Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for Outlook MCP by mpalermiti

Pod holds 16 of 16 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to Outlook MCP by mpalermiti.

Most discussed

me-token-to-replace is invalid on fresh install — microsoft-kiota >=1.13.0 breaks /me calls

Just want to start off by saying I LOVE this tool—thanks for building this. Really helpful to integrate Microsoft into my Hermes agent

Noticed that uv tool install outlook-graph-mcp==1.22.0 pulls the latest microsoft-kiota-* (1.14.0), because nothing caps its version.

Tested these:

kiota msgraph-sdk result
1.14.0 1.62.0 fails
1.13.0 1.62.0 fails
1.12.3 1.63.0 works

My workaround was to constrain to an older version

Read the thread · 2026-09-24 · open · external user · 5 comments

oauth: first-time MSA device-code consent via .default can land with no delegated permissions — AADSTS70000 blocks redeeming scopes afterwards

oauth: A first-time MSA device-code consent asked for .default can land with no delegated permissions on the session — and AADSTS70000 blocks redeeming scopes afterwards

On a consumer account (consumers tenant), walking the device-code flow with only https://graph.microsoft.com/.default as the scope can produce a session that authenticates but carries no delegated permissions. That session then cannot mint a scoped token later — the redeem attempt fails with:

AADSTS70000: The…

[Read the thread](https://github.com/mpalermiti/outlook-mcp/issues/82) · 2026-09-25 · open · outside contributor · 2 comments

### Auth fails after uv tool install

Hi, I hit an auth failure after installing with `uv tool install outlook-graph-mcp` on Ubuntu.

`outlook-mcp auth` fails before the device code is shown. The error comes from `azure-identity` / `msal_extensions` trying to use libsecret for the token cache, but the Python environment created by `uv tool` cannot import `gi`:

```text
ModuleNotFoundError: No module named 'gi'

ImportError: Unable to import module 'gi'
Runtime dependency of PyGObject is missing.

ValueError: Cache encryption is…

[Read the thread](https://github.com/mpalermiti/outlook-mcp/issues/7) · 2026-05-01 · closed · outside contributor · 2 comments

### Relative datetimes (+2h, now) pass validation on write paths and reach Graph verbatim as a 400

## Summary

`validate_datetime` accepts relative offsets (`+2h`, `7d`, `now`) on every datetime parameter — that was 1.20.0's headline ergonomics fix, driven by traces showing `after="7d"` refused 50 times. The **write** paths call it for its exception and discard the normalized value, so on those paths a relative offset passes validation and the literal token is sent to Graph.

`outlook_create_event(start="+2h", end="+3h")` therefore fails with:

ODataError: The value '+3h' of parameter…

Read the thread · 2026-09-21 · open · outside contributor · 1 comment

Calendar events are always anchored in UTC, so recurring series drift an hour across a DST boundary

Summary

outlook_create_event labels every start and end with the literal string timeZone: "UTC", regardless of what the caller asked for. For a single event that is lossy but harmless — the instant is correct, and only the zone it was scheduled in is lost. For a recurring event it is a correctness bug: Graph expands a series against the zone its master is anchored in, so a weekly 09:00 meeting created through this server becomes 08:00 the week daylight saving ends, and stays…

Read the thread · 2026-09-21 · closed · outside contributor · 1 comment

Graph now honours isOnlineMeeting on consumer mailboxes — the live test that pinned the old behaviour is failing, correctly

Summary

test_online_meeting_is_not_supported_on_personal_accounts fails on a current consumer mailbox, and it is right to. Graph now honours isOnlineMeeting on a personal Microsoft account and mints a real teams.live.com meeting. The test did exactly what its own docstring said it would:

If Microsoft ever starts honouring it, this test fails and tells us the parameter is worth adding.

That is the whole value of the pattern, so this is a report rather than a complaint. Three docs…

Read the thread · 2026-09-21 · open · outside contributor · 1 comment

outlook_list_events returns type: "" for every event — the $select never asks Graph for it

Summary

Three defects in one contract, each independently fixable. The first is the live one; the second is waste; the third turns into a user-visible lie the moment the first is fixed.

I found these while investigating an unrelated gap (showAs, PR to follow) and am not fixing them there — one concern per PR. Happy to take any or all of them if you'd like.

Environment

Read the thread · 2026-09-21 · open · outside contributor · 1 comment

Windows: every calendar tool fails (no IANA tz database), and the test suite cannot run

Running outlook-mcp on Windows 11, every calendar tool fails, and the test suite cannot complete. All of it traces back to POSIX assumptions rather than anything Graph-related.

Environment: Windows 11 (10.0.26200), Python 3.12.13, uv 0.12.5, at a6f6ac7.

1. No IANA time zone database — every calendar tool fails

outlook_list_events returns a message-free failure:

Error executing tool outlook_list_events

The real cause, caught by calling the code path directly:…

Read the thread · 2026-09-12 · closed · outside contributor · 1 comment

Most recent

Four tests always fail on Windows, from two causes — and the chmod one makes config.py's permission hardening inert there

Summary

Four tests fail on every run on Windows, from two different causes. Neither is a flake and neither can pass there, so a Windows contributor starts from a red suite and has to learn which four reds are theirs — I have been discounting them by hand across three pull requests, which is exactly the habit a permanently-red test creates.

The three chmod ones share a root cause that also affects the product: on Windows those calls do not do what the code believes, so config.py's…

Read the thread · 2026-09-25 · open · outside contributor · 0 comments

outlook_create_event ignores recurrence — recurring series cannot be created

Bug Description

outlook_create_event ignores the recurrence argument entirely — recurring (series) events cannot be created through the MCP server. The parameter is accepted by the tool schema, but never applied to the Graph event, so every "recurring" event is created as a single occurrence with recurrence: null.

Verified on outlook-graph-mcp 1.12.0 AND 1.14.0 (latest), mcp SDK 2.x, personal @outlook.com account.

Steps to Reproduce

  1. Call outlook_create_event with a…

Read the thread · 2026-09-07 · closed · external user · 0 comments

list_inbox: unconditional $orderby makes from_address and classification return 400 InefficientFilter on every call

Summary

list_inbox sets $orderby=receivedDateTime desc unconditionally, which violates Graph's filter/sort compatibility rules. Two advertised outlook_list_inbox parameters — from_address and classification — therefore return 400 InefficientFilter on every invocation in the shipped release.

Cause

src/outlook_mcp/tools/mail_read.py:122

query_params["$orderby"] = "receivedDateTime desc"

set unconditionally, while receivedDateTime only enters $filter…

Read the thread · 2026-09-03 · closed · 0 comments

outlook_search_mail: sanitize_kql strips ':' — documented KQL property restrictions silently return 0 results

Summary

sanitize_kql strips : from search queries, so every KQL property restriction that outlook_search_mail advertises in its own docstring is silently turned into a literal free-text phrase. Graph returns HTTP 200 with 0 results — no error — so a calling agent concludes there is no matching mail.

Cause

src/outlook_mcp/validation.py:16

_KQL_DANGEROUS = re.compile(r'[":()&|!*\\]')

src/outlook_mcp/validation.py:85-88

def sanitize_kql(query: str)…

[Read the thread](https://github.com/mpalermiti/outlook-mcp/issues/30) · 2026-09-03 · closed · 0 comments

### download_attachment double-decodes contentBytes → UnicodeDecodeError on all binary attachments (regression from #9)

## Summary

`outlook_download_attachment` fails on any non-text attachment (.docx, .pdf, images, etc.) with:

'utf-8' codec can't decode bytes in position 15-16: invalid continuation byte


Text attachments may coincidentally succeed; any file whose bytes aren't valid UTF-8 always fails, so in practice attachment download is broken for most real-world files.

## Root cause

`src/outlook_mcp/tools/mail_attachments.py`, `download_attachment()` (currently line 93 on `main`):

```python…

[Read the thread](https://github.com/mpalermiti/outlook-mcp/issues/25) · 2026-07-14 · closed · external user · 0 comments

### SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed

uv run outlook-mcp auth Authenticating with read-only scopes...

Token cache will be stored unencrypted on disk because PyGObject/libsecret is not importable in this Python environment (common with uv tool install on Linux — the tool's isolated venv can't see system PyGObject). To enable encrypted caching via libsecret/gnome-keyring, install the system packages (apt: gnome-keyring libsecret-1-0 python3-gi) and re-create the venv with --system-site-packages. See…

Read the thread · 2026-06-29 · closed · external user · 1 comment

outlook_create_task fails with 'dict' object has no attribute 'serialize' error

: outlook_create_task fails with "'dict' object has no attribute 'serialize'" error

Severity

High (blocks all task creation)

Summary

The task creation tool fails when attempting to create a task with due date, importance, or body fields. The Microsoft Graph SDK expects typed model objects but the code passes raw Python dictionaries.

Error Message

'dict' object has no attribute 'serialize'

Root Cause

The create_task() function builds the task payload as a raw dict[str, Any] and…

Read the thread · 2026-04-21 · closed · external user · 1 comment

outlook_list_contacts and outlook_search_contacts fail with phones property error

Bug Report #1: Contacts Listing Fails with Graph API 400 Error

Title

outlook_list_contacts and outlook_search_contacts fail with "phones property not found" error

Severity

High (blocks all contact operations)

Summary

The contacts listing and search tools fail with a Microsoft Graph API 400 error when attempting to query contact data. The error message indicates that the phones property is not available on the consumer Graph API contacts endpoint.

Error Message

Could not find a…

Read the thread · 2026-04-21 · closed · external user · 1 comment

The remaining reports are on the project's issue tracker.