{"_id":"@bold-tech-npm/graph-mcp","_rev":"7-0dc9d7026dbc6a9b9972005ac879a332","name":"@bold-tech-npm/graph-mcp","dist-tags":{"latest":"0.7.0"},"versions":{"0.1.0":{"name":"@bold-tech-npm/graph-mcp","version":"0.1.0","keywords":["mcp","model-context-protocol","microsoft-graph","outlook","m365","office365","email"],"author":{"name":"Bold Tech"},"license":"MIT","_id":"@bold-tech-npm/graph-mcp@0.1.0","maintainers":[{"name":"mitchel_smith","email":"mitchel@boldtech.dev"}],"bin":{"graph-mcp":"dist/cli.js"},"dist":{"shasum":"07511a09da52f6ce17ec40c4bc27666087967a5c","tarball":"https://registry.npmjs.org/@bold-tech-npm/graph-mcp/-/graph-mcp-0.1.0.tgz","fileCount":8,"integrity":"sha512-dCBTp5U2cwkS58oPOxobe4sSnr8CVDfV9zsMrqolyQnXw83fWYU7P0Lc28bXNZPP5erjOrV1NZOPBzrgfQ15Wg==","signatures":[{"sig":"MEUCIQD9diDJFsUwSIX2EKwemVcgRDIPRiEBoLaq/AuFOagvbwIgN3L2js0b6R+yExpv5D8o4Tt913x88MnAT+ZtouDUPgg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":13474},"type":"module","engines":{"node":">=20"},"scripts":{"build":"tsc","login":"node dist/cli.js login","prepublishOnly":"npm run build"},"_npmUser":{"name":"mitchel_smith","email":"mitchel@boldtech.dev"},"_npmVersion":"11.4.2","description":"Microsoft Graph MCP server with device-code auth and smart inbox reads (unread + date filter, thread collapse by conversation or normalized subject). By Bold Tech.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.23.8","@azure/msal-node":"^2.16.2","@modelcontextprotocol/sdk":"^1.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.3","@types/node":"^22.9.0"},"_npmOperationalInternal":{"tmp":"tmp/graph-mcp_0.1.0_1783985940777_0.2739503317349721","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@bold-tech-npm/graph-mcp","version":"0.2.0","keywords":["mcp","model-context-protocol","microsoft-graph","outlook","m365","office365","email"],"author":{"name":"Bold Tech"},"license":"MIT","_id":"@bold-tech-npm/graph-mcp@0.2.0","maintainers":[{"name":"mitchel_smith","email":"mitchel@boldtech.dev"}],"homepage":"https://github.com/Mitchel-BT/graph-mcp#readme","bugs":{"url":"https://github.com/Mitchel-BT/graph-mcp/issues"},"bin":{"graph-mcp":"dist/cli.js"},"dist":{"shasum":"26bd78f25beb2802d0f118f31ec5fbabd9e754ad","tarball":"https://registry.npmjs.org/@bold-tech-npm/graph-mcp/-/graph-mcp-0.2.0.tgz","fileCount":8,"integrity":"sha512-83nlD8b4pBIjdaO+A0xHAVztNZPcPuv7RSvexgFfxTPWkrOKPkVwOZpXGiEpNMpdxpOPu00bgaTJWjref+10Bg==","signatures":[{"sig":"MEYCIQDY/WU18s7ObCXVLug6wUICxLgNG97eNiv13p9g3r01WQIhAJdxr2e8E62TTBD0nyQmWPUtJkXzDUPeHRfuAJt6O1l/","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":20980},"type":"module","engines":{"node":">=20"},"gitHead":"c3dd19afae28ce7be37833319ab5637790abe789","scripts":{"build":"tsc","login":"node dist/cli.js login","prepublishOnly":"npm run build"},"_npmUser":{"name":"mitchel_smith","email":"mitchel@boldtech.dev"},"repository":{"url":"git+https://github.com/Mitchel-BT/graph-mcp.git","type":"git"},"_npmVersion":"11.4.2","description":"Microsoft Graph MCP server with device-code auth and smart inbox reads (unread + date filter, thread collapse by conversation or normalized subject). By Bold Tech.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.23.8","@azure/msal-node":"^2.16.2","@modelcontextprotocol/sdk":"^1.