Prerequisites
Keep prerequisites short and explicit.
Required
- VS Code with GitHub Copilot Chat agent mode enabled
- PowerShell 7 or later for the current scaffold
- Network access to Microsoft Graph and Microsoft Entra sign-in endpoints
- A Microsoft Graph execution substrate such as
merill/msgraph - A signed-in Microsoft account with consent for the required delegated scopes
- For live write tests, the current tenant and client app must allow the required write scopes such as
Mail.SendandCalendars.ReadWrite
Recommended
msgraphavailable onPATH, orGRAPH_GATEWAY_RUNNERset- A workspace-local runner install if you do not want to depend on global tools
- WorkIQ available for common read routing
Current Platform Note
- Windows is supported through the PowerShell scripts directly.
- macOS and Linux are supported through the
pwsh-backed.shwrappers inscripts/. - The current scaffold is cross-platform at the entrypoint level, but live behavior still depends on the installed runner and auth flow.
Light Setup Checklist
- Run the scaffold smoke test
- Install or point to a runner
- Check runner status
- Sign in to Graph
- Perform a read test before a write test
Write Test Note
- A successful delegated sign-in does not guarantee write access.
- Live mail and calendar writes can still fail with
403 ErrorAccessDeniedif the current client app or tenant policy does not allow the requested write scopes. - If that happens, use a custom Entra ID app registration or a tenant-approved client configuration for live write validation.
Admin Approval Note
- If the sign-in screen says that administrator approval is required for Microsoft Graph Command Line Tools, the tenant is blocking consent for the current client app.
- In that case, re-signing alone is not enough.
- Use one of these paths:
- ask a tenant admin to approve the app and required delegated scopes
- switch the runner to a tenant-approved custom app registration
- Use New-GraphGatewayAppConfig.ps1 or custom-app.env.example to prepare the environment for a custom app quickly.