outlook-delegateRead, search, and manage Outlook emails and calendar via Microsoft Graph API with delegate support. Supports sending as self, as owner (Send As), and on behalf of owner (Send on Behalf). Modified for delegate access from https://clawhub.ai/jotamed/outlook
Install via ClawdBot CLI:
clawdbot install 87Marc/outlook-delegateAccess another user's Outlook/Microsoft 365 email and calendar as a delegate via Microsoft Graph API. Supports three sending modes: as yourself, as the owner, or on behalf of the owner.
This skill is designed for scenarios where:
All three modes use the same Graph API call (/users/{delegate}/sendMail with the from field set). The difference between Send As and Send on Behalf is determined entirely by which Exchange permission is granted, not by the API endpoint.
| Mode | Command | Exchange Permission Required | from field | sender field | What Recipient Sees |
|------|---------|------------------------------|--------------|----------------|---------------------|
| As Self | send | (none extra) | Delegate | Delegate | "From: Assistant" |
| As Owner (Send As) | send-as | SendAs only | Owner | Owner | "From: Owner" |
| On Behalf Of | send-behalf | SendOnBehalf only | Owner | Delegate | "From: Assistant on behalf of Owner" |
ā ļø CRITICAL: Do NOT grant both SendAs and SendOnBehalf permissions. If both are granted, Exchange always uses SendAs, and the "on behalf of" indication will never appear. Choose ONE based on your desired behavior.
When you call send-as or send-behalf, the skill makes the same API call: it sends via the delegate's endpoint with the owner in the from field. Microsoft Graph automatically sets the sender property to the authenticated user (the delegate). Whether the recipient sees "on behalf of" depends solely on the Exchange permission:
sender and from to the owner. No indication of delegation.sender as the delegate and from as the owner. Recipient sees "on behalf of."~/.outlook-mcp/config.json{
"client_id": "your-app-client-id",
"client_secret": "your-app-client-secret",
"tenant_id": "your-tenant-id",
"owner_email": "owner@yourdomain.com",
"owner_name": "Owner Display Name",
"delegate_email": "assistant@yourdomain.com",
"delegate_name": "AI Assistant",
"timezone": "America/New_York"
}
| Field | Description |
|-------|-------------|
| client_id | Microsoft Entra ID App Registration client ID |
| client_secret | Microsoft Entra ID App Registration client secret |
| tenant_id | Your Microsoft Entra tenant ID (auto-detected during setup) |
| owner_email | The mailbox the assistant accesses as delegate |
| owner_name | Display name for the owner (used in From field) |
| delegate_email | The assistant's own email address |
| delegate_name | Display name for the assistant |
| timezone | IANA timezone for calendar operations (e.g., America/New_York, Europe/London, UTC) |
Create an app registration in Azure Portal:
http://localhost:8400/callbackIn your app ā API permissions ā Add a permission ā Microsoft Graph ā Delegated permissions:
Required for all modes:
Mail.ReadWrite ā Read/write assistant's own mailMail.Send ā Send mail as assistantCalendars.ReadWrite ā Read/write calendarsUser.Read ā Read own profileoffline_access ā Refresh tokensRequired for delegate access:
Mail.ReadWrite.Shared ā Read/write shared mailboxesMail.Send.Shared ā Send on behalf of othersCalendars.ReadWrite.Shared ā Read/write shared calendarsClick "Grant admin consent" (requires admin).
The owner (or an admin) must grant the assistant access via PowerShell.
Choose your sending mode FIRST, then grant the appropriate permissions:
# Connect to Exchange Online
Install-Module -Name ExchangeOnlineManagement
Connect-ExchangeOnline -UserPrincipalName admin@yourdomain.com
# REQUIRED: Full Mailbox Access (for reading owner's mail)
Add-MailboxPermission -Identity "owner@yourdomain.com" `
-User "assistant@yourdomain.com" `
-AccessRights FullAccess `
-InheritanceType All `
-AutoMapping $false
# REQUIRED: Calendar Delegate Access
Add-MailboxFolderPermission -Identity "owner@yourdomain.com:\Calendar" `
-User "assistant@yourdomain.com" `
-AccessRights Editor `
-SharingPermissionFlags Delegate
Then choose ONE of the following ā do NOT grant both:
# OPTION A: Send As (emails appear directly from owner, no indication)
Add-RecipientPermission -Identity "owner@yourdomain.com" `
-Trustee "assistant@yourdomain.com" `
-AccessRights SendAs `
-Confirm:$false
# OPTION B: Send on Behalf (emails show "assistant on behalf of owner")
Set-Mailbox -Identity "owner@yourdomain.com" `
-GrantSendOnBehalfTo "assistant@yourdomain.com"
Verify permissions:
# Check mailbox permissions
Get-MailboxPermission -Identity "owner@yourdomain.com" | Where-Object {$_.User -like "*assistant*"}
