Provider REST API

Productivity

Connect Claude to Microsoft Excel

Read and update cloud Excel workbooks, append table rows, and create and export charts. Toolspoke puts 15 of its actions behind one MCP endpoint that Claude, Cursor, and Codex all speak.

Connection
Provider REST API
Authentication
Sign in with Microsoft
Actions exposed
15
What a call bills
Nothing
Adapter
Maintained by Toolspoke

Connected in three steps

  1. 1

    Install Microsoft Excel

    Open the marketplace in your workspace, add Microsoft Excel to the project your agents work in, and it appears on the gateway immediately.

  2. 2

    Connect the credential

    Sign in to Microsoft Excel. Toolspoke holds the token encrypted and refreshes it when it expires.

  3. 3

    Point your agent at the gateway

    Give your client one address, https://toolspoke.com/mcp. Claude Code takes it as a command, Claude and Claude Desktop add it as a custom connector, and Cursor, Codex and VS Code each read it from a config file of their own.

.mcp.json
{
  "mcpServers": {
    "toolspoke": {
      "type": "http",
      "url": "https://toolspoke.com/mcp"
    }
  }
}

One block covers every tool you have installed. Microsoft Excel shows up in the client as soon as your policy allows it, and so does everything else you install later.

Where the address goes, per client

Claude Code

Run it in your project, then /mcp to sign in

claude mcp add --transport http toolspoke https://toolspoke.com/mcp
Claude and Claude Desktop

Settings, then Connectors, then Add custom connector

https://toolspoke.com/mcp
Cursor

~/.cursor/mcp.json, or .cursor/mcp.json for one project

{ "mcpServers": { "toolspoke": { "url": "https://toolspoke.com/mcp" } } }
Codex

~/.codex/config.toml

[mcp_servers.toolspoke]
url = "https://toolspoke.com/mcp"
VS Code

.vscode/mcp.json, or the MCP: Add Server command

{ "servers": { "toolspoke": { "type": "http", "url": "https://toolspoke.com/mcp" } } }

What Microsoft Excel asks for

Press connect and sign in to Microsoft Excel. Toolspoke keeps the token encrypted and refreshes it when it expires, so there is nothing to copy and nothing to rotate by hand.

The scopes it asks for

  • offline_access
  • https://graph.microsoft.com/Files.ReadWrite

What Claude can do in Microsoft Excel

15 actions, each one declared and named by the connector rather than discovered at runtime. A workspace policy grants a person all of them, a hand-picked selection, everything on the read side, everything on the write side, or none.

Reads
10Reads
Writes
4Writes
Destructive
1Destructive

Reads

10

Fetches data and changes nothing.

  • get_my_drive

    Return the signed-in user’s business OneDrive id and drive type. This checks Files.ReadWrite access; it does not prove a specific workbook is accessible. Use a work or school Microsoft account.

  • list_files

    List the root folder of a drive. Pick an .xlsx file; browse folder ids with list_folder. Results include non-workbooks. Follow @odata.nextLink with skip_token; do not treat one page as the full drive.

  • list_folder

    List a folder’s files and subfolders. Choose an .xlsx workbook, or recurse using returned folder ids. Follow @odata.nextLink with skip_token.

  • get_file

    Resolve a workbook’s file metadata and web link. This does not read its cells. Workbook actions require an existing Office Open XML workbook in business OneDrive or SharePoint; .xls and local files are unsupported.

  • list_worksheets

    List worksheets in the workbook, including their ids and names. Use those identifiers in range and chart calls.

  • read_range

    Read values, formulas and number formats from an explicit bounded A1 range. Read in small chunks for large worksheets.

  • list_tables

    List the workbook’s named tables. A table, rather than an arbitrary range, is required for append_rows.

  • list_rows

    Read table rows with their indices and values. Page using skip and limit; an incomplete page is not the whole table.

  • list_charts

    List charts in a worksheet, returning ids and names for image export.

  • get_chart_image

    Render a chart as a base64 PNG in value. Use a saved read-only script to fetch it and call create_artifact with format png and content set to value, then share the artifact link. Do not paste the base64 into chat. Work/school accounts only.

Writes

4

Creates or updates something on the other side.

  • add_worksheet

    Add a new worksheet to an existing workbook. Does not create a workbook file.

  • add_table

    Create a table over an existing worksheet range. This structures existing cells rather than appending new data.

  • append_rows

    Append rows to the end of an existing table. Read its columns first and match their order and count. This call is not idempotent: after a timeout, inspect the table before retrying to avoid duplicate rows.

  • add_chart

    Create a chart from an existing bounded data range in this worksheet. Include headings when useful. Export it with get_chart_image; email delivery uses a separate mail toolkit.

Destructive

1

Deletes or permanently alters something. Worth granting on purpose.

  • update_range

    Overwrite values, formulas or number formats in a bounded A1 range. Supply only the fields to change, matching the range dimensions; null skips a cell. Existing cells can be overwritten, so this requires destructive action permission.

What it will not do

Enforced by the gateway rather than left to convention, which is why each of these can be stated flatly.

It cannot call anything else
The 15 actions above are the whole of it. A call to any other name is refused before it reaches Microsoft Excel rather than forwarded on, and connecting your account does not add to the list: it is fixed by the connector, not discovered at run time.
It reaches no further than your credential
Toolspoke holds no access to Microsoft Excel of its own. Every call carries the credential you stored and nothing besides, so whatever that credential cannot reach, this connector cannot reach either.
It never hears from Microsoft Excel
Nothing is pushed to it. There is no webhook, no subscription and no polling, so this connector cannot notice by itself that something changed in Microsoft Excel. An agent has to ask.
It does not smooth over provider limits
Toolspoke does not retry, queue or back off around Microsoft Excel's own rate limits. A call that Microsoft Excel refuses comes back to the agent as a failed call.

Using Microsoft Excel with an agent

Written by whoever built this connector. Agents read the same text on demand through read_guide, so what is below is what they see.

Sign in with a Microsoft work or school account. Use an existing .xlsx workbook in OneDrive for Business or SharePoint. Start with getmydrive and listfiles; browse subfolders with listfolder. For a SharePoint library, obtain its drive id with the SharePoint toolkit. Carry both driveid and workbookid through all calls. List worksheets and tables before reading or writing. Read bounded ranges and paginate table rows. Appends are not idempotent: check for existing entries before retrying after an ambiguous timeout. Range updates overwrite cells and require destructive permission. Charts use existing worksheet data; getchartimage returns base64 PNG, which a script can save with create_artifact. Sending email requires a separate installed mail toolkit. This connector does not create or upload workbook files, run desktop Excel, configure forms, or receive Slack replies.

Before you connect it

What can Claude do in Microsoft Excel?

15 named actions: 10 that only read, 4 that write and 1 that delete or permanently alter something. They include get_my_drive, list_files and list_folder. Nothing outside that list is reachable: the connector declares each operation by name rather than proxying whatever an agent asks for.

What credentials does the Microsoft Excel connector need?

Nothing to paste. You sign in to Microsoft Excel over OAuth 2.0 and Toolspoke keeps the resulting token encrypted, refreshing it when it expires. It asks for offline_access and https://graph.microsoft.com/Files.ReadWrite, and can do nothing outside them.

Does the Microsoft Excel connector work with Cursor and Codex, or only Claude?

Any client that speaks MCP, and every one of them gets the same 15 actions. There is a single address, https://toolspoke.com/mcp. Claude Code adds it with claude mcp add --transport http, Claude and Claude Desktop take it as a custom connector in settings, Cursor reads it from .cursor/mcp.json, Codex from ~/.codex/config.toml, and VS Code from .vscode/mcp.json. Each of them signs in to the gateway itself, so there is no key to paste.

What does the Microsoft Excel connector not do?

The 15 actions above are the whole of it. A call to any other name is refused before it reaches Microsoft Excel rather than forwarded on, and connecting your account does not add to the list: it is fixed by the connector, not discovered at run time. Toolspoke holds no access to Microsoft Excel of its own. Every call carries the credential you stored and nothing besides, so whatever that credential cannot reach, this connector cannot reach either. Nothing is pushed to it. There is no webhook, no subscription and no polling, so this connector cannot notice by itself that something changed in Microsoft Excel. An agent has to ask. Toolspoke does not retry, queue or back off around Microsoft Excel's own rate limits. A call that Microsoft Excel refuses comes back to the agent as a failed call.

Can I limit which actions an agent can call?

Yes, in two places. The project switches Microsoft Excel's actions on and off one at a time, for everyone in the project at once, and the screen groups them by read, write and destructive so turning off everything that deletes is one click. An individual agent key can then be narrowed further, to particular toolkits in a project and to particular actions in a toolkit. Whatever it was granted, a key never reaches a project its owner cannot.

What gets recorded when an agent calls Microsoft Excel?

Every attempt, with the agent that made it and the person that agent belongs to, the full request payload, the response payload, the status, the duration, and what the call cost in sandbox time and model tokens. Values whose key names a secret are masked out before the record is shown to anyone. An operation the connector marks as not retained never has its response body written at all, so the gateway keeps no second copy of what was read.