{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/google-sheets-api.json",
        "name": "Google Sheets API",
        "score": 76.3,
        "shared": [
          "sheets.read",
          "sheets.write",
          "sheets.formulas",
          "sheets.tables"
        ],
        "slug": "google-sheets-api"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/nocodb.json",
        "name": "NocoDB",
        "score": 75.7,
        "shared": [
          "sheets.read",
          "sheets.write",
          "sheets.tables",
          "sheets.formulas"
        ],
        "slug": "nocodb"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/airtable.json",
        "name": "Airtable",
        "score": 70.9,
        "shared": [
          "sheets.read",
          "sheets.write",
          "sheets.tables",
          "sheets.formulas"
        ],
        "slug": "airtable"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/coda.json",
        "name": "Coda (Superhuman Docs)",
        "score": 64.8,
        "shared": [
          "sheets.read",
          "sheets.write",
          "sheets.tables",
          "sheets.formulas"
        ],
        "slug": "coda"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/baserow.json",
        "name": "Baserow",
        "score": 63.6,
        "shared": [
          "sheets.read",
          "sheets.write",
          "sheets.tables",
          "sheets.formulas"
        ],
        "slug": "baserow"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/smartsheet.json",
        "name": "Smartsheet API + MCP",
        "score": 67.6,
        "shared": [
          "sheets.read",
          "sheets.write",
          "sheets.formulas"
        ],
        "slug": "smartsheet"
      }
    ],
    "tool": {
      "slug": "microsoft-excel-graph",
      "name": "Microsoft Excel (Microsoft Graph workbook API)",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/graph/excel-concept-overview",
      "kind": "http-api",
      "category": "spreadsheets",
      "summary": "Workbook endpoints of Microsoft Graph for Excel files stored in OneDrive for work or school and SharePoint. Calls read and write ranges, tables, charts and named items, and run Excel worksheet functions on a file in place.",
      "url": "https://www.anchorterminal.com/tools/microsoft-excel-graph",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-excel-graph.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-excel-graph.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-excel-graph.json",
      "repo": "https://github.com/microsoftgraph/msgraph-sdk-javascript",
      "license": "MIT (SDKs)",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://graph.microsoft.com/v1.0",
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/microsoft-graph-client"
        },
        {
          "registry": "pypi",
          "name": "msgraph-sdk"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 tokens from Microsoft Entra ID, after a person registers an app. Registration is self-serve, with no partner or sales approval. The workbook reference pages list delegated permissions only, with Files.ReadWrite as least privileged, and mark application permissions as not supported. The overview page names Files.Read for read actions. A delegated token reaches every file its user can open.",
      "pricing": "byo-plan",
      "pricingNotes": "Workbook calls carry no per-call charge. Microsoft's list of metered Graph APIs names only SharePoint and OneDrive `assignSensitivityLabel`, at $0.00185 a call (https://learn.microsoft.com/en-us/graph/metered-api-list). Files must sit in OneDrive for work or school or SharePoint, which need a Microsoft 365 licence. The Microsoft 365 plan price page refused our reader on 2026-10-08. A free Microsoft 365 E5 developer sandbox is limited to Visual Studio subscribers and members of named partner programmes (https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq).",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the workbook documentation or the metered API list (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 835,
        "npmWeekly": 2882852,
        "pypiWeekly": 1578201,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/graph/api/resources/excel",
      "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
      "capabilities": [
        "sheets.read",
        "sheets.write",
        "sheets.tables",
        "sheets.formulas"
      ],
      "tags": [
        "hosted",
        "official",
        "oauth",
        "openapi",
        "typescript",
        "python",
        "enterprise"
      ],
      "lastRelease": "2025-09-19",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 58.5,
        "grade": "C",
        "agentReady": false,
        "rank": 399,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 73,
          "maintenance": 53,
          "payments": 15,
          "reliability": 62,
          "schema": 85,
          "security": 65,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 62,
            "points": 12.4,
            "reason": "A public Microsoft service health page at status.cloud.microsoft. It renders only with JavaScript, so we couldn't read components or history (20). No readable incident history (5). Excel resources are throttled at 5,000 requests per 10 seconds per app across all tenants and 1,500 per app per tenant, under a global 130,000 per 10 seconds, though Microsoft adds that the cost of a workbook call varies too much for the numbers to tell the whole story (15). Throttled responses carry `Retry-After`, the error guide gives a retry instruction per error code, and Microsoft asks for one request at a time per workbook. There is no idempotency key, and the row-add page says to repeat the request on a 504, which can add rows twice (12). No SLA naming the Graph API was found, and we didn't read the Online Services SLA document (0). The workbook endpoints are generally available on v1.0 (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 85,
            "points": 13.81,
            "reason": "OpenAPI 3.0.4 for all of Graph v1.0 in microsoftgraph/msgraph-metadata, with 1,442 workbook paths and 1,765 operations (25). learn.microsoft.com has no llms.txt, but every docs page we asked for with `accept=text/markdown` came back as Markdown (10). Reference pages state the purpose and the permissions of each call, and the overview explains sessions, nulls, unbounded and large ranges. Pages disagree on whether personal accounts and Files.Read work, and the workbookOperation page opens with a line that explains little (14). Cell values, formulas and number formats are untyped JSON (`values: { }` in the OpenAPI), and chart types are plain strings (7). An HTTP example on each page, plus separate pages for error codes and error handling (14). v1.0 and beta, with a dated public changelog (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 73,
            "points": 11.86,
            "reason": "A range is read by address, `$select` trims the properties returned and table rows take `$top` and `$skip`. A range answer carries values, text, formulas and number formats unless trimmed, and the whole-Graph OpenAPI is 44 MB (20). `$top` and `$skip` paging on table rows, plus server-side table sort and filter that change the workbook's own view (15). Errors carry a top-level code, a second-level code with a written instruction on whether to retry, and a request ID (18). No idempotency key on writes. Non-persistent sessions let an agent try edits without saving, and Microsoft's advice is sequential requests per workbook (8). Sessionless calls work with a bearer token and a file path, worksheet and chart IDs need their braces URL-encoded, and official SDKs cover C#, Java, Go, PHP, Python, PowerShell and JavaScript, though the npm JavaScript client dates from September 2023 (12)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 65,
            "points": 11.38,
