Outlook for AI agents

Outlook is Microsoft's email and calendar platform, combining messaging, scheduling, and contacts in one workspace. Professionals use it to manage communication and meetings across an organization. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

EmailOAuth 2.0MCP + RESToutlook.com
AUDIT LOG · OUTLOOKPOLICY: acme-support
09:41:07 · claude · u_8f2read
outlook.list_chats
List Teams chats✓ allowed · 212ms
09:41:08 · claude · u_8f2read
outlook.get_event
Get calendar event✓ allowed · 164ms
09:41:09 · claude · u_8f2write
outlook.create_task
Create To Do task✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
outlook.delete_event
Delete calendar event (Deprecated)✕ blocked · policy: deny
EVERY OUTLOOK CALL, ON THE RECORD
01 · USE CASES

What agents do in Outlook.

01

Create a calendar event

Schedule a meeting with attendees and a time slot directly on a connected calendar.

02

Draft an email for review

Create an email draft with recipients and content, held for review before sending.

03

Accept a meeting invite with approval

Accept a calendar event invite only after the recipient confirms they can attend.

02 · ACTIONS

306 Outlook actions, graded by risk.

Every Outlook action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

117

Look things up. Allowed by default.

  • outlook.get_event
    Get calendar event
  • outlook.list_chats
    List Teams chats
  • outlook.list_users
    List users
  • outlook.get_message
    Get email message
  • outlook.get_profile
    Get Outlook profile
  • outlook.list_events
    List events
  • outlook.list_places
    List places
  • outlook.get_calendar
    Get specific calendar
  • outlook.get_schedule
    Get schedule
  • outlook.query_emails
    Query Emails
  • outlook.get_mail_tips
    Get mail tips
  • outlook.list_contacts
    List Outlook contacts (Deprecated)
  • outlook.list_messages
    List Messages
  • outlook.search_events
    Search calendar events
  • outlook.get_mail_delta
    Get mail delta
  • outlook.get_me_outlook
    Get user outlook
+ 101 MORE

write

129

Create and change things. Allow, or ask the user first.

  • outlook.send_draft
    Send draft
  • outlook.send_email
    Send email
  • outlook.create_task
    Create To Do task
  • outlook.create_draft
    Create email draft
  • outlook.update_email
    Update email message
  • outlook.create_contact
    Create contact
  • outlook.update_contact
    Update Contact
  • outlook.create_calendar
    Create calendar
  • outlook.create_me_event
    Create calendar event for user
  • outlook.update_todo_task
    Update To Do task
  • outlook.create_email_rule
    Create Email Rule
  • outlook.update_email_rule
    Update Email Rule
  • outlook.create_draft_reply
    Create a draft reply
  • outlook.create_mail_folder
    Create mail folder
  • outlook.update_mail_folder
    Update mail folder
  • outlook.add_mail_attachment
    Add mail attachment
+ 113 MORE

destructive

60

Delete, cancel or archive. Ask first, or deny outright.

  • outlook.cancel_event
    Cancel user calendar event
  • outlook.delete_event
    Delete calendar event (Deprecated)
  • outlook.delete_contact
    Delete Contact
  • outlook.delete_message
    Delete Message
  • outlook.delete_calendar
    Delete calendar
  • outlook.delete_todo_task
    Delete To Do task
  • outlook.delete_email_rule
    Delete Email Rule
  • outlook.delete_mail_folder
    Delete mail folder
  • outlook.cancel_calendar_event
    Cancel user's calendar event
  • outlook.delete_calendar_event
    Delete calendar event
  • outlook.delete_calendar_group
    Delete calendar group
  • outlook.delete_contact_folder
    Delete contact folder
  • outlook.delete_event_extension
    Delete event extension
  • outlook.delete_master_category
    Delete master category
  • outlook.delete_event_attachment
    Delete event attachment
  • outlook.delete_event_permanently
    Permanently Delete Event
+ 44 MORE
03 · HOW IT WORKS

Outlook in three steps.

  1. 01Your users connect OutlookThey sign in to Outlook on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create To Do task” can wait for the user, and “delete calendar event (Deprecated)” can be denied outright.
  3. 03Any agent can actYour agent calls Outlook through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('outlook', {
  read: 'allow',
  write: 'ask',        // create_task
  destructive: 'deny',  // delete_event
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Outlook connects.

Users sign in to Outlook on Arc0 Connect and approve the scopes you request. Build with Arc0’s Outlook OAuth app, or bring your own so the Outlook consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same Outlook connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
OAuth 2.0 · OAuth 2.0 client credentials
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Outlook from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Outlook and Arc0, answered.

Q01

Can I use Outlook with Claude, ChatGPT or Cursor?

Yes. Connect Outlook to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Outlook actions you allow.

Q02

How do users connect Outlook?

Users sign in to Outlook on Arc0 Connect and approve the scopes you request. Build with Arc0’s Outlook OAuth app, or bring your own so the Outlook consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which Outlook actions can my agent take?

306 in total: 117 read, 129 write and 60 destructive, such as “create To Do task”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Outlook?

Yes. Actions like “delete calendar event (Deprecated)” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Outlook too?

Yes. The same Outlook connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Outlook into your agent.

Your users connect Outlook once, under your brand. Your agent gets 306 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan