M365 Agent MCP
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@M365 Agent MCPlist my recent emails"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
M365 Agent MCP
A remote MCP server for ChatGPT workspace agents. One Vercel deployment serves multiple agents, and each agent gets access only to the Microsoft 365 mailbox mapped to its secret URL key.
Mailboxes
This project is configured for these three agent mailboxes:
reservations@kwantu.co.zaassistant@kwantu.co.zaassistant@sapphireglobalfs.com
All three mailboxes must exist in the Microsoft 365 tenant identified by TENANT_ID. If one mailbox is in a different tenant, use a separate deployment for that tenant.
Related MCP server: Agent Email
Route Shape
Each MCP URL has this shape:
https://<vercel-domain>/api/agents/<agent-key>/mcpThe app route is:
app/api/agents/[agent]/[transport]/route.ts<agent-key> is a long random secret. The server resolves it through AGENT_MAILBOX_MAP; unknown keys return HTTP 404.
Tools
list_recent_emails: lists recent messages from the mapped mailbox.search_emails: searches messages in the mapped mailbox.read_email: reads one message from the mapped mailbox.send_email: sends HTML email from the mapped mailbox.
No database is used. Secrets and mailbox mapping live only in environment variables.
Microsoft Graph Setup
In Microsoft Entra admin center:
Create an app registration.
Create a client secret and copy the secret value immediately.
Add Microsoft Graph application permissions:
Mail.ReadMail.Send
Grant admin consent for the tenant.
Required tenant safety control: restrict the app to only the three agent mailboxes using Exchange Online App RBAC (Role Based Access Control for Applications). Without this, an admin-consented app can reach every mailbox in the tenant.
Note: the older
New-ApplicationAccessPolicymethod is now legacy. Use App RBAC below.
Connect-ExchangeOnline
# 1. Mail-enabled security group containing the three mailboxes.
# Use a different PrimarySmtpAddress if kwantu.co.za is not an accepted domain.
New-DistributionGroup `
-Name "M365 Agent MCP Mailboxes" `
-Alias "m365-agent-mcp-mailboxes" `
-Type Security `
-PrimarySmtpAddress "m365-agent-mcp-mailboxes@kwantu.co.za"
Add-DistributionGroupMember -Identity "m365-agent-mcp-mailboxes@kwantu.co.za" -Member "reservations@kwantu.co.za"
Add-DistributionGroupMember -Identity "m365-agent-mcp-mailboxes@kwantu.co.za" -Member "assistant@kwantu.co.za"
Add-DistributionGroupMember -Identity "m365-agent-mcp-mailboxes@kwantu.co.za" -Member "assistant@sapphireglobalfs.com"
# 2. Scope that resolves to the members of that group.
$group = Get-Group "m365-agent-mcp-mailboxes@kwantu.co.za"
New-ManagementScope `
-Name "M365 Agent MCP Mailboxes" `
-RecipientRestrictionFilter "MemberOfGroup -eq '$($group.DistinguishedName)'"
# 3. Register the app's service principal in Exchange.
# IMPORTANT: <ENTERPRISE_APP_OBJECT_ID> is the Object ID from
# Entra > Enterprise applications > (your app), NOT from App registrations.
New-ServicePrincipal `
-AppId "<CLIENT_ID>" `
-ObjectId "<ENTERPRISE_APP_OBJECT_ID>" `
-DisplayName "M365 Agent MCP"
# 4. Grant Mail.Read and Mail.Send, both limited to the scope above.
New-ManagementRoleAssignment `
-Name "M365 Agent MCP Mail Read" `
-App "<ENTERPRISE_APP_OBJECT_ID>" `
-Role "Application Mail.Read" `
-CustomResourceScope "M365 Agent MCP Mailboxes"
New-ManagementRoleAssignment `
-Name "M365 Agent MCP Mail Send" `
-App "<ENTERPRISE_APP_OBJECT_ID>" `
-Role "Application Mail.Send" `
-CustomResourceScope "M365 Agent MCP Mailboxes"
# 5. Verify. The three approved mailboxes should be in scope; an unrelated one should not.
Test-ServicePrincipalAuthorization -Identity "<ENTERPRISE_APP_OBJECT_ID>" -Resource "reservations@kwantu.co.za"
Test-ServicePrincipalAuthorization -Identity "<ENTERPRISE_APP_OBJECT_ID>" -Resource "assistant@kwantu.co.za"
Test-ServicePrincipalAuthorization -Identity "<ENTERPRISE_APP_OBJECT_ID>" -Resource "assistant@sapphireglobalfs.com"
Test-ServicePrincipalAuthorization -Identity "<ENTERPRISE_APP_OBJECT_ID>" -Resource "<unrelated-mailbox@your-domain>"Live Graph authorization changes can take up to a couple of hours to propagate, but Test-ServicePrincipalAuthorization bypasses that cache for verification.
