OpenClaw Microsoft Teams Setup Guide

Bring OpenClaw into Microsoft Teams for one-to-one chats, group chats and team channels, with Adaptive Cards for approvals and polls. Teams takes more setup than Telegram or Slack because it needs an Azure Bot and a public HTTPS address. This guide walks through both the fast automated route and the manual Azure portal route.

Quick answer

Create an Azure Bot (single tenant), point its messaging endpoint at https://<your-host>/api/messages, enable the Teams channel, upload a Teams app package, and add the App ID, client secret and tenant ID to channels.msteams. The @microsoft/teams.cli tool can automate most of it.

How it works

How OpenClaw connects to Microsoft Teams

  1. Someone messages the bot in TeamsIn a chat, group chat or channel
  2. Azure Bot Service receives itYour bot registration routes the message
  3. It's sent to your HTTPS endpointhttps://<host>/api/messages, verified with Teams SDK JWT authentication
  4. OpenClaw repliesWith text, attachments or Adaptive Cards

Unlike Telegram and Slack, Teams pushes messages to you. That's why OpenClaw needs an address on the public internet, even for testing.

Before you start

What you need

  • A Microsoft 365 tenant with Teams

    And permission to upload custom apps, which is often an admin setting.

  • An Azure subscription

    To create the Azure Bot. The Free pricing tier is fine for getting started.

  • A public HTTPS address

    A tunnel (Dev Tunnels, Tailscale Funnel or ngrok) for testing, or a real domain for production.

  • OpenClaw running

    With a model connected. The Teams plugin is bundled with current releases.

Fast route

Automate it with the Teams CLI

Microsoft's @microsoft/teams.cli creates the bot, generates credentials and uploads the app manifest for you. Start a tunnel first (step 3), then run:

Terminal
npm install -g @microsoft/teams.cli@preview
teams login
teams app create --name "OpenClaw" --endpoint "https://<tunnel-url>/api/messages"

Then skip to step 6 and add the credentials it gives you to OpenClaw.

1
Manual route · Step 1

Create the Azure Bot

  1. In the Azure portal, search for Azure Bot and click Create.
  2. Bot handle: a unique name, for example openclaw-msteams.
  3. Type of App: choose Single Tenant. Creating new multi-tenant bots is deprecated.
  4. Pricing tier: Free is fine for development.
  5. Microsoft App ID: choose Create new Microsoft App ID.
  6. Click Review + create, then Create. It takes 1–2 minutes.
2
Step 2

Collect the three credentials

CLIENT_IDApp IDOn the bot's Configuration page (Microsoft App ID)
CLIENT_SECRETClient secretFrom the linked app registration, under Certificates & secrets › New client secret. Copy it right away, because it's shown only once.
TENANT_IDTenant IDOn the bot's Configuration page, or Microsoft Entra ID overview

Store the secret safely. For production, the docs recommend certificate or managed identity authentication instead of a client secret.

3
Step 3

Give OpenClaw a public HTTPS endpoint

Teams can't reach localhost. Use a tunnel while testing:

Terminal
devtunnel create my-openclaw-bot --allow-anonymous
devtunnel host my-openclaw-bot
# Endpoint: https://<tunnel-id>.devtunnels.ms/api/messages

Microsoft's own tunnel service, designed for bots in development.

Then, in the Azure Bot's Configuration, set the Messaging endpoint to:

Messaging endpoint
https://<your-host>/api/messages
Expose only the Teams endpoint

Your gateway's Control UI and API give full control of your assistant. Make sure the public address only reaches /api/messages, or that the Teams webhook runs on its own port. The docs' example config uses port 3978. Never expose the whole gateway to the internet.

4
Step 4

Enable the Microsoft Teams channel

On your Azure Bot, open Channels, choose Microsoft Teams, accept the terms and click Apply.