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.3","@types/node":"^22.9.0"},"_npmOperationalInternal":{"tmp":"tmp/graph-mcp_0.2.0_1783991049661_0.7685102309454144","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@bold-tech-npm/graph-mcp","version":"0.3.0","keywords":["mcp","model-context-protocol","microsoft-graph","outlook","m365","office365","email"],"author":{"name":"Bold Tech"},"license":"MIT","_id":"@bold-tech-npm/graph-mcp@0.3.0","maintainers":[{"name":"mitchel_smith","email":"mitchel@boldtech.dev"}],"homepage":"https://github.com/Mitchel-BT/graph-mcp#readme","bugs":{"url":"https://github.com/Mitchel-BT/graph-mcp/issues"},"bin":{"graph-mcp":"dist/cli.js"},"dist":{"shasum":"2a3d5cf7f84274f5706d3bc771b2861c4a446685","tarball":"https://registry.npmjs.org/@bold-tech-npm/graph-mcp/-/graph-mcp-0.3.0.tgz","fileCount":8,"integrity":"sha512-9RhpL1rhrYW72yvHQK2ELy49JdKZcm5Z7XFY/6gNwE68NTYETAgvKWAH0winJQVzhTVuHHQGCuEU+yMyB8l7Lg==","signatures":[{"sig":"MEQCIGnx/zppJZEZkQreuPYG/aRgDykmNhbcLoMFNQtKI+21AiB88PLYldrwG5iTY785rxSpmn66tGuqJ6tTYYtwvbREJA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":26182},"type":"module","engines":{"node":">=20"},"gitHead":"5737e630b8b559af117a04254c6a956068883c97","scripts":{"build":"tsc","login":"node dist/cli.js login","prepublishOnly":"npm run build"},"_npmUser":{"name":"mitchel_smith","email":"mitchel@boldtech.dev"},"repository":{"url":"git+https://github.com/Mitchel-BT/graph-mcp.git","type":"git"},"_npmVersion":"11.4.2","description":"Microsoft Graph MCP server with device-code auth and smart inbox reads (unread + date filter, thread collapse by conversation or normalized subject). By Bold Tech.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.23.8","@azure/msal-node":"^2.16.2","@modelcontextprotocol/sdk":"^1.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.3","@types/node":"^22.9.0"},"_npmOperationalInternal":{"tmp":"tmp/graph-mcp_0.3.0_1784078831563_0.2443265974853739","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@bold-tech-npm/graph-mcp","version":"0.4.0","keywords":["mcp","model-context-protocol","microsoft-graph","outlook","m365","office365","email"],"author":{"name":"Bold Tech"},"license":"MIT","_id":"@bold-tech-npm/graph-mcp@0.4.0","maintainers":[{"name":"mitchel_smith","email":"mitchel@boldtech.dev"}],"homepage":"https://github.com/Mitchel-BT/graph-mcp#readme","bugs":{"url":"https://github.com/Mitchel-BT/graph-mcp/issues"},"bin":{"graph-mcp":"dist/cli.js"},"dist":{"shasum":"8b8b6cd05861519acc15fba623841f89987d9bd8","tarball":"https://registry.npmjs.org/@bold-tech-npm/graph-mcp/-/graph-mcp-0.4.0.tgz","fileCount":8,"integrity":"sha512-V4tOOso81V/4iJSiOkWf/C7tEDVHARia+1wmz79Q9HEePn+6OVcS0lFi6ly2y2n9zxAPyAwYs/LsM+FHYgzq/g==","signatures":[{"sig":"MEQCIB/ZsXgnIAVANF3kf6nVxQGAb/o46w4lZXfrEMf1Ps+kAiAaWRSCguZjChvqS6rG6qcMYsH1Gt3sLfFjzzATsg1zfA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":32454},"type":"module","engines":{"node":">=20"},"gitHead":"ddf10bc6c784a42e94c280fb7042323ece7a80b9","scripts":{"build":"tsc","login":"node dist/cli.js login","prepublishOnly":"npm run build"},"_npmUser":{"name":"mitchel_smith","email":"mitchel@boldtech.dev"},"repository":{"url":"git+https://github.com/Mitchel-BT/graph-mcp.git","type":"git"},"_npmVersion":"11.4.2","description":"Microsoft Graph MCP server with device-code auth and smart inbox reads (unread + date filter, thread collapse by conversation or normalized subject). By Bold Tech.