{"_id":"@mindstone/mcp-server-microsoft-files","_rev":"5-ada2acfa7a1cc0ce249f8e3a8aa369bb","name":"@mindstone/mcp-server-microsoft-files","dist-tags":{"latest":"0.2.1"},"versions":{"0.1.0":{"name":"@mindstone/mcp-server-microsoft-files","version":"0.1.0","license":"FSL-1.1-MIT","_id":"@mindstone/mcp-server-microsoft-files@0.1.0","maintainers":[{"name":"mindstone-engineering","email":"engineering@mindstone.com"}],"homepage":"https://github.com/mindstone/mcp-servers/tree/main/connectors/microsoft-files","bugs":{"url":"https://github.com/mindstone/mcp-servers/issues"},"bin":{"mcp-server-microsoft-files":"dist/index.js"},"dist":{"shasum":"fbb8bae02f1c6b58d68df237493ab13d12882317","tarball":"https://registry.npmjs.org/@mindstone/mcp-server-microsoft-files/-/mcp-server-microsoft-files-0.1.0.tgz","fileCount":33,"integrity":"sha512-pqAui1BCJJoaa+cUnfMQMYCDB0V7PJFDpCANq837V7G6kOgrMnEyoW9Y1z1L8b5yrbCuT7WlLIXMwYoUL+3gfw==","signatures":[{"sig":"MEUCIDMcxmkLtJS5bW0pTXzt3/KAB66K52GYpARZWZTNaLcZAiEA5OfKOvWsBDSb8/Rigoqofuqqr83gVIN8U+jjAUbh8+U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":99659},"type":"module","engines":{"node":">=20"},"gitHead":"a49de3e19e784f88bea43a06bcfb82e3c2386aa5","mcpName":"io.github.mindstone/mcp-server-microsoft-files","scripts":{"test":"vitest run","build":"shx rm -rf dist && tsc && shx chmod +x dist/index.js && npm run security:internal-refs","start":"node dist/index.js","watch":"tsc --watch","prepare":"npm run build","test:watch":"vitest","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build && npm test","security:internal-refs":"node scripts/check-internal-refs.mjs"},"_npmUser":{"name":"mindstone-engineering","email":"engineering@mindstone.com"},"repository":{"url":"git+https://github.com/mindstone/mcp-servers.git","type":"git","directory":"connectors/microsoft-files"},"_npmVersion":"11.11.1","description":"Microsoft 365 OneDrive Files MCP server — list, search, get, download, upload, delete, move, copy, and share files via Microsoft Graph","directories":{},"_nodeVersion":"25.8.2","dependencies":{"zod":"^3.23.0","@modelcontextprotocol/sdk":"^1.26.0","@mindstone/mcp-server-microsoft-shared":"^0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"msw":"^2.13.2","shx":"^0.3.4","vitest":"^4.1.3","typescript":"^5.8.2","@types/node":"^22","@vitest/coverage-v8":"^4.1.3","@mindstone/mcp-test-harness":"file:../../test-harness"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server-microsoft-files_0.1.0_1779223876533_0.24349249713048748","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@mindstone/mcp-server-microsoft-files","version":"0.1.1","license":"FSL-1.1-MIT","_id":"@mindstone/mcp-server-microsoft-files@0.1.1","maintainers":[{"name":"mindstone-engineering","email":"engineering@mindstone.com"}],"homepage":"https://github.com/mindstone/mcp-servers/tree/main/connectors/microsoft-files","bugs":{"url":"https://github.com/mindstone/mcp-servers/issues"},"bin":{"mcp-server-microsoft-files":"dist/index.js"},"dist":{"shasum":"90469f09c01aac2e24c1b65bbfa4489a9f1fe38a","tarball":"https://registry.npmjs.org/@mindstone/mcp-server-microsoft-files/-/mcp-server-microsoft-files-0.1.1.tgz","fileCount":33,"integrity":"sha512-kgDtgBtcBV+uOniKt/GGyviCUNoXCIDwbz3RKifHZdQxtlGypHTVg4t4QzsHhyGC42WPCb1RSospaWIOZXv6dw==","signatures":[{"sig":"MEUCIA9KhJJUTSb65TeA04D2rT9CDKuZOfiik2ZhLE0aUnPwAiEAxVsU+xVvloo7hVabx1L9SQa+Xiew1MsBiFCBB1ZS+OU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":103379},"type":"module","engines":{"node":">=20"},"gitHead":"2318e6429c67600786dad9cc697f2cde0b94b3a8","mcpName":"io.github.mindstone/mcp-server-microsoft-files","scripts":{"test":"vitest