5
Step 5

Build and upload the Teams app package

A Teams app package is a .zip containing three files: manifest.json, color.png (192×192) and outline.png (32×32, transparent). Use the builder for a starter manifest:

Make it yours

Teams manifest builder

Paste your App ID. The bot is enabled for personal chats, teams and group chats.

manifest.json

This is a starter manifest. The official docs also list RSC (resource-specific consent) permissions to add, for example so the bot can read channel messages. Add them from the OpenClaw Teams setup docs before uploading.

  1. Zip manifest.json, color.png and outline.png together. Put the files at the top level of the zip, not in a folder.
  2. Upload it. An admin can use the Teams admin center › Manage apps › Upload a custom app. If your org allows it, you can also use Apps › Manage your apps › Upload an app in Teams.
6
Step 6

Configure OpenClaw

~/.openclaw/.env
MSTEAMS_APP_ID=<CLIENT_ID>
MSTEAMS_APP_PASSWORD=<CLIENT_SECRET>
MSTEAMS_TENANT_ID=<TENANT_ID>

Keeps the secret out of your config file. This is the recommended way.

Terminal
openclaw gateway restart
openclaw channels status --probe
7
Step 7

Test it and approve yourself

  1. In Teams, open Apps, find your OpenClaw app and click Add.
  2. Send it a message in a personal chat.
  3. If direct messages use pairing, approve the request:
    Terminal
    openclaw pairing list msteams
    openclaw pairing approve msteams <CODE>
Channels and groups

Using OpenClaw in Teams channels and group chats

WhereWorks?Notes
Personal chatsYesControlled by dmPolicy and allowFrom
Group chatsOff by defaultAllow them with channels.msteams.groupPolicy
Team channelsYesResponds when @mentioned (mention gating), unless you change it with requireMention
Adaptive CardsYesFor polls and approvals
Files in chatsYesText and attachments in personal chats
Files in channels and groupsExtra setupNeeds sharePointSiteId and Microsoft Graph permissions
Going live

Production checklist

Tunnels are great for testing. For a company rollout, tighten things up.

Troubleshooting

Fix common Microsoft Teams problems

401 Unauthorized

The App ID, client secret or tenant ID doesn't match the Azure Bot. Check all three, and that the secret hasn't expired.

Bot never replies

Teams can't reach your endpoint. Check the tunnel is running and the messaging endpoint ends in /api/messages.

Can't upload the app

Custom app uploads are disabled in your tenant. Ask a Teams admin to allow them or upload it in the admin center.

Manifest rejected

Check the icon sizes (192×192 and 32×32), that the files are at the zip's top level, and that botId matches your App ID.

Silent in group chats

Group chats are blocked by default. Set channels.msteams.groupPolicy.

Can't send files in channels

Add sharePointSiteId and the Microsoft Graph permissions it needs.

More fixes: troubleshooting guide.

FAQ

OpenClaw Microsoft Teams questions

How do I connect OpenClaw to Microsoft Teams?

Create a single-tenant Azure Bot, set its messaging endpoint to https://your-host/api/messages, enable the Teams channel, upload a Teams app package, and add the App ID, client secret and tenant ID to channels.msteams in OpenClaw. Microsoft's Teams CLI can automate most steps.

Does OpenClaw for Teams need a public URL?

Yes. Teams sends messages to your bot over HTTPS, so OpenClaw needs a public HTTPS endpoint. Use Dev Tunnels, Tailscale Funnel or ngrok for testing and a stable domain in production.

Is the Microsoft Teams plugin included with OpenClaw?

Yes. The Microsoft Teams plugin ships bundled with current OpenClaw releases.

Does it cost anything to run OpenClaw on Teams?

OpenClaw is free and the Azure Bot Free tier is enough to get started. You still pay for your AI model, and possibly for Azure resources or hosting in production.

Can OpenClaw work in Teams group chats and channels?

Yes. Channels work with an @mention by default. Group chats are blocked by default and can be enabled with channels.msteams.groupPolicy.

Single tenant or multi-tenant?

Choose single tenant. Creating new multi-tenant Azure Bots is deprecated, and single tenant keeps the bot limited to your organization.

Other channels