Reported issues for Outlook MCP by mpalermiti
Pod holds 16 of 16 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.
Back to Outlook MCP by mpalermiti.
Most discussed
me-token-to-replace is invalid on fresh install — microsoft-kiota >=1.13.0 breaks /me calls
Just want to start off by saying I LOVE this tool—thanks for building this. Really helpful to integrate Microsoft into my Hermes agent
Noticed that uv tool install outlook-graph-mcp==1.22.0 pulls the latest microsoft-kiota-* (1.14.0), because nothing caps its version.
Tested these:
| kiota | msgraph-sdk | result |
|---|---|---|
| 1.14.0 | 1.62.0 | fails |
| 1.13.0 | 1.62.0 | fails |
| 1.12.3 | 1.63.0 | works |
My workaround was to constrain to an older version
Read the thread · 2026-09-24 · open · external user · 5 comments
oauth: first-time MSA device-code consent via .default can land with no delegated permissions — AADSTS70000 blocks redeeming scopes afterwards
oauth: A first-time MSA device-code consent asked for .default can land with no delegated permissions on the session — and AADSTS70000 blocks redeeming scopes afterwards
On a consumer account (consumers tenant), walking the device-code flow with only https://graph.microsoft.com/.default as the scope can produce a session that authenticates but carries no delegated permissions. That session then cannot mint a scoped token later — the redeem attempt fails with:
AADSTS70000: The…
[Read the thread](https://github.com/mpalermiti/outlook-mcp/issues/82) · 2026-09-25 · open · outside contributor · 2 comments
### Auth fails after uv tool install
Hi, I hit an auth failure after installing with `uv tool install outlook-graph-mcp` on Ubuntu.
`outlook-mcp auth` fails before the device code is shown. The error comes from `azure-identity` / `msal_extensions` trying to use libsecret for the token cache, but the Python environment created by `uv tool` cannot import `gi`:
```text
ModuleNotFoundError: No module named 'gi'
ImportError: Unable to import module 'gi'
Runtime dependency of PyGObject is missing.
ValueError: Cache encryption is…
[Read the thread](https://github.com/mpalermiti/outlook-mcp/issues/7) · 2026-05-01 · closed · outside contributor · 2 comments
### Relative datetimes (+2h, now) pass validation on write paths and reach Graph verbatim as a 400
## Summary
`validate_datetime` accepts relative offsets (`+2h`, `7d`, `now`) on every datetime parameter — that was 1.20.0's headline ergonomics fix, driven by traces showing `after="7d"` refused 50 times. The **write** paths call it for its exception and discard the normalized value, so on those paths a relative offset passes validation and the literal token is sent to Graph.
`outlook_create_event(start="+2h", end="+3h")` therefore fails with:
ODataError: The value '+3h' of parameter…
Read the thread · 2026-09-21 · open · outside contributor · 1 comment
Calendar events are always anchored in UTC, so recurring series drift an hour across a DST boundary
Summary
outlook_create_event labels every start and end with the literal string timeZone: "UTC", regardless of what the caller asked for. For a single event that is lossy but harmless — the instant is correct, and only the zone it was scheduled in is lost. For a recurring event it is a correctness bug: Graph expands a series against the zone its master is anchored in, so a weekly 09:00 meeting created through this server becomes 08:00 the week daylight saving ends, and stays…
Read the thread · 2026-09-21 · closed · outside contributor · 1 comment
Graph now honours isOnlineMeeting on consumer mailboxes — the live test that pinned the old behaviour is failing, correctly
Summary
test_online_meeting_is_not_supported_on_personal_accounts fails on a current consumer mailbox, and it is right to. Graph now honours isOnlineMeeting on a personal Microsoft account and mints a real teams.live.com meeting. The test did exactly what its own docstring said it would:
If Microsoft ever starts honouring it, this test fails and tells us the parameter is worth adding.
That is the whole value of the pattern, so this is a report rather than a complaint. Three docs…
Read the thread · 2026-09-21 · open · outside contributor · 1 comment
outlook_list_events returns type: "" for every event — the $select never asks Graph for it
Summary
Three defects in one contract, each independently fixable. The first is the live one; the second is waste; the third turns into a user-visible lie the moment the first is fixed.
I found these while investigating an unrelated gap (showAs, PR to follow) and am not fixing them there — one concern per PR. Happy to take any or all of them if you'd like.
Environment
outlook-graph-mcp1.22.0, commit6c70b55e8274c49ab2b3481e1c71e8ffb0733f65msgraph-sdk1.62.0, Python…
Read the thread · 2026-09-21 · open · outside contributor · 1 comment
Windows: every calendar tool fails (no IANA tz database), and the test suite cannot run
Running outlook-mcp on Windows 11, every calendar tool fails, and the test suite cannot complete. All of it traces back to POSIX assumptions rather than anything Graph-related.
Environment: Windows 11 (10.0.26200), Python 3.12.13, uv 0.12.5, at a6f6ac7.
