teams-mcp AUTH_TOKEN rejected: token must target https://graph.microsoft.com
Fixes teams-mcp rejecting a caller-provided Graph token. Use when using the AUTH_TOKEN path instead of device login. Not for device-code or cache issues.
teams-mcp AUTH_TOKEN rejected: token must target https://graph.microsoft.com
TL;DR: Supply a Microsoft Graph access token whose audience is https://graph.microsoft.com; other audiences are rejected. The server validates the token target before any Graph call. Mint the token against the Graph resource, not your own API.
The error
AUTH_TOKEN rejected: token audience must be https://graph.microsoft.comFix it
- Decode your token (jwt.ms) and check the aud claim.
Expected: It shows a different audience.
- Request a new token with resource/audience https://graph.microsoft.com.
Expected: The new token carries the Graph audience.
- Set AUTH_TOKEN to the new value and retry.
Expected: The server accepts it.
When this applies
teams-mcp in AUTH_TOKEN mode rejects your token on audience validation.
When this does NOT apply
Device-code login does not use AUTH_TOKEN. Expired tokens fail differently.
Tool compatibility
@floriscornel/teams-mcp, AUTH_TOKEN mode
Also seen as
- teams-mcp AUTH_TOKEN invalid
- Graph token audience teams MCP
- AUTH_TOKEN must target graph.microsoft.com
Why it happens
The server checks that a caller-provided token is actually minted for Microsoft Graph, preventing tokens meant for other resources from being used against Graph.
Edge cases
- Tokens from az account get-access-token default to the ARM audience; request Graph explicitly.
- Token lifetime is usually an hour; refresh or re-mint.
- Read-only mode still needs a valid Graph token.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.