graphslayer
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@graphslayerList the first 10 users in the contoso tenant and their managers"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
graphslayer
Works with GCC High. You can add commercial and GCC High tenants to the same server, and each call names the tenant it uses. See GCC High.
graphslayer is an MCP server that lets an AI agent, such as Claude, read and change a Microsoft 365 tenant through Microsoft Graph. The agent writes a short JavaScript script, the server runs it in a sandbox on your machine, and only the result the script returns goes back to the agent. One script can page through every user, join them to their groups, and return ten rows, instead of the agent pulling thousands of records into its context.
It has three tools, plus three for managing connections:
Tool | What it does |
| Searches the Microsoft Learn documentation and returns the matching passages with their links. |
| Runs a script over a built-in catalogue of Microsoft Graph: every path, method, property, and the permissions each call needs. It needs no tenant. |
| Runs a script against one tenant. It reads, and through a connection added read-write, it also writes. |
| List, add and remove the tenants the server can reach. |
Requirements
Node.js 22 or newer. Check with
node --version.macOS, Linux or Windows, on x64 or arm64.
About 250 MB of disk. Most of it is
workerd, the runtime the sandbox runs in.
On Linux, sign-ins are stored through the Secret Service. A desktop install already has it. A server or minimal install needs it added:
sudo apt install gnome-keyring libsecret-1-0 # Debian, Ubuntu
sudo dnf install gnome-keyring libsecret # Fedora, RHELOver SSH there is no session bus, so start the server with dbus-run-session -- <command>.
Related MCP server: Microsoft Graph MCP
Install
Add this to your MCP client's config:
{
"mcpServers": {
"graphslayer": {
"command": "npx",
"args": ["-y", "graphslayer"]
}
}
}In Claude Code it is one command:
claude mcp add graphslayer -- npx -y graphslayerClient | Config file |
Claude Desktop, macOS |
|
Claude Desktop, Windows |
|
Claude Desktop, Linux |
|
VS Code |
|
Restart the client after you edit the file.
Connect a tenant
A connection is one signed-in tenant. You can hold several, and every tool call names the one it uses. There are three kinds.
As yourself
Ask the agent to add a connection, or run:
npx -y graphslayer connect --alias contosoA browser window opens. Sign in with a work account and approve the permissions. The sign-in is stored in your operating system's keychain: Keychain on macOS, Credential Manager on Windows, and the Secret Service on Linux. Tokens and secrets never pass through the agent.
A connection is read-only unless you add it with --template read-write. Only then can
execute write through it.
As an application
An app-only connection runs as your own app registration, with the application permissions an administrator granted it. You add it from a terminal, because the agent never handles a credential:
npx -y graphslayer connect --app-only --tenant <tenant-id> --client-id <your-app-id> --mode readIt asks for the client secret, or with --cert <path>, for the password of a PEM file holding
the certificate and its private key. The secret goes to the keychain. --tenant, --client-id
and --mode are required, and --mode write is what lets execute write.
As an AI agent acting for you
An agent connection uses an Entra Agent ID agent identity. Graph sees you as the user and the agent as the app, so Microsoft's sign-in log shows which calls the agent made for you. It works in the commercial cloud.
First set up the agent in Entra: an agent identity blueprint with a certificate, an
access_agent scope on it, the Graph permissions granted to it and marked inheritable, and an
agent identity made from it. docs/agent-setup.md walks through each step.
Then:
npx -y graphslayer connect --agent --tenant <tenant-id> --blueprint-id <blueprint-app-id> \
--agent-id <agent-app-id> --cert <path-to-blueprint.pem> --mode read --alias agentIt asks for the certificate password, then opens a browser for you to sign in. Microsoft never
lets an agent identity hold Application.ReadWrite.All, RoleManagement.ReadWrite.All,
User.ReadWrite.All or Directory.AccessAsUser.All.
Scripts
The agent writes the body of an async function and returns what it wants back. In execute,
the graph object makes the calls:
const policies = await graph.all("/identity/conditionalAccess/policies", { select: ["displayName", "state"] });
return policies.filter((p) => p.state === "enabled").map((p) => p.displayName);return await graph.request({ method: "PATCH", path: "/users/{id}", body: { accountEnabled: false } });Call | What it does |
| Reads one object. |
| Reads one page, with a cursor for the next. |
| Reads every page, up to 2,000 items by default. |
| Sends up to 20 reads in one request. |
| Counts the items in a collection. |
| Sends any method. On a read-only connection, every method but GET is refused before anything is sent. |
The server handles the Graph details a script would otherwise get wrong:
It sets the consistency header that advanced directory queries need.
It waits and retries when Graph throttles. A write is resent only on a 429, because Graph may already have applied a write that came back with a 503 or 504.
It answers a wrong path with the closest real ones.
