OneCLI connects AI agents to Microsoft OneNote through Microsoft’s OAuth flow. Agents can read notebooks, sections, and pages, create new pages, and edit existing content. The gateway injects OAuth credentials into requests to the Microsoft Graph API automatically.
On self-hosted OneCLI, Microsoft OneNote needs your own Microsoft app first. See Self-hosted.
Skip this section on OneCLI Cloud. It’s only for self-hosted OneCLI without MICROSOFT_CLIENT_ID and MICROSOFT_CLIENT_SECRET set. One Microsoft app serves all four Microsoft apps in OneCLI, so you set it up once.
Set up your Microsoft app
Follow Self-hosted: use your own Microsoft app on the Outlook Mail page. If you already have one for another Microsoft app, it already works here. Then open Connections > Microsoft OneNote and select Connect Microsoft OneNote.
Custom credentials for Microsoft OneNote in OneCLI. The Microsoft app is shared, so the same client works here.
Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked — a read-only agent is a single grant. Organization rules add guardrails on top, like rate limits and blanket blocks. Everything is checked before credential injection, so a blocked request never reaches the Microsoft Graph API.