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.23.8","@azure/msal-node":"^2.16.2","@modelcontextprotocol/sdk":"^1.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.3","@types/node":"^22.9.0"},"_npmOperationalInternal":{"tmp":"tmp/graph-mcp_0.4.0_1784245895132_0.15915933722427122","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@bold-tech-npm/graph-mcp","version":"0.5.0","keywords":["mcp","model-context-protocol","microsoft-graph","outlook","m365","office365","email"],"author":{"name":"Bold Tech"},"license":"MIT","_id":"@bold-tech-npm/graph-mcp@0.5.0","maintainers":[{"name":"mitchel_smith","email":"mitchel@boldtech.dev"}],"homepage":"https://github.com/Mitchel-BT/graph-mcp#readme","bugs":{"url":"https://github.com/Mitchel-BT/graph-mcp/issues"},"bin":{"graph-mcp":"dist/cli.js"},"dist":{"shasum":"b9d4c99b527c8e08a70e16b36c177d81088d8f84","tarball":"https://registry.npmjs.org/@bold-tech-npm/graph-mcp/-/graph-mcp-0.5.0.tgz","fileCount":9,"integrity":"sha512-QHPuU1hxmtJOk0ohXwFcqvhDs9DRNL/1MUajv+7HC6utduJo007WzYMk1tKL/8+7pATug5BVRaqTJOFzgacfpg==","signatures":[{"sig":"MEUCIQCtuscOg66nsvVHSdI0z3fTtD1qHVU7yvM3wuAUu5fTrgIgSVAngufCDzADwrrTyj90yDmtziXGE6tqhlA5ZNNTw8M=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":36823},"type":"module","engines":{"node":">=20"},"gitHead":"ddf10bc6c784a42e94c280fb7042323ece7a80b9","scripts":{"build":"tsc","login":"node dist/cli.js login","prepublishOnly":"npm run build"},"_npmUser":{"name":"mitchel_smith","email":"mitchel@boldtech.dev"},"repository":{"url":"git+https://github.com/Mitchel-BT/graph-mcp.git","type":"git"},"_npmVersion":"11.4.2","description":"Microsoft Graph MCP server with device-code auth and smart inbox reads (unread + date filter, thread collapse by conversation or normalized subject). By Bold Tech.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.23.8","@azure/msal-node":"^2.16.2","@modelcontextprotocol/sdk":"^1.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.3","@types/node":"^22.9.0"},"_npmOperationalInternal":{"tmp":"tmp/graph-mcp_0.5.0_1784317114677_0.9913827731303362","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@bold-tech-npm/graph-mcp","version":"0.6.0","keywords":["mcp","model-context-protocol","microsoft-graph","outlook","m365","office365","email"],"author":{"name":"Bold Tech"},"license":"MIT","_id":"@bold-tech-npm/graph-mcp@0.6.0","maintainers":[{"name":"mitchel_smith","email":"mitchel@boldtech.dev"}],"homepage":"https://github.com/Mitchel-BT/graph-mcp#readme","bugs":{"url":"https://github.com/Mitchel-BT/graph-mcp/issues"},"bin":{"graph-mcp":"dist/cli.js"},"dist":{"shasum":"7a7fa9667fab6373bb9f43e13f0a128c1cdf3e6b","tarball":"https://registry.npmjs.org/@bold-tech-npm/graph-mcp/-/graph-mcp-0.6.0.tgz","fileCount":25,"integrity":"sha512-8y/y1QQyW0yTW5uwPikO5f99f8nqyd0JCLk3J3zgRyKoipcqr2/QB7nqLyADkEzLemjilzBkZYASvLNvKrOqZw==","signatures":[{"sig":"MEUCIQDuxv5zEqXESTGHM8PZqL3Bniws0h7D4vMrVPiP9hzqSQIgHiCd7tXNFclZk0PJuqDX9i8AnJpQ11bTZHmE43vIovQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":61859},"type":"module","engines":{"node":">=20"},"gitHead":"fd6b4f4601bde82cf1df2d8960a9dc8b2795f10e","scripts":{"build":"tsc","login":"node dist/cli.js login","prepublishOnly":"npm run build"},"_npmUser":{"name":"mitchel_smith","email":"mitchel@boldtech.dev"},"repository":{"url":"git+https://github.com/Mitchel-BT/graph-mcp.git","type":"git"},"_npmVersion":"11.4.2","description":"Microsoft Graph MCP server with device-code auth and smart inbox reads (unread + date filter, thread collapse by conversation or normalized subject). By Bold Tech.