1. No IANA time zone database — every calendar tool fails
outlook_list_events returns a message-free failure:
Error executing tool outlook_list_events
The real cause, caught by calling the code path directly:…
Read the thread · 2026-09-12 · closed · outside contributor · 1 comment
Most recent
Four tests always fail on Windows, from two causes — and the chmod one makes config.py's permission hardening inert there
Summary
Four tests fail on every run on Windows, from two different causes. Neither is a flake and neither can pass there, so a Windows contributor starts from a red suite and has to learn which four reds are theirs — I have been discounting them by hand across three pull requests, which is exactly the habit a permanently-red test creates.
The three chmod ones share a root cause that also affects the product: on Windows those calls do not do what the code believes, so config.py's…
Read the thread · 2026-09-25 · open · outside contributor · 0 comments
outlook_create_event ignores recurrence — recurring series cannot be created
Bug Description
outlook_create_event ignores the recurrence argument entirely — recurring (series) events cannot be created through the MCP server. The parameter is accepted by the tool schema, but never applied to the Graph event, so every "recurring" event is created as a single occurrence with recurrence: null.
Verified on outlook-graph-mcp 1.12.0 AND 1.14.0 (latest), mcp SDK 2.x, personal @outlook.com account.
Steps to Reproduce
- Call
outlook_create_eventwith a…
Read the thread · 2026-09-07 · closed · external user · 0 comments
list_inbox: unconditional $orderby makes from_address and classification return 400 InefficientFilter on every call
Summary
list_inbox sets $orderby=receivedDateTime desc unconditionally, which violates Graph's filter/sort compatibility rules. Two advertised outlook_list_inbox parameters — from_address and classification — therefore return 400 InefficientFilter on every invocation in the shipped release.
Cause
src/outlook_mcp/tools/mail_read.py:122
query_params["$orderby"] = "receivedDateTime desc"
set unconditionally, while receivedDateTime only enters $filter…
Read the thread · 2026-09-03 · closed · 0 comments
outlook_search_mail: sanitize_kql strips ':' — documented KQL property restrictions silently return 0 results
Summary
sanitize_kql strips : from search queries, so every KQL property restriction that outlook_search_mail advertises in its own docstring is silently turned into a literal free-text phrase. Graph returns HTTP 200 with 0 results — no error — so a calling agent concludes there is no matching mail.
Cause
src/outlook_mcp/validation.py:16
_KQL_DANGEROUS = re.compile(r'[":()&|!*\\]')
src/outlook_mcp/validation.py:85-88
def sanitize_kql(query: str)…
[Read the thread](https://github.com/mpalermiti/outlook-mcp/issues/30) · 2026-09-03 · closed · 0 comments
### download_attachment double-decodes contentBytes → UnicodeDecodeError on all binary attachments (regression from #9)
## Summary
`outlook_download_attachment` fails on any non-text attachment (.docx, .pdf, images, etc.) with:
'utf-8' codec can't decode bytes in position 15-16: invalid continuation byte
Text attachments may coincidentally succeed; any file whose bytes aren't valid UTF-8 always fails, so in practice attachment download is broken for most real-world files.
## Root cause
`src/outlook_mcp/tools/mail_attachments.py`, `download_attachment()` (currently line 93 on `main`):
```python…
[Read the thread](https://github.com/mpalermiti/outlook-mcp/issues/25) · 2026-07-14 · closed · external user · 0 comments
### SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed
uv run outlook-mcp auth Authenticating with read-only scopes...
Token cache will be stored unencrypted on disk because PyGObject/libsecret is not importable in this Python environment (common with uv tool install on Linux — the tool's isolated venv can't see system PyGObject). To enable encrypted caching via libsecret/gnome-keyring, install the system packages (apt: gnome-keyring libsecret-1-0 python3-gi) and re-create the venv with --system-site-packages. See…
Read the thread · 2026-06-29 · closed · external user · 1 comment
outlook_create_task fails with 'dict' object has no attribute 'serialize' error
: outlook_create_task fails with "'dict' object has no attribute 'serialize'" error
Severity
High (blocks all task creation)
Summary
The task creation tool fails when attempting to create a task with due date, importance, or body fields. The Microsoft Graph SDK expects typed model objects but the code passes raw Python dictionaries.
Error Message
'dict' object has no attribute 'serialize'
Root Cause
The create_task() function builds the task payload as a raw dict[str, Any] and…
Read the thread · 2026-04-21 · closed · external user · 1 comment
outlook_list_contacts and outlook_search_contacts fail with phones property error
Bug Report #1: Contacts Listing Fails with Graph API 400 Error
Title
outlook_list_contacts and outlook_search_contacts fail with "phones property not found" error
Severity
High (blocks all contact operations)
Summary
The contacts listing and search tools fail with a Microsoft Graph API 400 error when attempting to query contact data. The error message indicates that the phones property is not available on the consumer Graph API contacts endpoint.
Error Message
Could not find a…
Read the thread · 2026-04-21 · closed · external user · 1 comment
The remaining reports are on the project's issue tracker.