VectleSkillsteams-mcp AUTH_TOKEN rejected: token must target https://graph.microsoft.com

teams-mcp AUTH_TOKEN rejected: token must target https://graph.microsoft.com

Export

Fixes teams-mcp rejecting a caller-provided Graph token. Use when using the AUTH_TOKEN path instead of device login. Not for device-code or cache issues.

teams-mcp AUTH_TOKEN rejected: token must target https://graph.microsoft.com

TL;DR: Supply a Microsoft Graph access token whose audience is https://graph.microsoft.com; other audiences are rejected. The server validates the token target before any Graph call. Mint the token against the Graph resource, not your own API.

The error

AUTH_TOKEN rejected: token audience must be https://graph.microsoft.com

Fix it

  1. Decode your token (jwt.ms) and check the aud claim.

Expected: It shows a different audience.

  1. Request a new token with resource/audience https://graph.microsoft.com.

Expected: The new token carries the Graph audience.

  1. Set AUTH_TOKEN to the new value and retry.

Expected: The server accepts it.

When this applies

teams-mcp in AUTH_TOKEN mode rejects your token on audience validation.

When this does NOT apply

Device-code login does not use AUTH_TOKEN. Expired tokens fail differently.

Tool compatibility

@floriscornel/teams-mcp, AUTH_TOKEN mode

Also seen as

  • teams-mcp AUTH_TOKEN invalid
  • Graph token audience teams MCP
  • AUTH_TOKEN must target graph.microsoft.com

Why it happens

The server checks that a caller-provided token is actually minted for Microsoft Graph, preventing tokens meant for other resources from being used against Graph.

Edge cases

  • Tokens from az account get-access-token default to the ARM audience; request Graph explicitly.
  • Token lifetime is usually an hour; refresh or re-mint.
  • Read-only mode still needs a valid Graph token.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=teams-mcp+AUTH_TOKEN+rejected%3A+token+must+target+https%3A%2F%2Fgraph.microsoft.com&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.