Repository navigation
Add teams CLI: browser sign-in, channel search, and JSON output for agents - #1
Merged
Merged
Conversation
…output Co-authored-by: glenthomas <20847558+glenthomas@users.noreply.github.com>
Co-authored-by: glenthomas <20847558+glenthomas@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Add CLI for accessing data from Microsoft Teams
Add Sep 30, 2026
teams CLI: browser sign-in, channel search, and JSON output for agents
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a Go CLI that AI coding agents can call instead of an MCP server to read Microsoft Teams data through Microsoft Graph. Users sign in through a browser window opened by the CLI.
Auth (
internal/auth,internal/config)teams loginuses MSAL's interactive flow (auth code + PKCE,http://localhostredirect). If the browser can't be opened, the sign-in URL is printed to stderr.--device-codecovers headless machines;--timeoutdefaults to 5m.$TEAMS_CLI_CONFIG_DIRor the OS config dir). Tokens refresh silently. Login keeps only the account that just signed in.14d82eec-…) with tenantorganizations. Override with--client-id/--tenantor theTEAMS_CLI_CLIENT_ID/TEAMS_CLI_TENANT_IDenv vars. The values used at login are saved and reused by later commands.TEAMS_CLI_ACCESS_TOKENskips MSAL entirely (CI, or bring your own token).User.Read,Team.ReadBasic.All,Channel.ReadBasic.All,ChannelMessage.Read.All. The last one usually needs admin consent.Graph client (
internal/graph)@odata.nextLink, and retries on 429/502/503/504 that honourRetry-After(capped at 60s).nextLinkonly if it points to the Graph host, so the bearer token is never sent anywhere else.graphtestis an in-memory fake Graph server with seeded fixtures, used by the tests.Commands (
internal/cli,internal/teams)login,logout,whoami,teams,channels,messages,search,thread.--channel/--teamtake a name or an ID. Names match case-insensitively and ignoring punctuation, soplatform-engineeringfinds "Platform Engineering". If a name matches in several teams, the CLI returns anambiguouserror listing the matches. Not-found errors include the available names, capped at 100./messages?$top=50&$expand=replies, assuming Graph returns threads newest-activity-first, then filters locally by time window and query terms.--since, and caps the scan at--max-threads(default 1000) per channel."quoted phrases"must match exactly. HTML bodies are converted to plain text.type(messageorreply),threadId, team/channel, author, text,webUrl,replyCount. Envelope fieldstruncatedandwarningssay when results were cut short.--format textgives human-readable output.{"error":{code,message,details}}, with stable exit codes:error,timeoutusagenot_logged_in(missing session, or Graph 401)not_found,ambiguousforbidden,throttled,graph_errorReview notes
truncated.$expand=replies, and replies beyond whatever Graph returns inline are not paged separately.login.microsoftonline.com.Original prompt