Environment Variables
Set these four variables in Vercel:
TENANT_ID=<directory-tenant-id>
CLIENT_ID=<application-client-id>
CLIENT_SECRET=<client-secret-value>
AGENT_MAILBOX_MAP={"<reservations-key>":"reservations@kwantu.co.za","<kwantu-assistant-key>":"assistant@kwantu.co.za","<sapphire-assistant-key>":"assistant@sapphireglobalfs.com"}For local development, copy .env.example to .env.local and replace the placeholders.
1. Generate One Random Key Per Agent
From a terminal:
node -e "const crypto=require('crypto'); for (const name of ['reservations','kwantu-assistant','sapphire-assistant']) console.log(name + '=' + crypto.randomBytes(24).toString('hex'))"Example output shape:
reservations=<reservations-key>
kwantu-assistant=<kwantu-assistant-key>
sapphire-assistant=<sapphire-assistant-key>Then create the JSON map:
{
"<reservations-key>": "reservations@kwantu.co.za",
"<kwantu-assistant-key>": "assistant@kwantu.co.za",
"<sapphire-assistant-key>": "assistant@sapphireglobalfs.com"
}When entering AGENT_MAILBOX_MAP in Vercel, paste it as one line with no outer quotes.
2. Set The Four Environment Variables In Vercel
In Vercel:
Open the project.
Go to Settings, then Environment Variables.
Add
TENANT_ID,CLIENT_ID,CLIENT_SECRET, andAGENT_MAILBOX_MAP.Apply them to Production, Preview, and Development if you want all environments to work.
With the Vercel CLI, you can also run:
vercel env add TENANT_ID production
vercel env add CLIENT_ID production
vercel env add CLIENT_SECRET production
vercel env add AGENT_MAILBOX_MAP productionRepeat for preview and development if needed.
3. Deploy
Install dependencies and verify the build:
npm install
npm run buildDeploy:
vercel --prodOr push the repo to GitHub and import it into Vercel, then deploy from the Vercel dashboard.
4. Get The Per-Agent MCP URLs
After deployment, use your Vercel production domain and each generated key:
Reservations agent:
https://<vercel-domain>/api/agents/<reservations-key>/mcp
Kwantu assistant agent:
https://<vercel-domain>/api/agents/<kwantu-assistant-key>/mcp
Sapphire assistant agent:
https://<vercel-domain>/api/agents/<sapphire-assistant-key>/mcpPaste the relevant URL into each ChatGPT workspace agent as its custom MCP server URL.
Local Run
npm install
Copy-Item .env.example .env.local
npm run devLocal MCP URL:
http://localhost:3000/api/agents/<agent-key>/mcpThe health page is available at:
http://localhost:3000Validation Checklist
Unknown agent key returns HTTP 404.
If
MCP_AUTH_TOKENis set, requests without the correctAuthorization: Bearerheader return HTTP 401.Each known key can list/read only its mapped mailbox.
send_emailsends from the mapped mailbox and saves to Sent Items.Test-ServicePrincipalAuthorizationshows the three allowed mailboxes in scope.Test-ServicePrincipalAuthorizationshows an unrelated mailbox out of scope.
Client Secret Renewal
Client secrets expire. Before expiry, create a new secret in the app registration, update CLIENT_SECRET in Vercel, and redeploy.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityAmaintenanceA production-ready MCP server that provides secure, delegated access to Microsoft 365 services including Email, SharePoint, OneDrive, and Calendar. It enables AI models to search messages, browse files, manage calendar events, and parse document contents using OAuth 2.1 authentication.Last updatedMIT
- Alicense-qualityAmaintenanceAn open-source MCP server that provides AI agents with secure access to read, search, and manage emails via Microsoft 365 and Gmail. It features security-first defaults like recipient allowlists and markdown content conversion to facilitate safe agent interaction with mailboxes.Last updated3Apache 2.0
- FlicenseAqualityCmaintenanceLocal-first MCP server for agents that need to work across multiple Gmail and Microsoft 365 accounts without cloud token storage.Last updated6
- Alicense-qualityDmaintenanceA Python-based MCP server for Microsoft 365 Outlook email operations using OAuth 2.0 Client Credentials Flow, enabling automated email management for autonomous agents.Last updatedMIT
Related MCP Connectors
Hosted email MCP for AI agents with inboxes, send/receive, memory, recovery, and credits.
Shipmail MCP server for AI agent custom-domain email inboxes with REST API and webhooks.
Remote MCP server for The Colony — a social network for AI agents (posts, DMs, search, marketplace).
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/iahmadraza7/m365-agent-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server