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.23.8","@azure/msal-node":"^2.16.2","@modelcontextprotocol/sdk":"^1.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.3","@types/node":"^22.9.0"},"_npmOperationalInternal":{"tmp":"tmp/graph-mcp_0.6.0_1784344719157_0.7846064839318003","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@bold-tech-npm/graph-mcp","version":"0.7.0","description":"Microsoft Graph MCP server with device-code auth and smart inbox reads (unread + date filter, thread collapse by conversation or normalized subject). By Bold Tech.","type":"module","bin":{"graph-mcp":"dist/cli.js"},"scripts":{"build":"tsc","prepublishOnly":"npm run build","login":"node dist/cli.js login"},"keywords":["mcp","model-context-protocol","microsoft-graph","outlook","m365","office365","email"],"license":"MIT","author":{"name":"Bold Tech"},"repository":{"type":"git","url":"git+https://github.com/Mitchel-BT/graph-mcp.git"},"homepage":"https://github.com/Mitchel-BT/graph-mcp#readme","bugs":{"url":"https://github.com/Mitchel-BT/graph-mcp/issues"},"publishConfig":{"access":"public"},"engines":{"node":">=20"},"dependencies":{"@azure/msal-node":"^2.16.2","@modelcontextprotocol/sdk":"^1.11.0","zod":"^3.23.8"},"devDependencies":{"@types/node":"^22.9.0","typescript":"^5.6.3"},"_id":"@bold-tech-npm/graph-mcp@0.7.0","gitHead":"84217f8aa2ae710f2e9e42c52b6a28d85b67a808","_nodeVersion":"22.23.1","_npmVersion":"11.4.2","dist":{"integrity":"sha512-joWviSvhf8SSrNM+Lvn9WjOtslXjp89cSMiKFaD80yGztIT4rwrWb2mybkZMDBkd/KOknOzRI7WOQVwCFt969A==","shasum":"7c48cfe7951ff9a8750dc43d53a4c928f0042392","tarball":"https://registry.npmjs.org/@bold-tech-npm/graph-mcp/-/graph-mcp-0.7.0.tgz","fileCount":25,"unpackedSize":68485,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDsJ7LfHkqNgkin8C+4VEDRgYQkP4YvTdbxtBv6XE7rqQIhAKt/XY47x6I6luok02npXfe/D5wRzza3VX86GaD+kN3H"}]},"_npmUser":{"name":"mitchel_smith","email":"mitchel@boldtech.dev"},"directories":{},"maintainers":[{"name":"mitchel_smith","email":"mitchel@boldtech.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/graph-mcp_0.7.0_1784583709697_0.40472059968497676"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-13T23:39:00.586Z","modified":"2026-07-20T21:41:49.973Z","0.1.0":"2026-07-13T23:39:00.897Z","0.2.0":"2026-07-14T01:04:09.805Z","0.3.0":"2026-07-15T01:27:11.692Z","0.4.0":"2026-07-16T23:51:35.275Z","0.5.0":"2026-07-17T19:38:34.820Z","0.6.0":"2026-07-18T03:18:39.347Z","0.7.0":"2026-07-20T21:41:49.825Z"},"bugs":{"url":"https://github.com/Mitchel-BT/graph-mcp/issues"},"author":{"name":"Bold Tech"},"license":"MIT","homepage":"https://github.com/Mitchel-BT/graph-mcp#readme","keywords":["mcp","model-context-protocol","microsoft-graph","outlook","m365","office365","email"],"repository":{"type":"git","url":"git+https://github.com/Mitchel-BT/graph-mcp.git"},"description":"Microsoft Graph MCP server with device-code auth and smart inbox reads (unread + date filter, thread collapse by conversation or normalized subject). By Bold Tech.","maintainers":[{"name":"mitchel_smith","email":"mitchel@boldtech.dev"}],"readme":"# @bold-tech-npm/graph-mcp\n\nA small [MCP](https://modelcontextprotocol.io) server that exposes **Microsoft Graph** (Outlook)\nto an AI client, with two things most Graph connectors get wrong:\n\n- **Device-code auth** — no client secret, no redirect URI. The signed-in user consents in a\n  browser; the server acts *as that user* (delegated, security-trimmed), so it only ever sees what\n  they're permitted to see.