
List attachments for an email message with pagination support. Returns metadata only (id, name, size, contentType, isInline, lastModifiedDateTime) — use getmessageattachment for one attachment's content. selectfields overrides which fields are returned. messageid runs over 150 characters: copy it exactly from search results, and do not truncate it.
Get a specific attachment from an email message by ID. Returns full attachment details including base64-encoded content. Set returndownloadurl=true for a short-lived download URL instead (file attachments only). Both messageid and attachmentid run over 150 characters: copy them exactly from listmessageattachments, and do not truncate or rebuild them.
Get metadata for all attachments in an email message without downloading content. Returns only essential fields (id, name, size, contentType) with pagination support.
Retrieve calendar events within a time range with pagination support. When starttime and endtime are provided, automatically expands recurring meetings into individual occurrences. Returns event type and seriesMasterId.
Get a specific calendar event by ID. Event bodies are returned as plain text by default; pass bodyformat='html' for raw HTML. Use selectfields to limit which fields are returned.
Create a calendar event (one-time or recurring). Use recurrence parameter for recurring events.
Update a calendar event. For recurring events: updating an occurrence ID changes only that instance (creates an exception); updating the seriesMasterId (found in occurrence's seriesMasterId field) changes all future occurrences.
Delete a calendar event
Get today's calendar events
Get upcoming calendar events
Get past calendar events from previous days
Create a meeting with attendees (one-time or recurring)
Create a Teams meeting with enhanced online meeting support
Search for calendar events with pagination support
Get free/busy schedule information for users, distribution lists, or resources for a specified time period
Find optimal meeting times based on attendee availability, suggesting times that work for required participants
Retrieve contacts from a folder with pagination support
Get a specific contact by ID
Create a new contact
Update a contact
Delete a contact
Search for contacts with pagination support
Find contacts by email address with pagination support
Find contacts by company name with pagination support
Get all mail folders with pagination support
Get a specific mail folder by ID
Create a new mail folder
Update a mail folder
Delete a mail folder
Copy a mail folder
Move a mail folder
Get child folders of a parent folder with pagination support
Get a well-known folder by name
Get message counts for a folder
Retrieve messages from a mailbox folder, with pagination. Default fields: id, subject, from, toRecipients, receivedDateTime, sentDateTime, isRead, hasAttachments, importance, bodyPreview, conversationId, webLink. Body NOT included: use getmessage, or pass selectfields with the fields you want plus 'body' (it replaces the default). body_format applies only when a body is included.
Get a specific message by ID, including its body. Bodies are plain text by default; pass bodyformat='html' for raw HTML (HTML bodies can be very large). Set uniquebodyonly=true on a reply chain to get only this message's new content, dropping quoted history; it returns a wide but explicit field set, so a few rarely-read metadata fields are omitted. Use selectfields to limit fields returned.
Create a draft message. Attach files inline via attachments (base64 contentbytes, small files) and/or ONE large staged file via filereference (from the file upload API, POST /api/v1/files/, 3 MB to 100 MB) with filereferencefilename. Staged bytes stream into the draft without entering the model's context. Use send_draft to send the draft this returns.
Send an existing draft by ID: pass the 'id' from createdraftmessage, or find saved drafts with getmessages(folderid='drafts'). Required for a draft holding a large staged attachment. Graph re-IDs the message into Sent Items, so the draft ID stops resolving; an error here is not proof it was not sent -- check Sent Items first. Or use send_message to compose and send at once.
Forward an email to new recipients and send it immediately; Graph includes the original body and attachments and keeps the conversation thread. Find messageid with getmessages or searchmessages. To add CC/BCC or files, or to review before sending, use createforwarddraft then senddraft instead.
Create a forward draft of an email without sending it; Graph copies the original body and attachments. Optionally add CC/BCC, extra small files (attachments) or ONE staged 3-100 MB file (filereference). Find messageid with getmessages or searchmessages. Returns the draft id: send it with senddraft, edit with updatemessage, or discard with delete_message.
Send an email message
Update a message
Delete a message
Move a message to another mail folder by folder ID. Use getmailfolders or getwellknown_folder to find the destination folder ID (e.g. the 'archive' folder).
Reply to an email message. Sends a reply to the original sender with the given comment text (set reply_all=true to reply to all recipients). Sends immediately; does not create a draft.
Mark a message as read
Mark a message as unread
Get unread messages from a folder with pagination support. Returns the same lean field set as getmessages (no message body); use getmessage to read one, or pass select_fields including 'body' to widen.
Search for messages with pagination support. Returns the same lean field set as getmessages (no message body); use getmessage to read one. Returns message IDs that are 150+ characters long. Copy the entire 'id' field exactly, and do not truncate or rebuild it.
List users in the organization with pagination support, filtering, ordering
Search for users by name, email with pagination support and full-text search
Get detailed user information by email address (userPrincipalName)
Validate Microsoft Graph API credentials by attempting to fetch the authenticated user's profile

In an mcp.json file, add the configuration below, and restart Cursor.
