LokkaCAUTION
MCP (Model Context Protocol) for Microsoft 365. Includes support for Microsoft Graph and other services
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@merill/lokka) [](https://www.npmjs.com/package/@merill/lokka) [](https://www.npmjs.com/package/@merill/lokka) [](https://github.com/merill/lokka/stargazers) [](https://github.com/merill/lokka/blob/main/LICENSE)
Lokka is a model-context-protocol server for the Microsoft Graph and Azure RM APIs that allows you to query and manage your Azure and Microsoft 365 tenants with AI.
Please see Lokka.dev for how to use Lokka with your favorite AI model and chat client.
Lokka lets you use Claude Desktop, or any MCP Client, to use natural language to accomplish things in your Azure and Microsoft 365 tenant through the Microsoft APIs.
e.g.:
Create a new security group called 'Sales and HR' with a dynamic rule based on the department attribute.Find all the conditional access policies that haven't excluded the emergency access accountShow me all the Intune device configuration policies assigned to the 'Call center' groupWhat was the most expensive service in Azure last month?
Authentication Methods
Lokka now supports multiple authentication methods to accommodate different deployment scenarios:
Interactive Auth
For user-based authentication with interactive login, you can use the following configur
78278eba7a8dOBSERVED · 2026-10-05Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add website --env ACCESS_TOKEN=${ACCESS_TOKEN} --env CERTIFICATE_PASSWORD=${CERTIFICATE_PASSWORD} --env CLIENT_SECRET=${CLIENT_SECRET} --env USE_CLIENT_TOKEN=${USE_CLIENT_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"website": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ACCESS_TOKEN": "${ACCESS_TOKEN}",
"CERTIFICATE_PASSWORD": "${CERTIFICATE_PASSWORD}",
"CLIENT_SECRET": "${CLIENT_SECRET}",
"USE_CLIENT_TOKEN": "${USE_CLIENT_TOKEN}"
}
}
}
}Exposed tools (4)
2 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Lokka-Microsoft | read | A versatile tool to interact with Microsoft APIs including Microsoft Graph (Entra) and Azure Resource Management. IMPORTANT: For Graph API GET requests using advanced query parameters ($filter, $count, $search, $orderby), you are ADVISED to set |
add-graph-permission | write | Request additional Microsoft Graph permission scopes by performing a fresh interactive sign-in. This tool only works in interactive authentication mode and should be used if any Graph API call returns permissions related errors. |
get-auth-status | read | Check the current authentication status and mode of the MCP Server and also returns the current graph permission scopes of the access token for the current session. |
set-access-token | write | Set or update the access token for Microsoft Graph authentication. Use this when the MCP Client has obtained a fresh token through interactive authentication. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
logger.info(`Requesting fresh token with scopes: ${scopeString}`);logger.info(`Successfully acquired fresh token with additional scopes: ${scopes.join(', ')}`);logger.info(`Requesting fresh token with scopes: ${scopeString}`);logger.info(`Successfully acquired fresh token with additional scopes: ${scopes.join(', ')}`);.nojekyll
@azure/identity, @microsoft/microsoft-graph-client, @modelcontextprotocol/sdk, @types/jsonwebtoken, isomorphic-fetch, jsonwebtoken, zod, @types/isomorphic-fetch
@mdx-js/react, clsx, prism-react-renderer, react, react-dom
- **`set-access-token`**: Set or update access tokens for Microsoft Graph authentication
- **`set-access-token`**: Set or update access tokens for Microsoft Graph authentication
5. Copy the access token from the **Access token** tab
assets/lokka-demo-1.gif
Gates applied: no_behavioural_pass.
78278eba7a8dfull audit observations/trust-audit/mcp-server/merill__lokka.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-05 | 78278eba7a8d | CAUTION | B | 89 | first audit |
Questions
What is the Lokka MCP server?
MCP (Model Context Protocol) for Microsoft 365. Includes support for Microsoft Graph and other services
What tools does Lokka expose?
4 in total: 2 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Lokka safe to connect to an agent?
With care. The audit graded it B (89/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Lokka need?
It reads ACCESS_TOKEN, CERTIFICATE_PASSWORD, CLIENT_SECRET and USE_CLIENT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Lokka run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as website at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (78278eba7a8d), read on 2026-10-05. The repository is watched and re-audited when it changes.