run","build":"shx rm -rf dist && tsc && shx chmod +x dist/index.js && npm run security:internal-refs","start":"node dist/index.js","watch":"tsc --watch","prepare":"npm run build","test:watch":"vitest","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build && npm test","security:internal-refs":"node scripts/check-internal-refs.mjs"},"_npmUser":{"name":"mindstone-engineering","email":"engineering@mindstone.com"},"repository":{"url":"git+https://github.com/mindstone/mcp-servers.git","type":"git","directory":"connectors/microsoft-files"},"_npmVersion":"11.11.1","description":"Microsoft 365 OneDrive files via Graph: list, search, get, upload, download, share, read text.","directories":{},"_nodeVersion":"25.8.2","dependencies":{"zod":"^3.23.0","@modelcontextprotocol/sdk":"^1.26.0","@mindstone/mcp-server-microsoft-shared":"0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"msw":"^2.13.2","shx":"^0.3.4","vitest":"^4.1.3","typescript":"^5.8.2","@types/node":"^22","@vitest/coverage-v8":"^4.1.3","@mindstone/mcp-test-harness":"file:../../test-harness"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server-microsoft-files_0.1.1_1779281004398_0.4816100002878023","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@mindstone/mcp-server-microsoft-files","version":"0.1.2","license":"FSL-1.1-MIT","_id":"@mindstone/mcp-server-microsoft-files@0.1.2","maintainers":[{"name":"mindstone-engineering","email":"engineering@mindstone.com"}],"homepage":"https://github.com/mindstone/mcp-servers/tree/main/connectors/microsoft-files","bugs":{"url":"https://github.com/mindstone/mcp-servers/issues"},"bin":{"mcp-server-microsoft-files":"dist/index.js"},"dist":{"shasum":"a5efbe46cb03c67106833ffb81820ed146bbc81b","tarball":"https://registry.npmjs.org/@mindstone/mcp-server-microsoft-files/-/mcp-server-microsoft-files-0.1.2.tgz","fileCount":21,"integrity":"sha512-YlXUduz0/dJ7m84PVQxAAe/j2fxAT7+xATKMvjup5ZNzQtKPhgcs6liRpbuj3TQW13Snwr/nE+sZ9wBSJHGu1g==","signatures":[{"sig":"MEQCIAvb1J1wRQjJLR4TLdzTl/D/IeKngBieDakBYOY3+PC+AiBlPRA93X0LZTSanSiOZPKU7+UJOAK72GJf9pfOwqjbtw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@mindstone%2fmcp-server-microsoft-files@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":75048},"type":"module","_from":"file:mindstone-mcp-server-microsoft-files-0.1.2.tgz","engines":{"node":">=20"},"mcpName":"io.github.mindstone/mcp-server-microsoft-files","scripts":{"test":"vitest run","build":"shx rm -rf dist && tsc && shx chmod +x dist/index.js && npm run security:internal-refs","start":"node dist/index.js","watch":"tsc --watch","prepare":"npm run build","test:watch":"vitest","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build && npm test","security:internal-refs":"node scripts/check-internal-refs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:964e2b94-c863-4f95-a56c-c113c608e41c"}},"_resolved":"/home/runner/work/mcp-servers/mcp-servers/mindstone-mcp-server-microsoft-files-0.1.2.tgz","_integrity":"sha512-YlXUduz0/dJ7m84PVQxAAe/j2fxAT7+xATKMvjup5ZNzQtKPhgcs6liRpbuj3TQW13Snwr/nE+sZ9wBSJHGu1g==","repository":{"url":"git+https://github.com/mindstone/mcp-servers.git","type":"git","directory":"connectors/microsoft-files"},"_npmVersion":"11.16.0","description":"Microsoft 365 OneDrive files via Graph: list, search, get, upload, download, share, read text.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.23.0","@modelcontextprotocol/sdk":"^1.26.0","@mindstone/mcp-server-microsoft-shared":"^0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"msw":"^2.13.2","shx":"^0.3.4","vitest":"^4.1.3","typescript":"^5.8.2","@types/node":"^22","@vitest/coverage-v8":"^4.1.3","@mindstone/mcp-test-harness":"file:../../test-harness"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server-microsoft-files_0.1.2_1783094745372_0.013007241788070445","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@mindstone/mcp-server-microsoft-files","version":"0.2.0","license":"FSL-1.1-MIT","_id":"@mindstone/mcp-server-microsoft-files@0.2.0","maintainers":[{"name":"mindstone-engineering","email":"engineering@mindstone.com"}],"homepage":"https://github.com/mindstone/mcp-servers/tree/main/connectors/microsoft-files","bugs":{"url":"https://github.com/mindstone/mcp-servers/issues"},"bin":{"mcp-server-microsoft-files":"dist/index.js"},"dist":{"shasum":"502bbfd76171874dc6fc90a8ba30b71a11fda1b6","tarball":"https://registry.npmjs.org/@mindstone/mcp-server-microsoft-files/-/mcp-server-microsoft-files-0.2.0.tgz","fileCount":25,"integrity":"sha512-EZOlcUyfIT3b59ETes2FrJOm98a2MQm5xv7WZSloiIwNJIV+/MGVu8u6ymUdwZsgD8S7cDkAtpnki4vsnIz8+g==","signatures":[{"sig":"MEYCIQDTC2c0rhRKVEgg0a+s1UQ3/44msfy1Cbkzue0rh32yUgIhAOvuMtlGD0ujutCmJ9vI39JzX6ZmzcddH+IKpER1tJJi","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@mindstone%2fmcp-server-microsoft-files@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":133681},"type":"module","_from":"file:mindstone-mcp-server-microsoft-files-0.2.0.tgz","engines":{"node":">=20"},"mcpName":"io.github.mindstone/mcp-server-microsoft-files","scripts":{"test":"vitest run","build":"shx rm -rf dist && tsc && shx chmod +x dist/index.js && npm run security:internal-refs","start":"node dist/index.js","watch":"tsc --watch","prepare":"npm run build","test:watch":"vitest","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build && npm test","security:internal-refs":"node scripts/check-internal-refs.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:964e2b94-c863-4f95-a56c-c113c608e41c"}},"_resolved":"/home/runner/work/mcp-servers/mcp-servers/mindstone-mcp-server-microsoft-files-0.2.0.tgz","_integrity":"sha512-EZOlcUyfIT3b59ETes2FrJOm98a2MQm5xv7WZSloiIwNJIV+/MGVu8u6ymUdwZsgD8S7cDkAtpnki4vsnIz8+g==","repository":{"url":"git+https://github.com/mindstone/mcp-servers.git","type":"git","directory":"connectors/microsoft-files"},"_npmVersion":"11.16.0","description":"Microsoft 365 OneDrive files via Graph: list, search, get, upload, download, share, read text.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.23.0","@modelcontextprotocol/sdk":"^1.26.0","@mindstone/mcp-server-microsoft-shared":"^0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"msw":"^2.13.2","shx":"^0.3.4","vitest":"^4.1.3","typescript":"^5.8.2","@types/node":"^22","@vitest/coverage-v8":"^4.1.3","@mindstone/mcp-test-harness":"file:../../test-harness"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server-microsoft-files_0.2.0_1786107931430_0.9054876109206926","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@mindstone/mcp-server-microsoft-files","version":"0.2.1","mcpName":"io.github.mindstone/mcp-server-microsoft-files","description":"Microsoft 365 OneDrive files via Graph: list, search, get, upload, download, share, read text.","license":"FSL-1.1-MIT","type":"module","bin":{"mcp-server-microsoft-files":"dist/index.js"},"repository":{"type":"git","url":"git+https://github.com/mindstone/mcp-servers.git","directory":"connectors/microsoft-files"},"homepage":"https://github.com/mindstone/mcp-servers/tree/main/connectors/microsoft-files","publishConfig":{"access":"public"},"scripts":{"build":"shx rm -rf dist && tsc && shx chmod +x dist/index.js && npm run security:internal-refs","prepare":"npm run