In OAuth/OIDC-only mode the webmail never sets the basic-auth session cookie (sessionCookieName(0)); the login stores auth in the jmap_stalwart_ctx cookie via /api/auth/stalwart-context. The route was 401-ing for every real user.