You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: plugin/skills/auth-login/SKILL.md
+28-5Lines changed: 28 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -32,13 +32,36 @@ Stay in `read` until you actually need to install or remove a rule.
32
32
33
33
## One-time prerequisite (free, human)
34
34
35
-
Register a free **Azure AD app** (public client, device-code/public-client flow **enabled**) with
36
-
delegated permissions `Mail.Read` + `MailboxSettings.Read` (+ `MailboxSettings.ReadWrite` for rule
37
-
authoring). Personal Microsoft accounts need no admin consent. Then export, before first sign-in:
35
+
You register a free **Azure AD (Entra) app** once. The app registration and tenant are Entra-level
36
+
and **free forever** — only the steps to *get* a tenant trip people up, so follow these exactly. (All
37
+
verified during the first live run.)
38
+
39
+
**0. A personal Microsoft account has NO tenant by default.** It sits in the shared "Microsoft
40
+
Services" directory, where app registration is impossible. You must create your own tenant first.
41
+
42
+
**1. Create a tenant.** Per Microsoft docs the prerequisite is an Azure subscription — start the free
43
+
trial at <https://azure.microsoft.com/free>. It requires **card verification** (~£1 reversible hold,
44
+
no auto-charge; the trial subscription is *disabled* at 30 days, not upgraded). Durability: once the
45
+
tenant exists, the app registration and token issuance keep working at **zero cost** after the trial
46
+
subscription is disabled — the subscription is only needed to create the tenant, not to run the app.
47
+
48
+
**2. Use the Entra admin center — <https://entra.microsoft.com>, NOT portal.azure.com.** A tenant with
49
+
no active subscription makes the Azure portal default to the wrong directory (error `AADSTS160021`).
50
+
51
+
**3. Register the app** (Entra → App registrations → New registration):
52
+
53
+
| Setting | Value |
54
+
|---|---|
55
+
| Supported account types |**Personal Microsoft accounts only** (this makes `MSGRAPH_TENANT_ID="consumers"` correct) |
56
+
| Redirect URI |**leave blank** (device-code flow needs none) |
57
+
| Authentication → **Allow public client flows**|**Yes** — REQUIRED, or device-code fails. In the new "Authentication (Preview)" tab this toggle lives under the **Settings** sub-tab (no longer under "Advanced settings" — docs that say otherwise are outdated). |
58
+
| API permissions (delegated) |`Mail.Read`, `MailboxSettings.Read` (+ `MailboxSettings.ReadWrite` for rule authoring). Personal accounts need **no admin consent** — consent happens in-browser at sign-in. The default `User.Read` can stay; the kernel never requests it. |
0 commit comments