Skip to main content
Glama
Softeria

Microsoft 365 MCP Server

by Softeria

get-download-url

Read-only

Resolve a short-lived, pre-authenticated Microsoft Graph download URL for OneDrive or SharePoint files so clients can fetch binary content directly to disk without base64 or Authorization headers.

Instructions

Resolve a short-lived, pre-authenticated download URL for Microsoft Graph binary content that exposes one (drive/SharePoint file content). The returned URL streams the bytes with NO Authorization header, so the client can fetch it straight to disk (e.g. curl) without round-tripping base64 through the agent context. Prefer this over download-bytes for any file above a few KB or any bulk download. Returns { downloadUrl, name?, size?, contentType? }. Mail file attachments (/messages/{id}/attachments/{id}/$value), meeting recordings and other $value byte endpoints have no pre-authenticated URL from Graph itself, but call this tool for them anyway: a server running with --enable-attachment-urls mints its own single-use URL for them, and one without it answers with the reason and points at download-bytes.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
targetYesRelative Microsoft Graph path starting with "/". Either a driveItem content path or the item path itself, e.g. /drives/{drive-id}/items/{driveItem-id}/content, /me/drive/items/{driveItem-id}/content, or /sites/{site-id}/drive/items/{driveItem-id}. A trailing /content is optional and is stripped automatically for drive items. Mail attachment $value paths and meeting recordings are not supported (Graph exposes no pre-authenticated URL for them).

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.128.1

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only give readOnlyHint=true and openWorldHint=true. The description goes well beyond them: the URL is short-lived and pre-authenticated, streams bytes with NO Authorization header, is single-use for attachment endpoints, and depends on the --enable-attachment-urls server flag with a defined fallback response. That is substantive behavioral disclosure.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core resolution behavior, then the sibling preference, then the return shape, then edge cases. It is dense but every sentence carries information. The single long paragraph is slightly heavy, which keeps it off a 5.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is no output schema, and the description compensates by declaring the return shape { downloadUrl, name?, size?, contentType? }. Combined with the alternative-tool routing and the attachment server-flag behavior, an agent has everything needed to call it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so target's syntax (leading '/', driveItem content vs item path, auto-stripping of trailing /content) is already documented. The description adds value by clarifying the attachment/meeting-recording call path and server-flag nuance, though that clarification partially conflicts with the schema text that flatly says those paths are 'not supported'.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Resolve) and resource (short-lived, pre-authenticated download URL for Microsoft Graph binary content), and explicitly names the scope of what it applies to. It distinguishes itself from download-bytes by naming that sibling and the condition that separates them, so an agent can route without opening either schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states the selection rule: 'Prefer this over download-bytes for any file above a few KB or any bulk download.' It also covers non-obvious cases (mail attachment $value paths, meeting recordings) and tells the agent to call anyway because a flagged server mints its own URL, with the failure behavior described.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools