| name | officeclaw |
| description | Connect to personal Microsoft accounts via Microsoft Graph API to manage email, calendar events, and tasks. Use this skill when the user needs to read/write Outlook mail, manage calendar appointments, or handle Microsoft To Do tasks. |
| license | Apache-2.0 |
| homepage | https://github.com/danielithomas/officeclaw |
| user-invocable | true |
| compatibility | Requires Python 3.9+, network access to graph.microsoft.com, and one-time OAuth setup |
| metadata | {"author":"Daniel Thomas","version":"1.0.1","openclaw":{"requires":{"anyBins":["python","python3","officeclaw"],"env":[]},"os":["darwin","linux","win32"]}} |
OfficeClaw: Microsoft Graph API Integration
Connect your OpenClaw agent to personal Microsoft accounts (Outlook.com, Hotmail, Live) to manage email, calendar, and tasks through the Microsoft Graph API.
Installation
Install from PyPI:
pip install officeclaw
Or with uv:
uv pip install officeclaw
Verify installation:
officeclaw --version
Setup (One-Time)
Quick start: OfficeClaw ships with a default app registration — just run officeclaw auth login and go. No Azure setup needed.
Advanced: Want full control? Create your own Azure App Registration (free, ~5 minutes) and set OFFICECLAW_CLIENT_ID in your .env. See Microsoft's guide or follow the steps below.
1. Create an Azure App Registration
- Go to entra.microsoft.com → App registrations → New registration
- Name:
officeclaw (or anything you like)
- Supported account types: Personal Microsoft accounts only
- Redirect URI: leave blank (not needed for device code flow)
- Click Register
- Copy the Application (client) ID — this is your
OFFICECLAW_CLIENT_ID
- Go to Authentication → Advanced settings → Allow public client flows → Yes → Save
- Go to API permissions → Add permission → Microsoft Graph → Delegated permissions. Choose based on your needs:
Read-only (safest):
Mail.Read, Calendars.Read, Tasks.ReadWrite*
Full access (all features including send/delete):
Mail.Read, Mail.ReadWrite, Mail.Send
Calendars.Read, Calendars.ReadWrite
Tasks.ReadWrite
*Tasks.ReadWrite is the minimum available scope for Microsoft To Do — there is no read-only option.
Least privilege: Only grant the permissions you actually need. If you only want to read emails and calendar, skip Mail.ReadWrite, Mail.Send, and Calendars.ReadWrite. OfficeClaw will gracefully error on commands that require missing permissions.
2. Configure Environment
Create a .env file in your skill directory:
OFFICECLAW_CLIENT_ID=your-client-id-here
No client secret needed for device code flow. Write operations (send, delete) are disabled by default — enable only what you need.
3. Authenticate
officeclaw auth login
This displays a URL and code. Open the URL in a browser, enter the code, and sign in with your Microsoft account. Tokens are stored securely in ~/.officeclaw/token_cache.json (permissions 600).
When to Use This Skill
Activate this skill when the user needs to:
Email Operations
- Read emails: "Show me my latest emails", "Find emails from john@example.com"
- Send emails: "Send an email to...", "Reply to the last email from..."
- Manage inbox: "Mark emails as read", "Archive old emails", "Delete emails"
Calendar Operations
- View events: "What's on my calendar today?", "Show meetings this week"
- Create events: "Schedule a meeting with...", "Add dentist appointment on Friday"
- Update events: "Move the 2pm meeting to 3pm", "Cancel tomorrow's standup"
Task Management
- List tasks: "What's on my to-do list?", "Show incomplete tasks"
- Create tasks: "Add 'buy groceries' to my tasks", "Create a task to review report"
- Complete tasks: "Mark 'finish proposal' as done", "Complete all shopping tasks"
Available Commands
Authentication
officeclaw auth login
officeclaw auth status
officeclaw auth logout
Mail Commands
officeclaw mail list --limit 10
officeclaw mail list --unread
officeclaw mail get <message-id>
officeclaw mail send --to user@example.com --subject "Hello" --body "Message text"
officeclaw mail send --to user@example.com --subject "Report" --body "Attached" --attachment report.pdf
officeclaw mail search --query "from:boss@example.com"
officeclaw mail archive <message-id>
officeclaw mail mark-read <message-id>
officeclaw --json mail list
Calendar Commands
officeclaw calendar list --start 2026-02-01 --end 2026-02-28
officeclaw calendar create \
--subject "Team Meeting" \
--start "2026-02-15T10:00:00" \
--end "2026-02-15T11:00:00" \
--location "Conference Room"
officeclaw calendar get <event-id>
officeclaw calendar update <event-id> --subject "Updated Meeting"
officeclaw calendar delete <event-id>
officeclaw --json calendar list --start 2026-02-01 --end 2026-02-28
Task Commands
officeclaw tasks list-lists
officeclaw tasks list --list-id <list-id>
officeclaw tasks list --list-id <list-id> --status active
officeclaw tasks create --list-id <list-id> --title "Complete report" --due-date "2026-02-20"
officeclaw tasks complete --list-id <list-id> --task-id <task-id>
officeclaw tasks reopen --list-id <list-id> --task-id <task-id>
Output Format
Use --json flag for structured JSON output:
officeclaw --json mail list
Returns:
{
"status": "success",
"data": [
{
"id": "AAMkADEzN...",
"subject": "Meeting Notes",
"from": {"emailAddress": {"address": "sender@example.com"}},
"receivedDateTime": "2026-02-12T10:30:00Z",
"isRead": false
}
]
}
Error Handling
Common errors and solutions:
| Error | Cause | Solution |
|---|
AuthenticationError | Not logged in or token expired | Run officeclaw auth login |
AccessDenied | Missing permissions | Re-authenticate with required scopes |
ResourceNotFound | Invalid ID | Verify the ID exists |
RateLimitError | Too many API calls | Wait 60 seconds and retry |
Guidelines for Agents
When using this skill:
- Confirm destructive actions: Ask before deleting or sending
- Summarize results: Don't show raw JSON, provide summaries
- Handle errors gracefully: Guide user through re-authentication
- Respect privacy: Don't log email content
- Use JSON mode: For programmatic parsing, use
--json flag
- Batch operations: Process multiple items efficiently
Security & Privacy
- Write operations disabled by default: Send, reply, forward, and delete are all blocked unless explicitly enabled via
OFFICECLAW_ENABLE_SEND and OFFICECLAW_ENABLE_DELETE environment variables. This prevents accidental or unauthorised write actions.
- No client secret required: Uses device code flow (public client) by default
- Least-privilege permissions: You choose which Graph API scopes to grant — read-only is sufficient for most use cases. See the setup guide above.
- Tokens stored securely:
~/.officeclaw/token_cache.json with 600 file permissions
- No data storage: OfficeClaw passes data through, never stores email/calendar content
- No telemetry: No usage data collected
- Your own Azure app: Each user creates their own Azure app registration with their own client ID — no shared credentials
Troubleshooting
If the skill isn't working:
- Check authentication: Run
officeclaw auth status
- Re-authenticate: Run
officeclaw auth login
- Verify network: Ensure
graph.microsoft.com is reachable
- Check environment: Verify
OFFICECLAW_CLIENT_ID is set in .env
References