Field-by-field comparison

Compare the evidence before choosing an MCP.

Each signal stays separate, missing facts remain visible, and the column order follows your selection.

MCPs in this comparison

Uncheck an MCP to remove it. Comparing two or three keeps each signal in its own row.

Open canonical comparison link

Comparable alternatives

Shown only when capability or industry context overlaps.

Side-by-side MCP evidence comparison
Evidence fieldMicrosoft 365 MCP ServerWatchlist candidateMCP Unity Editor (Game Engine)MCP100 Selected
Task fit
Best for
  • Using Microsoft 365 email, calendar, OneDrive, documents, and personal productivity workflows through a self-hosted MCP
  • Organization Microsoft Graph workflows that need explicit Teams, meetings, SharePoint Sites and Lists, or user-management capabilities with deliberately narrowed access
  • Creating and editing Unity project assets, scenes, scripts, and editor state through supported AI coding clients
Not ideal for
  • A SharePoint-only deployment or a narrowly scoped integration when the broad configurable Graph surface is unnecessary
  • Unsupervised access to sensitive mail, files, meetings, tenant data, or write operations
  • Older Unity projects or game-development tasks that do not require direct Editor control
Avoid when
  • You cannot use a dedicated Microsoft identity, narrow allowed scopes/tools, and review the permissions required for the selected Microsoft 365 workload
  • You need a fully reviewed universal tool contract or verified maintainer-transfer and rollback evidence before deployment
  • You cannot review or revert agent-made project and scene changes
Provenance
Provenance details

Community implementation

Softeria · Publisher source ↗

Community implementation

github:codergamester · Publisher source ↗

Maintenance
Maintenance details

Repo: Aug 24, 2026

Package: Aug 24, 2026

Repo: Aug 10, 2026

Package: Not documented

Popularity evidence
GitHub stars

958

GitHub stars · checked 2026-09-08

1,865

GitHub stars · checked 2026-08-14T18:46:26.000Z

Package downloads / 30 days

173,619

package downloads / 30 days · checked 2026-09-08

No reliable download data
External adoption evidence
  • GitHub: repository stars: 932Exact attributable signal.GitHub: repository stars · Admission snapshot · checked 2026-08-24T12:00:00.000ZEvidence source ↗
  • npm: package downloads: 171,749Exact attributable signal.npm: package downloads · Rolling 30 days · checked 2026-08-24T12:00:00.000ZEvidence source ↗
Not documented
Client coverage
Client coverage detailsNot documented
Claude CodeLocal stdio
Claude DesktopLocal stdio
CodexLocal stdio
VS CodeLocal stdio
CursorLocal stdio
OpenCodeLocal stdio
Client coverage noteLocal stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server.
Access and data
AuthenticationThe documented options include Device Code Flow for local stdio, OAuth Authorization Code Flow for HTTP, a caller-supplied MS365_MCP_OAUTH_TOKEN, and a custom Microsoft Entra application for organization or production deployment. Use a dedicated identity, restrict consented Graph scopes, remove the MCP entry and local credentials when access is no longer needed, and revoke Microsoft authorization or tokens through the applicable account or Entra controls.The WebSocket server defaults to localhost:8090. Remote instructions can bind it to 0.0.0.0; no bearer-token or OAuth mechanism is documented.
CostThe MIT-licensed npm package has no separate package purchase price documented. Access still depends on the Microsoft account, service access, licenses, tenant permissions, and admin consent required by the chosen workload; self-hosted HTTP deployments can also incur normal hosting, container, and secret-management costs.The publisher describes the MIT-licensed project as free and open source. Unity, Node.js, hosting, client, and model costs are separate.
PermissionsThe MCP can read and write Microsoft Graph resources including email, calendar, OneDrive files, SharePoint Sites and Lists, Teams/chats/meetings, contacts, users, OneNote, Planner, To Do, and Excel. Organization-mode SharePoint can request broad Sites.Read.All, Sites.ReadWrite.All, and Sites.Manage.All scopes; use --allowed-scopes, --enabled-tools, --read-only, and Sites.Selected where the documented operation supports them.Executes Unity menus and controls scenes, GameObjects, components, materials, assets, packages, tests, logs, play mode, and project-state resources through a WebSocket bridge.
Data handlingThe local MCP handles Microsoft Graph request and response data. Documented local MSAL token caching is encrypted, while the headless fallback still depends on directory access controls. The HTTP deployment documents stateless per-request bearer-token Graph requests. Structured audit logging is enabled for Graph-reaching tool calls and can include principals, tool names, outcomes, resource identifiers, and recipient counts or domains; response bodies are not recorded by that structured log, and separate operational logging can record tool parameters. Token and PII redaction is documented as configurable rather than an absolute data-boundary guarantee.Unity scenes, assets, project state, and console logs are read or modified locally and returned through MCP. Remote transmission, retention, and telemetry are not documented.
Limitations
Tradeoffs
  • Personal and organization modes provide broad Microsoft Graph coverage, but the exposed surface changes with org mode, presets, enabled tools, allowed scopes, authentication mode, and read-only settings.
  • Sites.Selected and tool/scope filtering can reduce direct SharePoint access, while tenant-wide SharePoint discovery requires broader scopes.
  • A pinned self-hosted npm install avoids a moving latest tag, but full maintainer-transfer and rollback evidence has not been verified.
  • Direct Editor integration speeds iteration, but setup spans a Unity package and Node server and automated changes may leave the project in an invalid state.
Risk contextThis broad Microsoft Graph MCP can expose sensitive business email, files, SharePoint content, Teams/chats/meetings, contacts, and tenant information, and it includes material write and delete operations. Destructive-operation confirmation is documented as off by default; default organization-mode SharePoint permissions can be broad, and HTTP Dynamic Client Registration is enabled by default unless disabled. Use read-only mode, presets/tool filtering, allowed scopes, Sites.Selected when applicable, dedicated identities, and explicit review before enabling writes or tenant-wide discovery. GHSA-9w34-3f56-vwmh affected versions through 0.136.0; reviewed version 0.146.1 is above the documented 0.137.0 fixed version. This patched advisory is not a general security certification.Can make destructive project changes, install packages, execute menu items, and control play mode. Keep the bridge loopback-only and supervise all writes and deletions in a version-controlled project.
Evidence date
Editorial review2026-08-24T12:00:00.000Z2026-08-11
Candidate evidence2026-08-24T12:00:00.000Z2026-08-14T18:46:26.000Z

Popularity, maintenance, fit, permissions, and client support are independent evidence fields.

Read the evidence method →