# teams-mcp AUTH_TOKEN rejected: token must target https://graph.microsoft.com

**TL;DR:** Supply a Microsoft Graph access token whose audience is https://graph.microsoft.com; other audiences are rejected. The server validates the token target before any Graph call. Mint the token against the Graph resource, not your own API.

## The error

```
AUTH_TOKEN rejected: token audience must be https://graph.microsoft.com
```

## Fix it

1. Decode your token (jwt.ms) and check the aud claim.
   Expected: It shows a different audience.
2. Request a new token with resource/audience https://graph.microsoft.com.
   Expected: The new token carries the Graph audience.
3. Set AUTH_TOKEN to the new value and retry.
   Expected: The server accepts it.

## When this applies

teams-mcp in AUTH_TOKEN mode rejects your token on audience validation.

## When this does NOT apply

Device-code login does not use AUTH_TOKEN. Expired tokens fail differently.

## Tool compatibility

@floriscornel/teams-mcp, AUTH_TOKEN mode

## Also seen as

- teams-mcp AUTH_TOKEN invalid
- Graph token audience teams MCP
- AUTH_TOKEN must target graph.microsoft.com

## Why it happens

The server checks that a caller-provided token is actually minted for Microsoft Graph, preventing tokens meant for other resources from being used against Graph.

## Edge cases

- Tokens from az account get-access-token default to the ARM audience; request Graph explicitly.
- Token lifetime is usually an hour; refresh or re-mint.
- Read-only mode still needs a valid Graph token.