build","prepublishOnly":"npm run build && npm test","watch":"tsc --watch","start":"node dist/index.js","test":"vitest run","test:watch":"vitest","test:coverage":"vitest run --coverage","security:internal-refs":"node scripts/check-internal-refs.mjs"},"dependencies":{"@mindstone/mcp-server-microsoft-shared":"^0.1.0","@modelcontextprotocol/sdk":"^1.26.0","zod":"^3.23.0"},"devDependencies":{"@mindstone/mcp-test-harness":"file:../../test-harness","@types/node":"^22","@vitest/coverage-v8":"^4.1.3","msw":"^2.13.2","shx":"^0.3.4","typescript":"^5.8.2","vitest":"^4.1.3"},"engines":{"node":">=20"},"_id":"@mindstone/mcp-server-microsoft-files@0.2.1","bugs":{"url":"https://github.com/mindstone/mcp-servers/issues"},"_integrity":"sha512-YzQHvm/BAX57xOd+PinNQ5blNgatZWhxt+dXHYmqQ1yzwM2vhFuq4vQe7DoGDSxbRPMryNDu6IOj/kWpWazUMw==","_resolved":"/home/runner/work/mcp-servers/mcp-servers/mindstone-mcp-server-microsoft-files-0.2.1.tgz","_from":"file:mindstone-mcp-server-microsoft-files-0.2.1.tgz","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-YzQHvm/BAX57xOd+PinNQ5blNgatZWhxt+dXHYmqQ1yzwM2vhFuq4vQe7DoGDSxbRPMryNDu6IOj/kWpWazUMw==","shasum":"227506b95bd1a2fcc2ab58ee547c4cf6a3ba8af5","tarball":"https://registry.npmjs.org/@mindstone/mcp-server-microsoft-files/-/mcp-server-microsoft-files-0.2.1.tgz","fileCount":25,"unpackedSize":134683,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@mindstone%2fmcp-server-microsoft-files@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCID3aWr7CS6LfOpjgw5QCqAMsjSSqPWnNfmTYUXw/VhQqAiAhYdURAtDGa4834Nsz2EyRfGNpqpPE2TXh8mNVcHfqCQ=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:964e2b94-c863-4f95-a56c-c113c608e41c"}},"directories":{},"maintainers":[{"name":"mindstone-engineering","email":"engineering@mindstone.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-server-microsoft-files_0.2.1_1786323215070_0.22322454406885828"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-19T20:51:16.318Z","modified":"2026-08-10T00:53:35.574Z","0.1.0":"2026-05-19T20:51:16.728Z","0.1.1":"2026-05-20T12:43:24.550Z","0.1.2":"2026-07-03T16:05:45.505Z","0.2.0":"2026-08-07T13:05:31.604Z","0.2.1":"2026-08-10T00:53:35.238Z"},"bugs":{"url":"https://github.com/mindstone/mcp-servers/issues"},"license":"FSL-1.1-MIT","homepage":"https://github.com/mindstone/mcp-servers/tree/main/connectors/microsoft-files","repository":{"type":"git","url":"git+https://github.com/mindstone/mcp-servers.git","directory":"connectors/microsoft-files"},"description":"Microsoft 365 OneDrive files via Graph: list, search, get, upload, download, share, read text.","maintainers":[{"name":"mindstone-engineering","email":"engineering@mindstone.com"}],"readme":"# @mindstone/mcp-server-microsoft-files\n\n[![npm version](https://img.shields.io/npm/v/@mindstone/mcp-server-microsoft-files.svg)](https://www.npmjs.com/package/@mindstone/mcp-server-microsoft-files)\n[![License: FSL-1.1-MIT](https://img.shields.io/badge/License-FSL--1.1--MIT-blue.svg)](./LICENSE)\n\nMicrosoft 365 OneDrive Files MCP server — list, search, get, download, upload, delete, move, copy, share files, manage sharing permissions and version history, review file activity, and read text and Office document contents via the Microsoft Graph API.\n\n*Cohort-style Microsoft 365 OneDrive MCP. Reuses the OAuth surface owned by [`@mindstone/mcp-server-microsoft-mail`](../microsoft-mail/), so the host signs in once and gets files plus mail plus calendar plus Teams plus SharePoint from the same credentials.