Environment Variables
| Variable | Purpose |
|---|---|
TEAMS_CLI_ACCESS_TOKEN | Use a pre-obtained Microsoft Graph access token instead of keyring lookup. |
TEAMS_CLI_CLIENT_ID | Entra app client ID. Takes precedence over the profile, and auth login never saves it. |
TEAMS_CLI_CLIENT_SECRET | Client secret for client credentials flow. Prefer it to --client-secret, whose value shows in process listings. |
TEAMS_CLI_TENANT_ID | Tenant ID or tenant domain. Takes precedence over the profile, and auth login never saves it. |
TEAMS_CLI_SCOPES | Space-separated delegated Graph scopes for auth login, auth refresh, and auth consent-url. |
TEAMS_CLI_TOKEN_STORE | keyring (default) or file: where tokens are kept. file writes unencrypted 0600 files under the config directory's tokens/, for unattended processes and hosts without a keyring. Any other value is invalid input (exit code 2). See Token Caching. |
TEAMS_CLI_DISABLE_KEYRING | Test-only escape hatch used by CLI tests. |
TEAMS_CLI_BUILD_NAMESPACE | Build time only, read by cargo build: the storage namespace (keyring service and config directory) compiled into a source build. Defaults to teams-cli-dev for debug builds and teams-cli for release builds; must be teams-cli or teams-cli- plus lowercase letters, digits and hyphens. |
MS_TEAMS_CLI_VERSION | Docs build override for the sidebar release badge. |
TEAMS_CLI_ACCESS_TOKEN must be a Graph token. Tokens captured from the Teams client, including fossteams/teams-token files such as token-teams.jwt, have the wrong audience for Microsoft Graph and will fail with Invalid audience.