Skip to main content
Glama
dbfournier33

outlook-mcp

by dbfournier33

outlook-mcp

An MCP server that gives AI agents structured access to a Microsoft Outlook mailbox through the Microsoft Graph API — with one deliberate constraint at its core:

Agents read and draft. Only humans send.

There is no send tool in this server, and the OAuth token it holds does not include the Mail.Send scope. Even a fully compromised or badly prompted agent cannot send email through it — the capability doesn't exist at the token level. Everything outbound lands in your Drafts folder for human review.

I built this to power an autonomous operations pipeline: scheduled headless agent sessions sweep the mailbox twice a day, reconcile every open commitment and follow-up into a dashboard, and queue reply drafts for review. It runs identically under Claude Code and OpenAI Codex — one integration layer, two vendors' agents.

Permission model

Capability

Agent

Notes

List/search/read mail

✅

Full mailbox visibility

Organize (folders, move, batch triage)

✅

Reversible operations only

Create drafts / reply drafts

✅

Lands in Drafts, never sent

Send email

❌

No tool, and no Mail.Send scope on the token

Delete email

❌

Not implemented

Auth is MSAL Authorization Code Flow with PKCE through a localhost-only callback. Tokens cache to ~/.outlook-mcp/ with 0600 permissions.

Related MCP server: mailpouch

Tools (10)

Tool

Purpose

list_folders

Folder tree with counts

create_folder

Create a mail folder

list_emails

Page through a folder (subject, sender, preview, unread)

search_emails

KQL search across all folders (from:, subject:, free text)

read_email

Full message body (HTML converted to clean text), recipients, attachments list

move_emails

Move messages between folders

batch_move_emails

Bulk triage in one call

create_draft

New outbound draft

create_reply_draft

Reply/reply-all draft on an existing thread

summarize_folder

Folder statistics (volume, unread, top senders)

Setup

1. Register a (free) app in Entra ID

Microsoft Entra admin center → App registrations → New registration:

  • Supported account types: your tenant only, or multi-tenant + personal accounts (then use OUTLOOK_MCP_TENANT_ID=common)

  • Redirect URI: platform Mobile and desktop applications → add http://localhost:3847/auth/callback

  • Authentication → enable Allow public client flows

  • API permissions → Microsoft Graph → Delegated → Mail.ReadWrite, MailboxSettings.Read

No client secret is needed (public client + PKCE).

2. Build and authenticate

npm install
npm run build

export OUTLOOK_MCP_CLIENT_ID=<your app client id>
export OUTLOOK_MCP_TENANT_ID=<your tenant id or "common">

npm run auth   # opens browser once; token cache persists at ~/.outlook-mcp/

3. Connect an agent

Claude Code — .mcp.json in your project (or claude mcp add):

{
  "mcpServers": {
    "outlook": {
      "command": "node",
      "args": ["/path/to/outlook-mcp/dist/index.js"],
      "env": {
        "OUTLOOK_MCP_CLIENT_ID": "<client id>",
        "OUTLOOK_MCP_TENANT_ID": "<tenant id>"
      }
    }
  }
}

OpenAI Codex — ~/.codex/config.toml:

[mcp_servers.outlook]
command = "node"
args = ["/path/to/outlook-mcp/dist/index.js"]
env = { OUTLOOK_MCP_CLIENT_ID = "<client id>", OUTLOOK_MCP_TENANT_ID = "<tenant id>" }

Same server, same tools, either agent. That portability is the point of MCP.

Architecture

┌─────────────┐     stdio      ┌──────────────┐     HTTPS     ┌─────────────────┐
│ Claude Code │◄──────────────►│              │◄─────────────►│ Microsoft Graph │
├─────────────┤   JSON-RPC     │  outlook-mcp │   REST v1.0   │  /me/messages   │
│ OpenAI Codex│◄──────────────►│  (Node/TS)   │               │  /me/mailFolders│
└─────────────┘                └──────┬───────┘               └─────────────────┘
                                      │
                               ┌──────┴───────┐
                               │ MSAL + PKCE  │  Mail.ReadWrite only —
                               │ token cache  │  no Mail.Send on the token
                               └──────────────┘
  • Transport: stdio (JSON-RPC), one process per agent session

  • Auth: MSAL Auth Code Flow + PKCE, localhost callback, silent refresh from disk cache

  • Bodies: HTML mail converted to clean plain text before it reaches the model (token efficiency)

  • Validation: every tool input validated with zod before any Graph call

Development

npm run dev       # tsc --watch
npm run inspect   # MCP Inspector against the built server

License

MIT © Don Fournier

Related MCP Connectors

  • Email infrastructure for AI agents — send, receive, search, and reply to email over MCP.

  • Email inboxes for AI agents: send, receive, reply, search, and manage threaded email over MCP.

  • Your agent needs a mailbox of its own — to receive, thread, draft and send, with attachments, without borrowing your personal inbox or your company's SMTP. **What you can ask for** • "Create an inbox for this agent and tell me its address." • "Read the new messages in this thread and draft a reply." • "Send this message with the attachment and wait for the response." • "Search this inbox for everything from that domain." • "Show delivery metrics and the events on this inbox." **How to use it** Point any MCP client at https://mcp.aisa.one/mail/mcp and sign in with OAuth — there is no key to create or paste. 49 tools: create and delete inboxes, list and read messages, raw message bodies, attachments, threads, drafts and draft attachments, send and reply, message search, inbox events, metrics, and list entries — reads and writes. **Why this rather than the source** A real inbox an agent owns, rather than an SMTP credential it borrows from a human. **It is also a door to the rest** The same login reaches 26 sources and 580+ operations. Find the contact elsewhere in the catalogue, then write to them from here — without adding a second server. **What it costs** Finding and inspecting an operation is free. Running one is billed per call at API prices, with no seat and no monthly minimum, and every call takes max_price_usd so an agent cannot overspend by accident. **Where else it reaches** https://mcp.aisa.one/sales/mcp finds the person to write to.

  • Hosted email for AI agents: create inboxes, send, receive, and reply over MCP with scoped API keys

Related MCP Servers

  • A
    license
    Not graded
    quality
    B
    maintenance
    An open-source MCP server that provides AI agents with secure access to read, search, and manage emails via Microsoft 365 and Gmail. It features security-first defaults like recipient allowlists and markdown content conversion to facilitate safe agent interaction with mailboxes.
    6
    Apache 2.0
  • A
    license
    A
    quality
    A
    maintenance
    An MCP server that gives AI agents permission-gated, audit-logged access to private email providers (Proton Mail via Bridge and plain IMAP), running locally with OAuth-based authentication and human-controlled escalation for destructive operations.
    66
    86 npm
    11
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    An MCP server that gives Claude Code and Codex full control of a personal Outlook.com mailbox and calendar via the Microsoft Graph API, enabling mail, draft, folder, and calendar operations through natural language.
    31
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    An MCP server that provides an email operating system for AI agents, enabling inbox triage and reply drafting while enforcing un-bypassable safety constraints on sensitive actions like money transfers and banking changes.
    12
    107 npm
    MIT