# OneDrive and SharePoint files (Microsoft Graph) > Drive and driveItem endpoints of Microsoft Graph for files in OneDrive, OneDrive for work or school and SharePoint document libraries. Calls upload, download, list, search, share by link or invitation, and delete files and folders. - Canonical: https://www.anchorterminal.com/tools/onedrive-sharepoint - Markdown: https://www.anchorterminal.com/tools/onedrive-sharepoint.md (~10,000 tokens) - Slim: https://www.anchorterminal.com/tools/onedrive-sharepoint.min.md (~1,680 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/onedrive-sharepoint.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade B · 65.3/100 · rank #296 of 842 · #8 in File storage & sharing · not agent-ready · confidence medium** More from Microsoft, listed separately because each is its own product: [Microsoft Foundry fine-tuning (Azure OpenAI)](https://www.anchorterminal.com/tools/azure-foundry-fine-tuning.md) (Fine-tuning), [Azure AI Content Safety (Prompt Shields)](https://www.anchorterminal.com/tools/azure-ai-content-safety.md) (Guardrails & safety filters), [Azure AI Speech speech-to-text](https://www.anchorterminal.com/tools/azure-speech-to-text.md) (Speech-to-text), [Azure AI Speech text-to-speech](https://www.anchorterminal.com/tools/azure-text-to-speech.md) (Text-to-speech), [Microsoft Agent Framework](https://www.anchorterminal.com/tools/microsoft-agent-framework.md) (Agent frameworks & SDKs), [Microsoft Execution Containers](https://www.anchorterminal.com/tools/microsoft-execution-containers.md) (Code execution sandboxes), [Microsoft Entra Agent ID](https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md) (Agent auth & delegated access), [Azure Key Vault](https://www.anchorterminal.com/tools/azure-key-vault.md) (Secrets & credential vaults), [Azure Document Intelligence](https://www.anchorterminal.com/tools/azure-document-intelligence.md) (Document parsing & extraction), [Azure DevOps MCP Server](https://www.anchorterminal.com/tools/azure-devops-mcp.md) (Code & developer platforms), [Microsoft Learn MCP Server](https://www.anchorterminal.com/tools/microsoft-learn-mcp.md) (Code & developer platforms), [Playwright MCP](https://www.anchorterminal.com/tools/playwright-mcp.md) (Browser automation), [Azure MCP Server](https://www.anchorterminal.com/tools/azure-mcp.md) (Cloud & infrastructure), [Azure Maps](https://www.anchorterminal.com/tools/azure-maps.md) (Maps, geocoding & places), [Azure Translator](https://www.anchorterminal.com/tools/azure-translator.md) (Translation), [Microsoft Graph Calendar API](https://www.anchorterminal.com/tools/microsoft-graph-calendar.md) (Calendars & scheduling), [Azure Blob Storage](https://www.anchorterminal.com/tools/azure-blob-storage.md) (File storage & sharing), [Microsoft Teams (Microsoft Graph)](https://www.anchorterminal.com/tools/microsoft-teams.md) (Work & productivity), [Microsoft Dynamics 365 Sales](https://www.anchorterminal.com/tools/dynamics-365-sales.md) (CRM & customer platforms), [Microsoft Power Automate](https://www.anchorterminal.com/tools/power-automate.md) (Workflow automation), [Foundry Local](https://www.anchorterminal.com/tools/foundry-local.md) (Local AI), [Microsoft Advertising API](https://www.anchorterminal.com/tools/microsoft-advertising-api.md) (Advertising & campaign operations), [Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/tools/microsoft-excel-graph.md) (Spreadsheets & operational tables), [Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/tools/outlook-mail-graph.md) (Mailbox access). ## Assessment One REST surface covers personal OneDrive, work OneDrive and SharePoint libraries, with resumable uploads, sharing links that take an expiry date and per-file Selected permissions. The status page needs JavaScript, an app must be registered and consented to by a person, and the JavaScript client on npm lacks a token-leak fix merged in June 2026. ## Facts | Field | Value | | --- | --- | | Vendor | Microsoft (https://learn.microsoft.com/en-us/graph/onedrive-concept-overview) | | Kind | HTTP API | | Category | File storage & sharing (https://www.anchorterminal.com/categories/file-storage) | | Transport | HTTP | | Endpoint | `https://graph.microsoft.com/v1.0` | | Auth | OAuth · OAuth 2.0 tokens from Microsoft Entra ID, after a person registers an app. Registration is self-serve, with no partner or sales approval. Delegated permissions run from Files.Read to Files.ReadWrite.All and work for personal Microsoft accounts and work or school accounts. Application permissions (Files.Read.All, Files.ReadWrite.All, Sites.ReadWrite.All) need an administrator's consent. Selected scopes limit an app to chosen sites, lists, folders or files. | | Pricing | Your plan (Your plan) · File calls carry no per-call charge. Microsoft's list of metered Graph APIs names only `assignSensitivityLabel`, at $0.00185 a call (https://learn.microsoft.com/en-us/graph/metered-api-list). Storage comes from the account's own OneDrive or Microsoft 365 plan, 1 TB a user on the Business and E3 or E5 plans per the service description. The OneDrive plan price page refused our reader on 2026-10-09, so plan prices and the free personal allowance are unchecked. A free Microsoft 365 E5 developer sandbox is limited to Visual Studio subscribers and other qualifying members (https://learn.microsoft.com/en-us/office/developer-program/microsoft-365-developer-program-faq). | | x402 | No · No x402, MPP or L402 in the files documentation or the metered API list (checked 2026-10-09). | | Licence | MIT (SDKs) | | Packages | npm: `@microsoft/microsoft-graph-client`; pypi: `msgraph-sdk` | | Source | https://github.com/microsoftgraph/msgraph-sdk-python | | Docs | https://learn.microsoft.com/en-us/graph/api/resources/onedrive | | llms.txt | not found | | Last release | 2026-10-06 | | GitHub stars | 633 (as of 2026-10-09) | | npm downloads / week | 2,882,852 | | PyPI downloads / week | 1,578,201 | | Free tier | No charge for file calls. Storage is the account's own OneDrive or Microsoft 365 allowance. Plan prices unread on 2026-10-09 | | Drives | Personal OneDrive, OneDrive for work or school, SharePoint document libraries, group libraries and shared items, on the same endpoints | | Uploads | PUT `/content` up to 250 MB. Upload sessions above that, resumable, in fragments that are multiples of 320 KiB and under 60 MiB, 5 to 10 MiB advised | | Downloads | GET `/content` answers 302 to a pre-authenticated URL that can expire within minutes | | Sharing | `createLink` with view, edit or embed type, anonymous, organisation or named-user scope and `expirationDateTime`. `invite` grants read or write to recipients. Passwords on personal OneDrive only | | Deleting | DELETE sends an item to the recycle bin (93 days on SharePoint). `permanentDelete` removes it for good | | Rate limits | Per app per tenant 1,250 to 6,250 resource units a minute and 1,200,000 to 6,000,000 a day by licence count, 400 GB of ingress and of egress an hour. Per user 3,000 requests per 5 minutes | | Paging | 200 items a page by default, `@odata.nextLink`, with `$top`, `$select`, `$orderby`, `$expand` and `$skipToken` | | Permissions | Files.Read, Files.ReadWrite, Files.Read.All, Files.ReadWrite.All, Sites.Read.All, Sites.ReadWrite.All, plus Sites.Selected and Files.SelectedOperations.Selected | | Change events | `delta` with a saved token, and webhook subscriptions on a drive's root folder (any folder on personal OneDrive) | | MCP server | Work IQ OneDrive and Work IQ SharePoint, preview, Microsoft 365 Copilot licence needed. Not graded here | | SDKs | C#, Java, Go, PHP, Python (msgraph-sdk 1.64.0, 6 October 2026), PowerShell and JavaScript (npm 3.0.7 from September 2023) | | National clouds | Global, US Government L4 and L5, and China operated by 21Vianet | | Capabilities | storage.drive, storage.share, storage.presigned | | Tags | hosted, official, oauth, openapi, typescript, python, enterprise | | JSON | https://www.anchorterminal.com/api/v1/tools/onedrive-sharepoint.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 64 | 12.8 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 89 | 14.5 | | Agent ergonomics | 13% | 16.2 | 84 | 13.7 | | Security & auth | 14% | 17.5 | 73 | 12.8 | | Payments & pricing | 10% | 12.5 | 20 | 2.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 75 | 6.6 | | Transparency & trust (editorial 65, provenance 85) | 7% | 8.8 | 75 | 6.6 | | Negative events | up to −15 | up to −15 | 2026-06-16: a fix for a token leak through URL userinfo host confusion was merged into msgraph-sdk-javascript and the version set to 3.0.8, but npm still served 3.0.7 on 9 October 2026 and the repository's changelog doesn't mention it. Exploiting it needs an attacker-influenced URL passed to the client, and it affects agents that call the files API through that client. The Excel and Outlook listings took the same 4 points (https://github.com/microsoftgraph/msgraph-sdk-javascript/commit/5438ae90f50ef15d3656f0cf9c5485deee351f19, https://registry.npmjs.org/@microsoft/microsoft-graph-client/latest) | -4 | | **Total** | | | | **65.3 → B** | ### Why each score - Reliability 64: Graded on the v1.0 REST API. A public Microsoft service health page at status.cloud.microsoft (20). It shows nothing without JavaScript, so we couldn't read components or history (5). SharePoint and OneDrive limits are published in resource units, 1,250 to 6,250 a minute and 1,200,000 to 6,000,000 a day per app per tenant by licence count, 3,000 requests per 5 minutes a user, and 400 GB of ingress and of egress an hour per app (15). 429 and 503 responses carry `Retry-After`, upload sessions resume from `nextExpectedRanges` with backoff advice for 5xx errors, and `If-Match` and `conflictBehavior` guard overwrites. There is no idempotency key on `invite` or folder creation (14 of 15). The Online Services SLA page is drawn by script and gave us no text, so no SLA is counted (0). The file endpoints are generally available on v1.0 (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 89: OpenAPI 3.0.4 for all of Graph v1.0 in microsoftgraph/msgraph-metadata, with 1,516 paths under `/drives`, 172 of them outside the workbook API (25). learn.microsoft.com answers 404 for llms.txt, but every page we asked for with `Accept: text/markdown` came back as Markdown (10). Reference pages state the purpose of each call, list permissions from least to most privileged and say which options work only on personal OneDrive. The upload session page gives Sites.ReadWrite.All as the least privileged application permission where the small-upload page gives Files.ReadWrite.All, and the overview page is dated March 2024 (16). `createLink` declares `type` and `scope` as plain strings with no enumeration, `conflictBehavior` is an annotation outside the schema, path addressing is absent from the OpenAPI, and `retainInheritedPermissions` defaults to false there and to true on the reference page (9). An HTTP example and SDK snippets on each page, a status code table, and upload-specific handling for 404, 409 and 416 (14). v1.0 and beta, a dated changelog and a monthly What's new page (15). - Agent ergonomics 84: `$select` trims driveItem properties, a list returns 200 items a page by default, and responses without `$select` carry a tip to use it. The whole-Graph OpenAPI is 44 MB (21). `@odata.nextLink` paging with `$top`, `$skipToken`, `$orderby` and `$expand`, a search call and `delta` for changes since a token (20). Errors carry a code, a message and a request ID, the upload page says what to do on 404, 409, 416 and 5xx, and `delta` returns two named resync codes on 410 (17). Uploads resume, `If-Match` and `if-none-match` guard writes, `conflictBehavior` fails by default, `createLink` returns the existing link of the same type and DELETE goes to the recycle bin. No idempotency key (14). Items are addressed by ID or by path with one bearer token, but upload fragments must be multiples of 320 KiB and the token must be left off the fragment PUT. Official SDKs in C#, Java, Go, PHP, Python, PowerShell and JavaScript, the npm JavaScript client dating from September 2023 (12). - Security & auth 73: OAuth 2.0 through Microsoft Entra ID with delegated and application permissions from Files.Read to Sites.ReadWrite.All, revocable consent, and Selected scopes that hold an app to chosen sites, lists, folders or files. Download and upload URLs are pre-authenticated and short-lived, which we read as designed capability links and not as a credential in a URL (30). Files.Read for reading, Selected scopes with read, write, owner and fullcontrol roles, DELETE to the recycle bin and anonymous links that an administrator can disable. Nothing asks for confirmation before `permanentDelete` or an anonymous link (17). File names and contents written by other people reach the caller, and no injection guidance was found in the files reference pages (0). Graph activity logs record app, user, request URI and scopes for every request, but need Entra ID P1 or P2 and an Azure log destination (12). The Microsoft 365 bounty names SharePoint Online and OneDrive at $1,250 to $19,500, with a coordinated disclosure policy and an Office 365 SOC 2 Type 2 report. microsoft.com's security.txt passed its Expires date on 23 September 2026, and a token-leak fix in the JavaScript client is unreleased on npm (14). - Payments & pricing 20: No x402, MPP or L402 (0). File