Learn more in the official documentation ↗
1{
2 "mcpServers": {
3 "agent-handler": {
4 "url": "https://ah-api-develop.merge.dev/api/v1/tool-packs/{TOOL_PACK_ID}/registered-users/{REGISTERED_USER_ID}/mcp",
5 "headers": {
6 "Authorization": "Bearer yMt*****"
7 }
8 }
9 }
10}
11Open your Claude Desktop configuration file and add the server configuration below. You'll also need to restart the application for the changes to take effect.
Make sure Claude is using the Node v20+.
Learn more in the official documentation ↗
1{
2 "mcpServers": {
3 "agent-handler": {
4 "command": "npx",
5 "args": [
6 "-y",
7 "mcp-remote@latest",
8 "https://ah-api-develop.merge.dev/api/v1/tool-packs/{TOOL_PACK_ID}/registered-users/{REGISTERED_USER_ID}/mcp",
9 "--header",
10 "Authorization: Bearer ${AUTH_TOKEN}"
11 ],
12 "env": {
13 "AUTH_TOKEN": "yMt*****"
14 }
15 }
16 }
17}Open your Windsurf MCP configuration file and add the server configuration below.
Click on the refresh button in the top right of the Manage MCP server page or in the top right of the chat box in the box icon.
Learn more in the official documentation ↗
1{
2 "mcpServers": {
3 "agent-handler": {
4 "command": "npx",
5 "args": [
6 "-y",
7 "mcp-remote@latest",
8 "https://ah-api.merge.dev/api/v1/tool-packs/<tool-pack-id>/registered-users/<registered-user-id>/mcp",
9 "--header",
10 "Authorization: Bearer ${AUTH_TOKEN}"
11 ],
12 "env": {
13 "AUTH_TOKEN": "<ah-production-access-key>"
14 }
15 }
16 }
17 }In Command Palette (Cmd+Shift+P on macOS, Ctrl+Shift+P on Windows), run "MCP: Open User Configuration".
You can then add the configuration below and press "start" right under servers. Enter the auth token when prompted.
Learn more in the official documentation ↗
1{
2 "inputs": [
3 {
4 "type": "promptString",
5 "id": "agent-handler-auth",
6 "description": "Agent Handler AUTH_TOKEN", // "yMt*****" when prompt
7 "password": true
8 }
9 ],
10 "servers": {
11 "agent-handler": {
12 "type": "stdio",
13 "command": "npx",
14 "args": [
15 "-y",
16 "mcp-remote@latest",
17 "https://ah-api-develop.merge.dev/api/v1/tool-packs/{TOOL_PACK_ID}/registered-users/{REGISTERED_USER_ID}/mcp",
18 "--header",
19 "Authorization: Bearer ${input:agent-handler-auth}"
20 ]
21 }
22 }
23}Here are just some common use cases that apply not only to Outlook but also other calendar and email MCP servers:
Here are just a few popular tools segmented by data type:
Merge Agent Handler positions Outlook within a broader, enterprise-ready agent tooling platform rather than as a standalone MCP endpoint.
Yes, you can set custom security rules for Outlook tool calls in Merge Agent Handler.
Here are a few specific examples:
Here are the steps you can take:
1. Start with the pre-built Outlook connector. The Outlook connector comes with 40+ ready-to-use tools.
2. Add the Outlook connector to a Tool Pack. Navigate to "Tool Packs" in the sidebar and either create a new Tool Pack or select an existing one. Click "Add Connector" and select Outlook from the available connectors. You can also configure the authentication type (Individual or Shared credentials).
3. Associate the Tool Pack with your agent. Save your Tool Pack changes, then connect it to your agent using the MCP entry URL provided in the Tool Pack settings. Your agent will now have access to exactly the Outlook tools you've configured, with authentication, security rules, and logging handled automatically by Agent Handler.
It’s worth noting that there are additional steps you can take, like testing your tools and customizing them within the Connector Studio (e.g., modifying your tool descriptions).
Yes, Agent Handler for Employees lets your employees connect Claude, ChatGPT, Microsoft Copilot, Cursor, and other MCP-compatible AI tools to Outlook without bypassing IT governance.
Instead of setting up direct connections with personal credentials that IT can't monitor or revoke, each employee authenticates through Agent Handler and gets individual credentials tied to their identity.
IT also provisions access by role or group via SCIM. A sales rep, gets Outlook access to manage email and meetings, Salesforce to track pipeline, and Gong to review call recordings; while a legal team member gets Outlook access to handle contract communications, SharePoint to access legal documents, and DocuSign to track signature status.
Every tool call an employee's AI makes to Outlook is also inspected against your DLP rules and logged to a searchable audit trail, giving security teams full visibility into what data was accessed and by whom.
Whether you're an engineer experimenting with agents or a product manager looking to add tools, you can get started for free now