Skip to main content

Docker

A container image should mount only the config and secrets needed by the workflow.

docker run --rm \
-e TEAMS_CLI_ACCESS_TOKEN \
osodevops/teams-cli:latest \
teams auth status --output json

For long-lived delegated sessions, prefer host keyring storage outside Docker. For CI, use short-lived Microsoft Graph tokens or a controlled login bootstrap.

A container has no Secret Service, so a delegated session that must persist inside one uses the file token store on a mounted volume. Sign in once with the same settings, and keep the volume out of the image:

docker run --rm \
-e TEAMS_CLI_TOKEN_STORE=file \
-e XDG_CONFIG_HOME=/config \
-v teams-cli-config:/config \
osodevops/teams-cli:latest \
teams chat list --output json

The volume then holds a refresh token in plain text; see Token Caching.

Do not pass Teams client tokens captured from desktop, browser, or fossteams/teams-token sessions through TEAMS_CLI_ACCESS_TOKEN; Graph will reject them with Invalid audience.