# Check Send As
Get-RecipientPermission -Identity "owner@yourdomain.com" | Where-Object {$_.Trustee -like "*assistant*"}
# Check Send on Behalf
Get-Mailbox "owner@yourdomain.com" | Select-Object GrantSendOnBehalfTo
# Check Calendar permissions
Get-MailboxFolderPermission -Identity "owner@yourdomain.com:\Calendar"
| Action | Graph Permission | Exchange Permission |
|--------|-----------------|---------------------|
| Read owner's mail | Mail.ReadWrite.Shared | FullAccess |
| Send as self | Mail.Send | (none needed) |
| Send as owner | Mail.Send.Shared | SendAs only |
| Send on behalf of owner | Mail.Send.Shared | SendOnBehalf only |
| Read/write owner's calendar | Calendars.ReadWrite.Shared | Editor |
./scripts/outlook-token.sh refresh # Refresh expired token
./scripts/outlook-token.sh test # Test connection to both accounts
./scripts/outlook-token.sh get # Print access token
./scripts/outlook-token.sh info # Show configuration info
./scripts/outlook-mail.sh inbox [count] # Owner's inbox
./scripts/outlook-mail.sh unread [count] # Owner's unread
./scripts/outlook-mail.sh search "query" [count] # Search owner's mail
./scripts/outlook-mail.sh from <email> [count] # Owner's mail from sender
./scripts/outlook-mail.sh read <id> # Read email content
./scripts/outlook-mail.sh attachments <id> # List attachments
./scripts/outlook-mail.sh mark-read <id> # Mark as read
./scripts/outlook-mail.sh mark-unread <id> # Mark as unread
./scripts/outlook-mail.sh flag <id> # Flag as important
./scripts/outlook-mail.sh unflag <id> # Remove flag
./scripts/outlook-mail.sh delete <id> # Move to trash
./scripts/outlook-mail.sh archive <id> # Move to archive
./scripts/outlook-mail.sh move <id> <folder> # Move to folder
As Assistant (self):
./scripts/outlook-mail.sh send <to> <subject> <body>
./scripts/outlook-mail.sh reply <id> "body"
./scripts/outlook-mail.sh forward <id> <to> [message]
Recipient sees: "From: AI Assistant
As Owner (Send As ā requires SendAs permission, no indication):
./scripts/outlook-mail.sh send-as <to> <subject> <body>
./scripts/outlook-mail.sh reply-as <id> "body"
./scripts/outlook-mail.sh forward-as <id> <to> [message]
Recipient sees: "From: Owner
On Behalf of Owner (requires SendOnBehalf permission):
./scripts/outlook-mail.sh send-behalf <to> <subject> <body>
./scripts/outlook-mail.sh reply-behalf <id> "body"
./scripts/outlook-mail.sh forward-behalf <id> <to> [message]
Recipient sees: "From: AI Assistant on behalf of Owner
./scripts/outlook-mail.sh draft <to> <subject> <body> # Create draft in owner's mailbox
./scripts/outlook-mail.sh drafts [count] # List owner's drafts
./scripts/outlook-mail.sh send-draft <id> # Send draft as self
./scripts/outlook-mail.sh send-draft-as <id> # Send draft as owner
./scripts/outlook-mail.sh send-draft-behalf <id> # Send draft on behalf of owner
./scripts/outlook-mail.sh folders # List mail folders
./scripts/outlook-mail.sh stats # Inbox statistics
./scripts/outlook-mail.sh whoami # Show delegate info
Viewing Events:
./scripts/outlook-calendar.sh events [count] # Owner's upcoming events (future only)
./scripts/outlook-calendar.sh today # Today's events (timezone-aware)
./scripts/outlook-calendar.sh week # This week's events
./scripts/outlook-calendar.sh read <id> # Event details
./scripts/outlook-calendar.sh calendars # List all calendars
./scripts/outlook-calendar.sh free <start> <end> # Check availability
Creating Events:
./scripts/outlook-calendar.sh create <subject> <start> <end> [location]
./scripts/outlook-calendar.sh quick <subject> [time]
Date format: YYYY-MM-DDTHH:MM (e.g., 2026-01-26T10:00)
Managing Events:
./scripts/outlook-calendar.sh update <id> <field> <value>
./scripts/outlook-calendar.sh delete <id>
Fields: subject, location, start, end
Where the sent copy is saved depends on the endpoint used, not the sending mode:
| Command | Endpoint Used | Saved To |
|---------|--------------|----------|
| send (as self) | /users/{delegate}/sendMail | Delegate's Sent Items |
| send-as | /users/{delegate}/sendMail | Delegate's Sent Items * |
| send-behalf | /users/{delegate}/sendMail | Delegate's Sent Items * |
| All draft sends | /users/{owner}/messages/{id}/send | Owner's Sent Items |
\* Administrators can configure Exchange to also save a copy in the owner's Sent Items using:
Set-Mailbox -Identity "owner@yourdomain.com" -MessageCopyForSentAsEnabled $true -MessageCopyForSendOnBehalfEnabled $true
"Access denied" or "403 Forbidden"
ā Check that the assistant has MailboxPermission on the owner's mailbox
"ErrorSendAsDenied"
ā Missing SendAs or SendOnBehalf permission. Run the PowerShell commands above.
