{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "onedrive-sharepoint",
    "name": "OneDrive and SharePoint files (Microsoft Graph)",
    "vendor": "Microsoft",
    "vendorUrl": "https://learn.microsoft.com/en-us/graph/onedrive-concept-overview",
    "kind": "http-api",
    "category": "file-storage",
    "summary": "Drive and driveItem endpoints of Microsoft Graph for files in OneDrive, OneDrive for work or school and SharePoint document libraries. Calls upload, download, list, search, share by link or invitation, and delete files and folders.",
    "url": "https://www.anchorterminal.com/tools/onedrive-sharepoint",
    "markdownUrl": "https://www.anchorterminal.com/tools/onedrive-sharepoint.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/onedrive-sharepoint.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/onedrive-sharepoint.json",
    "repo": "https://github.com/microsoftgraph/msgraph-sdk-python",
    "license": "MIT (SDKs)",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://graph.microsoft.com/v1.0",
    "packages": [
      {
        "registry": "npm",
        "name": "@microsoft/microsoft-graph-client"
      },
      {
        "registry": "pypi",
        "name": "msgraph-sdk"
      }
    ],
    "auth": "oauth",
    "authNotes": "OAuth 2.0 tokens from Microsoft Entra ID, after a person registers an app. Registration is self-serve, with no partner or sales approval. Delegated permissions run from Files.Read to Files.ReadWrite.All and work for personal Microsoft accounts and work or school accounts. Application permissions (Files.Read.All, Files.ReadWrite.All, Sites.ReadWrite.All) need an administrator's consent. Selected scopes limit an app to chosen sites, lists, folders or files.",
    "pricing": "byo-plan",
    "pricingNotes": "File calls carry no per-call charge. Microsoft's list of metered Graph APIs names only `assignSensitivityLabel`, at $0.00185 a call (https://learn.microsoft.com/en-us/graph/metered-api-list). Storage comes from the account's own OneDrive or Microsoft 365 plan, 1 TB a user on the Business and E3 or E5 plans per the service description. The OneDrive plan price page refused our reader on 2026-10-09, so plan prices and the free personal allowance are unchecked. A free Microsoft 365 E5 developer sandbox is limited to Visual Studio subscribers and other qualifying members (https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq).",
    "priceSummary": "Your plan",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the files documentation or the metered API list (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 633,
      "npmWeekly": 2882852,
      "pypiWeekly": 1578201,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://learn.microsoft.com/en-us/graph/api/resources/onedrive",
    "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
    "capabilities": [
      "storage.drive",
      "storage.share",
      "storage.presigned"
    ],
    "tags": [
      "hosted",
      "official",
      "oauth",
      "openapi",
      "typescript",
      "python",
      "enterprise"
    ],
    "lastRelease": "2026-10-06",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 65.3,
      "grade": "B",
      "agentReady": false,
      "rank": 296,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 8,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 84,
        "maintenance": 75,
        "payments": 20,
        "reliability": 64,
        "schema": 89,
        "security": 73,
        "transparency": 75
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 64,
          "points": 12.8,
          "reason": "Graded on the v1.0 REST API. A public Microsoft service health page at status.cloud.microsoft (20). It shows nothing without JavaScript, so we couldn't read components or history (5). SharePoint and OneDrive limits are published in resource units, 1,250 to 6,250 a minute and 1,200,000 to 6,000,000 a day per app per tenant by licence count, 3,000 requests per 5 minutes a user, and 400 GB of ingress and of egress an hour per app (15). 429 and 503 responses carry `Retry-After`, upload sessions resume from `nextExpectedRanges` with backoff advice for 5xx errors, and `If-Match` and `conflictBehavior` guard overwrites. There is no idempotency key on `invite` or folder creation (14 of 15). The Online Services SLA page is drawn by script and gave us no text, so no SLA is counted (0). The file endpoints are generally available on v1.0 (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 89,
          "points": 14.46,
          "reason": "OpenAPI 3.0.4 for all of Graph v1.0 in microsoftgraph/msgraph-metadata, with 1,516 paths under `/drives`, 172 of them outside the workbook API (25). learn.microsoft.com answers 404 for llms.txt, but every page we asked for with `Accept: text/markdown` came back as Markdown (10). Reference pages state the purpose of each call, list permissions from least to most privileged and say which options work only on personal OneDrive. The upload session page gives Sites.ReadWrite.All as the least privileged application permission where the small-upload page gives Files.ReadWrite.All, and the overview page is dated March 2024 (16). `createLink` declares `type` and `scope` as plain strings with no enumeration, `conflictBehavior` is an annotation outside the schema, path addressing is absent from the OpenAPI, and `retainInheritedPermissions` defaults to false there and to true on the reference page (9). An HTTP example and SDK snippets on each page, a status code table, and upload-specific handling for 404, 409 and 416 (14). v1.0 and beta, a dated changelog and a monthly What's new page (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 84,
          "points": 13.65,
          "reason": "`$select` trims driveItem properties, a list returns 200 items a page by default, and responses without `$select` carry a tip to use it. The whole-Graph OpenAPI is 44 MB (21). `@odata.nextLink` paging with `$top`, `$skipToken`, `$orderby` and `$expand`, a search call and `delta` for changes since a token (20). Errors carry a code, a message and a request ID, the upload page says what to do on 404, 409, 416 and 5xx, and `delta` returns two named resync codes on 410 (17). Uploads resume, `If-Match` and `if-none-match` guard writes, `conflictBehavior` fails by default, `createLink` returns the existing link of the same type and DELETE goes to the recycle bin. No idempotency key (14). Items are addressed by ID or by path with one bearer token, but upload fragments must be multiples of 320 KiB and the token must be left off the fragment PUT. Official SDKs in C#, Java, Go, PHP, Python, PowerShell and JavaScript, the npm JavaScript client dating from September 2023 (12)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 73,
          "points": 12.78,
          "reason": "OAuth 2.0 through Microsoft Entra ID with delegated and application permissions from Files.Read to Sites.ReadWrite.All, revocable consent, and Selected scopes that hold an app to chosen sites, lists, folders or files. Download and upload URLs are pre-authenticated and short-lived, which we read as designed capability links and not as a credential in a URL (30). Files.Read for reading, Selected scopes with read, write, owner and fullcontrol roles, DELETE to the recycle bin and anonymous links that an administrator can disable. Nothing asks for confirmation before `permanentDelete` or an anonymous link (17). File names and contents written by other people reach the caller, and no injection guidance was found in the files reference pages (0). Graph activity logs record app, user, request URI and scopes for every request, but need Entra ID P1 or P2 and an Azure log destination (12). The Microsoft 365 bounty names SharePoint Online and OneDrive at $1,250 to $19,500, with a coordinated disclosure policy and an Office 365 SOC 2 Type 2 report. microsoft.com's security.txt passed its Expires date on 23 September 2026, and a token-leak fix in the JavaScript client is unreleased on npm (14)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 20,
          "points": 2.5,
          "reason": "No x402, MPP or L402 (0). File calls aren't on Microsoft's metered API list, whose one entry is `assignSensitivityLabel` at $0.00185 a call, but storage comes from a OneDrive or Microsoft 365 plan and the plan price page refused our reader today (10). The reference pages list delegated permissions for personal Microsoft accounts, so no Microsoft 365 licence is needed to call the API, but we couldn't read the size of the free personal allowance, and the free E5 developer sandbox is limited to Visual Studio subscribers and other qualifying members (10). A person registers an app in Entra and signs in to consent (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "reason": "msgraph-sdk-python v1.64.0 on 6 October 2026. The What's new page, updated 8 October 2026, lists generally available Files changes for September and August 2026, and the changelog feed's last v1.0 Files entry is 29 July 2026 (30). Five Python SDK releases since 22 July 2026, v1.60.0 to v1.64.0 (20). A public changelog, a What's new page and SDK issue trackers. The changelog feed stops at 3 August 2026, an issue about drive content returning None on the Python SDK has had no reply since 21 September 2026, and a security fix merged into the JavaScript client on 16 June 2026 hasn't reached npm (9 of 15). Current SDKs in most languages, with the JavaScript client the exception at 3.0.7 (10). Active releases on the Python package, none on the JavaScript one (6)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "note": "editorial 65, provenance 85",
          "reason": "Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDKs (15). Microsoft's data handling page for Microsoft 365 gives at most 30 days after active deletion and 180 days after a subscription ends for customer content, the SharePoint deletion page gives 93 days in the recycle bin and 14 further days of backups, and the privacy statement was updated in September 2026. We didn't read the data protection addendum (22). The Graph policy is at least 24 months' notice before a generally available API or version is removed, while the API terms reserve the right to change or discontinue any API with or without notice (18). Data residency for Microsoft 365 is documented by tenant geography. The sub-processor list sits on the Service Trust Portal, which we didn't read (10)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`$select` trims driveItem properties, a list returns 200 items a page by default, and responses without `$select` carry a tip to use it. The whole-Graph OpenAPI is 44 MB (21). `@odata.nextLink` paging with `$top`, `$skipToken`, `$orderby` and `$expand`, a search call and `delta` for changes since a token (20). Errors carry a code, a message and a request ID, the upload page says what to do on 404, 409, 416 and 5xx, and `delta` returns two named resync codes on 410 (17). Uploads resume, `If-Match` and `if-none-match` guard writes, `conflictBehavior` fails by default, `createLink` returns the existing link of the same type and DELETE goes to the recycle bin. No idempotency key (14). Items are addressed by ID or by path with one bearer token, but upload fragments must be multiples of 320 KiB and the token must be left off the fragment PUT. Official SDKs in C#, Java, Go, PHP, Python, PowerShell and JavaScript, the npm JavaScript client dating from September 2023 (12).",
          "maintenance": "msgraph-sdk-python v1.64.0 on 6 October 2026. The What's new page, updated 8 October 2026, lists generally available Files changes for September and August 2026, and the changelog feed's last v1.0 Files entry is 29 July 2026 (30). Five Python SDK releases since 22 July 2026, v1.60.0 to v1.64.0 (20). A public changelog, a What's new page and SDK issue trackers. The changelog feed stops at 3 August 2026, an issue about drive content returning None on the Python SDK has had no reply since 21 September 2026, and a security fix merged into the JavaScript client on 16 June 2026 hasn't reached npm (9 of 15). Current SDKs in most languages, with the JavaScript client the exception at 3.0.7 (10). Active releases on the Python package, none on the JavaScript one (6).",
          "payments": "No x402, MPP or L402 (0). File calls aren't on Microsoft's metered API list, whose one entry is `assignSensitivityLabel` at $0.00185 a call, but storage comes from a OneDrive or Microsoft 365 plan and the plan price page refused our reader today (10). The reference pages list delegated permissions for personal Microsoft accounts, so no Microsoft 365 licence is needed to call the API, but we couldn't read the size of the free personal allowance, and the free E5 developer sandbox is limited to Visual Studio subscribers and other qualifying members (10). A person registers an app in Entra and signs in to consent (0).",
          "reliability": "Graded on the v1.0 REST API. A public Microsoft service health page at status.cloud.microsoft (20). It shows nothing without JavaScript, so we couldn't read components or history (5). SharePoint and OneDrive limits are published in resource units, 1,250 to 6,250 a minute and 1,200,000 to 6,000,000 a day per app per tenant by licence count, 3,000 requests per 5 minutes a user, and 400 GB of ingress and of egress an hour per app (15). 429 and 503 responses carry `Retry-After`, upload sessions resume from `nextExpectedRanges` with backoff advice for 5xx errors, and `If-Match` and `conflictBehavior` guard overwrites. There is no idempotency key on `invite` or folder creation (14 of 15). The Online Services SLA page is drawn by script and gave us no text, so no SLA is counted (0). The file endpoints are generally available on v1.0 (10).",
          "schema": "OpenAPI 3.0.4 for all of Graph v1.0 in microsoftgraph/msgraph-metadata, with 1,516 paths under `/drives`, 172 of them outside the workbook API (25). learn.microsoft.com answers 404 for llms.txt, but every page we asked for with `Accept: text/markdown` came back as Markdown (10). Reference pages state the purpose of each call, list permissions from least to most privileged and say which options work only on personal OneDrive. The upload session page gives Sites.ReadWrite.All as the least privileged application permission where the small-upload page gives Files.ReadWrite.All, and the overview page is dated March 2024 (16). `createLink` declares `type` and `scope` as plain strings with no enumeration, `conflictBehavior` is an annotation outside the schema, path addressing is absent from the OpenAPI, and `retainInheritedPermissions` defaults to false there and to true on the reference page (9). An HTTP example and SDK snippets on each page, a status code table, and upload-specific handling for 404, 409 and 416 (14). v1.0 and beta, a dated changelog and a monthly What's new page (15).",
          "security": "OAuth 2.0 through Microsoft Entra ID with delegated and application permissions from Files.Read to Sites.ReadWrite.All, revocable consent, and Selected scopes that hold an app to chosen sites, lists, folders or files. Download and upload URLs are pre-authenticated and short-lived, which we read as designed capability links and not as a credential in a URL (30). Files.Read for reading, Selected scopes with read, write, owner and fullcontrol roles, DELETE to the recycle bin and anonymous links that an administrator can disable. Nothing asks for confirmation before `permanentDelete` or an anonymous link (17). File names and contents written by other people reach the caller, and no injection guidance was found in the files reference pages (0). Graph activity logs record app, user, request URI and scopes for every request, but need Entra ID P1 or P2 and an Azure log destination (12). The Microsoft 365 bounty names SharePoint Online and OneDrive at $1,250 to $19,500, with a coordinated disclosure policy and an Office 365 SOC 2 Type 2 report. microsoft.com's security.txt passed its Expires date on 23 September 2026, and a token-leak fix in the JavaScript client is unreleased on npm (14).",
          "transparency": "Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDKs (15). Microsoft's data handling page for Microsoft 365 gives at most 30 days after active deletion and 180 days after a subscription ends for customer content, the SharePoint deletion page gives 93 days in the recycle bin and 14 further days of backups, and the privacy statement was updated in September 2026. We didn't read the data protection addendum (22). The Graph policy is at least 24 months' notice before a generally available API or version is removed, while the API terms reserve the right to change or discontinue any API with or without notice (18). Data residency for Microsoft 365 is documented by tenant geography. The sub-processor list sits on the Service Trust Portal, which we didn't read (10)."
        },
        "sources": [
          {
            "what": "files overview in the v1.0 reference",
            "url": "https://learn.microsoft.com/en-us/graph/api/resources/onedrive?view=graph-rest-1.0",
            "seen": "2026-10-09"
          },
          {
            "what": "OneDrive concept overview",
            "url": "https://learn.microsoft.com/en-us/graph/onedrive-concept-overview",
            "seen": "2026-10-09"
          },
          {
            "what": "driveItem resource",
            "url": "https://learn.microsoft.com/en-us/graph/api/resources/driveitem?view=graph-rest-1.0",
            "seen": "2026-10-09"
          },
          {
            "what": "small upload (PUT content, 250 MB)",
            "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-put-content?view=graph-rest-1.0",
            "seen": "2026-10-09"
          },
          {
            "what": "upload sessions",
            "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-createuploadsession?view=graph-rest-1.0",
            "seen": "2026-10-09"
          },
          {
            "what": "download and pre-authenticated URLs",
            "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-get-content?view=graph-rest-1.0",
            "seen": "2026-10-09"
          },
          {
            "what": "list children and paging",
            "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-list-children?view=graph-rest-1.0",
            "seen": "2026-10-09"
          },
          {
            "what": "createLink (types, scopes, expiry)",
            "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-createlink?view=graph-rest-1.0",
            "seen": "2026-10-09"
          },
          {
            "what": "invite (permissions and invitations)",
            "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-invite?view=graph-rest-1.0",
            "seen": "2026-10-09"
          },
          {
            "what": "permission resource",
            "url": "https://learn.microsoft.com/en-us/graph/api/resources/permission?view=graph-rest-1.0",
            "seen": "2026-10-09"
          },
          {
            "what": "delete to recycle bin",
            "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-delete?view=graph-rest-1.0",
            "seen": "2026-10-09"
          },
          {
            "what": "permanent delete",
            "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-permanentdelete?view=graph-rest-1.0",
            "seen": "2026-10-09"
          },
          {
            "what": "delta",
            "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-delta?view=graph-rest-1.0",
            "seen": "2026-10-09"
          },
          {
            "what": "change notification subscriptions",
            "url": "https://learn.microsoft.com/en-us/graph/api/subscription-post-subscriptions?view=graph-rest-1.0",
            "seen": "2026-10-09"
          },
          {
            "what": "SharePoint and OneDrive throttling limits",
            "url": "https://learn.microsoft.com/en-us/sharepoint/dev/general-development/how-to-avoid-getting-throttled-or-blocked-in-sharepoint-online",
            "seen": "2026-10-09"
          },
          {
            "what": "Graph throttling limits",
            "url": "https://learn.microsoft.com/en-us/graph/throttling-limits",
            "seen": "2026-10-09"
          },
          {
            "what": "throttling guidance",
            "url": "https://learn.microsoft.com/en-us/graph/throttling",
            "seen": "2026-10-09"
          },
          {
            "what": "error responses",
            "url": "https://learn.microsoft.com/en-us/graph/errors",
            "seen": "2026-10-09"
          },
          {
            "what": "best practices",
            "url": "https://learn.microsoft.com/en-us/graph/best-practices-concept",
            "seen": "2026-10-09"
          },
          {
            "what": "Selected permissions for OneDrive and SharePoint",
            "url": "https://learn.microsoft.com/en-us/graph/permissions-selected-overview",
            "seen": "2026-10-09"
          },
          {
            "what": "Graph activity logs",
            "url": "https://learn.microsoft.com/en-us/graph/microsoft-graph-activity-logs-overview",
            "seen": "2026-10-09"
          },
          {
            "what": "metered APIs list",
            "url": "https://learn.microsoft.com/en-us/graph/metered-api-list",
            "seen": "2026-10-09"
          },
          {
            "what": "versioning, support and breaking change policy",
            "url": "https://learn.microsoft.com/en-us/graph/versioning-and-support",
            "seen": "2026-10-09"
          },
          {
            "what": "What's new in Microsoft Graph",
            "url": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
            "seen": "2026-10-09"
          },
          {
            "what": "Graph changelog feed",
            "url": "https://developer.microsoft.com/en-us/graph/changelog/rss",
            "seen": "2026-10-09"
          },
          {
            "what": "Work IQ MCP catalogue",
            "url": "https://learn.microsoft.com/en-us/microsoft-agent-365/tooling-servers-overview",
            "seen": "2026-10-09"
          },
          {
            "what": "app registration",
            "url": "https://learn.microsoft.com/en-us/graph/auth-register-app-v2",
            "seen": "2026-10-09"
          },
          {
            "what": "SDK overview",
            "url": "https://learn.microsoft.com/en-us/graph/sdks/sdks-overview",
            "seen": "2026-10-09"
          },
          {
            "what": "Microsoft 365 Developer Programme FAQ",
            "url": "https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq",
            "seen": "2026-10-09"
          },
          {
            "what": "OneDrive service description (storage by plan)",
            "url": "https://learn.microsoft.com/en-us/office365/servicedescriptions/onedrive-for-business-service-description",
            "seen": "2026-10-09"
          },
          {
            "what": "OneDrive plans page (refused our reader)",
            "url": "https://www.microsoft.com/en-us/microsoft-365/onedrive/compare-onedrive-plans",
            "seen": "2026-10-09"
          },
          {
            "what": "OpenAPI for Graph v1.0",
            "url": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
            "seen": "2026-10-09"
          },
          {
            "what": "service health page (JavaScript only)",
            "url": "https://status.cloud.microsoft/",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt",
            "url": "https://www.microsoft.com/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "Microsoft 365 bounty programme",
            "url": "https://www.microsoft.com/en-us/msrc/bounty-microsoft-cloud",
            "seen": "2026-10-09"
          },
          {
            "what": "SOC 2 Type 2 for Office 365",
            "url": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
            "seen": "2026-10-09"
          },
          {
            "what": "data retention, deletion and destruction in Microsoft 365",
            "url": "https://learn.microsoft.com/en-us/compliance/assurance/assurance-data-retention-deletion-and-destruction-overview",
            "seen": "2026-10-09"
          },
          {
            "what": "SharePoint data deletion",
            "url": "https://learn.microsoft.com/en-us/sharepoint/sharepoint-data-deletion",
            "seen": "2026-10-09"
          },
          {
            "what": "Microsoft 365 data residency",
            "url": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-overview",
            "seen": "2026-10-09"
          },
          {
            "what": "Microsoft APIs terms of use",
            "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy statement",
            "url": "https://privacy.microsoft.com/en-us/privacystatement",
            "seen": "2026-10-09"
          },
          {
            "what": "Online Services SLA page (script-drawn, no text read)",
            "url": "https://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services",
            "seen": "2026-10-09"
          },
          {
            "what": "msgraph-sdk-python releases",
            "url": "https://api.github.com/repos/microsoftgraph/msgraph-sdk-python/releases",
            "seen": "2026-10-09"
          },
          {
            "what": "npm latest for @microsoft/microsoft-graph-client",
            "url": "https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest",
            "seen": "2026-10-09"
          },
          {
            "what": "JavaScript client repository and token-leak fix",
            "url": "https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19",
            "seen": "2026-10-09"
          },
          {
            "what": "RDAP for microsoft.com",
            "url": "https://rdap.verisign.com/com/v1/domain/microsoft.com",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: status page components and incident history, which need JavaScript",
          "unchecked: OneDrive and Microsoft 365 plan prices and the free personal storage allowance, because the plans page refused our reader as an automated process",
          "unchecked: the Online Services SLA document, which is drawn by script, plus the data protection addendum and the sub-processor list on the Service Trust Portal",
          "unchecked: the advisory list of msgraph-sdk-javascript, because the GitHub API was rate-limited. The fix commit and the unpublished 3.0.8 were confirmed from a clone and from npm",
          "unchecked: pypi.org answered the msgraph-sdk project page with a client challenge, and its robots.txt disallows the JSON API, so the Python release dates come from the GitHub releases list",
          "The maximum file size for an upload session isn't stated on the upload page",
          "Whether Microsoft 365 audit logs record third-party file calls per app wasn't checked. Only Graph activity logs were read",
          "First release date of the files API, not established",
          "The lead was right on vendor, interface and docs. Its product URL, the OneDrive marketing page, wasn't used because www.microsoft.com refused our reader on the plans page"
        ]
      },
      "negative": -4,
      "negativeNotes": [
        "2026-06-16: a fix for a token leak through URL userinfo host confusion was merged into msgraph-sdk-javascript and the version set to 3.0.8, but npm still served 3.0.7 on 9 October 2026 and the repository's changelog doesn't mention it. Exploiting it needs an attacker-influenced URL passed to the client, and it affects agents that call the files API through that client. The Excel and Outlook listings took the same 4 points (https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19, https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest)"
      ],
      "verdict": "One REST surface covers personal OneDrive, work OneDrive and SharePoint libraries, with resumable uploads, sharing links that take an expiry date and per-file Selected permissions. The status page needs JavaScript, an app must be registered and consented to by a person, and the JavaScript client on npm lacks a token-leak fix merged in June 2026.",
      "bestFor": "Agents working on files that already live in a Microsoft 365 tenant or a personal OneDrive, where sharing has to follow the tenant's own policy.",
      "strengths": [
        "Upload sessions resume after a dropped connection, report `nextExpectedRanges`, and accept `If-Match` and `@microsoft.graph.conflictBehavior` (fail by default)",
        "`createLink` takes `expirationDateTime` and a scope of `anonymous`, `organization` or `users`, and returns the existing link when one of that type exists",
        "Selected scopes limit an application to chosen sites, lists, folders or files, each with a read, write, owner or fullcontrol role",
        "SharePoint publishes throttling numbers, with 1,250 to 6,250 resource units a minute per app per tenant and a stated cost of 1, 2 or 5 units a request",
        "DELETE moves an item to the recycle bin, and permanent removal is a separate `permanentDelete` call"
      ],
      "weaknesses": [
        "Link and scope types are plain strings in the OpenAPI, and path addressing such as `/root:/folder/file.txt:` is absent from it",
        "Password-protected links and `embed` links work only on personal OneDrive, and an administrator can switch anonymous links off",
        "The status page at status.cloud.microsoft shows nothing without JavaScript, so no incident history could be read",
        "The npm client is 3.0.7 from September 2023. A token-leak fix merged on 16 June 2026 set the version to 3.0.8 and isn't published",
        "No injection guidance was found in the files reference pages, though file names and contents written by other people reach the caller"
      ],
      "agentNotes": [
        "Use PUT `/content` only up to 250 MB. Above 10 MiB Microsoft advises `createUploadSession`, with fragments in multiples of 320 KiB and under 60 MiB each",
        "Send the bearer token on the `createUploadSession` POST only. The PUT calls to `uploadUrl` can return 401 if an `Authorization` header is included",
        "Set `expirationDateTime` and `scope` on `createLink`. Without a scope the tenant's default link type is created, which may be wider than intended",
        "Follow the 302 from GET `/content` straight away. Pre-authenticated download URLs can expire within minutes and need no `Authorization` header",
        "Wait for `Retry-After` on 429 and 503. Throttled requests still count against the limits, and continued overuse can get the app blocked"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 65.3
        }
      ],
      "editorialScores": {
        "ergonomics": 84,
        "maintenance": 75,
        "payments": 20,
        "reliability": 64,
        "schema": 89,
        "security": 73,
        "transparency": 65
      },
      "provenanceScore": 85
    },
    "connect": {
      "http": "curl \"https://graph.microsoft.com/v1.0/me/drive/root/children?\\$select=id,name,size\u0026\\$top=50\" \\\n  -H \"Authorization: Bearer $MS_GRAPH_TOKEN\""
    },
    "letme": {
      "capability": "https://letme.dev/storage.drive",
      "tool": "https://letme.dev/onedrive-sharepoint"
    },
    "sameCompany": [
      "azure-foundry-fine-tuning",
      "azure-ai-content-safety",
      "azure-speech-to-text",
      "azure-text-to-speech",
      "microsoft-agent-framework",
      "microsoft-execution-containers",
      "microsoft-entra-agent-id",
      "azure-key-vault",
      "azure-document-intelligence",
      "azure-devops-mcp",
      "microsoft-learn-mcp",
      "playwright-mcp",
      "azure-mcp",
      "azure-maps",
      "azure-translator",
      "microsoft-graph-calendar",
      "azure-blob-storage",
      "microsoft-teams",
      "dynamics-365-sales",
      "power-automate",
      "foundry-local",
      "microsoft-advertising-api",
      "microsoft-excel-graph",
      "outlook-mail-graph"
    ],
    "notable": [
      "The same endpoints address a user's OneDrive (`/me/drive`), another user's, a group library, a SharePoint site library (`/sites/{site-id}/drive`) and shared items (`/shares/{share-id}`) (https://learn.microsoft.com/en-us/graph/api/resources/onedrive)",
      "PUT `/content` takes files up to 250 MB. Upload sessions take larger files in sequential byte ranges, each a multiple of 320 KiB and under 60 MiB (https://learn.microsoft.com/en-us/graph/api/driveitem-createuploadsession)",
      "`createLink` accepts `type` (view, edit, embed), `scope` (`anonymous`, `organization`, `users`), `expirationDateTime` and, on personal OneDrive only, `password` (https://learn.microsoft.com/en-us/graph/api/driveitem-createlink)",
      "SharePoint limits are counted in resource units, 1 for a single-item read or download, 2 for a list, create, update, delete or upload, and 5 for any permission operation (https://learn.microsoft.com/en-us/sharepoint/dev/general-development/how-to-avoid-getting-throttled-or-blocked-in-sharepoint-online)",
      "The only metered Graph API is `assignSensitivityLabel` for SharePoint and OneDrive for work or school, at $0.00185 a call (https://learn.microsoft.com/en-us/graph/metered-api-list)",
      "Work IQ OneDrive and Work IQ SharePoint MCP servers are in preview and need a Microsoft 365 Copilot licence. This listing grades the REST API (https://learn.microsoft.com/en-us/microsoft-agent-365/tooling-servers-overview)",
      "The OpenAPI for Graph v1.0 has 1,516 paths under `/drives`, 172 of them outside the workbook API, and declares `retainInheritedPermissions` with a default of false where the reference page says true (https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml)",
      "Change notifications cover the root folder of a work OneDrive or any folder of a personal one, and `delta` returns changes since a saved token (https://learn.microsoft.com/en-us/graph/api/subscription-post-subscriptions)"
    ],
    "area": "everyday",
    "details": [
      {
        "label": "Free tier",
        "value": "No charge for file calls. Storage is the account's own OneDrive or Microsoft 365 allowance. Plan prices unread on 2026-10-09"
      },
      {
        "label": "Drives",
        "value": "Personal OneDrive, OneDrive for work or school, SharePoint document libraries, group libraries and shared items, on the same endpoints"
      },
      {
        "label": "Uploads",
        "value": "PUT `/content` up to 250 MB. Upload sessions above that, resumable, in fragments that are multiples of 320 KiB and under 60 MiB, 5 to 10 MiB advised"
      },
      {
        "label": "Downloads",
        "value": "GET `/content` answers 302 to a pre-authenticated URL that can expire within minutes"
      },
      {
        "label": "Sharing",
        "value": "`createLink` with view, edit or embed type, anonymous, organisation or named-user scope and `expirationDateTime`. `invite` grants read or write to recipients. Passwords on personal OneDrive only"
      },
      {
        "label": "Deleting",
        "value": "DELETE sends an item to the recycle bin (93 days on SharePoint). `permanentDelete` removes it for good"
      },
      {
        "label": "Rate limits",
        "value": "Per app per tenant 1,250 to 6,250 resource units a minute and 1,200,000 to 6,000,000 a day by licence count, 400 GB of ingress and of egress an hour. Per user 3,000 requests per 5 minutes"
      },
      {
        "label": "Paging",
        "value": "200 items a page by default, `@odata.nextLink`, with `$top`, `$select`, `$orderby`, `$expand` and `$skipToken`"
      },
      {
        "label": "Permissions",
        "value": "Files.Read, Files.ReadWrite, Files.Read.All, Files.ReadWrite.All, Sites.Read.All, Sites.ReadWrite.All, plus Sites.Selected and Files.SelectedOperations.Selected"
      },
      {
        "label": "Change events",
        "value": "`delta` with a saved token, and webhook subscriptions on a drive's root folder (any folder on personal OneDrive)"
      },
      {
        "label": "MCP server",
        "value": "Work IQ OneDrive and Work IQ SharePoint, preview, Microsoft 365 Copilot licence needed. Not graded here"
      },
      {
        "label": "SDKs",
        "value": "C#, Java, Go, PHP, Python (msgraph-sdk 1.64.0, 6 October 2026), PowerShell and JavaScript (npm 3.0.7 from September 2023)"
      },
      {
        "label": "National clouds",
        "value": "Global, US Government L4 and L5, and China operated by 21Vianet"
      }
    ],
    "provenance": {
      "legalEntity": "Microsoft Corporation",
      "domain": "microsoft.com",
      "domainRegistered": "1991-05-02",
      "domainNote": "The endpoint is on graph.microsoft.com. Upload and download URLs are issued on other Microsoft hosts. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
      "endpointOnVendorDomain": true,
      "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
      "privacy": "https://privacy.microsoft.com/en-us/privacystatement",
      "statusPage": "https://status.cloud.microsoft",
      "changelog": "https://developer.microsoft.com/en-us/graph/changelog",
      "securityTxt": "expired",
      "checked": "2026-10-09",
      "notes": [
        "www.microsoft.com/.well-known/security.txt still carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-09.",
        "The Microsoft service health page at status.cloud.microsoft needs JavaScript to show anything.",
        "The Microsoft APIs terms of use name Microsoft Corporation and were last updated in October 2025.",
        "The Microsoft privacy statement was last updated in September 2026.",
        "RDAP for microsoft.com gives a registration date of 1991-05-02.",
        "The Graph changelog feed's newest entry is dated 3 August 2026. The What's new page, updated 8 October 2026, lists later changes."
