m365-mcp
Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. Skill: m365-mcp Owner: sam2kb Summary: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. Tags: latest:1.1.0 Version history: v1.1.0 | 2026-09-01T16:38:17.765Z | user Release v1.1.0 v1.0.8 | 2026-09-01T16:22:59.136Z | user Release v1.0.8 v1.0.7 | 2026-08-09T18:59:32.788Z |
Rank
62
Safety
84
Downloads
1.2k
Updated
Oct 11, 2026
Version
1.1.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.2K downloadsadoption · observed Oct 11, 2026
- Latest release
- 1.1.0release · observed Sep 1, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17as61t77jh1v77gg4anjx6458arpac:m365-mcp- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/snapshot"
Documentation
CLAWHUB
122,230 characters of source documentation, loaded on request.
Extracted files
3 files captured from the source.
SKILL.md
---
name: m365-mcp
description: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.
metadata:
openclaw:
homepage: https://github.com/sam2kb/m365-mcp#readme
requires:
bins:
- m365-mcp
- m365-mcp-auth
envVars:
- name: M365_ACCOUNT
required: false
description: Optional account name selected from the local account store.
- name: M365_TIMEZONE
required: false
description: Optional IANA timezone for calendar operations; defaults to UTC.
- name: M365_MCP_AUTH_DIR
required: false
description: Optional absolute path for the local OAuth account and token store.
- name: M365_MCP_READ_ONLY
required: false
description: Set true to request read-only scopes and disable all mutating tools.
install:
- kind: node
package: "@sam2kb/m365-mcp"
bins:
- m365-mcp
- m365-mcp-auth
---
# m365-mcp
Production-grade Microsoft 365 MCP server combining the best of office365-connector (delegated OAuth, multi-account) and mcp-microsoft365 (MCP protocol, full scope), with production-ready features: pagination, rate limiting, retry logic, and full TypeScript.
## Requirements
- Node.js 18+
- Azure Entra ID App Registration with delegated Microsoft Graph permissions
- Device code OAuth (no client-credentials, no tenant-wide access)
## Capabilities
### Email (9 tools)
- List, read, send, reply, search, move, delete, mark read/unread, list folders
### Calendar (9 tools)
- List events with organizer/response status, today view, week view, create (with Teams meeting), update, explicit organizer cancellation, attendee decline, free/busy
### Contacts (12 tools)
- Rich contact CRUD, exact category assignment and any/all filtering, category enumeration, folder-scoped contacts, contact-folder CRUD, and relevance-ranked People API recipient search across mailbox and optional directory sources. People results support fuzzy search, identity-type filters, relevance scores, and optional profile details. Private Outlook Contact Lists and their membership are not exposed by Microsoft Graph.
### OneDrive (5 tools)
- List files, search, read content, metadata, create folders
### Teams (3 tools)
- List chats, read messages, send messages
### Tasks (5 tools)
- List lists, list tasks, create, update, delete
### Users (3 tools)
- List org users, profile lookup, manager lookup
## Security and consent
- The server contacts only Microsoft's OAuth and Graph services:
`login.microsoftonline.com` and `graph.microsoft.com`.
- Device-code OAuth grants delegated access as the signed-in user. Read tools can
expose private mail, files, calendars, contacts, Teams chats, tasks, and user data.
- Send, reply, move, create, update, cancel, decline, and delete tools change real Microsoft_meta.json
{
"ownerId": "kn7demym2b9z68njkdr0vh1f2d8asbsx",
"slug": "m365-mcp",
"version": "1.1.0",
"publishedAt": 1788280697765
}skill-card.md
## Description: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. This skill is ready for commercial/non-commercial use. ## Publisher: [sam2kb](https://clawhub.ai/user/sam2kb) ### License/Terms of Use: MIT-0 ## Use Case: Developers and agent operators use this skill to connect an MCP-capable agent to Microsoft 365 data and actions through delegated OAuth. It supports email, calendar, contacts, OneDrive, Teams, tasks, and user lookup workflows. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The global npm executable is not pinned by the skill evidence, so installed behavior can change across releases. Mitigation: Install only from the trusted npm publisher and pin the package version in managed environments when reproducibility is required. Risk: Microsoft OAuth tokens are stored as plaintext in the local auth directory. Mitigation: Keep the auth directory out of synced or shared folders, restrict filesystem permissions, and revoke Microsoft app consent if the token store or device may be compromised. Risk: Granted permissions can expose or modify private Microsoft 365 mail, files, calendars, contacts, Teams chats, tasks, and user data. Mitigation: Prefer M365_MCP_READ_ONLY=true unless write actions are required, and require explicit user confirmation for send, delete, update, move, cancel, and create tools. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/sam2kb/skills/m365-mcp) - [Project README](https://github.com/sam2kb/m365-mcp#readme) ## Skill Output: **Output Type(s):** [Text, API calls, Configuration instructions] **Output Format:** [MCP tool responses and setup guidance] **Output Parameters:** [1D] **Other Properties Related to Output:** [May expose or modify Microsoft 365 data depending on granted OAuth scopes, environment configuration, and selected tools.] ## Skill Version(s): 1.1.0 (source: release evidence) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/sam2kb/skills/m365-mcp",
"sourceUrl": "https://clawhub.ai/sam2kb/skills/m365-mcp",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T02:26:53.929Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T02:26:53.929Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.2K downloads",
"href": "https://clawhub.ai/sam2kb/m365-mcp",
"sourceUrl": "https://clawhub.ai/sam2kb/m365-mcp",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T02:26:53.929Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.1.0",
"href": "https://clawhub.ai/sam2kb/m365-mcp",
"sourceUrl": "https://clawhub.ai/sam2kb/m365-mcp",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-01T16:38:17.765Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.1.0",
"description": "Release v1.1.0",
"href": "https://clawhub.ai/sam2kb/m365-mcp",
"sourceUrl": "https://clawhub.ai/sam2kb/m365-mcp",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-01T16:38:17.765Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