Emails don't show "on behalf of"
ā You may have both SendAs and SendOnBehalf granted. When both exist, Exchange always uses SendAs (which hides the delegate). Remove the SendAs permission if you want "on behalf of" to appear.
"The mailbox is not found"
ā Verify owner_email in config.json is correct
"AADSTS90002: Tenant not found"
ā Check tenant_id in config.json matches your Microsoft Entra tenant
"Token expired"
ā Run outlook-token.sh refresh
Wrong timezone for calendar
ā Update timezone in config.json (use IANA format like America/New_York)
~/.outlook-mcp/ directory is automatically set to 700 and credential files to 600jq to prevent injection# Remove all permissions
Remove-MailboxPermission -Identity "owner@yourdomain.com" -User "assistant@yourdomain.com" -AccessRights FullAccess -Confirm:$false
# Remove Send As (if granted)
Remove-RecipientPermission -Identity "owner@yourdomain.com" -Trustee "assistant@yourdomain.com" -AccessRights SendAs -Confirm:$false
# Remove Send on Behalf (if granted)
Set-Mailbox -Identity "owner@yourdomain.com" -GrantSendOnBehalfTo @{Remove="assistant@yourdomain.com"}
# Remove Calendar access
Remove-MailboxFolderPermission -Identity "owner@yourdomain.com:\Calendar" -User "assistant@yourdomain.com" -Confirm:$false
~/.outlook-mcp/config.json ā Configuration (client ID, tenant ID, emails, timezone)~/.outlook-mcp/credentials.json ā OAuth tokens (access + refresh)jq to prevent injection and malformed payloadschmod 600)chmod 700)events command now shows only future events/common endpoint)Generated Feb 24, 2026
An AI assistant acts as a delegate for an executive, managing their email inbox and calendar. It can read, prioritize, and respond to emails, schedule meetings, and send communications on behalf of the executive, saving time and ensuring timely follow-ups.
A support team uses an AI assistant to handle shared mailbox access for customer inquiries. The assistant can send responses as the team or on behalf of a specific agent, streamlining ticket management and improving response consistency across shifts.
In a law firm, an AI assistant delegates access to a partner's mailbox to manage client communications and calendar appointments. It sends emails as the partner for official correspondence or on behalf for internal coordination, ensuring secure and professional interactions.
A project manager grants delegate access to an AI assistant to monitor project-related emails and calendar events. The assistant can send updates to stakeholders as the manager or on behalf, facilitating communication and keeping projects on track without manual oversight.
A medical office uses an AI assistant to delegate access to a doctor's mailbox for appointment scheduling and patient follow-ups. It sends emails as the doctor for medical notifications or on behalf for administrative tasks, enhancing efficiency while maintaining privacy.
Offer this skill as part of a monthly or annual subscription service for businesses, providing automated email and calendar management. Revenue is generated through tiered pricing based on features like delegate count or sending modes, targeting SMEs and enterprises.
Provide consulting services to help organizations set up and configure the delegate skill, including Azure app registration and Exchange permissions. Revenue comes from one-time setup fees and ongoing support contracts, ideal for complex enterprise deployments.
Offer a free version with basic email reading and self-sending capabilities, while charging for advanced features like Send As or Send on Behalf modes. Revenue is driven by upgrades and add-ons, appealing to individual professionals and small teams.
š¬ Integration Tip
Ensure proper Exchange permissions are set up via PowerShell before use, as incorrect settings can affect sending modes and require admin intervention.
CLI to manage emails via IMAP/SMTP. Use `himalaya` to list, read, write, reply, forward, search, and organize emails from the terminal. Supports multiple accounts and message composition with MML (MIME Meta Language).
Read and send email via IMAP/SMTP. Check for new/unread messages, fetch content, search mailboxes, mark as read/unread, and send emails with attachments. Works with any IMAP/SMTP server including Gmail, Outlook, 163.com, vip.163.com, 126.com, vip.126.com, 188.com, and vip.188.com.
Gmail API integration with managed OAuth. Read, send, and manage emails, threads, labels, and drafts. Use this skill when users want to interact with Gmail. For other third party apps, use the api-gateway skill (https://clawhub.ai/byungkyu/api-gateway).
Automatically logs into email accounts (Gmail, Outlook, QQ Mail, etc.) and generates daily email summaries. Use when the user wants to get a summary of their emails, check important messages, or create daily email digests.
Fetch content from Feishu (Lark) Wiki, Docs, Sheets, and Bitable. Automatically resolves Wiki URLs to real entities and converts content to Markdown.
Manage Feishu (Lark) calendars by listing, searching, checking schedules, syncing events, and marking tasks with automated date extraction.