# OneDrive and SharePoint files (Microsoft Graph) (slim) > Drive and driveItem endpoints of Microsoft Graph for files in OneDrive, OneDrive for work or school and SharePoint document libraries. Calls upload, download, list, search, share by link or invitation, and delete files and folders. - Full: https://www.anchorterminal.com/tools/onedrive-sharepoint.md (~10,000 tokens) · this version ~1,680 tokens · JSON https://www.anchorterminal.com/tools/onedrive-sharepoint.json · canonical https://www.anchorterminal.com/tools/onedrive-sharepoint - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **B · 65.3/100 · rank #296 of 842 · #8 in File storage & sharing · not agent-ready · confidence medium** Assessment: One REST surface covers personal OneDrive, work OneDrive and SharePoint libraries, with resumable uploads, sharing links that take an expiry date and per-file Selected permissions. The status page needs JavaScript, an app must be registered and consented to by a person, and the JavaScript client on npm lacks a token-leak fix merged in June 2026. ## Facts - Kind: HTTP API · vendor: Microsoft · category: File storage & sharing · legal entity: Microsoft Corporation · provenance 85/100 - Endpoint: `https://graph.microsoft.com/v1.0` (HTTP) - Auth: OAuth · pricing: Your plan · x402: no · licence: MIT (SDKs) - Probe metrics: not measured yet (probes haven't run) - Free tier: No charge for file calls. Storage is the account's own OneDrive or Microsoft 365 allowance. Plan prices unread on 2026-10-09 - Drives: Personal OneDrive, OneDrive for work or school, SharePoint document libraries, group libraries and shared items, on the same endpoints - Uploads: PUT `/content` up to 250 MB. Upload sessions above that, resumable, in fragments that are multiples of 320 KiB and under 60 MiB, 5 to 10 MiB advised - Downloads: GET `/content` answers 302 to a pre-authenticated URL that can expire within minutes - Sharing: `createLink` with view, edit or embed type, anonymous, organisation or named-user scope and `expirationDateTime`. `invite` grants read or write to recipients. Passwords on personal OneDrive only - Deleting: DELETE sends an item to the recycle bin (93 days on SharePoint). `permanentDelete` removes it for good - Rate limits: Per app per tenant 1,250 to 6,250 resource units a minute and 1,200,000 to 6,000,000 a day by licence count, 400 GB of ingress and of egress an hour. Per user 3,000 requests per 5 minutes - Paging: 200 items a page by default, `@odata.nextLink`, with `$top`, `$select`, `$orderby`, `$expand` and `$skipToken` - Permissions: Files.Read, Files.ReadWrite, Files.Read.All, Files.ReadWrite.All, Sites.Read.All, Sites.ReadWrite.All, plus Sites.Selected and Files.SelectedOperations.Selected - Change events: `delta` with a saved token, and webhook subscriptions on a drive's root folder (any folder on personal OneDrive) - MCP server: Work IQ OneDrive and Work IQ SharePoint, preview, Microsoft 365 Copilot licence needed. Not graded here - SDKs: C#, Java, Go, PHP, Python (msgraph-sdk 1.64.0, 6 October 2026), PowerShell and JavaScript (npm 3.0.7 from September 2023) - National clouds: Global, US Government L4 and L5, and China operated by 21Vianet - Scores: Reliability 64, Performance pending, Schema & documentation 89, Agent ergonomics 84, Security & auth 73, Payments & pricing 20, Task success pending, Maintenance & community 75, Transparency & trust 75 · negative events -4 · total over the 7 assessed categories - Why: Reliability, Graded on the v1.0 REST API. · Schema & documentation, OpenAPI 3.0.4 for all of Graph v1.0 in microsoftgraph/msgraph-metadata, with 1,516 paths under `/drives`, 172 of them outside the workbook A… · Agent ergonomics, `$select` trims driveItem properties, a list returns 200 items a page by default, and responses without `$select` carry a tip to use it. · Security & auth, OAuth 2.0 through Microsoft Entra ID with delegated and application permissions from Files.Read to Sites.ReadWrite.All, revocable consent, a… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, msgraph-sdk-python v1.64.0 on 6 October 2026. The What's new page, updated 8 October 2026, lists generally available Files changes for Septe… · Transparency & trust, Closed service under the Microsoft APIs terms of use, last updated October 2025, with MIT SDKs (15). - Sources: 46, open questions: 9, both in the full twin - Capabilities: storage.drive, storage.share, storage.presigned - JSON: https://www.anchorterminal.com/api/v1/tools/onedrive-sharepoint.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/onedrive-sharepoint.svg` or a link to https://www.anchorterminal.com/tools/onedrive-sharepoint from a page on microsoft.com or one of its subdomains, or the README of github.com/microsoftgraph/msgraph-sdk-python, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Use PUT `/content` only up to 250 MB. Above 10 MiB Microsoft advises `createUploadSession`, with fragments in multiples of 320 KiB and under 60 MiB each 2. Send the bearer token on the `createUploadSession` POST only. The PUT calls to `uploadUrl` can return 401 if an `Authorization` header is included 3. Set `expirationDateTime` and `scope` on `createLink`. Without a scope the tenant's default link type is created, which may be wider than intended 4. Follow the 302 from GET `/content` straight away. Pre-authenticated download URLs can expire within minutes and need no `Authorization` header 5. Wait for `Retry-After` on 429 and 503. Throttled requests still count against the limits, and continued overuse can get the app blocked ## Connect ```bash curl "https://graph.microsoft.com/v1.0/me/drive/root/children?\$select=id,name,size&\$top=50" \ -H "Authorization: Bearer $MS_GRAPH_TOKEN" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/onedrive-sharepoint ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Google Drive API + MCP | A | 79.6 | storage.drive, storage.share | https://www.anchorterminal.com/tools/google-drive-api.min.md | | Amazon S3 | BB | 77.9 | storage.presigned, storage.share | https://www.anchorterminal.com/tools/amazon-s3.min.md | | Cloudflare R2 | BB | 77.1 | storage.presigned, storage.share | https://www.anchorterminal.com/tools/cloudflare-r2.min.md | | Azure Blob Storage | BB | 75.7 | storage.presigned, storage.share | https://www.anchorterminal.com/tools/azure-blob-storage.min.md | | Backblaze B2 | BB | 75.3 | storage.presigned, storage.share | https://www.anchorterminal.com/tools/backblaze-b2.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)