calls aren't on Microsoft's metered API list, whose one entry is `assignSensitivityLabel` at $0.00185 a call, but storage comes from a OneDrive or Microsoft 365 plan and the plan price page refused our reader today (10). The reference pages list delegated permissions for personal Microsoft accounts, so no Microsoft 365 licence is needed to call the API, but we couldn't read the size of the free personal allowance, and the free E5 developer sandbox is limited to Visual Studio subscribers and other qualifying members (10). A person registers an app in Entra and signs in to consent (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 75: msgraph-sdk-python v1.64.0 on 6 October 2026. The What's new page, updated 8 October 2026, lists generally available Files changes for September and August 2026, and the changelog feed's last v1.0 Files entry is 29 July 2026 (30). Five Python SDK releases since 22 July 2026, v1.60.0 to v1.64.0 (20). A public changelog, a What's new page and SDK issue trackers. The changelog feed stops at 3 August 2026, an issue about drive content returning None on the Python SDK has had no reply since 21 September 2026, and a security fix merged into the JavaScript client on 16 June 2026 hasn't reached npm (9 of 15). Current SDKs in most languages, with the JavaScript client the exception at 3.0.7 (10). Active releases on the Python package, none on the JavaScript one (6). - Transparency & trust 75: Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDKs (15). Microsoft's data handling page for Microsoft 365 gives at most 30 days after active deletion and 180 days after a subscription ends for customer content, the SharePoint deletion page gives 93 days in the recycle bin and 14 further days of backups, and the privacy statement was updated in September 2026. We didn't read the data protection addendum (22). The Graph policy is at least 24 months' notice before a generally available API or version is removed, while the API terms reserve the right to change or discontinue any API with or without notice (18). Data residency for Microsoft 365 is documented by tenant geography. The sub-processor list sits on the Service Trust Portal, which we didn't read (10). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/onedrive-sharepoint.md (JSON https://www.anchorterminal.com/fixes/onedrive-sharepoint.json) ### What we couldn't check - unchecked: status page components and incident history, which need JavaScript - unchecked: OneDrive and Microsoft 365 plan prices and the free personal storage allowance, because the plans page refused our reader as an automated process - unchecked: the Online Services SLA document, which is drawn by script, plus the data protection addendum and the sub-processor list on the Service Trust Portal - unchecked: the advisory list of msgraph-sdk-javascript, because the GitHub API was rate-limited. The fix commit and the unpublished 3.0.8 were confirmed from a clone and from npm - unchecked: pypi.org answered the msgraph-sdk project page with a client challenge, and its robots.txt disallows the JSON API, so the Python release dates come from the GitHub releases list - The maximum file size for an upload session isn't stated on the upload page - Whether Microsoft 365 audit logs record third-party file calls per app wasn't checked. Only Graph activity logs were read - First release date of the files API, not established - The lead was right on vendor, interface and docs. Its product URL, the OneDrive marketing page, wasn't used because www.microsoft.com refused our reader on the plans page ### Sources - files overview in the v1.0 reference: (seen 2026-10-09) - OneDrive concept overview: (seen 2026-10-09) - driveItem resource: (seen 2026-10-09) - small upload (PUT content, 250 MB): (seen 2026-10-09) - upload sessions: (seen 2026-10-09) - download and pre-authenticated URLs: (seen 2026-10-09) - list children and paging: (seen 2026-10-09) - createLink (types, scopes, expiry): (seen 2026-10-09) - invite (permissions and invitations): (seen 2026-10-09) - permission resource: (seen 2026-10-09) - delete to recycle bin: (seen 2026-10-09) - permanent delete: (seen 2026-10-09) - delta: (seen 2026-10-09) - change notification subscriptions: (seen 2026-10-09) - SharePoint and OneDrive throttling limits: (seen 2026-10-09) - Graph throttling limits: (seen 2026-10-09) - throttling guidance: (seen 2026-10-09) - error responses: (seen 2026-10-09) - best practices: (seen 