Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
SILENTNoDisable console output
LOG_LEVELNoSet logging level (default: 'info')info
READ_ONLYNoAlternative to --read-only flag
ENABLED_TOOLSNoFilter tools using a regex pattern (alternative to --enabled-tools flag)
MS365_MCP_MAX_TOPNoHard cap for Graph $top / top on list requests (positive integer). When the model passes a larger value, the server clamps it to n so responses stay smaller. Example: MS365_MCP_MAX_TOP=15
MS365_MCP_ORG_MODENoEnable organization/work mode (alternative to --org-mode flag)
MS365_MCP_CLIENT_IDNoCustom Azure app client ID (defaults to built-in app)
MS365_MCP_MAX_ITEMSNoMaximum number of items accumulated when fetchAllPages: true (positive integer, default 10000). Pagination stops and the response is truncated once this many items are collected.10000
MS365_MCP_MAX_PAGESNoMaximum number of pages followed when a tool is called with fetchAllPages: true (positive integer, default 100). Bounds memory and latency for large result sets.100
MS365_MCP_TENANT_IDNoCustom tenant ID (defaults to 'common' for multi-tenant). Personal Microsoft accounts should set this to consumers.common
MS365_MCP_CLOUD_TYPENoMicrosoft cloud environment (alternative to --cloud flag)
MS365_MCP_REDACT_PIINoDisable scrubbing of JWTs, Bearer headers, OAuth token fields, and email addresses from log messages (default: enabled).true
MS365_MCP_USE_KEYTARNoSkipping the credential store on purpose (also accepts false, no or off)
MS365_MCP_BODY_FORMATNoReturn email bodies as HTML instead of plain text (default: text)text
MS365_MCP_DISABLE_DCRNoDisable OAuth Dynamic Client Registration (enabled by default in HTTP mode)
MS365_MCP_OAUTH_TOKENNoPre-existing OAuth token for Microsoft Graph API (BYOT method)
MS365_MCP_EXTRA_SCOPESNoAppend additional Graph scopes to the token request
MS365_MCP_KEYVAULT_URLNoAzure Key Vault URL for secrets management
MS365_MCP_CLIENT_SECRETNoCustom Azure app client secret
MS365_MCP_OUTPUT_FORMATNoEnable TOON output format (alternative to --toon flag)json
MS365_MCP_ALLOWED_SCOPESNoLimit exposed tools to Graph scopes covered by this allowlist
MS365_MCP_ATTACHMENT_HOSTNoInterface the MS365_MCP_ATTACHMENT_PORT listener binds (alternative to --attachment-host; requires --attachment-port).
MS365_MCP_ATTACHMENT_PORTNoServe the attachment route on its own listener on this port (alternative to --attachment-port; requires --enable-attachment-urls)
MS365_MCP_ALLOW_PAGINATIONNoDisable multi-page following entirely. When set, the fetchAllPages parameter is not advertised on tools, and any request that still passes it returns only the first page (default: pagination enabled).true
MS365_MCP_TOKEN_CACHE_PATHNoCustom file path for MSAL token cache
MS365_MCP_TRUST_PROXY_HOPSNoNumber of trusted reverse-proxy hops in HTTP mode (default 1).1
MS365_MCP_EXPECTED_USERNAMENoRequire local MSAL auth to use this Microsoft account username (case-insensitive; CLI flag takes precedence)
MS365_MCP_FORCE_WORK_SCOPESNoBackwards compatibility for MS365_MCP_ORG_MODE
MS365_MCP_ATTACHMENT_URL_KEYNorequired (or _KEY_FILE=/path). MS365_MCP_ATTACHMENT_URL_KEY=...
MS365_MCP_AUTH_CACHE_COMMANDNoExternal executable wrapper for provider-neutral auth-cache storage
MS365_MCP_ATTACHMENT_URL_BASENorequired. MS365_MCP_ATTACHMENT_URL_BASE=http://m365-mcp:3000
MS365_MCP_RATE_LIMIT_DISABLEDNoDisable per-IP rate limiting in HTTP mode (default: enabled — 30 req/min on /authorize, /token, /register; 120 req/min on /mcp)
MS365_MCP_ATTACHMENT_URL_TTL_SNooptional, default 120, max 300120
MS365_MCP_ATTACHMENT_URL_KEY_IDNooptional, default 11
MS365_MCP_HTTP_LOCAL_FILE_TOOLSNoRegister download-bytes-to-file over HTTP (alternative to --http-local-file-tools; same restrictions)
MS365_MCP_SELECTED_ACCOUNT_PATHNoCustom file path for selected account metadata
MS365_MCP_MESSAGE_SIGNOFF_PREFIXNoSignoff prepended to outgoing messages so recipients can tell they were agent-sent, e.g. 🤖. Default: none.
MS365_MCP_MESSAGE_SIGNOFF_SUFFIXNoSignoff appended to outgoing messages. Default: none.
MS365_MCP_ATTACHMENT_URL_KEY_FILENoalternative to KEY
MS365_MCP_EXPECTED_HOME_ACCOUNT_IDNoRequire local MSAL auth to use this exact MSAL homeAccountId (CLI flag takes precedence)
MS365_MCP_AUTH_CACHE_COMMAND_TIMEOUT_MSNoPer-invocation timeout for MS365_MCP_AUTH_CACHE_COMMAND (default: 10000)10000

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Server capabilities have not been inspected yet.

Tools

Functions exposed to the LLM to take actions

NameDescription

No tools

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources