{
  "data": {
    "similar": [
      {
        "grade": "A",
        "json": "https://www.anchorterminal.com/tools/google-drive-api.json",
        "name": "Google Drive API + MCP",
        "score": 79.6,
        "shared": [
          "storage.drive",
          "storage.share"
        ],
        "slug": "google-drive-api"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/amazon-s3.json",
        "name": "Amazon S3",
        "score": 77.9,
        "shared": [
          "storage.presigned",
          "storage.share"
        ],
        "slug": "amazon-s3"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/cloudflare-r2.json",
        "name": "Cloudflare R2",
        "score": 77.1,
        "shared": [
          "storage.presigned",
          "storage.share"
        ],
        "slug": "cloudflare-r2"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/azure-blob-storage.json",
        "name": "Azure Blob Storage",
        "score": 75.7,
        "shared": [
          "storage.presigned",
          "storage.share"
        ],
        "slug": "azure-blob-storage"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/backblaze-b2.json",
        "name": "Backblaze B2",
        "score": 75.3,
        "shared": [
          "storage.presigned",
          "storage.share"
        ],
        "slug": "backblaze-b2"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/box-api.json",
        "name": "Box API + MCP",
        "score": 69.4,
        "shared": [
          "storage.drive",
          "storage.share"
        ],
        "slug": "box-api"
      }
    ],
    "tool": {
      "slug": "onedrive-sharepoint",
      "name": "OneDrive and SharePoint files (Microsoft Graph)",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/graph/onedrive-concept-overview",
      "kind": "http-api",
      "category": "file-storage",
      "summary": "Drive and driveItem endpoints of Microsoft Graph for files in OneDrive, OneDrive for work or school and SharePoint document libraries. Calls upload, download, list, search, share by link or invitation, and delete files and folders.",
      "url": "https://www.anchorterminal.com/tools/onedrive-sharepoint",
      "markdownUrl": "https://www.anchorterminal.com/tools/onedrive-sharepoint.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/onedrive-sharepoint.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/onedrive-sharepoint.json",
      "repo": "https://github.com/microsoftgraph/msgraph-sdk-python",
      "license": "MIT (SDKs)",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://graph.microsoft.com/v1.0",
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/microsoft-graph-client"
        },
        {
          "registry": "pypi",
          "name": "msgraph-sdk"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 tokens from Microsoft Entra ID, after a person registers an app. Registration is self-serve, with no partner or sales approval. Delegated permissions run from Files.Read to Files.ReadWrite.All and work for personal Microsoft accounts and work or school accounts. Application permissions (Files.Read.All, Files.ReadWrite.All, Sites.ReadWrite.All) need an administrator's consent. Selected scopes limit an app to chosen sites, lists, folders or files.",
      "pricing": "byo-plan",
      "pricingNotes": "File calls carry no per-call charge. Microsoft's list of metered Graph APIs names only `assignSensitivityLabel`, at $0.00185 a call (https://learn.microsoft.com/en-us/graph/metered-api-list). Storage comes from the account's own OneDrive or Microsoft 365 plan, 1 TB a user on the Business and E3 or E5 plans per the service description. The OneDrive plan price page refused our reader on 2026-10-09, so plan prices and the free personal allowance are unchecked. A free Microsoft 365 E5 developer sandbox is limited to Visual Studio subscribers and other qualifying members (https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq).",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the files documentation or the metered API list (checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 633,
        "npmWeekly": 2882852,
        "pypiWeekly": 1578201,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/graph/api/resources/onedrive",
      "openapi": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
      "capabilities": [
        "storage.drive",
        "storage.share",
        "storage.presigned"
      ],
      "tags": [
        "hosted",
        "official",
        "oauth",
        "openapi",
        "typescript",
        "python",
        "enterprise"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.3,
        "grade": "B",
        "agentReady": false,
        "rank": 296,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 84,
          "maintenance": 75,
          "payments": 20,
          "reliability": 64,
          "schema": 89,
          "security": 73,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 64,
            "points": 12.8,
            "reason": "Graded on the v1.0 REST API. A public Microsoft service health page at status.cloud.microsoft (20). It shows nothing without JavaScript, so we couldn't read components or history (5). SharePoint and OneDrive limits are published in resource units, 1,250 to 6,250 a minute and 1,200,000 to 6,000,000 a day per app per tenant by licence count, 3,000 requests per 5 minutes a user, and 400 GB of ingress and of egress an hour per app (15). 429 and 503 responses carry `Retry-After`, upload sessions resume from `nextExpectedRanges` with backoff advice for 5xx errors, and `If-Match` and `conflictBehavior` guard overwrites. There is no idempotency key on `invite` or folder creation (14 of 15). The Online Services SLA page is drawn by script and gave us no text, so no SLA is counted (0). The file endpoints are generally available on v1.0 (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 89,
            "points": 14.46,
            "reason": "OpenAPI 3.0.4 for all of Graph v1.0 in microsoftgraph/msgraph-metadata, with 1,516 paths under `/drives`, 172 of them outside the workbook API (25). learn.microsoft.com answers 404 for llms.txt, but every page we asked for with `Accept: text/markdown` came back as Markdown (10). Reference pages state the purpose of each call, list permissions from least to most privileged and say which options work only on personal OneDrive. The upload session page gives Sites.ReadWrite.All as the least privileged application permission where the small-upload page gives Files.ReadWrite.All, and the overview page is dated March 2024 (16). `createLink` declares `type` and `scope` as plain strings with no enumeration, `conflictBehavior` is an annotation outside the schema, path addressing is absent from the OpenAPI, and `retainInheritedPermissions` defaults to false there and to true on the reference page (9). An HTTP example and SDK snippets on each page, a status code table, and upload-specific handling for 404, 409 and 416 (14). v1.0 and beta, a dated changelog and a monthly What's new page (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 84,
            "points": 13.65,
            "reason": "`$select` trims driveItem properties, a list returns 200 items a page by default, and responses without `$select` carry a tip to use it. The whole-Graph OpenAPI is 44 MB (21). `@odata.nextLink` paging with `$top`, `$skipToken`, `$orderby` and `$expand`, a search call and `delta` for changes since a token (20). Errors carry a code, a message and a request ID, the upload page says what to do on 404, 409, 416 and 5xx, and `delta` returns two named resync codes on 410 (17). Uploads resume, `If-Match` and `if-none-match` guard writes, `conflictBehavior` fails by default, `createLink` returns the existing link of the same type and DELETE goes to the recycle bin. No idempotency key (14). Items are addressed by ID or by path with one bearer token, but upload fragments must be multiples of 320 KiB and the token must be left off the fragment PUT. Official SDKs in C#, Java, Go, PHP, Python, PowerShell and JavaScript, the npm JavaScript client dating from September 2023 (12)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 73,
            "points": 12.78,
            "reason": "OAuth 2.0 through Microsoft Entra ID with delegated and application permissions from Files.Read to Sites.ReadWrite.All, revocable consent, and Selected scopes that hold an app to chosen sites, lists, folders or files. Download and upload URLs are pre-authenticated and short-lived, which we read as designed capability links and not as a credential in a URL (30). Files.Read for reading, Selected scopes with read, write, owner and fullcontrol roles, DELETE to the recycle bin and anonymous links that an administrator can disable. Nothing asks for confirmation before `permanentDelete` or an anonymous link (17). File names and contents written by other people reach the caller, and no injection guidance was found in the files reference pages (0). Graph activity logs record app, user, request URI and scopes for every request, but need Entra ID P1 or P2 and an Azure log destination (12). The Microsoft 365 bounty names SharePoint Online and OneDrive at $1,250 to $19,500, with a coordinated disclosure policy and an Office 365 SOC 2 Type 2 report. microsoft.com's security.txt passed its Expires date on 23 September 2026, and a token-leak fix in the JavaScript client is unreleased on npm (14)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 20,
            "points": 2.5,
            "reason": "No x402, MPP or L402 (0). File calls aren't on Microsoft's metered API list, whose one entry is `assignSensitivityLabel` at $0.00185 a call, but storage comes from a OneDrive or Microsoft 365 plan and the plan price page refused our reader today (10). The reference pages list delegated permissions for personal Microsoft accounts, so no Microsoft 365 licence is needed to call the API, but we couldn't read the size of the free personal allowance, and the free E5 developer sandbox is limited to Visual Studio subscribers and other qualifying members (10). A person registers an app in Entra and signs in to consent (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 75,
            "points": 6.56,
            "reason": "msgraph-sdk-python v1.64.0 on 6 October 2026. The What's new page, updated 8 October 2026, lists generally available Files changes for September and August 2026, and the changelog feed's last v1.0 Files entry is 29 July 2026 (30). Five Python SDK releases since 22 July 2026, v1.60.0 to v1.64.0 (20). A public changelog, a What's new page and SDK issue trackers. The changelog feed stops at 3 August 2026, an issue about drive content returning None on the Python SDK has had no reply since 21 September 2026, and a security fix merged into the JavaScript client on 16 June 2026 hasn't reached npm (9 of 15). Current SDKs in most languages, with the JavaScript client the exception at 3.0.7 (10). Active releases on the Python package, none on the JavaScript one (6)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 75,
            "points": 6.56,
            "note": "editorial 65, provenance 85",
            "reason": "Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDKs (15). Microsoft's data handling page for Microsoft 365 gives at most 30 days after active deletion and 180 days after a subscription ends for customer content, the SharePoint deletion page gives 93 days in the recycle bin and 14 further days of backups, and the privacy statement was updated in September 2026. We didn't read the data protection addendum (22). The Graph policy is at least 24 months' notice before a generally available API or version is removed, while the API terms reserve the right to change or discontinue any API with or without notice (18). Data residency for Microsoft 365 is documented by tenant geography. The sub-processor list sits on the Service Trust Portal, which we didn't read (10)."
          }
        ],
        "assessment": {
          "date": "2026-10-09",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "`$select` trims driveItem properties, a list returns 200 items a page by default, and responses without `$select` carry a tip to use it. The whole-Graph OpenAPI is 44 MB (21). `@odata.nextLink` paging with `$top`, `$skipToken`, `$orderby` and `$expand`, a search call and `delta` for changes since a token (20). Errors carry a code, a message and a request ID, the upload page says what to do on 404, 409, 416 and 5xx, and `delta` returns two named resync codes on 410 (17). Uploads resume, `If-Match` and `if-none-match` guard writes, `conflictBehavior` fails by default, `createLink` returns the existing link of the same type and DELETE goes to the recycle bin. No idempotency key (14). Items are addressed by ID or by path with one bearer token, but upload fragments must be multiples of 320 KiB and the token must be left off the fragment PUT. Official SDKs in C#, Java, Go, PHP, Python, PowerShell and JavaScript, the npm JavaScript client dating from September 2023 (12).",
            "maintenance": "msgraph-sdk-python v1.64.0 on 6 October 2026. The What's new page, updated 8 October 2026, lists generally available Files changes for September and August 2026, and the changelog feed's last v1.0 Files entry is 29 July 2026 (30). Five Python SDK releases since 22 July 2026, v1.60.0 to v1.64.0 (20). A public changelog, a What's new page and SDK issue trackers. The changelog feed stops at 3 August 2026, an issue about drive content returning None on the Python SDK has had no reply since 21 September 2026, and a security fix merged into the JavaScript client on 16 June 2026 hasn't reached npm (9 of 15). Current SDKs in most languages, with the JavaScript client the exception at 3.0.7 (10). Active releases on the Python package, none on the JavaScript one (6).",
            "payments": "No x402, MPP or L402 (0). File calls aren't on Microsoft's metered API list, whose one entry is `assignSensitivityLabel` at $0.00185 a call, but storage comes from a OneDrive or Microsoft 365 plan and the plan price page refused our reader today (10). The reference pages list delegated permissions for personal Microsoft accounts, so no Microsoft 365 licence is needed to call the API, but we couldn't read the size of the free personal allowance, and the free E5 developer sandbox is limited to Visual Studio subscribers and other qualifying members (10). A person registers an app in Entra and signs in to consent (0).",
            "reliability": "Graded on the v1.0 REST API. A public Microsoft service health page at status.cloud.microsoft (20). It shows nothing without JavaScript, so we couldn't read components or history (5). SharePoint and OneDrive limits are published in resource units, 1,250 to 6,250 a minute and 1,200,000 to 6,000,000 a day per app per tenant by licence count, 3,000 requests per 5 minutes a user, and 400 GB of ingress and of egress an hour per app (15). 429 and 503 responses carry `Retry-After`, upload sessions resume from `nextExpectedRanges` with backoff advice for 5xx errors, and `If-Match` and `conflictBehavior` guard overwrites. There is no idempotency key on `invite` or folder creation (14 of 15). The Online Services SLA page is drawn by script and gave us no text, so no SLA is counted (0). The file endpoints are generally available on v1.0 (10).",
            "schema": "OpenAPI 3.0.4 for all of Graph v1.0 in microsoftgraph/msgraph-metadata, with 1,516 paths under `/drives`, 172 of them outside the workbook API (25). learn.microsoft.com answers 404 for llms.txt, but every page we asked for with `Accept: text/markdown` came back as Markdown (10). Reference pages state the purpose of each call, list permissions from least to most privileged and say which options work only on personal OneDrive. The upload session page gives Sites.ReadWrite.All as the least privileged application permission where the small-upload page gives Files.ReadWrite.All, and the overview page is dated March 2024 (16). `createLink` declares `type` and `scope` as plain strings with no enumeration, `conflictBehavior` is an annotation outside the schema, path addressing is absent from the OpenAPI, and `retainInheritedPermissions` defaults to false there and to true on the reference page (9). An HTTP example and SDK snippets on each page, a status code table, and upload-specific handling for 404, 409 and 416 (14). v1.0 and beta, a dated changelog and a monthly What's new page (15).",
            "security": "OAuth 2.0 through Microsoft Entra ID with delegated and application permissions from Files.Read to Sites.ReadWrite.All, revocable consent, and Selected scopes that hold an app to chosen sites, lists, folders or files. Download and upload URLs are pre-authenticated and short-lived, which we read as designed capability links and not as a credential in a URL (30). Files.Read for reading, Selected scopes with read, write, owner and fullcontrol roles, DELETE to the recycle bin and anonymous links that an administrator can disable. Nothing asks for confirmation before `permanentDelete` or an anonymous link (17). File names and contents written by other people reach the caller, and no injection guidance was found in the files reference pages (0). Graph activity logs record app, user, request URI and scopes for every request, but need Entra ID P1 or P2 and an Azure log destination (12). The Microsoft 365 bounty names SharePoint Online and OneDrive at $1,250 to $19,500, with a coordinated disclosure policy and an Office 365 SOC 2 Type 2 report. microsoft.com's security.txt passed its Expires date on 23 September 2026, and a token-leak fix in the JavaScript client is unreleased on npm (14).",
            "transparency": "Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDKs (15). Microsoft's data handling page for Microsoft 365 gives at most 30 days after active deletion and 180 days after a subscription ends for customer content, the SharePoint deletion page gives 93 days in the recycle bin and 14 further days of backups, and the privacy statement was updated in September 2026. We didn't read the data protection addendum (22). The Graph policy is at least 24 months' notice before a generally available API or version is removed, while the API terms reserve the right to change or discontinue any API with or without notice (18). Data residency for Microsoft 365 is documented by tenant geography. The sub-processor list sits on the Service Trust Portal, which we didn't read (10)."
          },
          "sources": [
            {
              "what": "files overview in the v1.0 reference",
              "url": "https://learn.microsoft.com/en-us/graph/api/resources/onedrive?view=graph-rest-1.0",
              "seen": "2026-10-09"
            },
            {
              "what": "OneDrive concept overview",
              "url": "https://learn.microsoft.com/en-us/graph/onedrive-concept-overview",
              "seen": "2026-10-09"
            },
            {
              "what": "driveItem resource",
              "url": "https://learn.microsoft.com/en-us/graph/api/resources/driveitem?view=graph-rest-1.0",
              "seen": "2026-10-09"
            },
            {
              "what": "small upload (PUT content, 250 MB)",
              "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-put-content?view=graph-rest-1.0",
              "seen": "2026-10-09"
            },
            {
              "what": "upload sessions",
              "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-createuploadsession?view=graph-rest-1.0",
              "seen": "2026-10-09"
            },
            {
              "what": "download and pre-authenticated URLs",
              "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-get-content?view=graph-rest-1.0",
              "seen": "2026-10-09"
            },
            {
              "what": "list children and paging",
              "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-list-children?view=graph-rest-1.0",
              "seen": "2026-10-09"
            },
            {
              "what": "createLink (types, scopes, expiry)",
              "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-createlink?view=graph-rest-1.0",
              "seen": "2026-10-09"
            },
            {
              "what": "invite (permissions and invitations)",
              "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-invite?view=graph-rest-1.0",
              "seen": "2026-10-09"
            },
            {
              "what": "permission resource",
              "url": "https://learn.microsoft.com/en-us/graph/api/resources/permission?view=graph-rest-1.0",
              "seen": "2026-10-09"
            },
            {
              "what": "delete to recycle bin",
              "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-delete?view=graph-rest-1.0",
              "seen": "2026-10-09"
            },
            {
              "what": "permanent delete",
              "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-permanentdelete?view=graph-rest-1.0",
              "seen": "2026-10-09"
            },
            {
              "what": "delta",
              "url": "https://learn.microsoft.com/en-us/graph/api/driveitem-delta?view=graph-rest-1.0",
              "seen": "2026-10-09"
            },
            {
              "what": "change notification subscriptions",
              "url": "https://learn.microsoft.com/en-us/graph/api/subscription-post-subscriptions?view=graph-rest-1.0",
              "seen": "2026-10-09"
            },
            {
              "what": "SharePoint and OneDrive throttling limits",
              "url": "https://learn.microsoft.com/en-us/sharepoint/dev/general-development/how-to-avoid-getting-throttled-or-blocked-in-sharepoint-online",
              "seen": "2026-10-09"
            },
            {
              "what": "Graph throttling limits",
              "url": "https://learn.microsoft.com/en-us/graph/throttling-limits",
              "seen": "2026-10-09"
            },
            {
              "what": "throttling guidance",
              "url": "https://learn.microsoft.com/en-us/graph/throttling",
              "seen": "2026-10-09"
            },
            {
              "what": "error responses",
              "url": "https://learn.microsoft.com/en-us/graph/errors",
              "seen": "2026-10-09"
            },
            {
              "what": "best practices",
              "url": "https://learn.microsoft.com/en-us/graph/best-practices-concept",
              "seen": "2026-10-09"
            },
            {
              "what": "Selected permissions for OneDrive and SharePoint",
              "url": "https://learn.microsoft.com/en-us/graph/permissions-selected-overview",
              "seen": "2026-10-09"
            },
            {
              "what": "Graph activity logs",
              "url": "https://learn.microsoft.com/en-us/graph/microsoft-graph-activity-logs-overview",
              "seen": "2026-10-09"
            },
            {
              "what": "metered APIs list",
              "url": "https://learn.microsoft.com/en-us/graph/metered-api-list",
              "seen": "2026-10-09"
            },
            {
              "what": "versioning, support and breaking change policy",
              "url": "https://learn.microsoft.com/en-us/graph/versioning-and-support",
              "seen": "2026-10-09"
            },
            {
              "what": "What's new in Microsoft Graph",
              "url": "https://learn.microsoft.com/en-us/graph/whats-new-overview",
              "seen": "2026-10-09"
            },
            {
              "what": "Graph changelog feed",
              "url": "https://developer.microsoft.com/en-us/graph/changelog/rss",
              "seen": "2026-10-09"
            },
            {
              "what": "Work IQ MCP catalogue",
              "url": "https://learn.microsoft.com/en-us/microsoft-agent-365/tooling-servers-overview",
              "seen": "2026-10-09"
            },
            {
              "what": "app registration",
              "url": "https://learn.microsoft.com/en-us/graph/auth-register-app-v2",
              "seen": "2026-10-09"
            },
            {
              "what": "SDK overview",
              "url": "https://learn.microsoft.com/en-us/graph/sdks/sdks-overview",
              "seen": "2026-10-09"
            },
            {
              "what": "Microsoft 365 Developer Programme FAQ",
              "url": "https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq",
              "seen": "2026-10-09"
            },
            {
              "what": "OneDrive service description (storage by plan)",
              "url": "https://learn.microsoft.com/en-us/office365/servicedescriptions/onedrive-for-business-service-description",
              "seen": "2026-10-09"
            },
            {
              "what": "OneDrive plans page (refused our reader)",
              "url": "https://www.microsoft.com/en-us/microsoft-365/onedrive/compare-onedrive-plans",
              "seen": "2026-10-09"
            },
            {
              "what": "OpenAPI for Graph v1.0",
              "url": "https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml",
              "seen": "2026-10-09"
            },
            {
              "what": "service health page (JavaScript only)",
              "url": "https://status.cloud.microsoft/",
              "seen": "2026-10-09"
            },
            {
              "what": "security.txt",
              "url": "https://www.microsoft.com/.well-known/security.txt",
              "seen": "2026-10-09"
            },
            {
              "what": "Microsoft 365 bounty programme",
              "url": "https://www.microsoft.com/en-us/msrc/bounty-microsoft-cloud",
              "seen": "2026-10-09"
            },
            {
              "what": "SOC 2 Type 2 for Office 365",
              "url": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
              "seen": "2026-10-09"
            },
            {
              "what": "data retention, deletion and destruction in Microsoft 365",
              "url": "https://learn.microsoft.com/en-us/compliance/assurance/assurance-data-retention-deletion-and-destruction-overview",
              "seen": "2026-10-09"
            },
            {
              "what": "SharePoint data deletion",
              "url": "https://learn.microsoft.com/en-us/sharepoint/sharepoint-data-deletion",
              "seen": "2026-10-09"
            },
            {
              "what": "Microsoft 365 data residency",
              "url": "https://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-overview",
              "seen": "2026-10-09"
            },
            {
              "what": "Microsoft APIs terms of use",
              "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
              "seen": "2026-10-09"
            },
            {
              "what": "privacy statement",
              "url": "https://privacy.microsoft.com/en-us/privacystatement",
              "seen": "2026-10-09"
            },
            {
              "what": "Online Services SLA page (script-drawn, no text read)",
              "url": "https://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services",
              "seen": "2026-10-09"
            },
            {
              "what": "msgraph-sdk-python releases",
              "url": "https://api.github.com/repos/microsoftgraph/msgraph-sdk-python/releases",
              "seen": "2026-10-09"
            },
            {
              "what": "npm latest for @microsoft/microsoft-graph-client",
              "url": "https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest",
              "seen": "2026-10-09"
            },
            {
              "what": "JavaScript client repository and token-leak fix",
              "url": "https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19",
              "seen": "2026-10-09"
            },
            {
              "what": "RDAP for microsoft.com",
              "url": "https://rdap.verisign.com/com/v1/domain/microsoft.com",
              "seen": "2026-10-09"
            }
          ],
          "openQuestions": [
            "unchecked: status page components and incident history, which need JavaScript",
            "unchecked: OneDrive and Microsoft 365 plan prices and the free personal storage allowance, because the plans page refused our reader as an automated process",
            "unchecked: the Online Services SLA document, which is drawn by script, plus the data protection addendum and the sub-processor list on the Service Trust Portal",
            "unchecked: the advisory list of msgraph-sdk-javascript, because the GitHub API was rate-limited. The fix commit and the unpublished 3.0.8 were confirmed from a clone and from npm",
            "unchecked: pypi.org answered the msgraph-sdk project page with a client challenge, and its robots.txt disallows the JSON API, so the Python release dates come from the GitHub releases list",
            "The maximum file size for an upload session isn't stated on the upload page",
            "Whether Microsoft 365 audit logs record third-party file calls per app wasn't checked. Only Graph activity logs were read",
            "First release date of the files API, not established",
            "The lead was right on vendor, interface and docs. Its product URL, the OneDrive marketing page, wasn't used because www.microsoft.com refused our reader on the plans page"
          ]
        },
        "negative": -4,
        "negativeNotes": [
          "2026-06-16: a fix for a token leak through URL userinfo host confusion was merged into msgraph-sdk-javascript and the version set to 3.0.8, but npm still served 3.0.7 on 9 October 2026 and the repository's changelog doesn't mention it. Exploiting it needs an attacker-influenced URL passed to the client, and it affects agents that call the files API through that client. The Excel and Outlook listings took the same 4 points (https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19, https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest)"
        ],
        "verdict": "One REST surface covers personal OneDrive, work OneDrive and SharePoint libraries, with resumable uploads, sharing links that take an expiry date and per-file Selected permissions. The status page needs JavaScript, an app must be registered and consented to by a person, and the JavaScript client on npm lacks a token-leak fix merged in June 2026.",
        "bestFor": "Agents working on files that already live in a Microsoft 365 tenant or a personal OneDrive, where sharing has to follow the tenant's own policy.",
        "strengths": [
          "Upload sessions resume after a dropped connection, report `nextExpectedRanges`, and accept `If-Match` and `@microsoft.graph.conflictBehavior` (fail by default)",
          "`createLink` takes `expirationDateTime` and a scope of `anonymous`, `organization` or `users`, and returns the existing link when one of that type exists",
          "Selected scopes limit an application to chosen sites, lists, folders or files, each with a read, write, owner or fullcontrol role",
          "SharePoint publishes throttling numbers, with 1,250 to 6,250 resource units a minute per app per tenant and a stated cost of 1, 2 or 5 units a request",
          "DELETE moves an item to the recycle bin, and permanent removal is a separate `permanentDelete` call"
        ],
        "weaknesses": [
          "Link and scope types are plain strings in the OpenAPI, and path addressing such as `/root:/folder/file.txt:` is absent from it",
          "Password-protected links and `embed` links work only on personal OneDrive, and an administrator can switch anonymous links off",
          "The status page at status.cloud.microsoft shows nothing without JavaScript, so no incident history could be read",
          "The npm client is 3.0.7 from September 2023. A token-leak fix merged on 16 June 2026 set the version to 3.0.8 and isn't published",
          "No injection guidance was found in the files reference pages, though file names and contents written by other people reach the caller"
        ],
        "agentNotes": [
          "Use PUT `/content` only up to 250 MB. Above 10 MiB Microsoft advises `createUploadSession`, with fragments in multiples of 320 KiB and under 60 MiB each",
          "Send the bearer token on the `createUploadSession` POST only. The PUT calls to `uploadUrl` can return 401 if an `Authorization` header is included",
          "Set `expirationDateTime` and `scope` on `createLink`. Without a scope the tenant's default link type is created, which may be wider than intended",
          "Follow the 302 from GET `/content` straight away. Pre-authenticated download URLs can expire within minutes and need no `Authorization` header",
          "Wait for `Retry-After` on 429 and 503. Throttled requests still count against the limits, and continued overuse can get the app blocked"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.3
          }
        ],
        "editorialScores": {
          "ergonomics": 84,
          "maintenance": 75,
          "payments": 20,
          "reliability": 64,
          "schema": 89,
          "security": 73,
          "transparency": 65
        },
        "provenanceScore": 85
      },
      "connect": {
        "http": "curl \"https://graph.microsoft.com/v1.0/me/drive/root/children?\\$select=id,name,size\u0026\\$top=50\" \\\n  -H \"Authorization: Bearer $MS_GRAPH_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/storage.drive",
        "tool": "https://letme.dev/onedrive-sharepoint"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-document-intelligence",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "azure-blob-storage",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "foundry-local",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "notable": [
        "The same endpoints address a user's OneDrive (`/me/drive`), another user's, a group library, a SharePoint site library (`/sites/{site-id}/drive`) and shared items (`/shares/{share-id}`) (https://learn.microsoft.com/en-us/graph/api/resources/onedrive)",
        "PUT `/content` takes files up to 250 MB. Upload sessions take larger files in sequential byte ranges, each a multiple of 320 KiB and under 60 MiB (https://learn.microsoft.com/en-us/graph/api/driveitem-createuploadsession)",
        "`createLink` accepts `type` (view, edit, embed), `scope` (`anonymous`, `organization`, `users`), `expirationDateTime` and, on personal OneDrive only, `password` (https://learn.microsoft.com/en-us/graph/api/driveitem-createlink)",
        "SharePoint limits are counted in resource units, 1 for a single-item read or download, 2 for a list, create, update, delete or upload, and 5 for any permission operation (https://learn.microsoft.com/en-us/sharepoint/dev/general-development/how-to-avoid-getting-throttled-or-blocked-in-sharepoint-online)",
        "The only metered Graph API is `assignSensitivityLabel` for SharePoint and OneDrive for work or school, at $0.00185 a call (https://learn.microsoft.com/en-us/graph/metered-api-list)",
        "Work IQ OneDrive and Work IQ SharePoint MCP servers are in preview and need a Microsoft 365 Copilot licence. This listing grades the REST API (https://learn.microsoft.com/en-us/microsoft-agent-365/tooling-servers-overview)",
        "The OpenAPI for Graph v1.0 has 1,516 paths under `/drives`, 172 of them outside the workbook API, and declares `retainInheritedPermissions` with a default of false where the reference page says true (https://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml)",
        "Change notifications cover the root folder of a work OneDrive or any folder of a personal one, and `delta` returns changes since a saved token (https://learn.microsoft.com/en-us/graph/api/subscription-post-subscriptions)"
      ],
      "area": "everyday",
      "details": [
        {
          "label": "Free tier",
          "value": "No charge for file calls. Storage is the account's own OneDrive or Microsoft 365 allowance. Plan prices unread on 2026-10-09"
        },
        {
          "label": "Drives",
          "value": "Personal OneDrive, OneDrive for work or school, SharePoint document libraries, group libraries and shared items, on the same endpoints"
        },
        {
          "label": "Uploads",
          "value": "PUT `/content` up to 250 MB. Upload sessions above that, resumable, in fragments that are multiples of 320 KiB and under 60 MiB, 5 to 10 MiB advised"
        },
        {
          "label": "Downloads",
          "value": "GET `/content` answers 302 to a pre-authenticated URL that can expire within minutes"
        },
        {
          "label": "Sharing",
          "value": "`createLink` with view, edit or embed type, anonymous, organisation or named-user scope and `expirationDateTime`. `invite` grants read or write to recipients. Passwords on personal OneDrive only"
        },
        {
          "label": "Deleting",
          "value": "DELETE sends an item to the recycle bin (93 days on SharePoint). `permanentDelete` removes it for good"
        },
        {
          "label": "Rate limits",
          "value": "Per app per tenant 1,250 to 6,250 resource units a minute and 1,200,000 to 6,000,000 a day by licence count, 400 GB of ingress and of egress an hour. Per user 3,000 requests per 5 minutes"
        },
        {
          "label": "Paging",
          "value": "200 items a page by default, `@odata.nextLink`, with `$top`, `$select`, `$orderby`, `$expand` and `$skipToken`"
        },
        {
          "label": "Permissions",
          "value": "Files.Read, Files.ReadWrite, Files.Read.All, Files.ReadWrite.All, Sites.Read.All, Sites.ReadWrite.All, plus Sites.Selected and Files.SelectedOperations.Selected"
        },
        {
          "label": "Change events",
          "value": "`delta` with a saved token, and webhook subscriptions on a drive's root folder (any folder on personal OneDrive)"
        },
        {
          "label": "MCP server",
          "value": "Work IQ OneDrive and Work IQ SharePoint, preview, Microsoft 365 Copilot licence needed. Not graded here"
        },
        {
          "label": "SDKs",
          "value": "C#, Java, Go, PHP, Python (msgraph-sdk 1.64.0, 6 October 2026), PowerShell and JavaScript (npm 3.0.7 from September 2023)"
        },
        {
          "label": "National clouds",
          "value": "Global, US Government L4 and L5, and China operated by 21Vianet"
        }
      ],
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "domainNote": "The endpoint is on graph.microsoft.com. Upload and download URLs are issued on other Microsoft hosts. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
        "endpointOnVendorDomain": true,
        "terms": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
        "privacy": "https://privacy.microsoft.com/en-us/privacystatement",
        "statusPage": "https://status.cloud.microsoft",
        "changelog": "https://developer.microsoft.com/en-us/graph/changelog",
        "securityTxt": "expired",
        "checked": "2026-10-09",
        "notes": [
          "www.microsoft.com/.well-known/security.txt still carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-09.",
          "The Microsoft service health page at status.cloud.microsoft needs JavaScript to show anything.",
          "The Microsoft APIs terms of use name Microsoft Corporation and were last updated in October 2025.",
          "The Microsoft privacy statement was last updated in September 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02.",
          "The Graph changelog feed's newest entry is dated 3 August 2026. The What's new page, updated 8 October 2026, lists later changes."
        ],
        "score": 85,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Microsoft Corporation",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "microsoft.com, registered 1991-05-02 (35 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "graph.microsoft.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points",
            "points": 2.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
            "points": 8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.cloud.microsoft",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "published but past its Expires date",
            "points": 5,
            "max": 10,
            "state": "part"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-10-01",
            "words": 4555,
            "points": 2.3,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: October 2025 What's new?",
                "says": "Last updated 2025-10-01"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": false
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "WE MAKE NO WARRANTIES, EXPRESS OR IMPLIED, GUARANTEES OR CONDITIONS WITH RESPECT TO YOUR USE OF THE MICROSOFT APIs."
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "We may change, amend or terminate these API Terms at any time."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Unless you have use permissions expressly and specifically granted by Customers in connection with using your Application, you may not use Microsoft email protocols and APIs for any purpose other than:"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "Scrape, build databases or otherwise create copies of any data accessed or obtained using the Microsoft APIs, except as necessary to enable an intended usage scenario for your Application;",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "Use the Microsoft APIs, or any data obtained using the Microsoft APIs, to conduct performance testing of a Microsoft Offering unless expressly permitted by Microsoft",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "We may suspend or immediately terminate these API Terms, any rights granted herein, and/or your license to the Microsoft APIs, in our sole discretion at any time, for any reason."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Recoverable damages are limited to direct damages of up to 5 US dollars in total.",
                "quote": "YOU AGREE THAT YOUR EXCLUSIVE REMEDY IS TO RECOVER, FROM MICROSOFT OR ANY AFFILIATES, RESELLERS, DISTRIBUTORS, SUPPLIERS (AND RESPECTIVE EMPLOYEES, SHAREHOLDERS, OR DIRECTORS) AND VENDORS, ONLY DIRECT DAMAGES UP TO USD $5.00 COLLECTIVELY."
              },
              {
                "date": "2026-10-08",
                "text": "After a data breach involving the Microsoft APIs, the developer may make no public statement about it without Microsoft's prior written permission.",
                "quote": "You agree to refrain from making public statements (e.g., press, blogs, social media, bulletin boards, etc.) without prior written and express permission from Microsoft in each instance as it relates to the Microsoft APIs."
              },
              {
                "date": "2026-10-08",
                "text": "The developer must allow Microsoft reasonable access to its application so Microsoft can monitor compliance with the API terms.",
                "quote": "You will permit Microsoft reasonable access to your Application for purposes of monitoring compliance with these API Terms."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://privacy.microsoft.com/en-us/privacystatement",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-09-01",
            "words": 33580,
            "points": 8,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: September 2026",
                "says": "Last updated 2026-09-01"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "The data we collect depends on the context of your interactions with Microsoft and the choices you make, including your privacy settings and the products and features you use."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "When you delete an email or item from a mailbox in Outlook.com, the item generally goes into your Deleted Items folder where it remains for approximately 7 days unless you move it back to your inbox, you empty the folder, or the service empties the folder automatically, whichever comes first.",
                "says": "Names a period of 7 days"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Service providers that help us determine your device’s location."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "not use or share student personal data for advertising or similar commercial purposes, such as providing personalized advertising to students;"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "State Data Privacy Notice (including notice at collection details) and the Consumer Health Data Privacy Policy for additional information about your rights and the processing of your personal data."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have a privacy concern, complaint, or question for the Microsoft privacy team or Data Protection Officer, please visit our privacy support and requests page and click on “Contact the Microsoft privacy team or the Microsoft Data Protection Officer” menu.",
                "says": "Names a data protection officer"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "In such cases, we implement legal safeguards-such as standard contractual clauses approved by the European Commission – to help protect your rights and ensure your data remains protected.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "training",
                "label": "Says it may use customer content to train or improve models, and no opt-out was found",
                "found": true,
                "quote": "As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.",
                "costsPoints": true
              },
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "We also disclose personal data for digital advertising purposes."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict.",
                "quote": "In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control."
              },
              {
                "date": "2026-10-08",
                "text": "Advertisements may be chosen from the current interaction, including Copilot conversations and files shared in them.",
                "quote": "Ads may be shown that relate to the current interaction you are having with us, such as your Copilot conversations (including files you share); your current location; transactions; product usage; search queries; or the content you’re viewing."
