provides two separate address books:
Workspace CRMcontains active external people you are allowed to see.Workspace Employeescontains active workforce people and remains completely hidden without permission to read employee PII.
Depending on your permissions, vCards contain names, titles, academic degrees, email addresses, phone, mobile and fax numbers, postal addresses, language, company, and position. Workspace does not export birthdays, photos, groups, internal tags, or notes.
Changes and revocation
Do not edit or delete contacts in the CardDAV app. Workspace rejects write attempts. Update the data in Workspace; the client receives changes during its next synchronization. Disabled, deleted, or no longer visible contacts disappear during the next full reconciliation.
Revoke a lost or unused credential under Profile > Client credentials. Revocation stops further server access but does not delete contacts that a client has already stored locally.
Troubleshooting
- Check that you selected
CardDAV, notCalDAV. - Use the technical username instead of your email address.
- Use only a discovery URL that starts with
https://. - Check in your profile that the credential is active and has not expired.
- Rotate the secret if authentication keeps failing.
- Ask an administrator to check people, child-resource, and employee-PII permissions when an address book or individual fields are missing.
- Start a full reconciliation if the client reports an invalid sync token.