      ],
      "score": 85,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Microsoft Corporation",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "microsoft.com, registered 1991-05-02 (35 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "graph.microsoft.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points",
          "points": 2.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
          "points": 8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.cloud.microsoft",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "published but past its Expires date",
          "points": 5,
          "max": 10,
          "state": "part"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-10-01",
          "words": 4555,
          "points": 2.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: October 2025 What's new?",
              "says": "Last updated 2025-10-01"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "WE MAKE NO WARRANTIES, EXPRESS OR IMPLIED, GUARANTEES OR CONDITIONS WITH RESPECT TO YOUR USE OF THE MICROSOFT APIs."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "We may change, amend or terminate these API Terms at any time."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Unless you have use permissions expressly and specifically granted by Customers in connection with using your Application, you may not use Microsoft email protocols and APIs for any purpose other than:"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "Scrape, build databases or otherwise create copies of any data accessed or obtained using the Microsoft APIs, except as necessary to enable an intended usage scenario for your Application;",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "Use the Microsoft APIs, or any data obtained using the Microsoft APIs, to conduct performance testing of a Microsoft Offering unless expressly permitted by Microsoft",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may suspend or immediately terminate these API Terms, any rights granted herein, and/or your license to the Microsoft APIs, in our sole discretion at any time, for any reason."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Recoverable damages are limited to direct damages of up to 5 US dollars in total.",
              "quote": "YOU AGREE THAT YOUR EXCLUSIVE REMEDY IS TO RECOVER, FROM MICROSOFT OR ANY AFFILIATES, RESELLERS, DISTRIBUTORS, SUPPLIERS (AND RESPECTIVE EMPLOYEES, SHAREHOLDERS, OR DIRECTORS) AND VENDORS, ONLY DIRECT DAMAGES UP TO USD $5.00 COLLECTIVELY."
            },
            {
              "date": "2026-10-08",
              "text": "After a data breach involving the Microsoft APIs, the developer may make no public statement about it without Microsoft's prior written permission.",
              "quote": "You agree to refrain from making public statements (e.g., press, blogs, social media, bulletin boards, etc.) without prior written and express permission from Microsoft in each instance as it relates to the Microsoft APIs."
            },
            {
              "date": "2026-10-08",
              "text": "The developer must allow Microsoft reasonable access to its application so Microsoft can monitor compliance with the API terms.",
              "quote": "You will permit Microsoft reasonable access to your Application for purposes of monitoring compliance with these API Terms."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://privacy.microsoft.com/en-us/privacystatement",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-01",
          "words": 33580,
          "points": 8,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: September 2026",
              "says": "Last updated 2026-09-01"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "The data we collect depends on the context of your interactions with Microsoft and the choices you make, including your privacy settings and the products and features you use."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "When you delete an email or item from a mailbox in Outlook.com, the item generally goes into your Deleted Items folder where it remains for approximately 7 days unless you move it back to your inbox, you empty the folder, or the service empties the folder automatically, whichever comes first.",
              "says": "Names a period of 7 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Service providers that help us determine your device’s location."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "not use or share student personal data for advertising or similar commercial purposes, such as providing personalized advertising to students;"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "State Data Privacy Notice (including notice at collection details) and the Consumer Health Data Privacy Policy for additional information about your rights and the processing of your personal data."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have a privacy concern, complaint, or question for the Microsoft privacy team or Data Protection Officer, please visit our privacy support and requests page and click on “Contact the Microsoft privacy team or the Microsoft Data Protection Officer” menu.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "In such cases, we implement legal safeguards-such as standard contractual clauses approved by the European Commission – to help protect your rights and ensure your data remains protected.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.",
              "costsPoints": true
            },
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We also disclose personal data for digital advertising purposes."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict.",
              "quote": "In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control."
            },
            {
              "date": "2026-10-08",
              "text": "Advertisements may be chosen from the current interaction, including Copilot conversations and files shared in them.",
              "quote": "Ads may be shown that relate to the current interaction you are having with us, such as your Copilot conversations (including files you share); your current location; transactions; product usage; search queries; or the content you’re viewing."
            },
            {
              "date": "2026-10-08",
              "text": "Microsoft staff manually review some results of automated systems, including AI, against the source data.",
              "quote": "For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/onedrive-sharepoint.json",
    "live": {
      "slug": "onedrive-sharepoint",
      "probe": {
        "target": "https://graph.microsoft.com/v1.0",
        "method": "get",
        "lastAt": "2026-10-09T10:42:51.35573993Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 5,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 4,
        "p95ms24h": 18,
        "samples24h": 33,
        "samples30d": 33,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 33,
            "ok": 33
          }
        ]
      },
      "updatedAt": "2026-10-09T10:42:51.35573993Z"
    }
  }
}