              },
              {
                "date": "2026-10-08",
                "text": "Microsoft staff manually review some results of automated systems, including AI, against the source data.",
                "quote": "For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/onedrive-sharepoint.json",
      "live": {
        "slug": "onedrive-sharepoint",
        "probe": {
          "target": "https://graph.microsoft.com/v1.0",
          "method": "get",
          "lastAt": "2026-10-09T10:14:22.506571694Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 3,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 4,
          "p95ms24h": 14,
          "samples24h": 28,
          "samples30d": 28,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 28,
              "ok": 28
            }
          ]
        },
        "updatedAt": "2026-10-09T10:14:22.506571694Z"
      }
    },
    "verify": {
      "accepts": "a page on microsoft.com or one of its subdomains, or the README of github.com/microsoftgraph/msgraph-sdk-python",
      "badgeUrl": "https://www.anchorterminal.com/badges/onedrive-sharepoint.svg",
      "body": {
        "slug": "onedrive-sharepoint",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/onedrive-sharepoint",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/onedrive-sharepoint\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/onedrive-sharepoint.svg\" alt=\"OneDrive and SharePoint files (Microsoft Graph) on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![OneDrive and SharePoint files (Microsoft Graph) on Anchor Terminal](https://www.anchorterminal.com/badges/onedrive-sharepoint.svg)](https://www.anchorterminal.com/tools/onedrive-sharepoint)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/onedrive-sharepoint\"\u003eOneDrive and SharePoint files (Microsoft Graph) on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/onedrive-sharepoint",
    "json": "https://www.anchorterminal.com/tools/onedrive-sharepoint.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/onedrive-sharepoint.md",
    "slim": "https://www.anchorterminal.com/tools/onedrive-sharepoint.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 65.3/100 · rank #296 of 842 · #8 in File storage \u0026 sharing · not agent-ready · confidence medium**\n\n\nMore from Microsoft, listed separately because each is its own product: [Microsoft Foundry fine-tuning (Azure OpenAI)](https://www.anchorterminal.com/tools/azure-foundry-fine-tuning.md) (Fine-tuning), [Azure AI Content Safety (Prompt Shields)](https://www.anchorterminal.com/tools/azure-ai-content-safety.md) (Guardrails \u0026 safety filters), [Azure AI Speech speech-to-text](https://www.anchorterminal.com/tools/azure-speech-to-text.md) (Speech-to-text), [Azure AI Speech text-to-speech](https://www.anchorterminal.com/tools/azure-text-to-speech.md) (Text-to-speech), [Microsoft Agent Framework](https://www.anchorterminal.com/tools/microsoft-agent-framework.md) (Agent frameworks \u0026 SDKs), [Microsoft Execution Containers](https://www.anchorterminal.com/tools/microsoft-execution-containers.md) (Code execution sandboxes), [Microsoft Entra Agent ID](https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md) (Agent auth \u0026 delegated access), [Azure Key Vault](https://www.anchorterminal.com/tools/azure-key-vault.md) (Secrets \u0026 credential vaults), [Azure Document Intelligence](https://www.anchorterminal.com/tools/azure-document-intelligence.md) (Document parsing \u0026 extraction), [Azure DevOps MCP Server](https://www.anchorterminal.com/tools/azure-devops-mcp.md) (Code \u0026 developer platforms), [Microsoft Learn MCP Server](https://www.anchorterminal.com/tools/microsoft-learn-mcp.md) (Code \u0026 developer platforms), [Playwright MCP](https://www.anchorterminal.com/tools/playwright-mcp.md) (Browser automation), [Azure MCP Server](https://www.anchorterminal.com/tools/azure-mcp.md) (Cloud \u0026 infrastructure), [Azure Maps](https://www.anchorterminal.com/tools/azure-maps.md) (Maps, geocoding \u0026 places), [Azure Translator](https://www.anchorterminal.com/tools/azure-translator.md) (Translation), [Microsoft Graph Calendar API](https://www.anchorterminal.com/tools/microsoft-graph-calendar.md) (Calendars \u0026 scheduling), [Azure Blob Storage](https://www.anchorterminal.com/tools/azure-blob-storage.md) (File storage \u0026 sharing), [Microsoft Teams (Microsoft Graph)](https://www.anchorterminal.com/tools/microsoft-teams.md) (Work \u0026 productivity), [Microsoft Dynamics 365 Sales](https://www.anchorterminal.com/tools/dynamics-365-sales.md) (CRM \u0026 customer platforms), [Microsoft Power Automate](https://www.anchorterminal.com/tools/power-automate.md) (Workflow automation), [Foundry Local](https://www.anchorterminal.com/tools/foundry-local.md) (Local AI), [Microsoft Advertising API](https://www.anchorterminal.com/tools/microsoft-advertising-api.md) (Advertising \u0026 campaign operations), [Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/tools/microsoft-excel-graph.md) (Spreadsheets \u0026 operational tables), [Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/tools/outlook-mail-graph.md) (Mailbox access).\n\n## Assessment\n\nOne REST surface covers personal OneDrive, work OneDrive and SharePoint libraries, with resumable uploads, sharing links that take an expiry date and per-file Selected permissions. The status page needs JavaScript, an app must be registered and consented to by a person, and the JavaScript client on npm lacks a token-leak fix merged in June 2026.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Microsoft (https://learn.microsoft.com/en-us/graph/onedrive-concept-overview) |\n| Kind | HTTP API |\n| Category | File storage \u0026 sharing (https://www.anchorterminal.com/categories/file-storage) |\n| Transport | HTTP |\n| Endpoint | `https://graph.microsoft.com/v1.0` |\n| Auth | OAuth · OAuth 2.0 tokens from Microsoft Entra ID, after a person registers an app. Registration is self-serve, with no partner or sales approval. Delegated permissions run from Files.Read to Files.ReadWrite.All and work for personal Microsoft accounts and work or school accounts. Application permissions (Files.Read.All, Files.ReadWrite.All, Sites.ReadWrite.All) need an administrator's consent. Selected scopes limit an app to chosen sites, lists, folders or files. |\n| Pricing | Your plan (Your plan) · File calls carry no per-call charge. Microsoft's list of metered Graph APIs names only `assignSensitivityLabel`, at $0.00185 a call (https://learn.microsoft.com/en-us/graph/metered-api-list). Storage comes from the account's own OneDrive or Microsoft 365 plan, 1 TB a user on the Business and E3 or E5 plans per the service description. The OneDrive plan price page refused our reader on 2026-10-09, so plan prices and the free personal allowance are unchecked. A free Microsoft 365 E5 developer sandbox is limited to Visual Studio subscribers and other qualifying members (https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq). |\n| x402 | No · No x402, MPP or L402 in the files documentation or the metered API list (checked 2026-10-09). |\n| Licence | MIT (SDKs) |\n| Packages | npm: `@microsoft/microsoft-graph-client`; pypi: `msgraph-sdk` |\n| Source | https://github.com/microsoftgraph/msgraph-sdk-python |\n| Docs | https://learn.microsoft.com/en-us/graph/api/resources/onedrive |\n| llms.txt | not found |\n| Last release | 2026-10-06 |\n| GitHub stars | 633 (as of 2026-10-09) |\n| npm downloads / week | 2,882,852 |\n| PyPI downloads / week | 1,578,201 |\n| Free tier | No charge for file calls. Storage is the account's own OneDrive or Microsoft 365 allowance. Plan prices unread on 2026-10-09 |\n| Drives | Personal OneDrive, OneDrive for work or school, SharePoint document libraries, group libraries and shared items, on the same endpoints |\n| Uploads | PUT `/content` up to 250 MB. Upload sessions above that, resumable, in fragments that are multiples of 320 KiB and under 60 MiB, 5 to 10 MiB advised |\n| Downloads | GET `/content` answers 302 to a pre-authenticated URL that can expire within minutes |\n| Sharing | `createLink` with view, edit or embed type, anonymous, organisation or named-user scope and `expirationDateTime`. `invite` grants read or write to recipients. Passwords on personal OneDrive only |\n| Deleting | DELETE sends an item to the recycle bin (93 days on SharePoint). `permanentDelete` removes it for good |\n| Rate limits | Per app per tenant 1,250 to 6,250 resource units a minute and 1,200,000 to 6,000,000 a day by licence count, 400 GB of ingress and of egress an hour. Per user 3,000 requests per 5 minutes |\n| Paging | 200 items a page by default, `@odata.nextLink`, with `$top`, `$select`, `$orderby`, `$expand` and `$skipToken` |\n| Permissions | Files.Read, Files.ReadWrite, Files.Read.All, Files.ReadWrite.All, Sites.Read.All, Sites.ReadWrite.All, plus Sites.Selected and Files.SelectedOperations.Selected |\n| Change events | `delta` with a saved token, and webhook subscriptions on a drive's root folder (any folder on personal OneDrive) |\n| MCP server | Work IQ OneDrive and Work IQ SharePoint, preview, Microsoft 365 Copilot licence needed. Not graded here |\n| SDKs | C#, Java, Go, PHP, Python (msgraph-sdk 1.64.0, 6 October 2026), PowerShell and JavaScript (npm 3.0.7 from September 2023) |\n| National clouds | Global, US Government L4 and L5, and China operated by 21Vianet |\n| Capabilities | storage.drive, storage.share, storage.presigned |\n| Tags | hosted, official, oauth, openapi, typescript, python, enterprise |\n| JSON | https://www.anchorterminal.com/api/v1/tools/onedrive-sharepoint.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 64 | 12.8 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 89 | 14.5 |\n| Agent ergonomics | 13% | 16.2 | 84 | 13.7 |\n| Security \u0026 auth | 14% | 17.5 | 73 | 12.8 |\n| Payments \u0026 pricing | 10% | 12.5 | 20 | 2.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 75 | 6.6 |\n| Transparency \u0026 trust (editorial 65, provenance 85) | 7% | 8.8 | 75 | 6.6 |\n| Negative events | up to −15 | up to −15 | 2026-06-16: a fix for a token leak through URL userinfo host confusion was merged into msgraph-sdk-javascript and the version set to 3.0.8, but npm still served 3.0.7 on 9 October 2026 and the repository's changelog doesn't mention it. Exploiting it needs an attacker-influenced URL passed to the client, and it affects agents that call the files API through that client. The Excel and Outlook listings took the same 4 points (https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19, https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest)  | -4 |\n| **Total** | | | | **65.3 → B** |\n\n### Why each score\n\n- Reliability 64: Graded on the v1.0 REST API. A public Microsoft service health page at status.cloud.microsoft (20). It shows nothing without JavaScript, so we couldn't read components or history (5). SharePoint and OneDrive limits are published in resource units, 1,250 to 6,250 a minute and 1,200,000 to 6,000,000 a day per app per tenant by licence count, 3,000 requests per 5 minutes a user, and 400 GB of ingress and of egress an hour per app (15). 429 and 503 responses carry `Retry-After`, upload sessions resume from `nextExpectedRanges` with backoff advice for 5xx errors, and `If-Match` and `conflictBehavior` guard overwrites. There is no idempotency key on `invite` or folder creation (14 of 15). The Online Services SLA page is drawn by script and gave us no text, so no SLA is counted (0). The file endpoints are generally available on v1.0 (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 89: OpenAPI 3.0.4 for all of Graph v1.0 in microsoftgraph/msgraph-metadata, with 1,516 paths under `/drives`, 172 of them outside the workbook API (25). learn.microsoft.com answers 404 for llms.txt, but every page we asked for with `Accept: text/markdown` came back as Markdown (10). Reference pages state the purpose of each call, list permissions from least to most privileged and say which options work only on personal OneDrive. The upload session page gives Sites.ReadWrite.All as the least privileged application permission where the small-upload page gives Files.ReadWrite.All, and the overview page is dated March 2024 (16). `createLink` declares `type` and `scope` as plain strings with no enumeration, `conflictBehavior` is an annotation outside the schema, path addressing is absent from the OpenAPI, and `retainInheritedPermissions` defaults to false there and to true on the reference page (9). An HTTP example and SDK snippets on each page, a status code table, and upload-specific handling for 404, 409 and 416 (14). v1.0 and beta, a dated changelog and a monthly What's new page (15).\n- Agent ergonomics 84: `$select` trims driveItem properties, a list returns 200 items a page by default, and responses without `$select` carry a tip to use it. The whole-Graph OpenAPI is 44 MB (21). `@odata.nextLink` paging with `$top`, `$skipToken`, `$orderby` and `$expand`, a search call and `delta` for changes since a token (20). Errors carry a code, a message and a request ID, the upload page says what to do on 404, 409, 416 and 5xx, and `delta` returns two named resync codes on 410 (17). Uploads resume, `If-Match` and `if-none-match` guard writes, `conflictBehavior` fails by default, `createLink` returns the existing link of the same type and DELETE goes to the recycle bin. No idempotency key (14). Items are addressed by ID or by path with one bearer token, but upload fragments must be multiples of 320 KiB and the token must be left off the fragment PUT. Official SDKs in C#, Java, Go, PHP, Python, PowerShell and JavaScript, the npm JavaScript client dating from September 2023 (12).\n- Security \u0026 auth 73: OAuth 2.0 through Microsoft Entra ID with delegated and application permissions from Files.Read to Sites.ReadWrite.All, revocable consent, and Selected scopes that hold an app to chosen sites, lists, folders or files. Download and upload URLs are pre-authenticated and short-lived, which we read as designed capability links and not as a credential in a URL (30). Files.Read for reading, Selected scopes with read, write, owner and fullcontrol roles, DELETE to the recycle bin and anonymous links that an administrator can disable. Nothing asks for confirmation before `permanentDelete` or an anonymous link (17). File names and contents written by other people reach the caller, and no injection guidance was found in the files reference pages (0). Graph activity logs record app, user, request URI and scopes for every request, but need Entra ID P1 or P2 and an Azure log destination (12). The Microsoft 365 bounty names SharePoint Online and OneDrive at $1,250 to $19,500, with a coordinated disclosure policy and an Office 365 SOC 2 Type 2 report. microsoft.com's security.txt passed its Expires date on 23 September 2026, and a token-leak fix in the JavaScript client is unreleased on npm (14).\n- Payments \u0026 pricing 20: No x402, MPP or L402 (0). File calls aren't on Microsoft's metered API list, whose one entry is `assignSensitivityLabel` at $0.00185 a call, but storage comes from a OneDrive or Microsoft 365 plan and the plan price page refused our reader today (10). The reference pages list delegated permissions for personal Microsoft accounts, so no Microsoft 365 licence is needed to call the API, but we couldn't read the size of the free personal allowance, and the free E5 developer sandbox is limited to Visual Studio subscribers and other qualifying members (10). A person registers an app in Entra and signs in to consent (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 75: msgraph-sdk-python v1.64.0 on 6 October 2026. The What's new page, updated 8 October 2026, lists generally available Files changes for September and August 2026, and the changelog feed's last v1.0 Files entry is 29 July 2026 (30). Five Python SDK releases since 22 July 2026, v1.60.0 to v1.64.0 (20). A public changelog, a What's new page and SDK issue trackers. The changelog feed stops at 3 August 2026, an issue about drive content returning None on the Python SDK has had no reply since 21 September 2026, and a security fix merged into the JavaScript client on 16 June 2026 hasn't reached npm (9 of 15). Current SDKs in most languages, with the JavaScript client the exception at 3.0.7 (10). Active releases on the Python package, none on the JavaScript one (6).\n- Transparency \u0026 trust 75: Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDKs (15). Microsoft's data handling page for Microsoft 365 gives at most 30 days after active deletion and 180 days after a subscription ends for customer content, the SharePoint deletion page gives 93 days in the recycle bin and 14 further days of backups, and the privacy statement was updated in September 2026. We didn't read the data protection addendum (22). The Graph policy is at least 24 months' notice before a generally available API or version is removed, while the API terms reserve the right to change or discontinue any API with or without notice (18). Data residency for Microsoft 365 is documented by tenant geography. The sub-processor list sits on the Service Trust Portal, which we didn't read (10).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/onedrive-sharepoint.md (JSON https://www.anchorterminal.com/fixes/onedrive-sharepoint.json)\n\n### What we couldn't check\n\n- unchecked: status page components and incident history, which need JavaScript\n- unchecked: OneDrive and Microsoft 365 plan prices and the free personal storage allowance, because the plans page refused our reader as an automated process\n- unchecked: the Online Services SLA document, which is drawn by script, plus the data protection addendum and the sub-processor list on the Service Trust Portal\n- unchecked: the advisory list of msgraph-sdk-javascript, because the GitHub API was rate-limited. The fix commit and the unpublished 3.0.8 were confirmed from a clone and from npm\n- unchecked: pypi.org answered the msgraph-sdk project page with a client challenge, and its robots.txt disallows the JSON API, so the Python release dates come from the GitHub releases list\n- The maximum file size for an upload session isn't stated on the upload page\n- Whether Microsoft 365 audit logs record third-party file calls per app wasn't checked. Only Graph activity logs were read\n- First release date of the files API, not established\n- The lead was right on vendor, interface and docs. Its product URL, the OneDrive marketing page, wasn't used because www.microsoft.com refused our reader on the plans page\n\n### Sources\n\n- files overview in the v1.0 reference: \u003chttps://learn.microsoft.com/en-us/graph/api/resources/onedrive?view=graph-rest-1.0\u003e (seen 2026-10-09)\n- OneDrive concept overview: \u003chttps://learn.microsoft.com/en-us/graph/onedrive-concept-overview\u003e (seen 2026-10-09)\n- driveItem resource: \u003chttps://learn.microsoft.com/en-us/graph/api/resources/driveitem?view=graph-rest-1.0\u003e (seen 2026-10-09)\n- small upload (PUT content, 250 MB): \u003chttps://learn.microsoft.com/en-us/graph/api/driveitem-put-content?view=graph-rest-1.0\u003e (seen 2026-10-09)\n- upload sessions: \u003chttps://learn.microsoft.com/en-us/graph/api/driveitem-createuploadsession?view=graph-rest-1.0\u003e (seen 2026-10-09)\n- download and pre-authenticated URLs: \u003chttps://learn.microsoft.com/en-us/graph/api/driveitem-get-content?view=graph-rest-1.0\u003e (seen 2026-10-09)\n- list children and paging: \u003chttps://learn.microsoft.com/en-us/graph/api/driveitem-list-children?view=graph-rest-1.0\u003e (seen 2026-10-09)\n- createLink (types, scopes, expiry): \u003chttps://learn.microsoft.com/en-us/graph/api/driveitem-createlink?view=graph-rest-1.0\u003e (seen 2026-10-09)\n- invite (permissions and invitations): \u003chttps://learn.microsoft.com/en-us/graph/api/driveitem-invite?view=graph-rest-1.0\u003e (seen 2026-10-09)\n- permission resource: \u003chttps://learn.microsoft.com/en-us/graph/api/resources/permission?view=graph-rest-1.0\u003e (seen 2026-10-09)\n- delete to recycle bin: \u003chttps://learn.microsoft.com/en-us/graph/api/driveitem-delete?view=graph-rest-1.0\u003e (seen 2026-10-09)\n- permanent delete: \u003chttps://learn.microsoft.com/en-us/graph/api/driveitem-permanentdelete?view=graph-rest-1.0\u003e (seen 2026-10-09)\n- delta: \u003chttps://learn.microsoft.com/en-us/graph/api/driveitem-delta?view=graph-rest-1.0\u003e (seen 2026-10-09)\n- change notification subscriptions: \u003chttps://learn.microsoft.com/en-us/graph/api/subscription-post-subscriptions?view=graph-rest-1.0\u003e (seen 2026-10-09)\n- SharePoint and OneDrive throttling limits: \u003chttps://learn.microsoft.com/en-us/sharepoint/dev/general-development/how-to-avoid-getting-throttled-or-blocked-in-sharepoint-online\u003e (seen 2026-10-09)\n- Graph throttling limits: \u003chttps://learn.microsoft.com/en-us/graph/throttling-limits\u003e (seen 2026-10-09)\n- throttling guidance: \u003chttps://learn.microsoft.com/en-us/graph/throttling\u003e (seen 2026-10-09)\n- error responses: \u003chttps://learn.microsoft.com/en-us/graph/errors\u003e (seen 2026-10-09)\n- best practices: \u003chttps://learn.microsoft.com/en-us/graph/best-practices-concept\u003e (seen 2026-10-09)\n- Selected permissions for OneDrive and SharePoint: \u003chttps://learn.microsoft.com/en-us/graph/permissions-selected-overview\u003e (seen 2026-10-09)\n- Graph activity logs: \u003chttps://learn.microsoft.com/en-us/graph/microsoft-graph-activity-logs-overview\u003e (seen 2026-10-09)\n- metered APIs list: \u003chttps://learn.microsoft.com/en-us/graph/metered-api-list\u003e (seen 2026-10-09)\n- versioning, support and breaking change policy: \u003chttps://learn.microsoft.com/en-us/graph/versioning-and-support\u003e (seen 2026-10-09)\n- What's new in Microsoft Graph: \u003chttps://learn.microsoft.com/en-us/graph/whats-new-overview\u003e (seen 2026-10-09)\n- Graph changelog feed: \u003chttps://developer.microsoft.com/en-us/graph/changelog/rss\u003e (seen 2026-10-09)\n- Work IQ MCP catalogue: \u003chttps://learn.microsoft.com/en-us/microsoft-agent-365/tooling-servers-overview\u003e (seen 2026-10-09)\n- app registration: \u003chttps://learn.microsoft.com/en-us/graph/auth-register-app-v2\u003e (seen 2026-10-09)\n- SDK overview: \u003chttps://learn.microsoft.com/en-us/graph/sdks/sdks-overview\u003e (seen 2026-10-09)\n- Microsoft 365 Developer Programme FAQ: \u003chttps://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq\u003e (seen 2026-10-09)\n- OneDrive service description (storage by plan): \u003chttps://learn.microsoft.com/en-us/office365/servicedescriptions/onedrive-for-business-service-description\u003e (seen 2026-10-09)\n- OneDrive plans page (refused our reader): \u003chttps://www.microsoft.com/en-us/microsoft-365/onedrive/compare-onedrive-plans\u003e (seen 2026-10-09)\n- OpenAPI for Graph v1.0: \u003chttps://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml\u003e (seen 2026-10-09)\n- service health page (JavaScript only): \u003chttps://status.cloud.microsoft/\u003e (seen 2026-10-09)\n- security.txt: \u003chttps://www.microsoft.com/.well-known/security.txt\u003e (seen 2026-10-09)\n- Microsoft 365 bounty programme: \u003chttps://www.microsoft.com/en-us/msrc/bounty-microsoft-cloud\u003e (seen 2026-10-09)\n- SOC 2 Type 2 for Office 365: \u003chttps://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2\u003e (seen 2026-10-09)\n- data retention, deletion and destruction in Microsoft 365: \u003chttps://learn.microsoft.com/en-us/compliance/assurance/assurance-data-retention-deletion-and-destruction-overview\u003e (seen 2026-10-09)\n- SharePoint data deletion: \u003chttps://learn.microsoft.com/en-us/sharepoint/sharepoint-data-deletion\u003e (seen 2026-10-09)\n- Microsoft 365 data residency: \u003chttps://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-overview\u003e (seen 2026-10-09)\n- Microsoft APIs terms of use: \u003chttps://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use\u003e (seen 2026-10-09)\n- privacy statement: \u003chttps://privacy.microsoft.com/en-us/privacystatement\u003e (seen 2026-10-09)\n- Online Services SLA page (script-drawn, no text read): \u003chttps://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services\u003e (seen 2026-10-09)\n- msgraph-sdk-python releases: \u003chttps://api.github.com/repos/microsoftgraph/msgraph-sdk-python/releases\u003e (seen 2026-10-09)\n- npm latest for @microsoft/microsoft-graph-client: \u003chttps://registry.npmjs.org/@microsoft/microsoft-graph-client/latest\u003e (seen 2026-10-09)\n- JavaScript client repository and token-leak fix: \u003chttps://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19\u003e (seen 2026-10-09)\n- RDAP for microsoft.com: \u003chttps://rdap.verisign.com/com/v1/domain/microsoft.com\u003e (seen 2026-10-09)\n\n## Who's behind it (provenance 85/100, checked 2026-10-09)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Microsoft Corporation | 20/20 |\n| Domain age | microsoft.com, registered 1991-05-02 (35 years) | 15/15 |\n| Endpoint on the vendor's domain | graph.microsoft.com | 15/15 |\n| Terms of service | read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points | 2.3/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects, and has 1 clause that costs points | 8/10 |\n| Status page | status.cloud.microsoft | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | published but past its Expires date | 5/10 |\n\nThe endpoint is on graph.microsoft.com. Upload and download URLs are issued on other Microsoft hosts. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.\n\nwww.microsoft.com/.well-known/security.txt still carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-09.\n\nThe Microsoft service health page at status.cloud.microsoft needs JavaScript to show anything.\n\nThe Microsoft APIs terms of use name Microsoft Corporation and were last updated in October 2025.\n\nThe Microsoft privacy statement was last updated in September 2026.\n\nRDAP for microsoft.com gives a registration date of 1991-05-02.\n\nThe Graph changelog feed's newest entry is dated 3 August 2026. The What's new page, updated 8 October 2026, lists later changes.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use), read 2026-10-08, dated 2025-10-01, states 5 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"Scrape, build databases or otherwise create copies of any data accessed or obtained using the Microsoft APIs, except as necessary to enable an intended usage scenario for your Application;\"\n- To know. Restricts benchmarking or competitive use (costs points). \"Use the Microsoft APIs, or any data obtained using the Microsoft APIs, to conduct performance testing of a Microsoft Offering unless expressly permitted by Microsoft\"\n- To know. Says the terms or the service can change without notice (costs points). \"WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU.\"\n- To know. Says access can be ended without notice or for any reason. \"We may suspend or immediately terminate these API Terms, any rights granted herein, and/or your license to the Microsoft APIs, in our sole discretion at any time, for any reason.\"\n- Gives the date it was last updated. Last updated 2025-10-01.\n- Not found in the text. Names the governing law or courts.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Recoverable damages are limited to direct damages of up to 5 US dollars in total. \"YOU AGREE THAT YOUR EXCLUSIVE REMEDY IS TO RECOVER, FROM MICROSOFT OR ANY AFFILIATES, RESELLERS, DISTRIBUTORS, SUPPLIERS (AND RESPECTIVE EMPLOYEES, SHAREHOLDERS, OR DIRECTORS) AND VENDORS, ONLY DIRECT DAMAGES UP TO USD $5.00 COLLECTIVELY.\"\n- Also in the text (2026-10-08). After a data breach involving the Microsoft APIs, the developer may make no public statement about it without Microsoft's prior written permission. \"You agree to refrain from making public statements (e.g., press, blogs, social media, bulletin boards, etc.) without prior written and express permission from Microsoft in each instance as it relates to the Microsoft APIs.\"\n- Also in the text (2026-10-08). The developer must allow Microsoft reasonable access to its application so Microsoft can monitor compliance with the API terms. \"You will permit Microsoft reasonable access to your Application for purposes of monitoring compliance with these API Terms.\"\n\n**Privacy policy** (https://privacy.microsoft.com/en-us/privacystatement), read 2026-10-08, dated 2026-09-01, states 8 of the 8 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). \"As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.\"\n- To know. Says it sells personal data or shares it for advertising. \"We also disclose personal data for digital advertising purposes.\"\n- Gives the date it was last updated. Last updated 2026-09-01.\n- Says how long data is kept. Names a period of 7 days.\n- Gives a privacy contact. Names a data protection officer.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict. \"In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control.\"\n- Also in the text (2026-10-08). Advertisements may be chosen from the current interaction, including Copilot conversations and files shared in them. \"Ads may be shown that relate to the current interaction you are having with us, such as your Copilot conversations (including files you share); your current location; transactions; product usage; search queries; or the content you’re viewing.\"\n- Also in the text (2026-10-08). Microsoft staff manually review some results of automated systems, including AI, against the source data. \"For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data.\"\n\n## Live (updated 2026-10-09 10:14 UTC)\n\n- Right now: up, HTTP 200, 3 ms, checked 2026-10-09 10:14 UTC (get on `https://graph.microsoft.com/v1.0`)\n- Uptime 24h 100.0% (28 probes) · 30 days 100.0% (28 probes) · p50 4 ms · p95 14 ms\n- Always current: https://www.anchorterminal.com/api/v1/live/onedrive-sharepoint.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Upload sessions resume after a dropped connection, report `nextExpectedRanges`, and accept `If-Match` and `@microsoft.graph.conflictBehavior` (fail by default)\n- `createLink` takes `expirationDateTime` and a scope of `anonymous`, `organization` or `users`, and returns the existing link when one of that type exists\n- Selected scopes limit an application to chosen sites, lists, folders or files, each with a read, write, owner or fullcontrol role\n- SharePoint publishes throttling numbers, with 1,250 to 6,250 resource units a minute per app per tenant and a stated cost of 1, 2 or 5 units a request\n- DELETE moves an item to the recycle bin, and permanent removal is a separate `permanentDelete` call\n\n## Weaknesses\n\n- Link and scope types are plain strings in the OpenAPI, and path addressing such as `/root:/folder/file.txt:` is absent from it\n- Password-protected links and `embed` links work only on personal OneDrive, and an administrator can switch anonymous links off\n- The status page at status.cloud.microsoft shows nothing without JavaScript, so no incident history could be read\n- The npm client is 3.0.7 from September 2023. A token-leak fix merged on 16 June 2026 set the version to 3.0.8 and isn't published\n- No injection guidance was found in the files reference pages, though file names and contents written by other people reach the caller\n\n## Before you call it (notes for agents)\n\n1. Use PUT `/content` only up to 250 MB. Above 10 MiB Microsoft advises `createUploadSession`, with fragments in multiples of 320 KiB and under 60 MiB each\n2. Send the bearer token on the `createUploadSession` POST only. The PUT calls to `uploadUrl` can return 401 if an `Authorization` header is included\n3. Set `expirationDateTime` and `scope` on `createLink`. Without a scope the tenant's default link type is created, which may be wider than intended\n4. Follow the 302 from GET `/content` straight away. Pre-authenticated download URLs can expire within minutes and need no `Authorization` header\n5. Wait for `Retry-After` on 429 and 503. Throttled requests still count against the limits, and continued overuse can get the app blocked\n\n## Connect\n\nFirst request:\n\n```bash\ncurl \"https://graph.microsoft.com/v1.0/me/drive/root/children?\\$select=id,name,size\u0026\\$top=50\" \\\n  -H \"Authorization: Bearer $MS_GRAPH_TOKEN\"\n```\n\nThrough letme (picks today, calling later): https://letme.dev/onedrive-sharepoint. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Google Drive API + MCP | A | 79.6 | 11 | storage.drive, storage.share | no | https://www.anchorterminal.com/tools/google-drive-api.md |\n| Amazon S3 | BB | 77.9 | 15 | storage.presigned, storage.share | no | https://www.anchorterminal.com/tools/amazon-s3.md |\n| Cloudflare R2 | BB | 77.1 | 22 | storage.presigned, storage.share | no | https://www.anchorterminal.com/tools/cloudflare-r2.md |\n| Azure Blob Storage | BB | 75.7 | 40 | storage.presigned, storage.share | no | https://www.anchorterminal.com/tools/azure-blob-storage.md |\n| Backblaze B2 | BB | 75.3 | 48 | storage.presigned, storage.share | no | https://www.anchorterminal.com/tools/backblaze-b2.md |\n| Box API + MCP | B | 69.4 | 177 | storage.drive, storage.share | no | https://www.anchorterminal.com/tools/box-api.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The same endpoints address a user's OneDrive (`/me/drive`), another user's, a group library, a SharePoint site library (`/sites/{site-id}/drive`) and shared items (`/shares/{share-id}`) (source: \u003chttps://learn.microsoft.com/en-us/graph/api/resources/onedrive\u003e)\n- PUT `/content` takes files up to 250 MB. Upload sessions take larger files in sequential byte ranges, each a multiple of 320 KiB and under 60 MiB (source: \u003chttps://learn.microsoft.com/en-us/graph/api/driveitem-createuploadsession\u003e)\n- `createLink` accepts `type` (view, edit, embed), `scope` (`anonymous`, `organization`, `users`), `expirationDateTime` and, on personal OneDrive only, `password` (source: \u003chttps://learn.microsoft.com/en-us/graph/api/driveitem-createlink\u003e)\n- SharePoint limits are counted in resource units, 1 for a single-item read or download, 2 for a list, create, update, delete or upload, and 5 for any permission operation (source: \u003chttps://learn.microsoft.com/en-us/sharepoint/dev/general-development/how-to-avoid-getting-throttled-or-blocked-in-sharepoint-online\u003e)\n- The only metered Graph API is `assignSensitivityLabel` for SharePoint and OneDrive for work or school, at $0.00185 a call (source: \u003chttps://learn.microsoft.com/en-us/graph/metered-api-list\u003e)\n- Work IQ OneDrive and Work IQ SharePoint MCP servers are in preview and need a Microsoft 365 Copilot licence. This listing grades the REST API (source: \u003chttps://learn.microsoft.com/en-us/microsoft-agent-365/tooling-servers-overview\u003e)\n- The OpenAPI for Graph v1.0 has 1,516 paths under `/drives`, 172 of them outside the workbook API, and declares `retainInheritedPermissions` with a default of false where the reference page says true (source: \u003chttps://raw.githubusercontent.com/microsoftgraph/msgraph-metadata/master/openapi/v1.0/openapi.yaml\u003e)\n- Change notifications cover the root folder of a work OneDrive or any folder of a personal one, and `delta` returns changes since a saved token (source: \u003chttps://learn.microsoft.com/en-us/graph/api/subscription-post-subscriptions\u003e)\n\n## Compare\n\n- [Amazon S3 vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/amazon-s3-vs-onedrive-sharepoint.md): BB 77.9 vs B 65.3\n- [Backblaze B2 vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/backblaze-b2-vs-onedrive-sharepoint.md): BB 75.3 vs B 65.3\n- [Cloudflare R2 vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/cloudflare-r2-vs-onedrive-sharepoint.md): BB 77.1 vs B 65.3\n- [OneDrive and SharePoint files (Microsoft Graph) vs Tigris](https://www.anchorterminal.com/compare/onedrive-sharepoint-vs-tigris.md): B 65.3 vs E 44.4\n- [Box API + MCP vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/box-api-vs-onedrive-sharepoint.md): B 69.4 vs B 65.3\n- [Dropbox API + MCP vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/dropbox-api-vs-onedrive-sharepoint.md): B 68.2 vs B 65.3\n- [Google Drive API + MCP vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/google-drive-api-vs-onedrive-sharepoint.md): A 79.6 vs B 65.3\n- [Azure Blob Storage vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/azure-blob-storage-vs-onedrive-sharepoint.md): BB 75.7 vs B 65.3\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on microsoft.com or one of its subdomains, or the README of github.com/microsoftgraph/msgraph-sdk-python. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"onedrive-sharepoint\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/onedrive-sharepoint\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/onedrive-sharepoint.svg\" alt=\"OneDrive and SharePoint files (Microsoft Graph) on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![OneDrive and SharePoint files (Microsoft Graph) on Anchor Terminal](https://www.anchorterminal.com/badges/onedrive-sharepoint.svg)](https://www.anchorterminal.com/tools/onedrive-sharepoint)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/onedrive-sharepoint\"\u003eOneDrive and SharePoint files (Microsoft Graph) on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say OneDrive and SharePoint files (Microsoft Graph) is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/onedrive-sharepoint-dark.png\n- Light: https://www.anchorterminal.com/assets/share/onedrive-sharepoint-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "File storage \u0026 sharing",
        "url": "https://www.anchorterminal.com/categories/file-storage"
      },
      {
        "name": "OneDrive and SharePoint files (Microsoft Graph)",
        "url": ""
      }
    ],
    "description": "Drive and driveItem endpoints of Microsoft Graph for files in OneDrive, OneDrive for work or school and SharePoint document libraries. Calls upload, download, list, search, share by link or invitation, and delete files and folders.",
    "facts": [
      "rank #296 of 842",
      "OAuth auth",
      "0 desk reviews"
    ],
    "h1": "OneDrive and SharePoint files (Microsoft Graph)",
    "image": "https://www.anchorterminal.com/assets/og/tools-onedrive-sharepoint.png",
    "path": "/tools/onedrive-sharepoint",
    "published": "2026-10-01",
    "section": "tools",
    "title": "OneDrive and SharePoint files (Microsoft Graph), grade B (65.3/100)",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/onedrive-sharepoint"
  },
  "tokens": {
    "markdown": 10000,
    "slim": 1680
  },
  "version": 1
}