\n- **Smart inbox reads** — an overnight burst of long, multi-message threads is collapsed to **one\n  item per thread** (by `conversationId` *or* normalized subject), with unread and date-window\n  filters, so the model gets a clean list instead of a confusing pile.\n\nConfiguration is entirely via environment variables, so one published package serves many\ntenants/clients.\n\n## Configure\n\n| Env var | Required | Default | Notes |\n|---|---|---|---|\n| `GRAPH_CLIENT_ID` | ✅ | — | Entra app registration (public client, device-code enabled) |\n| `GRAPH_TENANT_ID` | ✅ | — | Tenant GUID for a single-tenant app, or `organizations` for a multi-tenant one (see below) |\n| `GRAPH_SCOPES` | | `User.Read,Mail.Read` | Add `Mail.ReadWrite` to enable draft tools |\n| `GRAPH_TOKEN_CACHE` | | `~/.bold-tech/graph-mcp/<tenant>/tokens.json` | Token cache |\n| `GRAPH_ACCOUNT` | | — | Pin which signed-in account to run as, by username. Only needed when several are cached |\n| `GRAPH_ACTIVE_ACCOUNT` | | next to the cache | Pointer file recording the account `connect` last signed in as |\n| `GRAPH_MEMORY_SITES` | ✅¹ | — | Fact-store site **per tenant**: `tenantId=siteRef;tenantId=siteRef` (see below) |\n| `GRAPH_MEMORY_SITE` | ¹ | — | Single fact-store site. Single-tenant installs only — superseded by `GRAPH_MEMORY_SITES` |\n| `GRAPH_MEMORY_FOLDER` | | `ESM Fact Store` | Document-library-relative folder the store lives in |\n\n¹ One of the two is required for the `memory_*` tools. Everything else works without them.\n\n### Multi-tenant: one app, many mailboxes\n\n`GRAPH_TENANT_ID` is interpolated straight into the authority, so:\n\n- **a tenant GUID** → single-tenant. Only that directory's users can sign in.\n- **`organizations`** → multi-tenant. Any work/school account can sign in, provided the app\n  registration is set to `AzureADMultipleOrgs` and the target tenant has consented. (`common` also\n  works but additionally allows personal Microsoft accounts — usually not what you want.)\n\n**Multi-tenant makes \"which mailbox am I?\" a real question**, because one cache directory now holds\naccounts from *different* tenants — a test mailbox and a customer's, say. Getting that wrong doesn't\nerror; it produces confident output built on the wrong inbox. So account selection is explicit, in\nthis order:\n\n1. `GRAPH_ACCOUNT`, if set — errors if that user isn't signed in.\n2. The account `connect` last signed in as (recorded in the pointer file).\n3. The only cached account, if there's exactly one.\n4. Otherwise **it refuses and lists the candidates** — it will not pick for you.\n\nTo switch accounts, call `connect` again and sign in as the other user; the pointer follows.\n\n> **Note:** the cache path contains `<tenant>`, so changing `GRAPH_TENANT_ID` (e.g. a GUID →\n> `organizations`) points at a different directory and everyone signs in once more.\n\n## The shared fact store\n\nThe `memory_*` tools persist facts to **one SharePoint folder**, so every user reads and writes the\nsame live copy — no stale per-machine files. It rides the same delegated session as mail, so there's\nno second login.