*\n\n## Status\n\n- **Version:** [0.2.1](./CHANGELOG.md) · [npm](https://www.npmjs.com/package/@mindstone/mcp-server-microsoft-files)\n- **Auth:** OAuth (host-orchestrated, shared with [`mcp-server-microsoft-mail`](../microsoft-mail/)) ([`MS_CLIENT_ID`](./server.json))\n- **Tools:** [20](./src/tools.ts) (files, folders, sharing, permissions, versions, activity)\n- **Surface:** cloud-api\n- **Machine-readable:** [`STATUS.json`](./STATUS.json)\n- **Shared library:** [`@mindstone/mcp-server-microsoft-shared`](https://www.npmjs.com/package/@mindstone/mcp-server-microsoft-shared)\n\n## Why this exists\n\nWhen we ported this in May 2026, Microsoft's own [Graph MCP](https://github.com/microsoft/mcp) lineup did not yet ship a stand-alone OneDrive server, and the community options at the time treated OneDrive as its own login surface — every connector ran a separate OAuth dance and stored its own copy of the refresh token. We pulled the bundled connector out of MindstoneRebel as a 1:1 port so that the same five-connector Microsoft 365 cohort (mail, calendar, files, teams, SharePoint) shares a single set of credentials, a single shared-library package for token persistence and request timeouts, and the structured `auth_required` envelope the host already knows how to recover from. Files reuses [`@mindstone/mcp-server-microsoft-mail`](../microsoft-mail/)'s `authenticate_microsoft_account` tool rather than declaring its own.\n\n## Example interaction\n\n> \"Find the latest version of `Q3-plan.docx` in my OneDrive and give me a sharing link my team can read.\"\n\nTools the host calls:\n1. `search_files` — `name:Q3-plan.docx`, returns the most recent matching item.\n2. `share_file` — creates a read-only sharing link for that item.\n\nResponse (trimmed):\n\n```json\n{\n  \"match\": {\n    \"id\": \"01H7...\",\n    \"name\": \"Q3-plan.docx\",\n    \"lastModifiedDateTime\": \"2026-05-18T17:42:00Z\"\n  },\n  \"share\": {\n    \"type\": \"view\",\n    \"scope\": \"organization\",\n    \"webUrl\": \"https://example-my.sharepoint.com/:w:/g/personal/.../EZk...\"\n  }\n}\n```\n\n## Requirements\n\n- Node.js 20+\n- npm\n- A host application that performs the Microsoft OAuth flow and writes per-account token files into `${MS_CONFIG_DIR}/credentials/${sanitised-email}.token.json` and an `${MS_CONFIG_DIR}/accounts.json` index. This server reads those files; it does not initiate OAuth itself.\n\n<!-- BEGIN INSTALL_LINKS: do not edit by hand; regenerated by scripts/gen-install-links.mjs -->\n## One-click install\n\n[![Add to Cursor](https://img.shields.io/badge/Add_to_Cursor-black?style=for-the-badge&logo=cursor&logoColor=white)](cursor://anysphere.cursor-deeplink/mcp/install?name=Microsoft%20365%20Files&config=eyJ0eXBlIjoic3RkaW8iLCJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBtaW5kc3RvbmUvbWNwLXNlcnZlci1taWNyb3NvZnQtZmlsZXMiXSwiZW52Ijp7Ik1TX0NMSUVOVF9JRCI6IiIsIk1TX0NPTkZJR19ESVIiOiIiLCJNU19NQ1BfUEFDS0FHRV9JRCI6Ik1pY3Jvc29mdDM2NUZpbGVzIiwiTUlDUk9TT0ZUX1JFUVVFU1RfVElNRU9VVF9NUyI6IjYwMDAwIn19)\n[![Add to VS Code](https://img.shields.io/badge/Add_to_VS_Code-007ACC?style=for-the-badge&logo=visual-studio-code&logoColor=white)](vscode:mcp/install?%7B%22name%22%3A%22Microsoft%20365%20Files%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40mindstone%2Fmcp-server-microsoft-files%22%5D%2C%22env%22%3A%7B%22MS_CLIENT_ID%22%3A%22%22%2C%22MS_CONFIG_DIR%22%3A%22%22%2C%22MS_MCP_PACKAGE_ID%22%3A%22Microsoft365Files%22%2C%22MICROSOFT_REQUEST_TIMEOUT_MS%22%3A%2260000%22%7D%7D)\n[![Add to VS Code Insiders](https://img.shields.io/badge/Add_to_VS_Code_Insiders-24bfa5?style=for-the-badge&logo=visual-studio-code&logoColor=white)](vscode-insiders:mcp/install?