Skip to main content
Glama
jhirono

Microsoft Todo MCP Service

by jhirono

auth-status

Check authentication status with Microsoft Graph API to verify token validity and determine if refresh is needed for Microsoft Todo task management.

Instructions

Check if you're authenticated with Microsoft Graph API. Shows current token status and expiration time, and indicates if the token needs to be refreshed.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Implementation Reference

  • Registration of the 'auth-status' tool. Includes empty input schema {}, detailed description, and inline async handler function that reads tokens from file or memory, checks expiration, determines if personal Microsoft account, and returns markdown text with authentication status.
    server.tool(
      "auth-status",
      "Check if you're authenticated with Microsoft Graph API. Shows current token status and expiration time, and indicates if the token needs to be refreshed.",
      {},
      async () => {
        const tokens = readTokens();
        if (!tokens && !currentAccessToken) {
          return {
            content: [
              {
                type: "text",
                text: "Not authenticated. Please run auth-server.js to authenticate with Microsoft.",
              },
            ],
          };
        }
        
        const tokenData = tokens || { 
          accessToken: currentAccessToken || "",
          refreshToken: currentRefreshToken || "",
          expiresAt: 0
        };
        
        const isExpired = Date.now() > tokenData.expiresAt;
        const expiryTime = new Date(tokenData.expiresAt).toLocaleString();
        
        // Check if it's a personal account
        const isPersonal = await isPersonalMicrosoftAccount();
        let accountMessage = "";
        
        if (isPersonal) {
          accountMessage = "\n\n⚠️ WARNING: You are using a personal Microsoft account. " +
            "Microsoft To Do API access is typically not available for personal accounts " +
            "through the Microsoft Graph API. You may encounter 'MailboxNotEnabledForRESTAPI' errors. " +
            "This is a Microsoft limitation, not an authentication issue.";
        }
        
        if (isExpired) {
          return {
            content: [
              {
                type: "text",
                text: `Authentication expired at ${expiryTime}. Will attempt to refresh when you call any API.${accountMessage}`,
              },
            ],
          };
        } else {
          return {
            content: [
              {
                type: "text",
                text: `Authenticated. Token expires at ${expiryTime}.${accountMessage}`,
              },
            ],
          };
        }
      }
    );
  • Inline handler function for the auth-status tool. Checks if tokens exist, determines expiration status, calls helper to check for personal account, constructs warning message if applicable, and returns structured content with authentication status and expiration info.
    async () => {
      const tokens = readTokens();
      if (!tokens && !currentAccessToken) {
        return {
          content: [
            {
              type: "text",
              text: "Not authenticated. Please run auth-server.js to authenticate with Microsoft.",
            },
          ],
        };
      }
      
      const tokenData = tokens || { 
        accessToken: currentAccessToken || "",
        refreshToken: currentRefreshToken || "",
        expiresAt: 0
      };
      
      const isExpired = Date.now() > tokenData.expiresAt;
      const expiryTime = new Date(tokenData.expiresAt).toLocaleString();
      
      // Check if it's a personal account
      const isPersonal = await isPersonalMicrosoftAccount();
      let accountMessage = "";
      
      if (isPersonal) {
        accountMessage = "\n\n⚠️ WARNING: You are using a personal Microsoft account. " +
          "Microsoft To Do API access is typically not available for personal accounts " +
          "through the Microsoft Graph API. You may encounter 'MailboxNotEnabledForRESTAPI' errors. " +
          "This is a Microsoft limitation, not an authentication issue.";
      }
      
      if (isExpired) {
        return {
          content: [
            {
              type: "text",
              text: `Authentication expired at ${expiryTime}. Will attempt to refresh when you call any API.${accountMessage}`,
            },
          ],
        };
      } else {
        return {
          content: [
            {
              type: "text",
              text: `Authenticated. Token expires at ${expiryTime}.${accountMessage}`,
            },
          ],
        };
      }
    }
  • Helper function specifically used by auth-status handler to determine if the authenticated Microsoft account is personal (non-business) by fetching /me endpoint and checking email domain against known personal domains, logging detailed warning if so.
    async function isPersonalMicrosoftAccount(): Promise<boolean> {
      try {
        const token = await getAccessToken();
        if (!token) return false;
        
        // Make a request to get user info
        const url = `${MS_GRAPH_BASE}/me`;
        const response = await fetch(url, {
          method: "GET",
          headers: {
            "Authorization": `Bearer ${token}`,
            "Accept": "application/json"
          }
        });
        
        if (!response.ok) {
          console.error(`Error getting user info: ${response.status}`);
          return false;
        }
        
        const userData = await response.json();
        const email = userData.mail || userData.userPrincipalName || '';
        
        // Check if the email domain indicates a personal account
        const personalDomains = ['outlook.com', 'hotmail.com', 'live.com', 'msn.com', 'passport.com'];
        const domain = email.split('@')[1]?.toLowerCase();
        
        if (domain && personalDomains.some(d => domain.includes(d))) {
          console.error(`
    =================================================================
    WARNING: Personal Microsoft Account Detected
    
    Your Microsoft account (${email}) appears to be a personal account.
    Microsoft To Do API access is typically not available for personal accounts
    through the Microsoft Graph API, only for Microsoft 365 business accounts.
    
    You may encounter the "MailboxNotEnabledForRESTAPI" error when trying to
    access To Do lists or tasks. This is a limitation of the Microsoft Graph API,
    not an issue with your authentication or this application.
    
    You can still use Microsoft To Do through the web interface or mobile apps,
    but API access is restricted for personal accounts.
    =================================================================
          `);
          return true;
        }
        
        return false;
      } catch (error) {
        console.error("Error checking account type:", error);
        return false;
      }
  • Helper function to read authentication tokens from tokens.json file, parse JSON, log details, used by auth-status to check current token status.
    function readTokens(): TokenData | null {
      try {
        console.error(`Attempting to read tokens from: ${TOKEN_FILE_PATH}`);
        if (!existsSync(TOKEN_FILE_PATH)) {
          console.error('Token file does not exist');
          return null;
        }
        const data = readFileSync(TOKEN_FILE_PATH, 'utf8');
        console.error('Token file content length:', data.length);
        
        const tokenData = JSON.parse(data) as TokenData;
        console.error('Token parsed successfully, expires at:', new Date(tokenData.expiresAt).toLocaleString());
        return tokenData;
      } catch (error) {
        console.error('Failed to read tokens from file:', error);
        return null;
      }

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changedv1.0.0
    • removedInput schema / additionalProperties
      Removed value: -false
  2. First observed

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden. It discloses what the tool returns (token status, expiration time, refresh indication) and implicitly indicates it is a non-mutating check. However, it does not clarify whether it makes network calls or could trigger a refresh, which would enhance transparency.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences, front-loaded with the primary purpose, and contains no redundant information. Every clause adds value, making it highly concise and well-structured.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple status-check tool with no parameters, the description is complete enough. It explains what the tool does and what information it provides, without requiring an output schema. The low complexity means the description fully covers the context.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool has zero parameters, so the input schema is fully covered. The baseline for 0 parameters is 4, and the description adds no parameter-related info, which is appropriate. No additional meaning is needed for non-existent parameters.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool checks authentication status with Microsoft Graph API, showing token status, expiration time, and refresh need. It uses a specific verb and resource, and is clearly distinct from all sibling tools, which are task-related.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies the tool should be used to verify authentication, but does not explicitly state when to use it, any prerequisites, or exclusions. There are no alternative auth tools among siblings, so it doesn't name alternatives, but it also doesn't provide contextual guidance like 'use before making API calls.'

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.