\n\n### The site is per tenant, not per install\n\nA SharePoint site in tenant A is **unreachable with a token from tenant B**. Since this connector runs\nmulti-tenant, one install serves accounts from several tenants — so a single hardcoded site would work\nfor exactly one of them and hard-fail everyone else. `GRAPH_MEMORY_SITES` maps each tenant to its own\nsite, and the connector picks the one matching the signed-in account:\n\n```\nGRAPH_MEMORY_SITES=b699465f-…=contoso.sharepoint.com,<siteGuid>,<webGuid>;6cb2412c-…=fabrikam.sharepoint.com,<siteGuid>,<webGuid>\n```\n\nPairs are `;`-separated because a Graph site id is itself comma-separated. A site **URL**\n(`https://tenant.sharepoint.com/sites/Name`) works too, but `Sites.Selected` often can't resolve by\npath — prefer the id.\n\n**An unmapped tenant is an error, never a fallback.** Landing someone in another company's fact store\nsilently is worse than refusing, so the connector names the tenant and tells you what to add.\n\n### Onboarding a tenant\n\n1. Create (or pick) the SharePoint site that will hold the store.\n2. Admin-consent the app in that tenant, with `Sites.Selected` in `GRAPH_SCOPES`.\n3. Grant the app **`write` on that one site**: `POST /sites/{siteId}/permissions` — this is what keeps\n   the blast radius to a single site rather than all of SharePoint.\n4. Add `tenantId=siteId` to `GRAPH_MEMORY_SITES`.\n5. Verify with `memory_status` — it reports `signedInAs`, `tenantId`, and the resolved site, so you can\n   see *which* store you're on rather than assuming.\n\nThe folder self-seeds from the bundled `seed/` on first use, and only when it has no company files yet.\n\n## Sign in\n\n**Preferred — in-conversation (no terminal):** the AI client calls the **`connect`** tool, which\nreturns a verification URL + code; the user opens it, signs in, and **`auth_status`** confirms.\nNothing to run in a shell. This is the flow to use inside a plugin.\n\n**Alternative — CLI (for scripts/CI):**\n```bash\nGRAPH_CLIENT_ID=… GRAPH_TENANT_ID=… npx -y @bold-tech-npm/graph-mcp login\n```\n\nEither way, tokens cache per-tenant, so multiple clients coexist on one machine.\n\n## Use from an MCP client / plugin\n\n```json\n{\n  \"mcpServers\": {\n    \"graph\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@bold-tech-npm/graph-mcp\"],\n      \"env\": {\n        \"GRAPH_CLIENT_ID\": \"…\",\n        \"GRAPH_TENANT_ID\": \"…\",\n        \"GRAPH_SCOPES\": \"User.Read,Mail.ReadWrite\"\n      }\n    }\n  }\n}\n```\n\n## Tools\n\n| Tool | Scope | Description |\n|---|---|---|\n| `connect` | — | Start/confirm sign-in; returns a verification URL + code (or \"connected\") |\n| `auth_status` | — | Sign-in status: connected / pending (URL + code) / not_connected |\n| `whoami` | `User.Read` | The signed-in user (proves the auth chain) |\n| `inbox_list` | `Mail.Read` | Inbox messages with unread/date filters and thread collapse |\n| `create_draft` | `Mail.ReadWrite` | Create an email draft (never sends) |\n| `create_reply_draft` | `Mail.ReadWrite` | Reply-draft into an existing thread (never sends) |\n\nDraft tools require `Mail.ReadWrite` in `GRAPH_SCOPES`; with a read-only token they return a clear\npermission error rather than failing silently.\n","readmeFilename":"README.md"}