Skip to main content

Build a Microsoft Teams AI Agent with nanoinfra

Connect nanoinfra to Microsoft Teams through an Azure Bot registration.

What you will build​

  • a working local nanoinfra reply
  • an Azure Bot registration Teams delivers to
  • one direct message thread with the agent

When to use this​

Use Teams when the organisation already runs it and a second chat tool is not an option.

Direct messages only. This channel supports one-to-one conversations. It does not answer in channels or group chats.

It also differs from every other channel in one way that shapes the whole setup: Teams delivers over a public HTTPS webhook, not a WebSocket. So nanoinfra has to be reachable from Microsoft, which means a tunnel or a reverse proxy in front of it.

Install​

Quick Start ranks four install methods easiest first. This is the first of them. Use pip, Docker or a source checkout instead if you prefer, and come back here.

uv tool install nanoinfra
nanoinfra onboard --wizard
nanoinfra agent -m "Hello!"

Teams needs its optional dependency:

nanoinfra plugins enable msteams

Register the bot​

  1. Open Microsoft Teams developer portal.
  2. Create an app and add a bot to it.
  3. Copy the app id and create an app password.
  4. Note the tenant id of the directory the app lives in.
  5. Set the messaging endpoint to your public HTTPS URL, ending in the path below.

Minimal working example​

{
"channels": {
"msteams": {
"enabled": true,
"appId": "YOUR_APP_ID",
"appPassword": "YOUR_APP_PASSWORD",
"tenantId": "YOUR_TENANT_ID",
"path": "/api/messages"
}
}
}

appId and appPassword are required. path defaults to /api/messages, and it must match the messaging endpoint you registered.

Start the gateway, then send the bot a direct message.

It should return a pairing code. Approve that code from a trusted local surface, and not the example below:

nanoinfra agent -m "/pairing approve <the code the bot sent you>"

If you missed the code, list the pending requests:

nanoinfra agent -m "/pairing"

Production notes​

  • The endpoint must be reachable from Microsoft over HTTPS. Use a tunnel or a reverse proxy, and terminate TLS there rather than in nanoinfra.
  • Restart the gateway after you edit config.json.

Security notes​

  • The app password authenticates your bot to Microsoft. Keep it in an environment variable and reference it from config.
  • Keep allowFrom narrow. A public webhook is reachable by anything that learns the URL, and the allowlist is what decides who the agent answers.

Troubleshooting​

  • Run nanoinfra channels status to confirm nanoinfra sees the channel as enabled.
  • If Teams reports a delivery failure, check that the registered messaging endpoint ends in the same path your config sets.
  • Run nanoinfra gateway --verbose while debugging channel startup.