2026-10-09) - Selected permissions for OneDrive and SharePoint: (seen 2026-10-09) - Graph activity logs: (seen 2026-10-09) - metered APIs list: (seen 2026-10-09) - versioning, support and breaking change policy: (seen 2026-10-09) - What's new in Microsoft Graph: (seen 2026-10-09) - Graph changelog feed: (seen 2026-10-09) - Work IQ MCP catalogue: (seen 2026-10-09) - app registration: (seen 2026-10-09) - SDK overview: (seen 2026-10-09) - Microsoft 365 Developer Programme FAQ: (seen 2026-10-09) - OneDrive service description (storage by plan): (seen 2026-10-09) - OneDrive plans page (refused our reader): (seen 2026-10-09) - OpenAPI for Graph v1.0: (seen 2026-10-09) - service health page (JavaScript only): (seen 2026-10-09) - security.txt: (seen 2026-10-09) - Microsoft 365 bounty programme: (seen 2026-10-09) - SOC 2 Type 2 for Office 365: (seen 2026-10-09) - data retention, deletion and destruction in Microsoft 365: (seen 2026-10-09) - SharePoint data deletion: (seen 2026-10-09) - Microsoft 365 data residency: (seen 2026-10-09) - Microsoft APIs terms of use: (seen 2026-10-09) - privacy statement: (seen 2026-10-09) - Online Services SLA page (script-drawn, no text read): (seen 2026-10-09) - msgraph-sdk-python releases: (seen 2026-10-09) - npm latest for @microsoft/microsoft-graph-client: (seen 2026-10-09) - JavaScript client repository and token-leak fix: (seen 2026-10-09) - RDAP for microsoft.com: (seen 2026-10-09) ## Who's behind it (provenance 85/100, checked 2026-10-09) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Microsoft Corporation | 20/20 | | Domain age | microsoft.com, registered 1991-05-02 (35 years) | 15/15 | | Endpoint on the vendor's domain | graph.microsoft.com | 15/15 | | Terms of service | read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points | 2.3/10 | | Privacy policy | read, states 8 of the 8 things a reader expects, and has 1 clause that costs points | 8/10 | | Status page | status.cloud.microsoft | 10/10 | | Changelog | published | 10/10 | | security.txt | published but past its Expires date | 5/10 | The endpoint is on graph.microsoft.com. Upload and download URLs are issued on other Microsoft hosts. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23. www.microsoft.com/.well-known/security.txt still carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-09. The Microsoft service health page at status.cloud.microsoft needs JavaScript to show anything. The Microsoft APIs terms of use name Microsoft Corporation and were last updated in October 2025. The Microsoft privacy statement was last updated in September 2026. RDAP for microsoft.com gives a registration date of 1991-05-02. The Graph changelog feed's newest entry is dated 3 August 2026. The What's new page, updated 8 October 2026, lists later changes. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use), read 2026-10-08, dated 2025-10-01, states 5 of the 7 things a reader expects. - To know. Restricts automated access (costs points). "Scrape, build databases or otherwise create copies of any data accessed or obtained using the Microsoft APIs, except as necessary to enable an intended usage scenario for your Application;" - To know. Restricts benchmarking or competitive use (costs points). "Use the Microsoft APIs, or any data obtained using the Microsoft APIs, to conduct performance testing of a Microsoft Offering unless expressly permitted by Microsoft" - To know. Says the terms or the service can change without notice (costs points). "WE MAY MODIFY THESE API TERMS AT ANY TIME, WITH OR WITHOUT PRIOR NOTICE TO YOU." - To know. Says access can be ended without notice or for any reason. "We may suspend or immediately terminate these API Terms, any rights granted herein, and/or your license to the Microsoft APIs, in our sole discretion at any time, for any reason." - Gives the date it was last updated. Last updated 2025-10-01. - Not found in the text. Names the governing law or courts. - Says how changes to the terms are announced. Says it gives notice of a change. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). Recoverable damages are limited to direct damages of up to 5 US dollars in total. "YOU AGREE THAT YOUR EXCLUSIVE REMEDY IS TO RECOVER, FROM MICROSOFT OR ANY AFFILIATES, RESELLERS, DISTRIBUTORS, SUPPLIERS (AND RESPECTIVE EMPLOYEES, SHAREHOLDERS, OR DIRECTORS) AND VENDORS, ONLY DIRECT DAMAGES UP TO USD $5.00 COLLECTIVELY." - Also in the text (2026-10-08). After a data breach involving the Microsoft APIs, the developer may make no public statement about it without Microsoft's prior written permission. "You agree to refrain from making public statements (e.g., press, blogs, social media, bulletin boards, etc.) without prior written and express permission from Microsoft in each instance as it relates to the Microsoft APIs." - Also in the text (2026-10-08). The developer must allow Microsoft reasonable access to its application so Microsoft can monitor compliance with the API terms. "You will permit Microsoft reasonable access to your Application for purposes of monitoring compliance with these API Terms." **Privacy policy** (https://privacy.microsoft.com/en-us/privacystatement), read 2026-10-08, dated 2026-09-01, states 8 of the 8 things a reader expects. - To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models." - To know. Says it sells personal data or shares it for advertising. "We also disclose personal data for digital advertising purposes." - Gives the date it was last updated. Last updated 2026-09-01. - Says how long data is kept. Names a period of 7 days. - Gives a privacy contact. Names a data protection officer. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict. "In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control." - Also in the text (2026-10-08). Advertisements may be chosen from the current interaction, including Copilot conversations and files shared in them. "Ads may be shown that relate to the current interaction you are having with us, such as your Copilot conversations (including files you share); your current location; transactions; product usage; search queries; or the content you’re viewing." - Also in the text (2026-10-08). Microsoft staff manually review some results of automated systems, including AI, against the source data. "For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data." ## Live (updated 2026-10-09 09:26 UTC) - Right now: up, HTTP 200, 5 ms, checked 2026-10-09 09:26 UTC (get on `https://graph.microsoft.com/v1.0`) - Uptime 24h 100.0% (20 probes) · 30 days 100.0% (20 probes) · p50 4 ms · p95 14 ms - Always current: https://www.anchorterminal.com/api/v1/live/onedrive-sharepoint.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - Upload sessions resume after a dropped connection, report `nextExpectedRanges`, and accept `If-Match` and `@microsoft.graph.conflictBehavior` (fail by default) - `createLink` takes `expirationDateTime` and a scope of `anonymous`, `organization` or `users`, and returns the existing link when one of that type exists - Selected scopes limit an application to chosen sites, lists, folders or files, each with a read, write, owner or fullcontrol role - SharePoint publishes throttling numbers, with 1,250 to 6,250 resource units a minute per app per tenant and a stated cost of 1, 2 or 5 units a request - DELETE moves an item to the recycle bin, and permanent removal is a separate `permanentDelete` call ## Weaknesses - Link and scope types are plain strings in the OpenAPI, and path addressing such as `/root:/folder/file.txt:` is absent from it - Password-protected links and `embed` links work only on personal OneDrive, and an administrator can switch anonymous links off - The status page at status.cloud.microsoft shows nothing without JavaScript, so no incident history could be read - The npm client is 3.0.7 from September 2023. A token-leak fix merged on 16 June 2026 set the version to 3.0.8 and isn't published - No injection guidance was found in the files reference pages, though file names and contents written by other people reach the caller ## Before you call it (notes for agents) 1. Use PUT `/content` only up to 250 MB. Above 10 MiB Microsoft advises `createUploadSession`, with fragments in multiples of 320 KiB and under 60 MiB each 2. Send the bearer token on the `createUploadSession` POST only. The PUT calls to `uploadUrl` can return 401 if an `Authorization` header is included 3. Set `expirationDateTime` and `scope` on `createLink`. Without a scope the tenant's default link type is created, which may be wider than intended 4. Follow the 302 from GET `/content` straight away. Pre-authenticated download URLs can expire within minutes and need no `Authorization` header 5. Wait for `Retry-After` on 429 and 503. Throttled requests still count against the limits, and continued overuse can get the app blocked ## Connect First request: ```bash curl "https://graph.microsoft.com/v1.0/me/drive/root/children?\$select=id,name,size&\$top=50" \ -H "Authorization: Bearer $MS_GRAPH_TOKEN" ``` Through letme (picks today, calling later): https://letme.dev/onedrive-sharepoint. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Google Drive API + MCP | A | 79.6 | 11 | storage.drive, storage.share | no | https://www.anchorterminal.com/tools/google-drive-api.md | | Amazon S3 | BB | 77.9 | 15 | storage.presigned, storage.share | no | https://www.anchorterminal.com/tools/amazon-s3.md | | Cloudflare R2 | BB | 77.1 | 22 | storage.presigned, storage.share | no | https://www.anchorterminal.com/tools/cloudflare-r2.md | | Azure Blob Storage | BB | 75.7 | 40 | storage.presigned, storage.share | no | https://www.anchorterminal.com/tools/azure-blob-storage.md | | Backblaze B2 | BB | 75.3 | 48 | storage.presigned, storage.share | no | https://www.anchorterminal.com/tools/backblaze-b2.md | | Box API + MCP | B | 69.4 | 177 | storage.drive, storage.share | no | https://www.anchorterminal.com/tools/box-api.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The same endpoints address a user's OneDrive (`/me/drive`), another user's, a group library, a SharePoint site library (`/sites/{site-id}/drive`) and shared items (`/shares/{share-id}`) (source: ) - PUT `/content` takes files up to 250 MB. Upload sessions take larger files in sequential byte ranges, each a multiple of 320 KiB and under 60 MiB (source: ) - `createLink` accepts `type` (view, edit, embed), `scope` (`anonymous`, `organization`, `users`), `expirationDateTime` and, on personal OneDrive only, `password` (source: ) - SharePoint limits are counted in resource units, 1 for a single-item read or download, 2 for a list, create, update, delete or upload, and 5 for any permission operation (source: ) - The only metered Graph API is `assignSensitivityLabel` for SharePoint and OneDrive for work or school, at $0.00185 a call (source: ) - Work IQ OneDrive and Work IQ SharePoint MCP servers are in preview and need a Microsoft 365 Copilot licence. This listing grades the REST API (source: ) - The OpenAPI for Graph v1.0 has 1,516 paths under `/drives`, 172 of them outside the workbook API, and declares `retainInheritedPermissions` with a default of false where the reference page says true (source: ) - Change notifications cover the root folder of a work OneDrive or any folder of a personal one, and `delta` returns changes since a saved token (source: ) ## Compare - [Amazon S3 vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/amazon-s3-vs-onedrive-sharepoint.md): BB 77.9 vs B 65.3 - [Backblaze B2 vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/backblaze-b2-vs-onedrive-sharepoint.md): BB 75.3 vs B 65.3 - [Cloudflare R2 vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/cloudflare-r2-vs-onedrive-sharepoint.md): BB 77.1 vs B 65.3 - [OneDrive and SharePoint files (Microsoft Graph) vs Tigris](https://www.anchorterminal.com/compare/onedrive-sharepoint-vs-tigris.md): B 65.3 vs E 44.4 - [Box API + MCP vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/box-api-vs-onedrive-sharepoint.md): B 69.4 vs B 65.3 - [Dropbox API + MCP vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/dropbox-api-vs-onedrive-sharepoint.md): B 68.2 vs B 65.3 - [Google Drive API + MCP vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/google-drive-api-vs-onedrive-sharepoint.md): A 79.6 vs B 65.3 - [Azure Blob Storage vs OneDrive and SharePoint files (Microsoft Graph)](https://www.anchorterminal.com/compare/azure-blob-storage-vs-onedrive-sharepoint.md): BB 75.7 vs B 65.3 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on microsoft.com or one of its subdomains, or the README of github.com/microsoftgraph/msgraph-sdk-python. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "onedrive-sharepoint", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html OneDrive and SharePoint files (Microsoft Graph) on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![OneDrive and SharePoint files (Microsoft Graph) on Anchor Terminal](https://www.anchorterminal.com/badges/onedrive-sharepoint.svg)](https://www.anchorterminal.com/tools/onedrive-sharepoint) ``` Plain link: ```html OneDrive and SharePoint files (Microsoft Graph) on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say OneDrive and SharePoint files (Microsoft Graph) is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/onedrive-sharepoint-dark.png - Light: https://www.anchorterminal.com/assets/share/onedrive-sharepoint-light.png