Build a Microsoft Teams AI Agent with nanoinfra
Connect nanoinfra to Microsoft Teams through an Azure Bot registration.
What you will build
- a working local nanoinfra reply
- an Azure Bot registration Teams delivers to
- one direct message thread with the agent
When to use this
Use Teams when the organisation already runs it and a second chat tool is not an option.
Direct messages only. This channel supports one-to-one conversations. It does not answer in channels or group chats.
It also differs from every other channel in one way that shapes the whole setup: Teams delivers over a public HTTPS webhook, not a WebSocket. So nanoinfra has to be reachable from Microsoft, which means a tunnel or a reverse proxy in front of it.
Install
Quick Start ranks four install methods easiest first. This is the first of them. Use pip, Docker or a source checkout instead if you prefer, and come back here.
uv tool install nanoinfra
nanoinfra onboard --wizard
nanoinfra agent -m "Hello!"
Teams needs its optional dependency:
nanoinfra plugins enable msteams
Register the bot
- Open Microsoft Teams developer portal.
- Create an app and add a bot to it.
- Copy the app id and create an app password.
- Note the tenant id of the directory the app lives in.
- Set the messaging endpoint to your public HTTPS URL, ending in the
pathbelow.
Minimal working example
{
"channels": {
"msteams": {
"enabled": true,
"appId": "YOUR_APP_ID",
"appPassword": "YOUR_APP_PASSWORD",
"tenantId": "YOUR_TENANT_ID",
"path": "/api/messages"
}
}
}
appId and appPassword are required. path defaults to /api/messages, and it must
match the messaging endpoint you registered.
Start the gateway, then send the bot a direct message.
It should return a pairing code. Approve that code from a trusted local surface, and not the example below:
nanoinfra agent -m "/pairing approve <the code the bot sent you>"
If you missed the code, list the pending requests:
nanoinfra agent -m "/pairing"
Production notes
- The endpoint must be reachable from Microsoft over HTTPS. Use a tunnel or a reverse proxy, and terminate TLS there rather than in nanoinfra.
- Restart the gateway after you edit
config.json.
Security notes
- The app password authenticates your bot to Microsoft. Keep it in an environment variable and reference it from config.
- Keep
allowFromnarrow. A public webhook is reachable by anything that learns the URL, and the allowlist is what decides who the agent answers.
Troubleshooting
- Run
nanoinfra channels statusto confirm nanoinfra sees the channel as enabled. - If Teams reports a delivery failure, check that the registered messaging endpoint ends
in the same
pathyour config sets. - Run
nanoinfra gateway --verbosewhile debugging channel startup.