Observed Signal · Jul 19, 2026 · Technical Release · Source: DEV Community · Impact: 2/5 · Sentiment: Positive

TypeScript OneNote MCP Server and Microsoft Graph Auth Fixes

Executive Signal Summary

A developer rewrote an existing OneNote Model Context Protocol (MCP) server in TypeScript and documented key learnings about Microsoft Graph authentication. The rewrite fixed a silent 401 error caused by requesting application-level ".All" scopes (incompatible with personal Microsoft accounts) by switching to resource-qualified delegated scopes. The author also highlights that personal Microsoft accounts may return compact non-JWT tokens, recommends avoiding token-format validation, and describes architecture improvements: Zod-typed MCP tools, a single OneNoteClient class, dependency-free HTML→text conversion, stderr-only logging for MCP stdio, and Vitest-based tests.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Practical technical guidance and an open-source TypeScript rewrite that resolve Microsoft Graph authentication pitfalls for developers building MCP integrations with conversational AI; useful to engineers but not industry-shifting.

SIGNAL RADAR

Track Microsoft Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Author rewrote an existing OneNote MCP server in TypeScript to improve structure, typing, and dependencies.
  • Requesting Notes.Read.All / Notes.ReadWrite.All caused silent HTTP 401 errors for personal Microsoft accounts because .All scopes are application-level permissions not consentable by MSAs.
  • Fix: use resource-qualified delegated scopes (https://graph.microsoft.com/Notes.Read, https://graph.microsoft.com/Notes.ReadWrite, https://graph.microsoft.com/User.Read) which work for both personal and work/school accounts.
  • Personal Microsoft accounts can return compact (non-JWT) tokens; code should not validate token format but rely on Microsoft Graph for token validity.
  • New server uses Zod schemas for MCP tools, a unified OneNoteClient class, dependency-free HTML→text conversion, stderr-only logging for JSON-RPC safety, and Vitest tests with mocked Graph clients.

Connected Companies & Entities

2 Entities mapped

“I started with danosb/onenote-mcp, a JavaScript MCP server that uses Microsoft Graph to access OneNote....”

“I started with danosb/onenote-mcp (https://github.com/danosb/onenote-mcp), a JavaScript MCP server that uses Microsoft Graph to access OneNo...”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jul 19, 2026
Original Coverage Title: “I Rewrote a OneNote MCP Server in TypeScript — Here's What I Learned About Microsoft Graph Auth”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Conversational AI & LLM IntegrationMay 1, 2026

Build a TypeScript MCP Server (2026 Tutorial)

This technical tutorial shows how to build a Model Context Protocol (MCP) server in TypeScript using the @modelcontextprotocol/sdk (tested with v1.29.0) and Node.js. The post notes MCP has surpassed 97 million monthly SDK downloads and over 10,000 public server implementations, and that major AI clients (Claude, Cursor, Windsurf, OpenAI) speak the protocol natively. The guide walks through project initialization, TypeScript configuration (Node16 module resolution and "type": "module"), registering example tools (word_count, to_slug), exposing a resource, testing via stdio JSON-RPC, connecting to Claude Desktop, and an optional Streamable HTTP transport (protocol version 2025-03-26) for networked deployments. The article includes troubleshooting tips, FAQ items, and recommended next steps (file system resources, DB wrappers, auth).

Read assessment
Identity & AuthenticationApr 29, 2026

Adding OAuth 2.1 to MCP Server in TypeScript

A technical tutorial showing how to add OAuth 2.1 (authorization code flow with PKCE S256) to a Model Context Protocol (MCP) server implemented in TypeScript. The post demonstrates a Hono-based server using the KavachOS auth library and @kavachos/hono adapter, and implements RFC 9728 (.well-known/oauth-protected-resource), RFC 7591 dynamic client registration, RFC 8707 resource indicators, and token validation middleware. The article includes code snippets, an end-to-end test flow (including the Anthropic MCP Inspector), recommended npm packages, common pitfalls (missing discovery endpoint, hardcoded client_id, missing resource binding, delayed token revocation, lack of audit logs), and benefits such as per-agent revocation, agent-level rate limits, audit logs, and a path to enterprise SSO via SAML/OIDC upstreams. Published 2026-04-29.

Read assessment
Identity & Server AuthorizationJun 26, 2026

MCP Server Auth: API Is the Real Boundary

This technical post describes replacing a single shared TEAMKB_API_KEY with a per-user token registry for the intent-brain / teamkb MCP (model-connected platform) system. The author implemented identity (per-user bearer tokens resolved to {actor, role}), server-side authorization (a Fastify onRequest write gate that 403s unauthorized mutating requests to admin prefixes), and a structured per-read access log separate from the governance audit trail. The piece emphasizes that the MCP client’s conditional tool registration is a UX convenience, not a security boundary, and that the API (server gate) is the true enforcement point. Defensive details include constant-time token comparisons (timingSafeStrEq) and a non-early-return token resolution to blunt timing attacks. The change set shipped 23 tests and additional ancillary updates to related agent and tooling projects.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.