%7B%22name%22%3A%22Microsoft%20365%20Files%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40mindstone%2Fmcp-server-microsoft-files%22%5D%2C%22env%22%3A%7B%22MS_CLIENT_ID%22%3A%22%22%2C%22MS_CONFIG_DIR%22%3A%22%22%2C%22MS_MCP_PACKAGE_ID%22%3A%22Microsoft365Files%22%2C%22MICROSOFT_REQUEST_TIMEOUT_MS%22%3A%2260000%22%7D%7D)\n\nAfter clicking the button, your host will prompt you to fill: `MS_CLIENT_ID`, `MS_CONFIG_DIR`, `MS_MCP_PACKAGE_ID`, `MICROSOFT_REQUEST_TIMEOUT_MS`.\n\n<details>\n<summary>Manual config for Claude Desktop / Claude Code / Goose / Continue.dev (Microsoft 365 Files)</summary>\n\n```json\n{\n  \"mcpServers\": {\n    \"Microsoft 365 Files\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@mindstone/mcp-server-microsoft-files\"\n      ],\n      \"env\": {\n        \"MS_CLIENT_ID\": \"\",\n        \"MS_CONFIG_DIR\": \"\",\n        \"MS_MCP_PACKAGE_ID\": \"Microsoft365Files\",\n        \"MICROSOFT_REQUEST_TIMEOUT_MS\": \"60000\"\n      }\n    }\n  }\n}\n```\n\n</details>\n<!-- END INSTALL_LINKS -->\n\n## Quick Start\n\n### Install & build\n\n```bash\ncd <path-to-repo>/connectors/microsoft-files\nnpm install\nnpm run build\n```\n\n### npx (once published)\n\n```bash\nnpx -y @mindstone/mcp-server-microsoft-files\n```\n\n### Local\n\n```bash\nnode dist/index.js\n```\n\n## Configuration\n\nThis server runs alongside a host application that owns the Microsoft 365 OAuth flow. The host writes credentials to disk; this server reads them.\n\n### Required environment variables\n\n| Name | Description |\n| ---- | ----------- |\n| `MS_CLIENT_ID` | Microsoft Entra (Azure AD) application client ID. |\n| `MS_CONFIG_DIR` | Path to the per-user Microsoft config directory (`credentials/`, `accounts.json`). |\n\n### Optional environment variables\n\n| Name | Description | Default |\n| ---- | ----------- | ------- |\n| `MS_ACCOUNT_EMAIL` | Account email when running in multi-account per-instance mode. | First account in `accounts.json`. |\n| `MS_MCP_PACKAGE_ID` | Logical package ID surfaced in error responses. | `Microsoft365Files` |\n| `MICROSOFT_REQUEST_TIMEOUT_MS` | Override the upstream Microsoft Graph request timeout (max `300000` ms). | `60000` |\n| `MICROSOFT_DISABLE_REFRESH` | Set to `1` to disable token refresh on this surface. Tools fail closed with the structured `auth_required` response so the host can drive reauth. Cloud surfaces set this to `1`. | unset |\n\n## Host configuration examples\n\n### Claude Desktop / Cursor\n\n```json\n{\n  \"mcpServers\": {\n    \"Microsoft365Files\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@mindstone/mcp-server-microsoft-files\"],\n      \"env\": {\n        \"MS_CLIENT_ID\": \"your-entra-application-client-id\",\n        \"MS_CONFIG_DIR\": \"/absolute/path/to/microsoft-config\"\n      }\n    }\n  }\n}\n```\n\nSign in via [`@mindstone/mcp-server-microsoft-mail`](../microsoft-mail/)'s `authenticate_microsoft_account` first; the files tools then reuse the credentials it writes to `${MS_CONFIG_DIR}/`.\n\n### Local development (no npm publish needed)\n\n```json\n{\n  \"mcpServers\": {\n    \"Microsoft365Files\": {\n      \"command\": \"node\",\n      \"args\": [\"<path-to-repo>/connectors/microsoft-files/dist/index.js\"],\n      \"env\": {\n        \"MS_CLIENT_ID\": \"your-entra-application-client-id\",\n        \"MS_CONFIG_DIR\": \"/absolute/path/to/microsoft-config\"\n      }\n    }\n  }\n}\n```\n\n## Tools (20)\n\n| Tool | Description |\n| ---- | ----------- |\n| `list_files` | List files and folders in OneDrive (root by default). |\n| `get_file` | Get metadata for a specific file or folder. |\n| `download_file` | Get a short-lived download URL for a