Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
SILENTNoDisable console output. Set to 'true' or '1'.
LOG_LEVELNoSet logging level (default: 'info').
READ_ONLYNoAlternative to --read-only flag. Set to 'true' or '1' to enable read-only mode.
ENABLED_TOOLSNoFilter tools using a regex pattern (alternative to --enabled-tools flag).
AZURE_CLIENT_IDNoAzure client ID for DefaultAzureCredential when using Azure Key Vault.
AZURE_TENANT_IDNoAzure tenant ID for DefaultAzureCredential when using Azure Key Vault.
MS365_MCP_MAX_TOPNoHard cap for Graph $top / top on list requests (positive integer). When the model passes a larger value, the server clamps it to n.
MS365_MCP_ORG_MODENoEnable organization/work mode (alternative to --org-mode flag). Set to 'true' or '1'.
AZURE_CLIENT_SECRETNoAzure client secret for DefaultAzureCredential when using Azure Key Vault.
MS365_MCP_CLIENT_IDNoCustom Azure app client ID (defaults to built-in app).
MS365_MCP_MAX_ITEMSNoMaximum number of items accumulated when fetchAllPages: true (positive integer, default: 10000).10000
MS365_MCP_MAX_PAGESNoMaximum number of pages followed when a tool is called with fetchAllPages: true (positive integer, default: 100).100
MS365_MCP_TENANT_IDNoCustom tenant ID (defaults to 'common' for multi-tenant). Personal Microsoft accounts should set this to 'consumers'.common
MS365_MCP_CLOUD_TYPENoMicrosoft cloud environment (alternative to --cloud flag). Valid values: 'global' or 'china'.global
MS365_MCP_REDACT_PIINoDisable scrubbing of JWTs, Bearer headers, OAuth token fields, and email addresses from log messages (default: enabled). Set to 'false' or '0' to disable.
MS365_MCP_USE_KEYTARNoSet to '0', 'false', 'no', or 'off' to skip the credential store and use a .cache-key file instead.
MS365_MCP_BODY_FORMATNoReturn email bodies as HTML instead of plain text (default: text). Set to 'html' to enable.text
MS365_MCP_OAUTH_TOKENNoPre-existing OAuth token for Microsoft Graph API (BYOT method).
MS365_MCP_EXTRA_SCOPESNoAppend additional Graph scopes to the token request (for use with your own app registration + graph-batch).
MS365_MCP_KEYVAULT_URLNoAzure Key Vault URL for secrets management.
MS365_MCP_CLIENT_SECRETNoCustom Azure app client secret (optional, for your own Azure app registration).
MS365_MCP_OUTPUT_FORMATNoSet to 'toon' to enable TOON output format (alternative to --toon flag). Default: json.
MS365_MCP_ALLOWED_SCOPESNoLimit exposed tools to Graph scopes covered by this allowlist.
MS365_MCP_ATTACHMENT_HOSTNoInterface the MS365_MCP_ATTACHMENT_PORT listener binds (alternative to --attachment-host; requires --attachment-port). Defaults to the host --http bound.
MS365_MCP_ATTACHMENT_PORTNoServe the attachment route on its own listener on this port (alternative to --attachment-port; requires --enable-attachment-urls).
MS365_MCP_ALLOW_PAGINATIONNoDisable multi-page following entirely. When set, the fetchAllPages parameter is not advertised on tools, and any request that still passes it returns only the first page (default: pagination enabled).
MS365_MCP_TOKEN_CACHE_PATHNoCustom file path for MSAL token cache.
MS365_MCP_TRUST_PROXY_HOPSNoNumber of trusted reverse-proxy hops in HTTP mode (default: 1).1
MS365_MCP_EXPECTED_USERNAMENoRequire local MSAL auth to use this Microsoft account username (case-insensitive; CLI flag takes precedence).
MS365_MCP_FORCE_WORK_SCOPESNoBackwards compatibility for MS365_MCP_ORG_MODE.
MS365_MCP_ATTACHMENT_URL_KEYNoRequired (or use MS365_MCP_ATTACHMENT_URL_KEY_FILE) for attachment URLs. Signing key.
MS365_MCP_AUTH_CACHE_COMMANDNoExternal executable wrapper for provider-neutral auth-cache storage.
MS365_MCP_ATTACHMENT_URL_BASENoRequired for attachment URLs. Deliberately not MS365_MCP_PUBLIC_URL; fetched server-to-server and commonly a container address.
MS365_MCP_RATE_LIMIT_DISABLEDNoDisable per-IP rate limiting in HTTP mode (default: enabled). Set to 'true' or '1'.
MS365_MCP_ATTACHMENT_URL_TTL_SNoOptional TTL in seconds for attachment URLs (default: 120, max: 300).120
MS365_MCP_ATTACHMENT_URL_KEY_IDNoOptional key ID for attachment URL signing (default: 1).1
MS365_MCP_SELECTED_ACCOUNT_PATHNoCustom file path for selected account metadata.
MS365_MCP_MESSAGE_SIGNOFF_PREFIXNoSignoff prepended to outgoing messages so recipients can tell they were agent-sent (e.g. '🤖'). Default: none.
MS365_MCP_MESSAGE_SIGNOFF_SUFFIXNoSignoff appended to outgoing messages. Default: none.
MS365_MCP_ATTACHMENT_URL_KEY_FILENoPath to file containing the signing key for attachment URLs (alternative to MS365_MCP_ATTACHMENT_URL_KEY).
MS365_MCP_EXPECTED_HOME_ACCOUNT_IDNoRequire local MSAL auth to use this exact MSAL homeAccountId (CLI flag takes precedence).
MS365_MCP_AUTH_CACHE_COMMAND_TIMEOUT_MSNoPer-invocation timeout for MS365_MCP_AUTH_CACHE_COMMAND (default: 10000).10000

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Server capabilities have not been inspected yet.

Tools

Functions exposed to the LLM to take actions

NameDescription

No tools

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources