Skip to main content

Environment Variables

VariablePurpose
TEAMS_CLI_ACCESS_TOKENUse a pre-obtained Microsoft Graph access token instead of keyring lookup.
TEAMS_CLI_CLIENT_IDEntra app client ID. Takes precedence over the profile, and auth login never saves it.
TEAMS_CLI_CLIENT_SECRETClient secret for client credentials flow. Prefer it to --client-secret, whose value shows in process listings.
TEAMS_CLI_TENANT_IDTenant ID or tenant domain. Takes precedence over the profile, and auth login never saves it.
TEAMS_CLI_SCOPESSpace-separated delegated Graph scopes for auth login, auth refresh, and auth consent-url.
TEAMS_CLI_TOKEN_STOREkeyring (default) or file: where tokens are kept. file writes unencrypted 0600 files under the config directory's tokens/, for unattended processes and hosts without a keyring. Any other value is invalid input (exit code 2). See Token Caching.
TEAMS_CLI_DISABLE_KEYRINGTest-only escape hatch used by CLI tests.
TEAMS_CLI_BUILD_NAMESPACEBuild time only, read by cargo build: the storage namespace (keyring service and config directory) compiled into a source build. Defaults to teams-cli-dev for debug builds and teams-cli for release builds; must be teams-cli or teams-cli- plus lowercase letters, digits and hyphens.
MS_TEAMS_CLI_VERSIONDocs build override for the sidebar release badge.

TEAMS_CLI_ACCESS_TOKEN must be a Graph token. Tokens captured from the Teams client, including fossteams/teams-token files such as token-teams.jwt, have the wrong audience for Microsoft Graph and will fail with Invalid audience.