Client Credentials
Client credentials create app-only tokens.
Appropriate use
Use app-only tokens only for Graph operations whose permissions explicitly support application access.
Not for normal message sends
Normal live Teams chat and channel message posting requires delegated auth. The CLI rejects app-only tokens before mutating message commands so agents receive deterministic PERMISSION_DENIED errors.
export TEAMS_CLI_CLIENT_SECRET=<secret>
teams auth login --client-credentials --client-id <id> --tenant-id <tenant>
Prefer TEAMS_CLI_CLIENT_SECRET to --client-secret: a value passed as a flag shows in process
listings and shell history. teams auth login --help names the variable but never prints its value.
A client credentials login does not save its IDs to the profile, unlike a delegated login.
For unattended posting, use future Teams bot mode.