Skip to main content
Python dependency commands on this page use a PM-prepared source checkout. After a dependency change, reactivate the checkout and restart Mibyan. Connect Mibyan to Microsoft Teams as a bot. Unlike Slack’s Socket Mode, Teams delivers messages by calling a public HTTPS webhook, so your instance needs a publicly reachable endpoint — either a dev tunnel (local dev) or a real domain (production). Need meeting summaries from Microsoft Graph events rather than normal bot conversations? Use the dedicated setup page: Teams Meetings.
Run mibyan gateway setup and pick Microsoft Teams for a guided walk-through.

How the Bot Responds

Teams delivers @mentions as regular messages with <at>BotName</at> tags, which Mibyan strips automatically before processing. Without resource-specific consent (RSC) Teams only delivers messages that @mention the bot, so no filtering is needed. Once the app manifest grants ChannelMessage.Read.Group or ChatMessage.Read.Chat, Teams delivers every message in the conversation — set require_mention: true (or TEAMS_REQUIRE_MENTION=true) so the bot only answers channel/group-chat messages that @mention it or reply to one of its own messages. Personal chats are never gated, and a gated message is dropped before its attachments are downloaded.
For source or local installs, include the Teams extra so the bundled adapter can import the Microsoft Teams SDK:

Step 1: Install the Teams CLI

The @microsoft/teams.cli automates bot registration — no Azure portal needed.
To verify your login and find your own AAD object ID (needed for TEAMS_ALLOWED_USERS):

Step 2: Expose the Webhook Port

Teams cannot deliver messages to localhost. For local development, use any tunnel tool to get a public HTTPS URL. The default port is 3978 — change it with TEAMS_PORT if needed.
Copy the https:// URL from the output — you’ll use it in the next step. Leave the tunnel running while developing. The public tunnel URL uses HTTPS, but Mibyan’ local webhook listener uses plain HTTP. The tunnel terminates TLS and forwards HTTP to port 3978; do not configure the local tunnel port as HTTPS. For production, point your bot’s endpoint at your server’s public domain instead (see Production Deployment).

Step 3: Create the Bot

The CLI outputs your CLIENT_ID, CLIENT_SECRET, and TENANT_ID, plus an install link for Step 6. Save the client secret — it won’t be shown again.

Step 4: Configure Environment Variables

Add to ~/.mibyan/.env:

Step 5: Start the Gateway

Docker (must run from the directory that contains docker-compose.yml — usually your cloned mibyan-agent repo, not ~):
Native / systemd install (typical mibyan one-liner installer under ~/.mibyan/mibyan-agent):
The Teams SDK is optional. When policy permits, the gateway requests the teams extra through PM on first start. PM prepares a complete environment instead of modifying the running interpreter. To request the extra explicitly from the prepared source checkout:
The default webhook port is 3978 (override with TEAMS_PORT). Check that it’s running:
Look for:

Step 6: Install the App in Teams

Open the printed link in your browser — it opens directly in the Teams client. After installing, send a direct message to your bot — it’s ready.

Configuration Reference

Environment Variables

config.yaml

Alternatively, configure via ~/.mibyan/config.yaml:

Features

Interactive Approval Cards

When the agent needs to run a potentially dangerous command, it sends an Adaptive Card with four buttons instead of asking you to type /approve:
  • Allow Once — approve this specific command
  • Allow Session — approve this pattern for the rest of the session
  • Always Allow — permanently approve this pattern
  • Deny — reject the command
Clicking a button resolves the approval inline and replaces the card with the decision.

Meeting Summary Delivery (Teams Meeting Pipeline)

When the Teams meeting pipeline plugin is enabled, this adapter also handles outbound delivery of meeting summaries — one Teams integration surface, not two. After a meeting’s transcript is summarized, the writer posts the summary into your chosen Teams target. Pipeline summary delivery is configured under the teams platform entry alongside the bot config:
If the teams_pipeline plugin is not enabled, these settings are inert — they only wire up when the pipeline runtime binds to the Graph webhook ingress.

Production Deployment

For a permanent server, terminate TLS at a reverse proxy and forward requests to the plain HTTP Mibyan listener, normally http://127.0.0.1:3978. Register the proxy’s public HTTPS endpoint with Teams:
If you’ve already created the bot and just need to update the endpoint:
Make sure the public HTTPS endpoint is reachable from the internet and uses a valid TLS certificate. Teams rejects self-signed certificates. Keep the Mibyan listener behind the proxy; port 3978 does not serve HTTPS itself.

Troubleshooting


Security

Always set TEAMS_ALLOWED_USERS with the AAD object IDs of authorized users. Without this, anyone who can find or install your bot can interact with it.Treat TEAMS_CLIENT_SECRET like a password — rotate it periodically via the Azure portal or Teams CLI.
  • Store credentials in ~/.mibyan/.env with permissions 600 (chmod 600 ~/.mibyan/.env)
  • The bot only accepts messages from users in TEAMS_ALLOWED_USERS; unauthorized messages are silently dropped
  • Your public endpoint (/api/messages) is authenticated by the Teams Bot Framework — requests without valid JWTs are rejected