A collection read with no
selectasks for a small set of useful fields. A page of a hundred groups drops from about 223 kB to about 27 kB. Passselect: ["*"]for every field.
A script can make at most 200 Graph calls, and its output is capped at about 10,000 tokens.
In search, the script reads the index object instead. This returns the least-privileged
permission for listing Conditional Access policies:
return index.paths["/identity/conditionalAccess/policies"]?.scopes?.get?.delegated;The sandbox
Scripts run in a fresh V8 isolate inside workerd, which the server starts on your machine. The
isolate has no file system and no network. Its only way out is a call back to the server, which
holds the token and makes the Graph request, so the token never enters the script. The search
sandbox has no network at all.
GCC High
A connection names its cloud when you add it, and every call through it uses that cloud's sign-in and Graph endpoints. One server can hold commercial and GCC High tenants at the same time.
npx -y graphslayer connect --cloud usgov-high --alias agencyCloud | Sign-in | Graph |
|
|
|
|
|
|
GCC High tenants usually require a compliant device for sign-in. If the browser sign-in fails, check that the machine is enrolled in the tenant before you suspect the server.
search takes cloud: "usgov-high" to use the GCC High catalogue. It leaves out the 2,739 paths
that GCC High does not have. Its permission data is copied from commercial, because Microsoft does
not publish a GCC High version, so treat it as a guide there.
Where calls are recorded
graphslayer keeps no log of its own. Microsoft 365 records its calls in the tenant:
Record | What it shows | What it needs |
Entra sign-in log | Each sign-in, and for an agent connection, the agent and the person | Every tenant |
Entra and workload audit logs | Each change: what changed, who made it, and when | Every tenant |
Microsoft Graph activity logs | Every Graph request, reads included | Entra ID P1 or P2, and a diagnostic setting that sends the logs to Log Analytics, Storage or Event Hubs |
Every request carries User-Agent: graphslayer/<version>, so you can find the server's calls:
MicrosoftGraphActivityLogs
| where UserAgent startswith "graphslayer/"
| project TimeGenerated, UserId, AppId, RequestMethod, RequestUri, ResponseStatusCodeAn agent connection's calls are non-interactive sign-ins, which the sign-in log hides by default:
GET /beta/auditLogs/signIns?$filter=signInEventTypes/any(t: t eq 'nonInteractiveUser') and appId eq '<agent-app-id>'Configuration
Variable | What it does |
| Where connections and the token cache are kept. Default |
| Your own public client app registration for sign-in. Default is Microsoft's Graph Command Line Tools app. |
| Set to |
When your MCP client disconnects, the server shuts down workerd before it exits. If you kill the
server with kill -9, check for a leftover workerd process with pgrep -fl workerd.
Development
git clone https://github.com/poamslayer/graphslayer.git
cd graphslayer
npm install
npm test
npm run build
node dist/cli/main.js --helpTo run your build from an MCP client, use "command": "node" with
"args": ["/absolute/path/to/graphslayer/dist/cli/main.js"]. Node does not reload changed code,
so rebuild, then reconnect the client.
The design decisions are in docs/adr, and the project's vocabulary is in CONTEXT.md.
Release
Rebuild the Graph catalogue from Microsoft's current metadata, and read the report it prints. A path listed as unclassified, or a type it could not resolve, means Microsoft changed a shape, so look at it before you ship. It needs python3 with PyYAML.
npm run build:index -- --refresh npm testBump the version in a pull request and merge it.
Create the release:
gh release create v<version> --generate-notes. A GitHub Actions workflow publishes it to npm through trusted publishing, with provenance. It needs no token.
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Manage Microsoft 365 email, calendar, contacts and inbox rules via the Graph API with OAuth 2.0.
The governed runtime for agent skills. Search the catalog and inspect a skill before running it.
Permissioned access to Outlook, OneDrive and Teams via the user's own Microsoft account
Scoped agent execution. Server-side credentials, policy, budgets and verifiable receipts.
Related MCP Servers
- AlicenseNot gradedqualityFmaintenanceEnables AI assistants to interact with Microsoft 365 services (users, mail, calendar, files) via Microsoft Graph API.70 npm1MIT
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to interact with Microsoft 365 through the Microsoft Graph API, including searching Teams messages, managing chats, and sending messages.77 npmMIT
- AlicenseCqualityCmaintenanceEnables AI assistants to interact with Microsoft 365 and Office services through the Microsoft Graph API, providing tools for email, calendar, files, Teams, SharePoint, and more with configurable permissions and output formats.188MIT
- AlicenseAqualityBmaintenanceEnables AI agents to read Microsoft 365 tenant data, such as users, license usage, and stale accounts, while enforcing least-privilege by refusing to run with excessive Azure permissions.4MIT