            "reason": "OAuth 2.0 through Entra ID with scoped, revocable consent. The workbook reference pages list delegated permissions only, and a Files.ReadWrite token reaches every file its user can open (27). The overview names Files.Read for reads while the reference pages give Files.ReadWrite as least privileged even for a range read. A non-persistent session keeps changes out of the file. Per-file Selected scopes exist for OneDrive and SharePoint, but the workbook pages don't list them. Nothing asks for confirmation before a delete (12). Cell contents written by other people reach the caller with no injection guidance in the workbook docs (0). Graph activity logs record app, user, URI and status for every request, but need Entra ID P1 or P2 and an Azure log destination (12). Microsoft 365 bounty of $1,250 to $19,500, a coordinated disclosure policy and an Office 365 SOC 2 Type 2 report. microsoft.com's security.txt passed its Expires date on 23 September 2026, and a token-leak fix in the JavaScript client is unreleased on npm (14)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 15,
            "points": 1.88,
            "reason": "No x402, MPP or L402 (0). Workbook calls aren't on Microsoft's metered API list, so there is no per-call charge, but the file's home needs a Microsoft 365 licence and the plan price page refused our reader today (10). The free E5 developer sandbox is limited to Visual Studio subscribers and named partner programmes. The overview says consumer OneDrive isn't supported, while some reference pages list personal accounts (5). A person registers an app in Entra and signs in to consent (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 53,
            "points": 4.64,
            "reason": "msgraph-sdk 1.64.0 reached PyPI on 6 October 2026, but the last Workbooks and charts entry in the Graph changelog is dated 19 September 2025 and the overview page March 2024. We scored this line between the two, a departure from the checklist's single date (10). Six Python SDK releases since 14 July 2026, from 1.59.2 to 1.64.0 (20). A public changelog and SDK issue trackers. The seven newest open issues on msgraph-sdk-python had no or one reply, and a security fix merged into the JavaScript client on 16 June 2026 hasn't reached npm (7). Current SDKs in most languages, with the JavaScript client the exception at 3.0.7 from September 2023 (10). Active releases on the Python package, none on the JavaScript one (6)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 75,
            "points": 6.56,
            "note": "editorial 65, provenance 85",
            "reason": "Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDKs (15). Microsoft's data handling page for Microsoft 365 gives at most 30 days after active deletion and 180 days after a subscription ends for customer content, Excel files included, and the privacy statement was updated in September 2026. We didn't read the DPA (22). The Graph policy is at least 24 months' notice before a GA API or version is removed, with breaking changes only on a new version number (18). Data residency for Microsoft 365 is documented by tenant geography. The sub-processor list sits on the Service Trust Portal, which we didn't read (10)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "A range is read by address, `$select` trims the properties returned and table rows take `$top` and `$skip`. A range answer carries values, text, formulas and number formats unless trimmed, and the whole-Graph OpenAPI is 44 MB (20). `$top` and `$skip` paging on table rows, plus server-side table sort and filter that change the workbook's own view (15). Errors carry a top-level code, a second-level code with a written instruction on whether to retry, and a request ID (18). No idempotency key on writes. Non-persistent sessions let an agent try edits without saving, and Microsoft's advice is sequential requests per workbook (8). Sessionless calls work with a bearer token and a file path, worksheet and chart IDs need their braces URL-encoded, and official SDKs cover C#, Java, Go, PHP, Python, PowerShell and JavaScript, though the npm JavaScript client dates from September 2023 (12).",
            "maintenance": "msgraph-sdk 1.64.0 reached PyPI on 6 October 2026, but the last Workbooks and charts entry in the Graph changelog is dated 19 September 2025 and the overview page March 2024. We scored this line between the two, a departure from the checklist's single date (10). Six Python SDK releases since 14 July 2026, from 1.59.2 to 1.64.0 (20). A public changelog and SDK issue trackers. The seven newest open issues on msgraph-sdk-python had no or one reply, and a security fix merged into the JavaScript client on 16 June 2026 hasn't reached npm (7). Current SDKs in most languages, with the JavaScript client the exception at 3.0.7 from September 2023 (10). Active releases on the Python package, none on the JavaScript one (6).",
            "payments": "No x402, MPP or L402 (0). Workbook calls aren't on Microsoft's metered API list, so there is no per-call charge, but the file's home needs a Microsoft 365 licence and the plan price page refused our reader today (10). The free E5 developer sandbox is limited to Visual Studio subscribers and named partner programmes. The overview says consumer OneDrive isn't supported, while some reference pages list personal accounts (5). A person registers an app in Entra and signs in to consent (0).",
            "reliability": "A public Microsoft service health page at status.cloud.microsoft. It renders only with JavaScript, so we couldn't read components or history (20). No readable incident history (5). Excel resources are throttled at 5,000 requests per 10 seconds per app across all tenants and 1,500 per app per tenant, under a global 130,000 per 10 seconds, though Microsoft adds that the cost of a workbook call varies too much for the numbers to tell the whole story (15). Throttled responses carry `Retry-After`, the error guide gives a retry instruction per error code, and Microsoft asks for one request at a time per workbook. There is no idempotency key, and the row-add page says to repeat the request on a 504, which can add rows twice (12). No SLA naming the Graph API was found, and we didn't read the Online Services SLA document (0). The workbook endpoints are generally available on v1.0 (10).",
            "schema": "OpenAPI 3.0.4 for all of Graph v1.0 in microsoftgraph/msgraph-metadata, with 1,442 workbook paths and 1,765 operations (25). learn.microsoft.com has no llms.txt, but every docs page we asked for with `accept=text/markdown` came back as Markdown (10). Reference pages state the purpose and the permissions of each call, and the overview explains sessions, nulls, unbounded and large ranges. Pages disagree on whether personal accounts and Files.Read work, and the workbookOperation page opens with a line that explains little (14). Cell values, formulas and number formats are untyped JSON (`values: { }` in the OpenAPI), and chart types are plain strings (7). An HTTP example on each page, plus separate pages for error codes and error handling (14). v1.0 and beta, with a dated public changelog (15).",
            "security": "OAuth 2.0 through Entra ID with scoped, revocable consent. The workbook reference pages list delegated permissions only, and a Files.ReadWrite token reaches every file its user can open (27). The overview names Files.Read for reads while the reference pages give Files.ReadWrite as least privileged even for a range read. A non-persistent session keeps changes out of the file. Per-file Selected scopes exist for OneDrive and SharePoint, but the workbook pages don't list them. Nothing asks for confirmation before a delete (12). Cell contents written by other people reach the caller with no injection guidance in the workbook docs (0). Graph activity logs record app, user, URI and status for every request, but need Entra ID P1 or P2 and an Azure log destination (12). Microsoft 365 bounty of $1,250 to $19,500, a coordinated disclosure policy and an Office 365 SOC 2 Type 2 report. microsoft.com's security.txt passed its Expires date on 23 September 2026, and a token-leak fix in the JavaScript client is unreleased on npm (14).",
            "transparency": "Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDKs (15). Microsoft's data handling page for Microsoft 365 gives at most 30 days after active deletion and 180 days after a subscription ends for customer content, Excel files included, and the privacy statement was updated in September 2026. We didn't read the DPA (22). The Graph policy is at least 24 months' notice before a GA API or version is removed, with breaking changes only on a new version number (18). Data residency for Microsoft 365 is documented by tenant geography. The sub-processor list sits on the Service Trust Portal, which we didn't read (10)."
          },
          "sources": [
            {
              "what": "Excel overview in the v1.0 reference (sessions, scopes, ranges, nulls)",
              "url": "https://learn.microsoft.com/en-us/graph/api/resources/excel?view=graph-rest-1.0",
              "seen": "2026-10-08"
            },
            {
              "what": "best practices for the Excel API",
              "url": "https://learn.microsoft.com/en-us/graph/workbook-best-practice",
              "seen": "2026-10-08"
            },
            {
              "what": "throttling limits, Excel service limits",
              "url": "https://learn.microsoft.com/en-us/graph/throttling-limits#excel-service-limits",
              "seen": "2026-10-08"
            },
            {
              "what": "throttling guidance",
              "url": "https://learn.microsoft.com/en-us/graph/throttling",
              "seen": "2026-10-08"
            },
            {
              "what": "error handling for Excel APIs",
              "url": "https://learn.microsoft.com/en-us/graph/workbook-error-handling",
              "seen": "2026-10-08"
            },
            {
              "what": "error codes for workbooks and charts",
              "url": "https://learn.microsoft.com/en-us/graph/workbook-error-codes",
              "seen": "2026-10-08"
            },
            {
              "what": "createSession reference and permissions",
              "url": "https://learn.microsoft.com/en-us/graph/api/workbook-createsession?view=graph-rest-1.0",
              "seen": "2026-10-08"
            },
            {
              "what": "range get and update reference",
              "url": "https://learn.microsoft.com/en-us/graph/api/range-get?view=graph-rest-1.0",
              "seen": "2026-10-08"
            },
            {
              "what": "list and add table rows reference",
              "url": "https://learn.microsoft.com/en-us/graph/api/table-post-rows?view=graph-rest-1.0",
              "seen": "2026-10-08"
            },
            {
              "what": "metered APIs list",
              "url": "https://learn.microsoft.com/en-us/graph/metered-api-list",
              "seen": "2026-10-08"
            },
            {
              "what": "versioning, support and breaking change policy",
              "url": "https://learn.microsoft.com/en-us/graph/versioning-and-support",
              "seen": "2026-10-08"
            },
            {
              "what": "Selected permissions for OneDrive and SharePoint",
              "url": "https://learn.microsoft.com/en-us/graph/permissions-selected-overview",
              "seen": "2026-10-08"
            },
            {
              "what": "Graph activity logs",
              "url": "https://learn.microsoft.com/en-us/graph/microsoft-graph-activity-logs-overview",
              "seen": "2026-10-08"
            },
            {
              "what": "change notifications overview",
              "url": "https://learn.microsoft.com/en-us/graph/api/resources/change-notifications-api-overview?view=graph-rest-1.0",
              "seen": "2026-10-08"
            },
            {
              "what": "Work IQ MCP catalogue",
              "url": "https://learn.microsoft.com/en-us/microsoft-agent-365/tooling-servers-overview",
              "seen": "2026-10-08"
            },
            {
              "what": "Microsoft 365 Developer Programme FAQ",
              "url": "https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI for Graph v1.0",
              "url": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
              "seen": "2026-10-08"
            },
            {
              "what": "Graph changelog feed",
              "url": "https://developer.microsoft.com/en-us/graph/changelog/rss",
              "seen": "2026-10-08"
            },
            {
              "what": "service health page (JavaScript only)",
              "url": "https://status.cloud.microsoft/",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://www.microsoft.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "Microsoft 365 bounty programme",
              "url": "https://www.microsoft.com/en-us/msrc/bounty-microsoft-cloud",
              "seen": "2026-10-08"
            },
            {
              "what": "SOC 2 Type 2 for Office 365",
              "url": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
              "seen": "2026-10-08"
            },
            {
              "what": "data retention, deletion and destruction in Microsoft 365",
              "url": "https://learn.microsoft.com/en-us/compliance/assurance/assurance-data-retention-deletion-and-destruction-overview",
              "seen": "2026-10-08"
            },
            {
              "what": "Microsoft 365 data residency",
              "url": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-overview",
              "seen": "2026-10-08"
            },
            {
              "what": "Microsoft APIs terms of use",
              "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy statement",
              "url": "https://privacy.microsoft.com/en-us/privacystatement",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI msgraph-sdk releases",
              "url": "https://pypi.org/pypi/msgraph-sdk/json",
              "seen": "2026-10-08"
            },
            {
              "what": "npm latest for @microsoft/microsoft-graph-client",
              "url": "https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "JavaScript client repository and token-leak fix",
              "url": "https://github.com/microsoftgraph/msgraph-sdk-javascript",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: status page components and incident history, which need JavaScript",
            "unchecked: Microsoft 365 plan prices, because the pricing page refused our reader",
            "unchecked: the Online Services SLA document, the DPA and the sub-processor list on the Service Trust Portal",
            "Whether application permissions and the per-file Selected scopes work on workbook endpoints. The reference pages say application permissions aren't supported",
            "Whether personal Microsoft accounts work. The overview says consumer OneDrive isn't supported, while the range and list-rows pages list Files.ReadWrite for personal accounts",
            "Whether Microsoft will publish msgraph-sdk-javascript 3.0.8 or an advisory for the 16 June 2026 fix",
            "First release date of the workbook API, not established"
          ]
        },
        "negative": -4,
        "negativeNotes": [
          "2026-06-16: a fix for a token leak through URL userinfo host confusion was merged into msgraph-sdk-javascript and the version set to 3.0.8, but npm still served 3.0.7 on 8 October 2026 and the repository lists no published advisory. Exploiting it needs an attacker-influenced URL passed to the client, and it affects agents that call the workbook API through that client (https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19, https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest)"
        ],
        "verdict": "Ranges, tables, charts and 366 worksheet function endpoints are reachable over REST with a public OpenAPI, and a non-persistent session lets an agent test changes without saving them. The reference pages list delegated permissions only, with Files.ReadWrite as the least privileged scope, and writes take no idempotency key.",
        "bestFor": "Agents working on .xlsx files that already live in a Microsoft 365 tenant, and for using Excel's calculation engine through function endpoints.",
        "strengths": [
          "Non-persistent sessions (`persistChanges: false`) keep changes in a temporary copy, so an agent can calculate or test edits without saving",
          "The OpenAPI for Graph v1.0 holds 1,442 workbook paths and 1,765 operations, 366 of the paths for worksheet functions",
          "Error handling guide gives a retry instruction for each of 22 required second-level error codes",
          "Throttling limits are published at 5,000 requests per 10 seconds per app and 1,500 per app per tenant, with `Retry-After` on throttled responses",
          "Microsoft's policy is at least 24 months' notice before a generally available Graph API is removed"
        ],
        "weaknesses": [
          "Reference pages list delegated permissions only and mark application permissions as not supported",
          "Files.ReadWrite is the least privileged permission on the reference pages, even for reading a range or listing rows",
          "No idempotency key on writes. The row-add page says to repeat the request on a 504",
          "Cell values, formulas and number formats are untyped JSON in the OpenAPI",
          "The last Workbooks and charts changelog entry is dated 19 September 2025, and the overview page is dated March 2024"
        ],
        "agentNotes": [
          "Create a session with POST /workbook/createSession and send `workbook-session-id` on every call. Persistent sessions expire after about 5 minutes idle",
          "Set `persistChanges` to false when you only need a calculation or a chart image, so nothing is saved to the file",
          "Send one request at a time per workbook and wait for each response. Microsoft warns that parallel writes cause throttling, timeouts and merge conflicts",
          "Add rows in one call with a two-dimensional `values` array, and check the table before repeating a row add that returned 504",
          "Read bounded addresses such as A1:D500. A whole-column range such as C:C returns null for values, and writes to it are refused"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 58.5
          }
        ],
        "editorialScores": {
          "ergonomics": 73,
          "maintenance": 53,
          "payments": 15,
          "reliability": 62,
          "schema": 85,
          "security": 65,
          "transparency": 65
        },
        "provenanceScore": 85
      },
      "connect": {
        "http": "curl https://graph.microsoft.com/v1.0/me/drive/items/{id}/workbook/worksheets \\\n  -H \"Authorization: Bearer $MS_GRAPH_TOKEN\" \\\n  -H \"workbook-session-id: $SESSION_ID\""
      },
      "letme": {
        "capability": "https://letme.dev/sheets.read",
        "tool": "https://letme.dev/microsoft-excel-graph"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-translator",
        "microsoft-graph-calendar",
        "dynamics-365-sales",
        "microsoft-advertising-api",
        "outlook-mail-graph"
      ],
      "notable": [
        "The Excel REST API reaches only .xlsx workbooks, and the overview says workbooks in consumer OneDrive aren't supported (https://learn.microsoft.com/en-us/graph/api/resources/excel)",
        "Persistent sessions expire after about 5 minutes of inactivity and non-persistent sessions after about 7, and an expired session returns 404 (https://learn.microsoft.com/en-us/graph/api/resources/excel)",
        "Excel resources are throttled at 5,000 requests per 10 seconds per app across all tenants and 1,500 per app per tenant, under a global 130,000 per 10 seconds (https://learn.microsoft.com/en-us/graph/throttling-limits#excel-service-limits)",
        "Microsoft advises against parallel requests to one workbook, writes above all, and says to send the next request only after the current one succeeds (https://learn.microsoft.com/en-us/graph/workbook-best-practice)",
        "Reference pages for range get, range update, list rows, add rows and createSession list Files.ReadWrite (delegated) as least privileged and application permissions as not supported (https://learn.microsoft.com/en-us/graph/api/range-get)",
        "Change notifications cover driveItem changes under a drive's root folder. No cell or range events were found in the reviewed documentation (https://learn.microsoft.com/en-us/graph/api/resources/change-notifications-api-overview)",
        "No Excel server appears in the Work IQ MCP catalogue, which lists Word, OneDrive and SharePoint servers in preview (https://learn.microsoft.com/en-us/microsoft-agent-365/tooling-servers-overview)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Free tier",
          "value": "No charge for workbook calls. The file's home (OneDrive for work or school, or SharePoint) needs a Microsoft 365 licence"
        },
        {
          "label": "Files",
          "value": ".xlsx only, in OneDrive for work or school, SharePoint sites and group drives. The overview says consumer OneDrive isn't supported"
        },
        {
          "label": "Sessions",
          "value": "Persistent, non-persistent (`persistChanges: false`) or sessionless. Idle expiry after about 5 minutes (persistent) or 7 (non-persistent)"
        },
        {
          "label": "Rate limits",
          "value": "5,000 requests per 10 seconds per app across all tenants, 1,500 per app per tenant, global 130,000 per 10 seconds per app"
        },
        {
          "label": "Size limits",
          "value": "A range read above 5,000,000 cells returns null properties. Excel on the web caps request and response payloads at 5 MB, per the Office add-ins limits page the error guide links to"
        },
        {
          "label": "Permissions",
          "value": "Delegated Files.ReadWrite on the reference pages, Files.Read for reads per the overview. Application permissions marked not supported"
        },
        {
          "label": "Long-running calls",
          "value": "`Prefer: respond-async` on createSession and row add returns 202 with a Location to poll, about every 30 seconds"
        },
        {
          "label": "Batching",
          "value": "Rows are added many at a time through one `values` array. Graph JSON batching takes up to 20 requests"
        },
        {
          "label": "Change events",
          "value": "driveItem notifications at drive root level only, no cell or range events found"
        },
        {
          "label": "SDKs",
          "value": "C#, Java, Go, PHP, Python (msgraph-sdk 1.64.0, 6 October 2026), PowerShell, CLI and JavaScript (npm 3.0.7 from September 2023)"
        },
        {
          "label": "National clouds",
          "value": "Global, US Government L4 and L5. Not available in China operated by 21Vianet"
        }
      ],
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "domainNote": "The endpoint is on graph.microsoft.com. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
        "endpointOnVendorDomain": true,
        "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
        "privacy": "https://privacy.microsoft.com/en-us/privacystatement",
        "statusPage": "https://status.cloud.microsoft",
        "changelog": "https://developer.microsoft.com/en-us/graph/changelog",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "www.microsoft.com/.well-known/security.txt still carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08.",
          "The Microsoft service health page at status.cloud.microsoft needs JavaScript to show anything.",
          "The Microsoft APIs terms of use name Microsoft Corporation and were last updated in October 2025.",
          "The Microsoft privacy statement was last updated in September 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02."
        ],
        "score": 85,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Microsoft Corporation",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "microsoft.com, registered 1991-05-02 (35 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "graph.microsoft.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points",
            "points": 2.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
            "points": 8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.cloud.microsoft",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "published but past its Expires date",
            "points": 5,
            "max": 10,
            "state": "part"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-10-01",
            "words": 4555,
            "points": 2.3,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: October 2025 What's new?",
                "says": "Last updated 2025-10-01"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": false
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "WE MAKE NO WARRANTIES, EXPRESS OR IMPLIED, GUARANTEES OR CONDITIONS WITH RESPECT TO YOUR USE OF THE MICROSOFT APIs."
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "We may change, amend or terminate these API Terms at any time."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Unless you have use permissions expressly and specifically granted by Customers in connection with using your Application, you may not use Microsoft email protocols and APIs for any purpose other than:"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "Scrape, build databases or otherwise create copies of any data accessed or obtained using the Microsoft APIs, except as necessary to enable an intended usage scenario for your Application;",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "Use the Microsoft APIs, or any data obtained using the Microsoft APIs, to conduct performance testing of a Microsoft Offering unless expressly permitted by Microsoft",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "We may suspend or immediately terminate these API Terms, any rights granted herein, and/or your license to the Microsoft APIs, in our sole discretion at any time, for any reason."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Recoverable damages are limited to direct damages of up to 5 US dollars in total.",
                "quote": "YOU AGREE THAT YOUR EXCLUSIVE REMEDY IS TO RECOVER, FROM MICROSOFT OR ANY AFFILIATES, RESELLERS, DISTRIBUTORS, SUPPLIERS (AND RESPECTIVE EMPLOYEES, SHAREHOLDERS, OR DIRECTORS) AND VENDORS, ONLY DIRECT DAMAGES UP TO USD $5.00 COLLECTIVELY."
              },
              {
                "date": "2026-10-08",
                "text": "After a data breach involving the Microsoft APIs, the developer may make no public statement about it without Microsoft's prior written permission.",
                "quote": "You agree to refrain from making public statements (e.g., press, blogs, social media, bulletin boards, etc.) without prior written and express permission from Microsoft in each instance as it relates to the Microsoft APIs."
              },
              {
                "date": "2026-10-08",
                "text": "The developer must allow Microsoft reasonable access to its application so Microsoft can monitor compliance with the API terms.",
                "quote": "You will permit Microsoft reasonable access to your Application for purposes of monitoring compliance with these API Terms."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://privacy.microsoft.com/en-us/privacystatement",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-09-01",
            "words": 33580,
            "points": 8,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: September 2026",
                "says": "Last updated 2026-09-01"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "The data we collect depends on the context of your interactions with Microsoft and the choices you make, including your privacy settings and the products and features you use."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "When you delete an email or item from a mailbox in Outlook.com, the item generally goes into your Deleted Items folder where it remains for approximately 7 days unless you move it back to your inbox, you empty the folder, or the service empties the folder automatically, whichever comes first.",
                "says": "Names a period of 7 days"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Service providers that help us determine your device’s location."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "not use or share student personal data for advertising or similar commercial purposes, such as providing personalized advertising to students;"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "State Data Privacy Notice (including notice at collection details) and the Consumer Health Data Privacy Policy for additional information about your rights and the processing of your personal data."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have a privacy concern, complaint, or question for the Microsoft privacy team or Data Protection Officer, please visit our privacy support and requests page and click on “Contact the Microsoft privacy team or the Microsoft Data Protection Officer” menu.",
                "says": "Names a data protection officer"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "In such cases, we implement legal safeguards-such as standard contractual clauses approved by the European Commission – to help protect your rights and ensure your data remains protected.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "training",
                "label": "Says it may use customer content to train or improve models, and no opt-out was found",
                "found": true,
                "quote": "As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.",
                "costsPoints": true
              },
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "We also disclose personal data for digital advertising purposes."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict.",
                "quote": "In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control."
              },
              {
                "date": "2026-10-08",
                "text": "Advertisements may be chosen from the current interaction, including Copilot conversations and files shared in them.",
                "quote": "Ads may be shown that relate to the current interaction you are having with us, such as your Copilot conversations (including files you share); your current location; transactions; product usage; search queries; or the content you’re viewing."
              },
              {
                "date": "2026-10-08",
                "text": "Microsoft staff manually review some results of automated systems, including AI, against the source data.",
                "quote": "For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-excel-graph.json",
      "live": {
        "slug": "microsoft-excel-graph",
        "probe": {
          "target": "https://graph.microsoft.com/v1.0",
          "method": "get",
          "lastAt": "2026-10-08T18:20:34.888847521Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 3,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 30,
          "p95ms24h": 57,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.cloud.microsoft",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T15:36:56.168932402Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "microsoftgraph/msgraph-sdk-javascript",
            "version": "3.0.7",
            "released": "2023-09-19",
            "seenAt": "2026-10-08T16:20:40.005701271Z"
          },
          {
            "registry": "npm",
            "name": "@microsoft/microsoft-graph-client",
            "version": "3.0.7",
            "seenAt": "2026-10-08T16:20:38.997085198Z"
          },
          {
            "registry": "pypi",
            "name": "msgraph-sdk",
            "version": "1.64.0",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:20:39.875494563Z"
          }
        ],
        "githubStars": 835,
        "npmWeekly": 2882852,
        "pypiWeekly": 1578201,
        "securityTxt": {
          "url": "https://microsoft.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-23T16:00:00.000Z",
          "checkedAt": "2026-10-08T15:39:08.216544687Z"
        },
        "pages": [
          {
            "url": "https://developer.microsoft.com/en-us/graph/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:14.635541799Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7bb1f9551c94"
          }
        ],
        "updatedAt": "2026-10-08T18:20:34.888847521Z"
      }
    },
    "verify": {
      "accepts": "a page on microsoft.com or one of its subdomains, or the README of github.com/microsoftgraph/msgraph-sdk-javascript",
      "badgeUrl": "https://www.anchorterminal.com/badges/microsoft-excel-graph.svg",
      "body": {
        "slug": "microsoft-excel-graph",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/microsoft-excel-graph",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/microsoft-excel-graph\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/microsoft-excel-graph.svg\" alt=\"Microsoft Excel (Microsoft Graph workbook API) on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Microsoft Excel (Microsoft Graph workbook API) on Anchor Terminal](https://www.anchorterminal.com/badges/microsoft-excel-graph.svg)](https://www.anchorterminal.com/tools/microsoft-excel-graph)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/microsoft-excel-graph\"\u003eMicrosoft Excel (Microsoft Graph workbook API) on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/microsoft-excel-graph",
    "json": "https://www.anchorterminal.com/tools/microsoft-excel-graph.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/microsoft-excel-graph.md",
    "slim": "https://www.anchorterminal.com/tools/microsoft-excel-graph.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 58.5/100 · rank #399 of 629 · #7 in Spreadsheets \u0026 operational tables · not agent-ready · confidence medium**\n\n\nMore from Microsoft, listed separately because each is its own product: [Microsoft Foundry fine-tuning (Azure OpenAI)](https://www.anchorterminal.com/tools/azure-foundry-fine-tuning.md) (Fine-tuning), [Azure AI Content Safety (Prompt Shields)](https://www.anchorterminal.com/tools/azure-ai-content-safety.md) (Guardrails \u0026 safety filters), [Azure AI Speech speech-to-text](https://www.anchorterminal.com/tools/azure-speech-to-text.md) (Speech-to-text), [Azure AI Speech text-to-speech](https://www.anchorterminal.com/tools/azure-text-to-speech.md) (Text-to-speech), [Microsoft Agent Framework](https://www.anchorterminal.com/tools/microsoft-agent-framework.md) (Agent frameworks \u0026 SDKs), [Microsoft Execution Containers](https://www.anchorterminal.com/tools/microsoft-execution-containers.md) (Code execution sandboxes), [Microsoft Entra Agent ID](https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md) (Agent auth \u0026 delegated access), [Azure Key Vault](https://www.anchorterminal.com/tools/azure-key-vault.md) (Secrets \u0026 credential vaults), [Azure DevOps MCP Server](https://www.anchorterminal.com/tools/azure-devops-mcp.md) (Code \u0026 developer platforms), [Microsoft Learn MCP Server](https://www.anchorterminal.com/tools/microsoft-learn-mcp.md) (Code \u0026 developer platforms), [Playwright MCP](https://www.anchorterminal.com/tools/playwright-mcp.md) (Browser automation), [Azure MCP Server](https://www.anchorterminal.com/tools/azure-mcp.md) (Cloud \u0026 infrastructure), [Azure Translator](https://www.anchorterminal.com/tools/azure-translator.md) (Translation), [Microsoft Graph Calendar API](https://www.anchorterminal.com/tools/microsoft-graph-calendar.md) (Calendars \u0026 scheduling), [Microsoft Dynamics 365 Sales](https://www.anchorterminal.com/tools/dynamics-365-sales.md) (CRM \u0026 customer platforms), [Microsoft Advertising API](https://www.anchorterminal.com/tools/microsoft-advertising-api.md) (Advertising \u0026 campaign operations), [Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/tools/outlook-mail-graph.md) (Mailbox access).\n\n## Assessment\n\nRanges, tables, charts and 366 worksheet function endpoints are reachable over REST with a public OpenAPI, and a non-persistent session lets an agent test changes without saving them. The reference pages list delegated permissions only, with Files.ReadWrite as the least privileged scope, and writes take no idempotency key.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Microsoft (https://learn.microsoft.com/en-us/graph/excel-concept-overview) |\n| Kind | HTTP API |\n| Category | Spreadsheets \u0026 operational tables (https://www.anchorterminal.com/categories/spreadsheets) |\n| Transport | HTTP |\n| Endpoint | `https://graph.microsoft.com/v1.0` |\n| Auth | OAuth · OAuth 2.0 tokens from Microsoft Entra ID, after a person registers an app. Registration is self-serve, with no partner or sales approval. The workbook reference pages list delegated permissions only, with Files.ReadWrite as least privileged, and mark application permissions as not supported. The overview page names Files.Read for read actions. A delegated token reaches every file its user can open. |\n| Pricing | Your plan (Your plan) · Workbook calls carry no per-call charge. Microsoft's list of metered Graph APIs names only SharePoint and OneDrive `assignSensitivityLabel`, at $0.00185 a call (https://learn.microsoft.com/en-us/graph/metered-api-list). Files must sit in OneDrive for work or school or SharePoint, which need a Microsoft 365 licence. The Microsoft 365 plan price page refused our reader on 2026-10-08. A free Microsoft 365 E5 developer sandbox is limited to Visual Studio subscribers and members of named partner programmes (https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq). |\n| x402 | No · No x402, MPP or L402 in the workbook documentation or the metered API list (checked 2026-10-08). |\n| Licence | MIT (SDKs) |\n| Packages | npm: `@microsoft/microsoft-graph-client`; pypi: `msgraph-sdk` |\n| Source | https://github.com/microsoftgraph/msgraph-sdk-javascript |\n| Docs | https://learn.microsoft.com/en-us/graph/api/resources/excel |\n| llms.txt | not found |\n| Last release | 2025-09-19 |\n| GitHub stars | 835 (as of 2026-10-08) |\n| npm downloads / week | 2,882,852 |\n| PyPI downloads / week | 1,578,201 |\n| Free tier | No charge for workbook calls. The file's home (OneDrive for work or school, or SharePoint) needs a Microsoft 365 licence |\n| Files | .xlsx only, in OneDrive for work or school, SharePoint sites and group drives. The overview says consumer OneDrive isn't supported |\n| Sessions | Persistent, non-persistent (`persistChanges: false`) or sessionless. Idle expiry after about 5 minutes (persistent) or 7 (non-persistent) |\n| Rate limits | 5,000 requests per 10 seconds per app across all tenants, 1,500 per app per tenant, global 130,000 per 10 seconds per app |\n| Size limits | A range read above 5,000,000 cells returns null properties. Excel on the web caps request and response payloads at 5 MB, per the Office add-ins limits page the error guide links to |\n| Permissions | Delegated Files.ReadWrite on the reference pages, Files.Read for reads per the overview. Application permissions marked not supported |\n| Long-running calls | `Prefer: respond-async` on createSession and row add returns 202 with a Location to poll, about every 30 seconds |\n| Batching | Rows are added many at a time through one `values` array. Graph JSON batching takes up to 20 requests |\n| Change events | driveItem notifications at drive root level only, no cell or range events found |\n| SDKs | C#, Java, Go, PHP, Python (msgraph-sdk 1.64.0, 6 October 2026), PowerShell, CLI and JavaScript (npm 3.0.7 from September 2023) |\n| National clouds | Global, US Government L4 and L5. Not available in China operated by 21Vianet |\n| Capabilities | sheets.read, sheets.write, sheets.tables, sheets.formulas |\n| Tags | hosted, official, oauth, openapi, typescript, python, enterprise |\n| JSON | https://www.anchorterminal.com/api/v1/tools/microsoft-excel-graph.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 62 | 12.4 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 85 | 13.8 |\n| Agent ergonomics | 13% | 16.2 | 73 | 11.9 |\n| Security \u0026 auth | 14% | 17.5 | 65 | 11.4 |\n| Payments \u0026 pricing | 10% | 12.5 | 15 | 1.9 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 53 | 4.6 |\n| Transparency \u0026 trust (editorial 65, provenance 85) | 7% | 8.8 | 75 | 6.6 |\n| Negative events | up to −15 | up to −15 | 2026-06-16: a fix for a token leak through URL userinfo host confusion was merged into msgraph-sdk-javascript and the version set to 3.0.8, but npm still served 3.0.7 on 8 October 2026 and the repository lists no published advisory. Exploiting it needs an attacker-influenced URL passed to the client, and it affects agents that call the workbook API through that client (https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19, https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest)  | -4 |\n| **Total** | | | | **58.5 → C** |\n\n### Why each score\n\n- Reliability 62: A public Microsoft service health page at status.cloud.microsoft. It renders only with JavaScript, so we couldn't read components or history (20). No readable incident history (5). Excel resources are throttled at 5,000 requests per 10 seconds per app across all tenants and 1,500 per app per tenant, under a global 130,000 per 10 seconds, though Microsoft adds that the cost of a workbook call varies too much for the numbers to tell the whole story (15). Throttled responses carry `Retry-After`, the error guide gives a retry instruction per error code, and Microsoft asks for one request at a time per workbook. There is no idempotency key, and the row-add page says to repeat the request on a 504, which can add rows twice (12). No SLA naming the Graph API was found, and we didn't read the Online Services SLA document (0). The workbook endpoints are generally available on v1.0 (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 85: OpenAPI 3.0.4 for all of Graph v1.0 in microsoftgraph/msgraph-metadata, with 1,442 workbook paths and 1,765 operations (25). learn.microsoft.com has no llms.txt, but every docs page we asked for with `accept=text/markdown` came back as Markdown (10). Reference pages state the purpose and the permissions of each call, and the overview explains sessions, nulls, unbounded and large ranges. Pages disagree on whether personal accounts and Files.Read work, and the workbookOperation page opens with a line that explains little (14). Cell values, formulas and number formats are untyped JSON (`values: { }` in the OpenAPI), and chart types are plain strings (7). An HTTP example on each page, plus separate pages for error codes and error handling (14). v1.0 and beta, with a dated public changelog (15).\n- Agent ergonomics 73: A range is read by address, `$select` trims the properties returned and table rows take `$top` and `$skip`. A range answer carries values, text, formulas and number formats unless trimmed, and the whole-Graph OpenAPI is 44 MB (20). `$top` and `$skip` paging on table rows, plus server-side table sort and filter that change the workbook's own view (15). Errors carry a top-level code, a second-level code with a written instruction on whether to retry, and a request ID (18). No idempotency key on writes. Non-persistent sessions let an agent try edits without saving, and Microsoft's advice is sequential requests per workbook (8). Sessionless calls work with a bearer token and a file path, worksheet and chart IDs need their braces URL-encoded, and official SDKs cover C#, Java, Go, PHP, Python, PowerShell and JavaScript, though the npm JavaScript client dates from September 2023 (12).\n- Security \u0026 auth 65: OAuth 2.0 through Entra ID with scoped, revocable consent. The workbook reference pages list delegated permissions only, and a Files.ReadWrite token reaches every file its user can open (27). The overview names Files.Read for reads while the reference pages give Files.ReadWrite as least privileged even for a range read. A non-persistent session keeps changes out of the file. Per-file Selected scopes exist for OneDrive and SharePoint, but the workbook pages don't list them. Nothing asks for confirmation before a delete (12). Cell contents written by other people reach the caller with no injection guidance in the workbook docs (0). Graph activity logs record app, user, URI and status for every request, but need Entra ID P1 or P2 and an Azure log destination (12). Microsoft 365 bounty of $1,250 to $19,500, a coordinated disclosure policy and an Office 365 SOC 2 Type 2 report. microsoft.com's security.txt passed its Expires date on 23 September 2026, and a token-leak fix in the JavaScript client is unreleased on npm (14).\n- Payments \u0026 pricing 15: No x402, MPP or L402 (0). Workbook calls aren't on Microsoft's metered API list, so there is no per-call charge, but the file's home needs a Microsoft 365 licence and the plan price page refused our reader today (10). The free E5 developer sandbox is limited to Visual Studio subscribers and named partner programmes. The overview says consumer OneDrive isn't supported, while some reference pages list personal accounts (5). A person registers an app in Entra and signs in to consent (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 53: msgraph-sdk 1.64.0 reached PyPI on 6 October 2026, but the last Workbooks and charts entry in the Graph changelog is dated 19 September 2025 and the overview page March 2024. We scored this line between the two, a departure from the checklist's single date (10). Six Python SDK releases since 14 July 2026, from 1.59.2 to 1.64.0 (20). A public changelog and SDK issue trackers. The seven newest open issues on msgraph-sdk-python had no or one reply, and a security fix merged into the JavaScript client on 16 June 2026 hasn't reached npm (7). Current SDKs in most languages, with the JavaScript client the exception at 3.0.7 from September 2023 (10). Active releases on the Python package, none on the JavaScript one (6).\n- Transparency \u0026 trust 75: Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDKs (15). Microsoft's data handling page for Microsoft 365 gives at most 30 days after active deletion and 180 days after a subscription ends for customer content, Excel files included, and the privacy statement was updated in September 2026. We didn't read the DPA (22). The Graph policy is at least 24 months' notice before a GA API or version is removed, with breaking changes only on a new version number (18). Data residency for Microsoft 365 is documented by tenant geography. The sub-processor list sits on the Service Trust Portal, which we didn't read (10).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/microsoft-excel-graph.md (JSON https://www.anchorterminal.com/fixes/microsoft-excel-graph.json)\n\n### What we couldn't check\n\n- unchecked: status page components and incident history, which need JavaScript\n- unchecked: Microsoft 365 plan prices, because the pricing page refused our reader\n- unchecked: the Online Services SLA document, the DPA and the sub-processor list on the Service Trust Portal\n- Whether application permissions and the per-file Selected scopes work on workbook endpoints. The reference pages say application permissions aren't supported\n- Whether personal Microsoft accounts work. The overview says consumer OneDrive isn't supported, while the range and list-rows pages list Files.ReadWrite for personal accounts\n- Whether Microsoft will publish msgraph-sdk-javascript 3.0.8 or an advisory for the 16 June 2026 fix\n- First release date of the workbook API, not established\n\n### Sources\n\n- Excel overview in the v1.0 reference (sessions, scopes, ranges, nulls): \u003chttps://learn.microsoft.com/en-us/graph/api/resources/excel?view=graph-rest-1.0\u003e (seen 2026-10-08)\n- best practices for the Excel API: \u003chttps://learn.microsoft.com/en-us/graph/workbook-best-practice\u003e (seen 2026-10-08)\n- throttling limits, Excel service limits: \u003chttps://learn.microsoft.com/en-us/graph/throttling-limits#excel-service-limits\u003e (seen 2026-10-08)\n- throttling guidance: \u003chttps://learn.microsoft.com/en-us/graph/throttling\u003e (seen 2026-10-08)\n- error handling for Excel APIs: \u003chttps://learn.microsoft.com/en-us/graph/workbook-error-handling\u003e (seen 2026-10-08)\n- error codes for workbooks and charts: \u003chttps://learn.microsoft.com/en-us/graph/workbook-error-codes\u003e (seen 2026-10-08)\n- createSession reference and permissions: \u003chttps://learn.microsoft.com/en-us/graph/api/workbook-createsession?view=graph-rest-1.0\u003e (seen 2026-10-08)\n- range get and update reference: \u003chttps://learn.microsoft.com/en-us/graph/api/range-get?view=graph-rest-1.0\u003e (seen 2026-10-08)\n- list and add table rows reference: \u003chttps://learn.microsoft.com/en-us/graph/api/table-post-rows?view=graph-rest-1.0\u003e (seen 2026-10-08)\n- metered APIs list: \u003chttps://learn.microsoft.com/en-us/graph/metered-api-list\u003e (seen 2026-10-08)\n- versioning, support and breaking change policy: \u003chttps://learn.microsoft.com/en-us/graph/versioning-and-support\u003e (seen 2026-10-08)\n- Selected permissions for OneDrive and SharePoint: \u003chttps://learn.microsoft.com/en-us/graph/permissions-selected-overview\u003e (seen 2026-10-08)\n- Graph activity logs: \u003chttps://learn.microsoft.com/en-us/graph/microsoft-graph-activity-logs-overview\u003e (seen 2026-10-08)\n- change notifications overview: \u003chttps://learn.microsoft.com/en-us/graph/api/resources/change-notifications-api-overview?view=graph-rest-1.0\u003e (seen 2026-10-08)\n- Work IQ MCP catalogue: \u003chttps://learn.microsoft.com/en-us/microsoft-agent-365/tooling-servers-overview\u003e (seen 2026-10-08)\n- Microsoft 365 Developer Programme FAQ: \u003chttps://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq\u003e (seen 2026-10-08)\n- OpenAPI for Graph v1.0: \u003chttps://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml\u003e (seen 2026-10-08)\n- Graph changelog feed: \u003chttps://developer.microsoft.com/en-us/graph/changelog/rss\u003e (seen 2026-10-08)\n- service health page (JavaScript only): \u003chttps://status.cloud.microsoft/\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://www.microsoft.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- Microsoft 365 bounty programme: \u003chttps://www.microsoft.com/en-us/msrc/bounty-microsoft-cloud\u003e (seen 2026-10-08)\n- SOC 2 Type 2 for Office 365: \u003chttps://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2\u003e (seen 2026-10-08)\n- data retention, deletion and destruction in Microsoft 365: \u003chttps://learn.microsoft.com/en-us/compliance/assurance/assurance-data-retention-deletion-and-destruction-overview\u003e (seen 2026-10-08)\n- Microsoft 365 data residency: \u003chttps://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-overview\u003e (seen 2026-10-08)\n- Microsoft APIs terms of use: \u003chttps://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use\u003e (seen 2026-10-08)\n- privacy statement: \u003chttps://privacy.microsoft.com/en-us/privacystatement\u003e (seen 2026-10-08)\n- PyPI msgraph-sdk releases: \u003chttps://pypi.org/pypi/msgraph-sdk/json\u003e (seen 2026-10-08)\n- npm latest for @microsoft/microsoft-graph-client: \u003chttps://registry.npmjs.org/@microsoft/microsoft-graph-client/latest\u003e (seen 2026-10-08)\n- JavaScript client repository and token-leak fix: \u003chttps://github.com/microsoftgraph/msgraph-sdk-javascript\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 85/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Microsoft Corporation | 20/20 |\n| Domain age | microsoft.com, registered 1991-05-02 (35 years) | 15/15 |\n| Endpoint on the vendor's domain | graph.microsoft.com | 15/15 |\n| Terms of service | read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points | 2.3/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects, and has 1 clause that costs points | 8/10 |\n| Status page | status.cloud.microsoft | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | published but past its Expires date | 5/10 |\n\nThe endpoint is on graph.microsoft.com. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.\n\nwww.microsoft.com/.well-known/security.txt still carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08.\n\nThe Microsoft service health page at status.cloud.microsoft needs JavaScript to show anything.\n\nThe Microsoft APIs terms of use name Microsoft Corporation and were last updated in October 2025.\n\nThe Microsoft privacy statement was last updated in September 2026.\n\nRDAP for microsoft.com gives a registration date of 1991-05-02.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use), read 2026-10-08, dated 2025-10-01, states 5 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"Scrape, build databases or otherwise create copies of any data accessed or obtained using the Microsoft APIs, except as necessary to enable an intended usage scenario for your Application;\"\n- To know. Restricts benchmarking or competitive use (costs points). \"Use the Microsoft APIs, or any data obtained using the Microsoft APIs, to conduct performance testing of a Microsoft Offering unless expressly permitted by Microsoft\"\n- To know. Says the terms or the service can change without notice (costs points). \"WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.\"\n- To know. Says access can be ended without notice or for any reason. \"We may suspend or immediately terminate these API Terms, any rights granted herein, and/or your license to the Microsoft APIs, in our sole discretion at any time, for any reason.\"\n- Gives the date it was last updated. Last updated 2025-10-01.\n- Not found in the text. Names the governing law or courts.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Recoverable damages are limited to direct damages of up to 5 US dollars in total. \"YOU AGREE THAT YOUR EXCLUSIVE REMEDY IS TO RECOVER, FROM MICROSOFT OR ANY AFFILIATES, RESELLERS, DISTRIBUTORS, SUPPLIERS (AND RESPECTIVE EMPLOYEES, SHAREHOLDERS, OR DIRECTORS) AND VENDORS, ONLY DIRECT DAMAGES UP TO USD $5.00 COLLECTIVELY.\"\n- Also in the text (2026-10-08). After a data breach involving the Microsoft APIs, the developer may make no public statement about it without Microsoft's prior written permission. \"You agree to refrain from making public statements (e.g., press, blogs, social media, bulletin boards, etc.) without prior written and express permission from Microsoft in each instance as it relates to the Microsoft APIs.\"\n- Also in the text (2026-10-08). The developer must allow Microsoft reasonable access to its application so Microsoft can monitor compliance with the API terms. \"You will permit Microsoft reasonable access to your Application for purposes of monitoring compliance with these API Terms.\"\n\n**Privacy policy** (https://privacy.microsoft.com/en-us/privacystatement), read 2026-10-08, dated 2026-09-01, states 8 of the 8 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). \"As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.\"\n- To know. Says it sells personal data or shares it for advertising. \"We also disclose personal data for digital advertising purposes.\"\n- Gives the date it was last updated. Last updated 2026-09-01.\n- Says how long data is kept. Names a period of 7 days.\n- Gives a privacy contact. Names a data protection officer.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict. \"In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control.\"\n- Also in the text (2026-10-08). Advertisements may be chosen from the current interaction, including Copilot conversations and files shared in them. \"Ads may be shown that relate to the current interaction you are having with us, such as your Copilot conversations (including files you share); your current location; transactions; product usage; search queries; or the content you’re viewing.\"\n- Also in the text (2026-10-08). Microsoft staff manually review some results of automated systems, including AI, against the source data. \"For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data.\"\n\n## Live (updated 2026-10-08 18:20 UTC)\n\n- Right now: up, HTTP 200, 3 ms, checked 2026-10-08 18:20 UTC (get on `https://graph.microsoft.com/v1.0`)\n- Uptime 24h 100.0% (33 probes) · 30 days 100.0% (33 probes) · p50 30 ms · p95 57 ms\n- Vendor status page: unknown, no machine-readable status found\n- github `microsoftgraph/msgraph-sdk-javascript` 3.0.7, released 2023-09-19\n- npm `@microsoft/microsoft-graph-client` 3.0.7\n- pypi `msgraph-sdk` 1.64.0, released 2026-10-06\n- security.txt: expired, expires 2026-09-23T16:00:00.000Z\n- Watching changelog \u003chttps://developer.microsoft.com/en-us/graph/changelog\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/microsoft-excel-graph.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Non-persistent sessions (`persistChanges: false`) keep changes in a temporary copy, so an agent can calculate or test edits without saving\n- The OpenAPI for Graph v1.0 holds 1,442 workbook paths and 1,765 operations, 366 of the paths for worksheet functions\n- Error handling guide gives a retry instruction for each of 22 required second-level error codes\n- Throttling limits are published at 5,000 requests per 10 seconds per app and 1,500 per app per tenant, with `Retry-After` on throttled responses\n- Microsoft's policy is at least 24 months' notice before a generally available Graph API is removed\n\n## Weaknesses\n\n- Reference pages list delegated permissions only and mark application permissions as not supported\n- Files.ReadWrite is the least privileged permission on the reference pages, even for reading a range or listing rows\n- No idempotency key on writes. The row-add page says to repeat the request on a 504\n- Cell values, formulas and number formats are untyped JSON in the OpenAPI\n- The last Workbooks and charts changelog entry is dated 19 September 2025, and the overview page is dated March 2024\n\n## Before you call it (notes for agents)\n\n1. Create a session with POST /workbook/createSession and send `workbook-session-id` on every call. Persistent sessions expire after about 5 minutes idle\n2. Set `persistChanges` to false when you only need a calculation or a chart image, so nothing is saved to the file\n3. Send one request at a time per workbook and wait for each response. Microsoft warns that parallel writes cause throttling, timeouts and merge conflicts\n4. Add rows in one call with a two-dimensional `values` array, and check the table before repeating a row add that returned 504\n5. Read bounded addresses such as A1:D500. A whole-column range such as C:C returns null for values, and writes to it are refused\n\n## Connect\n\nFirst request:\n\n```bash\ncurl https://graph.microsoft.com/v1.0/me/drive/items/{id}/workbook/worksheets \\\n  -H \"Authorization: Bearer $MS_GRAPH_TOKEN\" \\\n  -H \"workbook-session-id: $SESSION_ID\"\n```\n\nThrough letme (picks today, calling later): https://letme.dev/microsoft-excel-graph. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Google Sheets API | BB | 76.3 | 33 | sheets.read, sheets.write, sheets.formulas, sheets.tables | no | https://www.anchorterminal.com/tools/google-sheets-api.md |\n| NocoDB | BB | 75.7 | 37 | sheets.read, sheets.write, sheets.tables, sheets.formulas | no | https://www.anchorterminal.com/tools/nocodb.md |\n| Airtable | BB | 70.9 | 118 | sheets.read, sheets.write, sheets.tables, sheets.formulas | no | https://www.anchorterminal.com/tools/airtable.md |\n| Coda (Superhuman Docs) | B | 64.8 | 247 | sheets.read, sheets.write, sheets.tables, sheets.formulas | no | https://www.anchorterminal.com/tools/coda.md |\n| Baserow | B | 63.6 | 276 | sheets.read, sheets.write, sheets.tables, sheets.formulas | no | https://www.anchorterminal.com/tools/baserow.md |\n| Smartsheet API + MCP | B | 67.6 | 190 | sheets.read, sheets.write, sheets.formulas | no | https://www.anchorterminal.com/tools/smartsheet.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The Excel REST API reaches only .xlsx workbooks, and the overview says workbooks in consumer OneDrive aren't supported (source: \u003chttps://learn.microsoft.com/en-us/graph/api/resources/excel\u003e)\n- Persistent sessions expire after about 5 minutes of inactivity and non-persistent sessions after about 7, and an expired session returns 404 (source: \u003chttps://learn.microsoft.com/en-us/graph/api/resources/excel\u003e)\n- Excel resources are throttled at 5,000 requests per 10 seconds per app across all tenants and 1,500 per app per tenant, under a global 130,000 per 10 seconds (source: \u003chttps://learn.microsoft.com/en-us/graph/throttling-limits#excel-service-limits\u003e)\n- Microsoft advises against parallel requests to one workbook, writes above all, and says to send the next request only after the current one succeeds (source: \u003chttps://learn.microsoft.com/en-us/graph/workbook-best-practice\u003e)\n- Reference pages for range get, range update, list rows, add rows and createSession list Files.ReadWrite (delegated) as least privileged and application permissions as not supported (source: \u003chttps://learn.microsoft.com/en-us/graph/api/range-get\u003e)\n- Change notifications cover driveItem changes under a drive's root folder. No cell or range events were found in the reviewed documentation (source: \u003chttps://learn.microsoft.com/en-us/graph/api/resources/change-notifications-api-overview\u003e)\n- No Excel server appears in the Work IQ MCP catalogue, which lists Word, OneDrive and SharePoint servers in preview (source: \u003chttps://learn.microsoft.com/en-us/microsoft-agent-365/tooling-servers-overview\u003e)\n\n## Compare\n\n- [Airtable vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/airtable-vs-microsoft-excel-graph.md): BB 70.9 vs C 58.5\n- [Baserow vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/baserow-vs-microsoft-excel-graph.md): B 63.6 vs C 58.5\n- [Coda (Superhuman Docs) vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/coda-vs-microsoft-excel-graph.md): B 64.8 vs C 58.5\n- [Google Sheets API vs Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/compare/google-sheets-api-vs-microsoft-excel-graph.md): BB 76.3 vs C 58.5\n- [Microsoft Excel (Microsoft Graph workbook API) vs NocoDB](https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-nocodb.md): C 58.5 vs BB 75.7\n- [Microsoft Excel (Microsoft Graph workbook API) vs Smartsheet API + MCP](https://www.anchorterminal.com/compare/microsoft-excel-graph-vs-smartsheet.md): C 58.5 vs B 67.6\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on microsoft.com or one of its subdomains, or the README of github.com/microsoftgraph/msgraph-sdk-javascript. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"microsoft-excel-graph\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/microsoft-excel-graph\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/microsoft-excel-graph.svg\" alt=\"Microsoft Excel (Microsoft Graph workbook API) on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Microsoft Excel (Microsoft Graph workbook API) on Anchor Terminal](https://www.anchorterminal.com/badges/microsoft-excel-graph.svg)](https://www.anchorterminal.com/tools/microsoft-excel-graph)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/microsoft-excel-graph\"\u003eMicrosoft Excel (Microsoft Graph workbook API) on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Microsoft Excel (Microsoft Graph workbook API) is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/microsoft-excel-graph-dark.png\n- Light: https://www.anchorterminal.com/assets/share/microsoft-excel-graph-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Spreadsheets \u0026 operational tables",
        "url": "https://www.anchorterminal.com/categories/spreadsheets"
      },
      {
        "name": "Microsoft Excel (Microsoft Graph workbook API)",
        "url": ""
      }
    ],
    "description": "Workbook endpoints of Microsoft Graph for Excel files stored in OneDrive for work or school and SharePoint. Calls read and write ranges, tables, charts and named items, and run Excel worksheet functions on a file in place.",
    "facts": [
      "rank #399 of 629",
      "OAuth auth",
      "0 desk reviews"
    ],
    "h1": "Microsoft Excel (Microsoft Graph workbook API)",
    "image": "https://www.anchorterminal.com/assets/og/tools-microsoft-excel-graph.png",
    "path": "/tools/microsoft-excel-graph",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Microsoft Excel (Microsoft Graph workbook API), grade C (58.5/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/microsoft-excel-graph"
  },
  "tokens": {
    "markdown": 8600,
    "slim": 1580
  },
  "version": 1
}
