How OpenClaw connects to Microsoft Teams
- Someone messages the bot in TeamsIn a chat, group chat or channel
- Azure Bot Service receives itYour bot registration routes the message
- It's sent to your HTTPS endpoint
https://<host>/api/messages, verified with Teams SDK JWT authentication - OpenClaw repliesWith text, attachments or Adaptive Cards
Unlike Telegram and Slack, Teams pushes messages to you. That's why OpenClaw needs an address on the public internet, even for testing.
What you need
- A Microsoft 365 tenant with Teams
And permission to upload custom apps, which is often an admin setting.
- An Azure subscription
To create the Azure Bot. The Free pricing tier is fine for getting started.
- A public HTTPS address
A tunnel (Dev Tunnels, Tailscale Funnel or ngrok) for testing, or a real domain for production.
- OpenClaw running
With a model connected. The Teams plugin is bundled with current releases.
Automate it with the Teams CLI
Microsoft's @microsoft/teams.cli creates the bot, generates credentials and uploads the app manifest for you. Start a tunnel first (step 3), then run:
npm install -g @microsoft/teams.cli@preview
teams login
teams app create --name "OpenClaw" --endpoint "https://<tunnel-url>/api/messages"Then skip to step 6 and add the credentials it gives you to OpenClaw.
Create the Azure Bot
- In the Azure portal, search for Azure Bot and click Create.
- Bot handle: a unique name, for example
openclaw-msteams. - Type of App: choose Single Tenant. Creating new multi-tenant bots is deprecated.
- Pricing tier: Free is fine for development.
- Microsoft App ID: choose Create new Microsoft App ID.
- Click Review + create, then Create. It takes 1–2 minutes.
Collect the three credentials
CLIENT_IDApp IDOn the bot's Configuration page (Microsoft App ID)CLIENT_SECRETClient secretFrom the linked app registration, under Certificates & secrets › New client secret. Copy it right away, because it's shown only once.TENANT_IDTenant IDOn the bot's Configuration page, or Microsoft Entra ID overviewStore the secret safely. For production, the docs recommend certificate or managed identity authentication instead of a client secret.
Give OpenClaw a public HTTPS endpoint
Teams can't reach localhost. Use a tunnel while testing:
devtunnel create my-openclaw-bot --allow-anonymous
devtunnel host my-openclaw-bot
# Endpoint: https://<tunnel-id>.devtunnels.ms/api/messagesMicrosoft's own tunnel service, designed for bots in development.
Tailscale Funnel publishes a port from your tailnet to the internet with HTTPS. Follow Tailscale's Funnel docs and expose only the Teams webhook.
ngrok gives you a public HTTPS URL that forwards to your machine. Use the port your Teams webhook listens on.
Then, in the Azure Bot's Configuration, set the Messaging endpoint to:
https://<your-host>/api/messagesYour gateway's Control UI and API give full control of your assistant. Make sure the public address only reaches /api/messages, or that the Teams webhook runs on its own port. The docs' example config uses port 3978. Never expose the whole gateway to the internet.
Enable the Microsoft Teams channel
On your Azure Bot, open Channels, choose Microsoft Teams, accept the terms and click Apply.
Build and upload the Teams app package
A Teams app package is a .zip containing three files: manifest.json, color.png (192×192) and outline.png (32×32, transparent). Use the builder for a starter manifest:
Teams manifest builder
Paste your App ID. The bot is enabled for personal chats, teams and group chats.
This is a starter manifest. The official docs also list RSC (resource-specific consent) permissions to add, for example so the bot can read channel messages. Add them from the OpenClaw Teams setup docs before uploading.
- Zip
manifest.json,color.pngandoutline.pngtogether. Put the files at the top level of the zip, not in a folder. - Upload it. An admin can use the Teams admin center › Manage apps › Upload a custom app. If your org allows it, you can also use Apps › Manage your apps › Upload an app in Teams.
Configure OpenClaw
MSTEAMS_APP_ID=<CLIENT_ID>
MSTEAMS_APP_PASSWORD=<CLIENT_SECRET>
MSTEAMS_TENANT_ID=<TENANT_ID>Keeps the secret out of your config file. This is the recommended way.
{
channels: {
msteams: {
enabled: true,
appId: "<CLIENT_ID>",
appPassword: "<CLIENT_SECRET>",
tenantId: "<TENANT_ID>",
webhook: { path: "/api/messages" },
},
},
}openclaw gateway restart
openclaw channels status --probeTest it and approve yourself
- In Teams, open Apps, find your OpenClaw app and click Add.
- Send it a message in a personal chat.
- If direct messages use pairing, approve the request:
Terminal
openclaw pairing list msteams openclaw pairing approve msteams <CODE>
Using OpenClaw in Teams channels and group chats
| Where | Works? | Notes |
|---|---|---|
| Personal chats | Yes | Controlled by dmPolicy and allowFrom |
| Group chats | Off by default | Allow them with channels.msteams.groupPolicy |
| Team channels | Yes | Responds when @mentioned (mention gating), unless you change it with requireMention |
| Adaptive Cards | Yes | For polls and approvals |
| Files in chats | Yes | Text and attachments in personal chats |
| Files in channels and groups | Extra setup | Needs sharePointSiteId and Microsoft Graph permissions |
Production checklist
Tunnels are great for testing. For a company rollout, tighten things up.
Fix common Microsoft Teams problems
401 UnauthorizedThe App ID, client secret or tenant ID doesn't match the Azure Bot. Check all three, and that the secret hasn't expired.
Bot never repliesTeams can't reach your endpoint. Check the tunnel is running and the messaging endpoint ends in /api/messages.
Can't upload the appCustom app uploads are disabled in your tenant. Ask a Teams admin to allow them or upload it in the admin center.
Manifest rejectedCheck the icon sizes (192×192 and 32×32), that the files are at the zip's top level, and that botId matches your App ID.
Silent in group chatsGroup chats are blocked by default. Set channels.msteams.groupPolicy.
Can't send files in channelsAdd sharePointSiteId and the Microsoft Graph permissions it needs.
More fixes: troubleshooting guide.
OpenClaw Microsoft Teams questions
How do I connect OpenClaw to Microsoft Teams?
Create a single-tenant Azure Bot, set its messaging endpoint to https://your-host/api/messages, enable the Teams channel, upload a Teams app package, and add the App ID, client secret and tenant ID to channels.msteams in OpenClaw. Microsoft's Teams CLI can automate most steps.
Does OpenClaw for Teams need a public URL?
Yes. Teams sends messages to your bot over HTTPS, so OpenClaw needs a public HTTPS endpoint. Use Dev Tunnels, Tailscale Funnel or ngrok for testing and a stable domain in production.
Is the Microsoft Teams plugin included with OpenClaw?
Yes. The Microsoft Teams plugin ships bundled with current OpenClaw releases.
Does it cost anything to run OpenClaw on Teams?
OpenClaw is free and the Azure Bot Free tier is enough to get started. You still pay for your AI model, and possibly for Azure resources or hosting in production.
Can OpenClaw work in Teams group chats and channels?
Yes. Channels work with an @mention by default. Group chats are blocked by default and can be enabled with channels.msteams.groupPolicy.
Single tenant or multi-tenant?
Choose single tenant. Creating new multi-tenant Azure Bots is deprecated, and single tenant keeps the bot limited to your organization.