Read, search, draft, send and organize Microsoft Outlook mail via Microsoft Graph, safe by default.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
A safe-by-default Model Context Protocol server for Microsoft Outlook mail, over Microsoft Graph. It lets an agent read and operate a mailbox β list folders and messages, full-text search, read bodies and attachment metadata, list contacts, and (in higher modes) create drafts, send / reply / forward, mark read, move messages, and delete. It also manages OneDrive files β browse, search, download, upload, create folders, move/rename, and delete.
Browser sign-in: on first run it opens your browser to the Microsoft sign-in page, then caches the token and refreshes it silently β the server never sees your password.
Part of the dockndevai MCP server suite β one governance model across all of them.
The server starts read-only (see Safe by default); higher-capability tools are only registered when you raise the mode.
| Tool | For | Needs mode |
|---|---|---|
whoami | confirm which mailbox is in use | read-only |
list_folders | mail folders with unread/total counts | read-only |
list_messages | recent messages (by folder, unread-only) | read-only |
search_messages | full-text search across the mailbox | read-only |
get_message | one message with full body + recipients | read-only |
list_attachments | attachment metadata (bytes not returned) | read-only |
list_contacts | personal contacts | read-only |
create_draft | prepare a draft without sending | read-write |
send_mail | compose & send a new email | read-write + OUTLOOK_ALLOW_SEND |
reply_mail / forward_mail | reply (all) / forward a message | read-write + OUTLOOK_ALLOW_SEND |
mark_read | mark read / unread (reversible) | read-write |
move_message | move to another folder (reversible) | read-write |
delete_message | delete (to Deleted Items) | admin + OUTLOOK_ALLOW_DELETE |
list_drive_items / get_drive_item | browse OneDrive files & folders | read-only |
search_drive_files | search OneDrive | read-only |
download_drive_file | read a OneDrive file's text | read-only |
upload_drive_file | create/overwrite a OneDrive file | read-write |
create_drive_folder / move_drive_item | create folder / move-rename | read-write |
delete_drive_item | delete a OneDrive item (β recycle bin) | admin + OUTLOOK_ALLOW_DELETE |
You need an Entra (Azure AD) app registration. For the default browser sign-in, register a public client and add the redirect URI http://localhost (platform: Mobile and desktop applications), then use its Application (client) ID as OUTLOOK_CLIENT_ID. Grant delegated Mail.Read (and Mail.Send / Mail.ReadWrite if you want to send or organize). No client secret is needed for interactive use.
Prefer automation? Use app-only auth instead: set OUTLOOK_CLIENT_SECRET + OUTLOOK_TENANT_ID + OUTLOOK_USER (see Authentication).
On first use the server opens your browser to sign in and caches the token at ~/.mcp-outlook/token.json (0600); later runs refresh silently.
See docs/CLIENTS.md for Claude Code / Cursor / Codex / VS Code / Windsurf snippets, and .env.example for every supported variable.
Auth mode is chosen automatically (override with OUTLOOK_AUTH):
OUTLOOK_CLIENT_ID set. Authorization-code + PKCE with a loopback redirect: the browser opens, you approve once, and the access + refresh token are cached on disk. Operates on the signed-in user's mailbox (/me). The server never handles your password.OUTLOOK_CLIENT_SECRET present. The server fetches an app token itself; requires OUTLOOK_TENANT_ID and OUTLOOK_USER (the mailbox to act on, since an app token has no signed-in user). Grant the app application Mail permissions with admin consent.OUTLOOK_TOKEN set to a pre-obtained Graph bearer token. You manage its lifetime.The access model is enforced by src/security.ts β defence in depth on top of the Graph token's own scopes/roles:
OUTLOOK_MODE β read-only (default) β read-write β admin. A tool is registered only if the mode allows its capability. Read-only exposes the 7 read tools; drafts/moves need read-write; deletes need admin.OUTLOOK_ALLOW_SEND β sending mail (send / reply / forward) can't be undone, so on top of read-write it also requires this flag. Drafting is always allowed in read-write; nothing leaves the mailbox until sent.OUTLOOK_ALLOW_DELETE β deletes require this flag on top of admin mode.OUTLOOK_FOLDER_ALLOWLIST / OUTLOOK_PROTECTED_FOLDERS β confine which folders can be written to / moved into; mark folders (e.g. sentitems, archive) that may be read but never modified.OUTLOOK_ALLOW_SEND / OUTLOOK_ALLOW_DELETE gates.OUTLOOK_DRY_RUN β validate and log writes without executing them.OUTLOOK_AUDIT_LOG β a JSON audit line per guarded operation, on stderr (default on).list_attachments returns metadata only.See SECURITY.md.
MIT
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/mcp-outlook)<a href="https://allmcps.com/mcp/mcp-outlook"><img src="https://allmcps.com/api/badge/mcp-outlook?style=directory" alt="MCP Outlook on AllMCPs" /></a>