file. |\n| `search_files` | Search for files in OneDrive by name or content. |\n| `upload_file` | Upload a file to OneDrive (text up to 4 MB; binary as base64 up to 10 MB via a resumable upload session). |\n| `create_folder` | Create a new folder in OneDrive. |\n| `delete_file` | Delete a file or folder. |\n| `move_file` | Move a file or folder to a new location. |\n| `copy_file` | Copy a file or folder to a new location. |\n| `get_recent` | List recently accessed files. |\n| `get_shared` | List files shared with you by others. |\n| `share_file` | Create a sharing link for a file or folder. |\n| `read_text_file` | Read the contents of a text file. |\n| `invite_to_file` | Share a file or folder with specific people by email (read or write). |\n| `list_file_permissions` | List the sharing permissions granted on a file or folder. |\n| `revoke_file_permission` | Revoke a sharing permission by ID. |\n| `list_file_versions` | List the version history of a file. |\n| `restore_file_version` | Restore a previous version, replacing the current content. |\n| `list_file_activities` | List recent file activity (drive-wide or per item; OneDrive for Business / SharePoint only). |\n| `read_document` | Extract the text of a Word (.docx) or PowerPoint (.pptx) file directly. |\n\n## Security notes\n\n- No authentication tool of its own; sign-in is delegated to [`@mindstone/mcp-server-microsoft-mail`](../microsoft-mail/) so the cohort has a single OAuth surface.\n- Token-provider refresh failures map to the structured `auth_required` response so the host can drive reauth without crashing.\n- `upload_file` enforces empty-content validation in line with the bundled connector to reject zero-byte uploads as a misuse.\n- Binary uploads chunk to the preauthenticated upload-session URL **without** the Graph access token, as Graph requires. The session URL is validated before any byte is sent: HTTPS on the default port, no userinfo, Microsoft OneDrive/SharePoint hosts only, and redirects are rejected rather than followed.\n- Content authored in Microsoft 365 (file names, grantee identities, activity actors and action keys, permission roles, extracted document text, and Graph error messages) is returned inside `<untrusted-content>` envelopes; Graph responses on the permission/version/activity/upload/document paths are Zod-validated at the boundary. Functional identifiers (permission/version/item IDs) and `webUrl`s stay structural so they can round-trip into follow-up tool calls.\n- Permission/version/activity lists follow `@odata.nextLink` pagination (bounded, with an explicit `truncated` flag); continuation links are only followed back to the Graph host so the access token cannot leak to another origin.\n- `read_document` downloads are byte-capped mid-stream (not just by advertised metadata size) and Office ZIP inflation is bounded per-entry and cumulatively, so ZIP bombs cannot expand in memory.\n- `read_document` follows Graph's redirect to the pre-authenticated download URL manually: each hop is revalidated against the same OneDrive/SharePoint host policy as upload sessions, hops are capped, and the access token is only sent to the Graph host — never forwarded across origins.\n- Numeric limits (`top`, `maxSize`, `maxChars`) must be positive integers and are rejected before any network request.\n- Per-tool Graph calls run under a composed caller + cohort timeout signal.\n\n## Licence\n\n[FSL-1.1-MIT](./LICENSE) — Functional Source License, Version 1.1, with MIT future licence. Free for non-competing use; relicenses to MIT on the converter date in `LICENSE`.\n","readmeFilename":"README.md"}