Skip to main content

Client Credentials

Client credentials create app-only tokens.

Appropriate use​

Use app-only tokens only for Graph operations whose permissions explicitly support application access.

Not for normal message sends​

Normal live Teams chat and channel message posting requires delegated auth. The CLI rejects app-only tokens before mutating message commands so agents receive deterministic PERMISSION_DENIED errors.

export TEAMS_CLI_CLIENT_SECRET=<secret>
teams auth login --client-credentials --client-id <id> --tenant-id <tenant>

Prefer TEAMS_CLI_CLIENT_SECRET to --client-secret: a value passed as a flag shows in process listings and shell history. teams auth login --help names the variable but never prints its value. A client credentials login does not save its IDs to the profile, unlike a delegated login.

For unattended posting, use future Teams bot mode.